Skip to main content
Category: Certification and Accreditation

ISO/IEC 17021

Also known as: ISO/IEC 17021-1
Simply put

ISO/IEC 17021 is a standard that sets the requirements for the organizations that audit and certify management systems, such as those certifying companies against ISO/IEC 27001. Rather than telling a company how to build its own management system, it governs the certification bodies themselves, helping ensure that certifications are issued consistently and competently. It works alongside accreditation, where an accreditation body assesses whether a certification body meets these requirements.

Formal definition

ISO/IEC 17021-1 specifies requirements for bodies providing audit and certification of management systems, establishing principles and criteria for the competence, consistency, and impartiality of such certification bodies. In the certification ecosystem, certification bodies implement ISO/IEC 17021-1 while accreditation bodies assess conformance to it, forming the basis on which management system certifications (for example, an ISMS certified against ISO/IEC 27001) can be recognized as credible. The 17021 family also includes technical specifications (the 17021-x series) that define competence requirements for personnel involved in auditing and certifying specific types of management systems, for instance, ISO/IEC TS 17021-13:2021 for compliance management systems and ISO/IEC TS 17021-15:2023 for management systems for quality in healthcare. Note that this standard governs the certification and accreditation infrastructure and is distinct from the management system requirements a certified organization must itself meet.

Why it matters

For organizations pursuing ISO/IEC 27001 certification, the credibility of the certificate depends heavily on the competence and impartiality of the certification body that issues it. ISO/IEC 17021-1 is the standard that governs those bodies, setting requirements for how they audit and certify management systems. Without a common baseline for the certifiers themselves, a certificate would carry little assurance, since there would be no consistent expectation of how audits are conducted or how impartiality is maintained. In this sense, 17021-1 underpins the trust that a relying party places in an ISO 27001 certificate.

The standard also clarifies an often-misunderstood division of roles in the certification ecosystem. Certification bodies implement ISO/IEC 17021-1, while accreditation bodies assess whether those certification bodies conform to it. This layered structure, accreditation of the certifier, certification of the organization, is what allows a management system certification to be recognized as credible beyond the two parties directly involved. GRC professionals evaluating whether an ISO 27001 certificate is meaningful typically look to whether the issuing certification body is accredited against this standard.

It is important to keep the boundary clear: ISO/IEC 17021-1 governs the certification and accreditation infrastructure, not the organization being certified. A company implementing an ISMS meets the requirements of ISO/IEC 27001 (clauses 4 through 10, with Annex A reference controls selected via a Statement of Applicability); it does not itself implement 17021-1. Conflating the two leads to confusion about who is accountable for what in a certification engagement.

Who it's relevant to

GRC and compliance managers evaluating certification bodies
Professionals selecting or vetting a certification body for ISO 27001 benefit from understanding that 17021-1 defines the competence, consistency, and impartiality expected of that body. This helps them assess whether a prospective certifier is accredited against a recognized standard and, in turn, whether a resulting certificate will be viewed as credible by their own customers and stakeholders.
Auditors and personnel within certification bodies
Individuals working for bodies that audit and certify management systems are directly governed by 17021-1 and, where applicable, the relevant 17021-x technical specifications that set competence requirements for their specific sector, for example, compliance management systems or healthcare quality management systems. Understanding these requirements is central to how they conduct audits and maintain impartiality.
Security and compliance teams relying on ISO 27001 certificates
Teams that receive or evaluate ISO 27001 certificates from vendors or partners should recognize that the credibility of a certificate depends in part on the accreditation of the issuing body against 17021-1. It is worth remembering the distinction: 17021-1 governs the certifier, while ISO 27001 governs the organization's ISMS, and a certificate attests only to the defined scope of that management system.

Inside ISO/IEC 17021

Requirements for certification bodies
ISO/IEC 17021 sets out requirements for bodies providing audit and certification of management systems, including the competence, consistency, and impartiality expected of those bodies. It is the standard against which certification bodies themselves are assessed, rather than a standard organizations seeking certification implement directly.
Relationship to accreditation
Accreditation bodies typically use ISO/IEC 17021 (and its management-system-specific parts) to assess and accredit certification bodies. This is what underpins the credibility of an accredited ISO/IEC 27001 certificate, since the certifying body has been evaluated for its ability to conduct audits competently and impartially.
Impartiality and conflict-of-interest provisions
The standard addresses safeguards intended to protect the impartiality of certification decisions, such as separating consultancy activities from certification activities. These provisions help maintain confidence that a certification decision reflects an objective audit rather than a commercial relationship.
Auditor competence and audit process expectations
ISO/IEC 17021 covers expectations for auditor competence and for how management system audits are planned and conducted, contributing to consistency across certification bodies. The specific interpretation and application depend on the certification body and the management system standard being audited.
Distinction from ISO/IEC 27001
ISO/IEC 27001 is the management system standard an organization is certified against, whereas ISO/IEC 17021 governs the bodies that perform that certification. The two operate at different levels: one is implemented by the organization, the other constrains the certifier.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 17021.

