ISO/IEC 17021-1
ISO/IEC 17021-1 is a standard that sets out the requirements for organizations that audit and certify management systems, such as the certification bodies that issue ISO/IEC 27001 certificates. It defines what these certification bodies must do to operate competently and impartially, which in turn supports confidence in the certificates they issue. It does not set requirements for the management systems being certified themselves, but for the bodies performing the certification.
ISO/IEC 17021-1 specifies requirements for bodies providing audit and certification of management systems. It functions as an accreditation-facing conformity assessment standard: accreditation bodies assess certification bodies against its requirements, and certification bodies implement its requirements to structure their audit and certification processes. In the ISO 27001 context, an accredited certification body operating under ISO/IEC 17021-1 (typically together with applicable sector-specific requirements) is what enables an accredited ISMS certification to be issued. Note that ISO/IEC 17021-1 governs the certification body, not the certifiable ISMS requirements found in ISO/IEC 27001 clauses 4 through 10; competence requirements for audit and certification personnel are addressed in related documents in the ISO/IEC 17021 family (for example ISO/IEC TS 17021-15). This standard is distinct from SOC 2, which is a CPA-performed attestation examination under AICPA SSAE 18 rather than an accredited certification, and the details of accreditation arrangements can vary by accreditation body and scope.
Why it matters
When an organization pursues ISO/IEC 27001 certification, the value of the resulting certificate depends heavily on the credibility of the body that issued it. ISO/IEC 17021-1 is the standard that establishes what a certification body must do to operate competently and impartially. Without a common, accreditation-facing baseline governing certification bodies, ISMS certificates would carry inconsistent weight, and the assurance they are meant to convey to customers, regulators, and partners would be difficult to trust.
Who it's relevant to
Inside ISO/IEC 17021-1
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 17021-1.