Skip to main content
Category: Certification and Accreditation

IAF CertSearch

Also known as: IAF Certification Database, iafcertsearch.org
Simply put

IAF CertSearch is an online database that lets users search for and confirm the status of accredited certifications issued by certification bodies around the world. It helps organizations verify that a supplier's or partner's certificate is genuine and currently valid rather than relying solely on a copy of a certificate. Because it covers accredited certifications from many economies, it is often used to check certifications across global supply chains.

Formal definition

IAF CertSearch is a global online database used to search and validate the status of accredited certifications issued by accredited certification bodies, where 'certification' refers to third-party attestation related to products, processes, systems, or persons as defined by ISO/IEC 17000. In the SOC 2 and ISO 27001 context, it is relevant primarily for validating ISO management system certifications (such as ISO/IEC 27001), since those outcomes are accredited certifications; it does not apply to SOC 2 examinations, which are attestation reports issued by a licensed CPA firm rather than accredited certifications. The database allows verification and ongoing monitoring of certification status (for example, whether a certificate is valid, suspended, or withdrawn), supporting supply-chain assurance. Verification results reflect only the certifications and status information submitted to the database by participating certification bodies and are subject to the accuracy and timeliness of that data; entitlement to free versus paid access can vary by verification volume and feature set, so specific access terms should be confirmed against current service documentation.

Why it matters

For organizations relying on ISO management system certifications from suppliers and partners, a paper or PDF copy of a certificate is easy to alter and hard to verify independently. IAF CertSearch matters because it provides a way to confirm that an accredited certification, such as ISO/IEC 27001, is genuine and currently valid rather than expired, suspended, or withdrawn. This is particularly valuable in due diligence and vendor risk workflows, where relying solely on a certificate copy provided by the vendor introduces the risk of accepting a document that no longer reflects the certificate's actual status.

Because the database aggregates accredited certifications across many economies, it supports supply-chain assurance at scale. A compliance or procurement team assessing multiple vendors can check certification status against a single source rather than contacting each certification body individually. The 'Certified Once, Accepted Everywhere' principle underpins this: an accredited certificate verified in one economy can be recognized in others, which streamlines cross-border vendor assessments.

It is important to keep the scope of this tool clear. IAF CertSearch applies to accredited certifications, which include ISO/IEC 27001 and other ISO management system standards, but it does not apply to SOC 2 examinations. A SOC 2 outcome is an attestation report issued by a licensed CPA firm, not an accredited certification, so it would not appear in this database and must be verified through other means, typically by reviewing the report itself.

Who it's relevant to

GRC and Compliance Managers
Teams responsible for vendor and third-party risk can use IAF CertSearch to independently confirm that a supplier's ISO/IEC 27001 certificate is genuine and currently valid, rather than accepting a certificate copy at face value. This supports more reliable due diligence during onboarding and periodic reassessment.
Procurement and Supply-Chain Teams
Because the database covers accredited certifications across many economies, procurement teams evaluating global suppliers can verify certification status from a single source and monitor it over time using features such as watchlists, rather than contacting each certification body individually.
Auditors and Assessors
Assessors validating an organization's or its vendors' accredited certifications can use the tool to check current status, keeping in mind that it covers accredited certifications such as ISO/IEC 27001 and not SOC 2 examinations, which are attestation reports issued by a licensed CPA firm and must be verified separately.
Organizations Holding ISO/IEC 27001 Certification
Certified organizations may find their own certificate listed in the database and can use it to demonstrate valid, verifiable certification status to customers and partners, reducing back-and-forth requests for certificate copies during others' due diligence.

Inside IAF CertSearch

Global Accreditation Database
IAF CertSearch is a global online database of accredited certifications, allowing users to verify whether a certification (such as an ISO 27001 certificate) is genuine and issued under accredited status. Ownership of the database was transferred to Global Accreditation Cooperation Inc. (Global ACI) following a 2025 General Assembly resolution, in connection with the wind-down of the International Accreditation Forum, which ceased operations on 1 January 2026.
Certification Verification Function
The platform enables verification of an organization's certification by drawing on data uploaded by participating accreditation bodies and certification bodies. For an ISO 27001 certificate, this typically helps confirm the certificate's validity, the issuing certification body, and its accredited status.
Access Tiers
Verification access is offered on tiered terms: low-volume verification is available at no cost, while higher-volume verification and API-based access are offered under paid plans. The specific limits and pricing depend on the plan selected and may vary over time.
Scope and Certificate Details
Where data has been provided, a record can include the certified organization, the applicable standard, the certification body, and the defined scope of certification. For ISO 27001, the certificate covers only the defined scope of the ISMS as recorded, not the entire organization by default.

