Skip to main content
Category: Certification and Accreditation

ISO/IEC 17021-1

Also known as: ISO/IEC 17021-1 Conformity Assessment Standard
Simply put

ISO/IEC 17021-1 is a standard that sets out the requirements for organizations that audit and certify management systems, such as the certification bodies that issue ISO/IEC 27001 certificates. It defines what these certification bodies must do to operate competently and impartially, which in turn supports confidence in the certificates they issue. It does not set requirements for the management systems being certified themselves, but for the bodies performing the certification.

Formal definition

ISO/IEC 17021-1 specifies requirements for bodies providing audit and certification of management systems. It functions as an accreditation-facing conformity assessment standard: accreditation bodies assess certification bodies against its requirements, and certification bodies implement its requirements to structure their audit and certification processes. In the ISO 27001 context, an accredited certification body operating under ISO/IEC 17021-1 (typically together with applicable sector-specific requirements) is what enables an accredited ISMS certification to be issued. Note that ISO/IEC 17021-1 governs the certification body, not the certifiable ISMS requirements found in ISO/IEC 27001 clauses 4 through 10; competence requirements for audit and certification personnel are addressed in related documents in the ISO/IEC 17021 family (for example ISO/IEC TS 17021-15). This standard is distinct from SOC 2, which is a CPA-performed attestation examination under AICPA SSAE 18 rather than an accredited certification, and the details of accreditation arrangements can vary by accreditation body and scope.

Why it matters

When an organization pursues ISO/IEC 27001 certification, the value of the resulting certificate depends heavily on the credibility of the body that issued it. ISO/IEC 17021-1 is the standard that establishes what a certification body must do to operate competently and impartially. Without a common, accreditation-facing baseline governing certification bodies, ISMS certificates would carry inconsistent weight, and the assurance they are meant to convey to customers, regulators, and partners would be difficult to trust.

Who it's relevant to

Compliance and GRC managers pursuing ISO 27001
For teams seeking an ISO/IEC 27001 certificate, ISO/IEC 17021-1 explains why selecting an accredited certification body matters: the accreditation reflects that the body has been assessed against this standard. This helps distinguish an accredited ISMS certification from other, non-accredited attestations of conformity.
Certification bodies
Certification bodies must implement the requirements of ISO/IEC 17021-1 to structure their audit and certification processes and to demonstrate competence and impartiality. Their ongoing accreditation depends on being assessed against these requirements by an accreditation body.
Accreditation bodies
Accreditation bodies use ISO/IEC 17021-1 as the benchmark against which they assess certification bodies. The standard defines the requirements they evaluate when granting or maintaining accreditation for management system certification activities.
Auditors and certification personnel
Individuals involved in the audit and certification process operate within the framework this standard sets for their certification body. Competence requirements for such personnel are addressed in related documents in the ISO/IEC 17021 family, such as ISO/IEC TS 17021-15.

Inside ISO/IEC 17021-1

Conformity assessment requirements for certification bodies
ISO/IEC 17021-1 sets out requirements for bodies providing audit and certification of management systems, establishing the competence, consistency, and impartiality expected of organizations that issue certifications such as ISO/IEC 27001.
Impartiality and independence provisions
The standard addresses safeguards to manage conflicts of interest, requiring certification bodies to maintain independence from the organizations they audit so that certification decisions are not compromised.
Competence requirements for auditors and personnel
It defines expectations for the competence of audit teams and other personnel involved in the certification process, supporting reliable and consistent certification outcomes.
The certification audit process
The standard describes the structure of the certification lifecycle, which typically includes an initial certification audit followed by surveillance activities and periodic recertification, though specific arrangements depend on the certification body and scheme.
Basis for accreditation of certification bodies
ISO/IEC 17021-1 provides the criteria against which certification bodies are commonly assessed for accreditation, underpinning the credibility of certificates such as those issued for an ISO/IEC 27001 ISMS.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 17021-1.