Is ISO/IEC 17021 the standard my organization gets certified against?
No. ISO/IEC 17021 sets requirements for the bodies that provide audit and certification of management systems, not for the organizations being certified. Your organization is certified against a management system standard such as ISO/IEC 27001, while the certification body performing your audit is expected to operate in conformance with ISO/IEC 17021. In other words, ISO/IEC 17021 governs the auditor's side of the relationship rather than the auditee's.
Does ISO/IEC 17021 apply to SOC 2 examinations too?
No. ISO/IEC 17021 relates to certification bodies operating in the ISO management system world and is not part of the SOC 2 framework. A SOC 2 examination is an attestation engagement performed by a licensed CPA firm under the AICPA's SSAE 18 standard, resulting in a report rather than a certification. The accreditation and competence expectations for a CPA firm performing a SOC 2 engagement come from a different body of professional standards, so ISO/IEC 17021 should not be cited as governing SOC 2 work.
How does ISO/IEC 17021 relate to whether my certification body is accredited?
Accreditation typically involves an accreditation body assessing a certification body's conformance with the applicable requirements for management system certification, of which ISO/IEC 17021 is a central reference. When selecting a certification body for an ISO/IEC 27001 engagement, organizations often check that the body is accredited, since accreditation provides assurance that the body operates to recognized requirements. The specifics of how accreditation is granted and maintained vary by accreditation body and jurisdiction.
Why should I care about ISO/IEC 17021 when choosing a certification body?
The requirements addressed by ISO/IEC 17021, such as impartiality, competence, and consistency of the certification process, affect the credibility and recognition of the certificate you receive. In most cases, an ISO/IEC 27001 certificate issued by an accredited body carries broader recognition with customers and partners than one issued by an unaccredited body. Because recognition needs vary by market and stakeholder, it is worth confirming a body's accreditation status and scope before engaging it.
What does ISO/IEC 17021 mean for the impartiality of my audit?
Impartiality of the certification body is one of the core concerns addressed under ISO/IEC 17021. In practice this typically influences arrangements such as separating consulting from certification activities and managing conflicts of interest, so that the body issuing your certificate is not also the party that designed your ISMS. The exact controls a certification body applies to safeguard impartiality depend on the body and its accreditation, so ask how they handle these boundaries if consulting and certification are both under discussion.
Does a certification body operating under ISO/IEC 17021 guarantee my ISMS is secure?
No. A certification body's conformance with ISO/IEC 17021 concerns the integrity and competence of the certification process, not a guarantee of your organization's security outcomes. An ISO/IEC 27001 certificate covers only the defined scope of the ISMS and reflects conformance assessed at the time of audit and during surveillance; it does not certify freedom from breaches. Accreditation and a sound certification process add credibility to the certificate but do not extend its scope or eliminate residual risk.

Common misconceptions

Organizations seeking ISO/IEC 27001 certification must implement ISO/IEC 17021.
ISO/IEC 17021 applies to certification bodies, not to the organizations being certified. An organization pursuing ISO/IEC 27001 implements the ISMS requirements in clauses 4 through 10 and selects Annex A controls via a Statement of Applicability; it does not conform to ISO/IEC 17021 itself, though it benefits when its chosen certification body operates under that standard.
ISO/IEC 17021 is relevant to SOC 2 examinations.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certification. The certification-body accreditation model reflected in ISO/IEC 17021 does not govern SOC 2 engagements, which operate under a different professional framework.
Conformance with ISO/IEC 17021 by the certifier guarantees an organization's security or freedom from breaches.
ISO/IEC 17021 addresses the competence and impartiality of the certification body; it does not extend the scope of what a certificate covers. An ISO/IEC 27001 certificate covers only the defined scope of the ISMS, and no certification guarantees freedom from breaches.

Best practices

Confirm that your ISO/IEC 27001 certification body is accredited, since accreditation is typically based on the certification body's conformance with ISO/IEC 17021 and its management-system-specific parts.
Keep the roles clear internally: implement and maintain the ISMS against ISO/IEC 27001 clauses 4 through 10 with Annex A controls selected via your Statement of Applicability, and recognize that ISO/IEC 17021 constrains your certifier rather than your organization.
When selecting a certification body, review its impartiality safeguards, particularly any separation between consultancy and certification activities, as these provisions bear on the credibility of the resulting certificate.
Verify auditor competence expectations are met for your specific scope, understanding that interpretation and application typically vary by certification body and by the management system standard being audited.
Do not treat an accredited certificate as coverage beyond the defined ISMS scope; document precisely what is in scope and communicate that boundary to stakeholders who may otherwise assume broader assurance.
Avoid conflating framework levels when communicating with auditors or clients: distinguish ISO/IEC 27001 (the standard you are certified against) from ISO/IEC 17021 (governing the certifier), and from SOC 2, which is a CPA attestation report under a separate framework.