Skip to main content
Category: Certification and Accreditation

ANSI National Accreditation Board

Also known as: ANAB, ANSI National Accreditation Board
Simply put

The ANSI National Accreditation Board (ANAB) is a non-governmental organization that provides accreditation services to public- and private-sector organizations. It is a wholly owned subsidiary of the American National Standards Institute (ANSI), a non-profit organization, and offers its services in over 75 countries.

Formal definition

ANAB is an accreditation body operating as a wholly owned subsidiary of the American National Standards Institute (ANSI). It provides accreditation services to public- and private-sector organizations across more than 75 countries and is described as the largest accreditation body in North America. In the compliance context, accreditation bodies such as ANAB assess and recognize the competence of certification bodies, laboratories, and similar organizations; note that ANAB itself accredits such bodies rather than issuing certifications to end organizations directly, and the specific scope of any accreditation depends on the program and standard involved.

Why it matters

In the ISO/IEC 27001 ecosystem, trust flows through a chain: an organization earns certification from a certification body, and that certification body is itself accredited by an accreditation body such as ANAB. This layered structure matters because it provides assurance that the certification body performing your audit is itself competent and operating to recognized requirements. When a certificate is issued under an accredited program, stakeholders can place greater confidence in its meaning than they could in an unaccredited or self-declared certification.

Who it's relevant to

Compliance and GRC Managers
When selecting a certification body for an ISO/IEC 27001 engagement, or when evaluating a vendor's certificate, understanding that a certification body may itself be accredited by an organization such as ANAB helps you judge the independent oversight behind a certificate. Remember that accreditation applies to the certification body's competence, not to a guarantee about any specific organization's security, and that the scope of accreditation depends on the program involved.
Certification Bodies
Organizations that audit and issue ISO/IEC 27001 certificates rely on accreditation bodies like ANAB to assess and recognize their competence. Accreditation is the mechanism through which a certification body demonstrates it operates to recognized requirements, which in turn supports the credibility of the certificates it issues.
Vendor Risk and Procurement Teams
Teams reviewing supplier assurance documentation benefit from knowing where accreditation fits in the trust chain. A certificate issued by an accredited certification body carries the added weight of independent recognition of that body's competence, though this should be treated as one input into a broader assessment rather than a standalone assurance of a supplier's security posture.
Auditors and Security Engineers
Professionals working alongside certification and attestation processes should understand the distinction between accreditation (recognition of a body's competence) and certification (issued to an end organization). ANAB accredits certification bodies and laboratories rather than issuing certifications directly, a distinction that clarifies how assurance is layered across the compliance ecosystem.

Inside ANAB

Accreditation body role
ANAB is an accreditation body that assesses and accredits certification bodies (also called registrars), rather than issuing management system certificates directly to organizations. It provides oversight that certification bodies operate competently and impartially.
Certification body oversight
ANAB evaluates whether certification bodies performing ISO/IEC 27001 audits meet applicable accreditation requirements. An ISO 27001 certificate typically carries more weight when issued by a body accredited by a recognized accreditation body such as ANAB.
Relationship to ISO 27001 certification
ISO/IEC 27001 is a certification issued by an accredited certification body against the ISMS requirements in clauses 4 through 10. ANAB sits above that process as the accreditor of the certification body, not as the certifier of the end organization's ISMS.
Scope of accreditation
Accreditation applies to the certification bodies and the specific standards or schemes for which they are accredited. It does not extend to guaranteeing the outcome of any individual organization's certification, which depends on the defined ISMS scope and the certification body's assessment.

Common questions

Answers to the questions practitioners most commonly ask about ANAB.

Does ANAB certify my organization's ISO 27001 ISMS directly?
No. ANAB does not audit or certify organizations against ISO/IEC 27001. It is an accreditation body that assesses and accredits the certification bodies that, in turn, issue ISO 27001 certificates. Your organization engages an accredited certification body for the actual certification; ANAB's role is to provide oversight of that body's competence and impartiality.
Is ANAB involved in issuing or overseeing SOC 2 reports?
No. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 standard, and the resulting SOC 2 report is not a certification issued through an accreditation chain. ANAB's accreditation activity relates to certification bodies operating under management system standards such as ISO 27001, not to CPA firms performing SOC 2 examinations.
How do I confirm that a certification body offering ISO 27001 certification is ANAB-accredited?
Accreditation bodies typically maintain a public directory of the certification bodies they accredit, along with the scopes for which each is accredited. When selecting a certification body, you can verify that its accreditation covers ISO 27001 and, depending on scope, confirm the accreditation mark it is authorized to display. Terms and available details vary, so confirm directly with the accreditation body and the certification body.
Why should I prefer an accredited certification body over a non-accredited one for ISO 27001?
In most engagements, an accredited certification body's certificate carries broader recognition because the accreditation provides independent oversight of the body's competence, impartiality, and audit process. Depending on your stakeholders' requirements, a certificate from an accredited body may be expected or preferred, though the specific expectations vary by customer, sector, and region.
Does an ANAB-accredited certification body's involvement guarantee my ISMS is secure?
No. Accreditation supports confidence in the certification body's competence and process, and an ISO 27001 certificate attests that the ISMS meets the standard's requirements within a defined scope at the time of assessment. It does not guarantee freedom from security incidents, nor does it extend to activities or systems outside the defined scope of the ISMS.
How does the accreditation relationship affect ongoing surveillance and recertification?
Certification bodies typically operate within a certification cycle that includes periodic surveillance audits and recertification, and their adherence to these processes is subject to the oversight of their accreditation body. The specific cycle, timing, and surveillance frequency are set by the certification body in line with applicable requirements and can vary, so confirm the schedule directly with your chosen body.

Common misconceptions

ANAB certifies organizations to ISO 27001.
ANAB accredits certification bodies; it does not itself issue ISO/IEC 27001 certificates to organizations. The certificate is issued by an accredited certification body that has been assessed against accreditation requirements, and it covers only the defined scope of the ISMS.
An ANAB-accredited certification body is relevant to SOC 2 reports.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certification. Accreditation bodies such as ANAB relate to certification schemes like ISO/IEC 27001 and are not part of the SOC 2 attestation model.
Accreditation guarantees an organization is free from security incidents.
Accreditation supports confidence in the competence and impartiality of the certification body, but an ISO 27001 certificate attests only to the defined scope of the ISMS at the time of assessment. It does not guarantee freedom from breaches, and accreditation does not change that limitation.

Best practices

Verify that the certification body issuing an ISO/IEC 27001 certificate is accredited by a recognized accreditation body such as ANAB, as this typically lends greater credibility to the certificate.
Distinguish accreditation of the certification body from certification of your organization's ISMS, and communicate this distinction clearly to stakeholders who may confuse the two.
Confirm the specific scope for which a certification body is accredited to ensure it covers ISO/IEC 27001 and matches the scope you intend to certify.
When reviewing a supplier's ISO 27001 certificate, check both the certification body's accreditation status and the defined ISMS scope stated on the certificate, since coverage is limited to that scope.
Do not treat an accredited ISO 27001 certificate as interchangeable with a SOC 2 report; the two follow different models, and satisfying one does not automatically satisfy the other.
Document how accreditation and certification fit into your vendor assurance or GRC processes so that audit and procurement decisions rely on the correct evidence for each framework.