ISO/IEC 17021
ISO/IEC 17021 is a standard that sets the requirements for the organizations that audit and certify management systems, such as those certifying companies against ISO/IEC 27001. Rather than telling a company how to build its own management system, it governs the certification bodies themselves, helping ensure that certifications are issued consistently and competently. It works alongside accreditation, where an accreditation body assesses whether a certification body meets these requirements.
ISO/IEC 17021-1 specifies requirements for bodies providing audit and certification of management systems, establishing principles and criteria for the competence, consistency, and impartiality of such certification bodies. In the certification ecosystem, certification bodies implement ISO/IEC 17021-1 while accreditation bodies assess conformance to it, forming the basis on which management system certifications (for example, an ISMS certified against ISO/IEC 27001) can be recognized as credible. The 17021 family also includes technical specifications (the 17021-x series) that define competence requirements for personnel involved in auditing and certifying specific types of management systems, for instance, ISO/IEC TS 17021-13:2021 for compliance management systems and ISO/IEC TS 17021-15:2023 for management systems for quality in healthcare. Note that this standard governs the certification and accreditation infrastructure and is distinct from the management system requirements a certified organization must itself meet.
Why it matters
For organizations pursuing ISO/IEC 27001 certification, the credibility of the certificate depends heavily on the competence and impartiality of the certification body that issues it. ISO/IEC 17021-1 is the standard that governs those bodies, setting requirements for how they audit and certify management systems. Without a common baseline for the certifiers themselves, a certificate would carry little assurance, since there would be no consistent expectation of how audits are conducted or how impartiality is maintained. In this sense, 17021-1 underpins the trust that a relying party places in an ISO 27001 certificate.
The standard also clarifies an often-misunderstood division of roles in the certification ecosystem. Certification bodies implement ISO/IEC 17021-1, while accreditation bodies assess whether those certification bodies conform to it. This layered structure, accreditation of the certifier, certification of the organization, is what allows a management system certification to be recognized as credible beyond the two parties directly involved. GRC professionals evaluating whether an ISO 27001 certificate is meaningful typically look to whether the issuing certification body is accredited against this standard.
It is important to keep the boundary clear: ISO/IEC 17021-1 governs the certification and accreditation infrastructure, not the organization being certified. A company implementing an ISMS meets the requirements of ISO/IEC 27001 (clauses 4 through 10, with Annex A reference controls selected via a Statement of Applicability); it does not itself implement 17021-1. Conflating the two leads to confusion about who is accountable for what in a certification engagement.
Who it's relevant to
Inside ISO/IEC 17021
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 17021.