Does ISO/IEC 17021-1 apply to my organization when we pursue ISO 27001 certification?
Not directly. ISO/IEC 17021-1 sets requirements for the certification bodies that audit and certify management systems, not for the organizations seeking certification. Your organization is assessed against ISO/IEC 27001 itself; ISO/IEC 17021-1 governs the competence, consistency, and impartiality of the certification body performing that assessment. In practice, it operates in the background as a quality benchmark for the auditing body rather than as a standard you implement internally.
Is ISO/IEC 17021-1 something an organization can be certified against?
No. ISO/IEC 17021-1 is a conformity assessment standard used to accredit and evaluate certification bodies, so an organization does not obtain certification against it. Instead, an accreditation body assesses whether a certification body conforms to ISO/IEC 17021-1. This is distinct from your organization being certified against ISO/IEC 27001 by that certification body. The chain typically runs accreditation body to certification body to certified organization.
How does ISO/IEC 17021-1 affect how our certification body conducts our ISO 27001 audit?
ISO/IEC 17021-1 informs requirements the certification body must meet regarding auditor competence, impartiality, and the structure of the audit process, which typically includes a two-stage initial certification, followed by surveillance and recertification activities over the certification cycle. In most engagements, this is why you experience a documented audit approach with defined stages rather than an ad hoc review. The specific execution still depends on your ISMS scope and the certification body's procedures.
Why should we choose a certification body whose accreditation reflects ISO/IEC 17021-1?
Selecting a certification body operating under accreditation aligned to ISO/IEC 17021-1 helps provide assurance that the body meets recognized requirements for impartiality and competence, which can affect how widely your ISO 27001 certificate is recognized by customers and partners. Accredited certification is generally regarded as more credible than unaccredited certification, though recognition ultimately depends on the accreditation body and the expectations of your stakeholders.
Does ISO/IEC 17021-1 mean the same audit rules apply regardless of which management system we certify?
ISO/IEC 17021-1 provides the common requirements applicable to bodies certifying management systems generally, but discipline-specific requirements can supplement it for particular schemes. For information security management systems, additional requirements specific to ISO/IEC 27001 certification typically apply alongside ISO/IEC 17021-1. The precise combination depends on the certification scheme and the accreditation under which the body operates, so confirm the applicable requirements with your certification body.
Can our internal team use ISO/IEC 17021-1 to prepare for an ISO 27001 audit?
It offers limited direct value for internal preparation, since it is aimed at certification bodies rather than at organizations implementing an ISMS. For preparation, your team would typically focus on the ISO/IEC 27001 requirements in clauses 4 through 10 and the Annex A reference controls selected through your Statement of Applicability. Understanding ISO/IEC 17021-1 can, however, help you anticipate how a certification body structures its audit stages and applies impartiality and competence expectations.

Common misconceptions

ISO/IEC 17021-1 is the standard that organizations get certified against for information security.
ISO/IEC 17021-1 applies to the certification bodies that perform audits and issue certifications, not to the organizations seeking certification. Organizations are certified against a management system standard such as ISO/IEC 27001, which contains the ISMS requirements in clauses 4 through 10 and the Annex A reference controls.
ISO/IEC 17021-1 is relevant to SOC 2 examinations.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report, not a certification. ISO/IEC 17021-1 governs certification bodies operating within the ISO certification model and does not apply to SOC 2 engagements.
Any firm can issue an ISO 27001 certificate as long as it follows a standard audit process.
Credible ISO/IEC 27001 certificates are typically issued by certification bodies whose conformity to ISO/IEC 17021-1 supports their accreditation. This distinguishes an accredited certification from a report or attestation such as those produced under SOC 2.

Best practices

When selecting a certification body for ISO/IEC 27001, verify that it is accredited, since accreditation is commonly based on conformity with ISO/IEC 17021-1.
Confirm the defined scope of the ISMS before certification, recognizing that an ISO/IEC 27001 certificate covers only the scope stated and not the entire organization by default.
Distinguish clearly in internal and client communications between an ISO/IEC 27001 certification issued by an accredited body and a SOC 2 report produced by a CPA firm, as these are different outcomes under different frameworks.
Plan for the ongoing certification lifecycle, which typically includes surveillance and recertification activities, rather than treating certification as a one-time event.
Do not assume that a certification body's involvement guarantees freedom from breaches; certification and reports address defined controls and scope and have inherent limitations.
Where mapping ISO/IEC 27001 certification alongside SOC 2 or other standards, treat any correspondence as partial, since satisfying one framework does not automatically satisfy another.