Common questions

Answers to the questions practitioners most commonly ask about IAF CertSearch.

Is IAF CertSearch still maintained by the International Accreditation Forum?
Not in its original form. The database was historically operated under the International Accreditation Forum (IAF), but ownership arrangements have changed. Following governance changes, responsibility for the database transitioned to a successor organization. When citing who maintains the database, verify the current operating body directly, since the custodian and its policies may vary over time and administrative changes affect where authoritative confirmation should be sought.
Is IAF CertSearch completely free to use?
Not entirely. Basic, low-volume certificate verification is typically available at no cost, but the service is not free without limits. Higher-volume verification, bulk lookups, and API-based access are generally offered through paid plans. Organizations planning to integrate verification into automated vendor-management workflows should confirm the current plan tiers and volume thresholds directly, since these terms depend on the provider's offering and may change.
Can I use IAF CertSearch to verify a SOC 2 report?
No. IAF CertSearch covers accredited certifications issued against management system standards, such as ISO/IEC 27001, and does not cover SOC 2. A SOC 2 outcome is an attestation report produced by a licensed CPA firm under the AICPA's SSAE 18 standard, not an accredited certification, so it would not appear in this database. To validate a SOC 2 report, you would typically request the report directly from the service organization or its auditor rather than searching a certification registry.
How do I confirm that a vendor's ISO 27001 certificate is genuine using IAF CertSearch?
In most cases you can search by the organization name, certificate number, or certification body to locate a corresponding entry. A valid entry typically indicates that the certificate was issued by a certification body operating under an accredited scheme. Confirm that the details displayed, such as certified organization, certification body, and status, match the certificate the vendor provided. Be aware that results depend on whether the certification body uploads its data to the database, so an absent record does not necessarily mean a certificate is invalid.
What should I do if a vendor's ISO 27001 certificate does not appear in IAF CertSearch?
A missing record is not conclusive proof of an invalid certificate, because participation in the database depends on the certification body populating it. In such situations, you can typically verify directly with the issuing certification body or the relevant accreditation body. It is also worth confirming the certificate is issued under an accredited scheme, since unaccredited certifications carry less assurance. Treat verification as one input among several in your vendor due-diligence process.
Does a valid IAF CertSearch entry tell me what a vendor's ISO 27001 certificate actually covers?
Only partially. A database entry confirms the existence and status of a certification but does not, on its own, convey the full scope of the certified Information Security Management System (ISMS). The ISO 27001 certificate covers only the defined ISMS scope, and the controls applied are selected via the Statement of Applicability informed by risk assessment. To understand what is included, review the certificate's stated scope and, where appropriate, request the Statement of Applicability rather than relying solely on the registry entry.

Common misconceptions

IAF CertSearch is maintained by the International Accreditation Forum.
The International Accreditation Forum ceased operations on 1 January 2026, and a 2025 General Assembly resolution approved the transfer of ownership of IAF CertSearch to Global Accreditation Cooperation Inc. (Global ACI). References to the IAF as the current maintainer are out of date.
IAF CertSearch is a fully free online database for all uses.
Only low-volume verification is available at no cost. Higher-volume verification and API access are offered under paid plans, so treating the service as universally free is inaccurate.
A record in IAF CertSearch guarantees an organization's overall security posture.
The database helps confirm the validity and accredited status of a certification within its recorded scope. For ISO 27001, the certificate covers only the defined ISMS scope and does not, in itself, guarantee freedom from breaches or address controls outside that scope. It is also not a substitute for reviewing a SOC 2 report, which is a separate CPA attestation, not a certification.

Best practices

When verifying an ISO 27001 certificate, use IAF CertSearch to confirm the certificate's validity and accredited status rather than relying solely on a PDF supplied by the certified organization.
Confirm the current ownership and operating entity of the database before citing it, noting that ownership transferred to Global Accreditation Cooperation Inc. (Global ACI) following the wind-down of the International Accreditation Forum.
Review the recorded scope of certification, since an ISO 27001 certificate covers only the defined scope of the ISMS and may not extend to all systems or business units you rely on.
Select an access tier that matches your verification volume, recognizing that low-volume checks are free while higher-volume or API-based verification requires a paid plan.
Do not treat a verified ISO 27001 certificate as equivalent to a SOC 2 report; the two frameworks map only partially, and a certification confirmed in IAF CertSearch does not substitute for a CPA-issued SOC 2 attestation.
Cross-check any discrepancies directly with the issuing certification body, since database records depend on data uploaded by participating accreditation and certification bodies and may lag or omit certain details.