ISO/IEC 17065
ISO/IEC 17065 is an international standard that sets out the requirements a certification body must meet in order to certify products, processes, and services. It defines how such bodies should operate so that their certifications are competent, consistent, and impartial. It focuses on the certification bodies themselves rather than on the products being certified.
ISO/IEC 17065:2012, titled 'Conformity assessment, Requirements for bodies certifying products, processes and services,' is an International Standard (Edition 1, published 2012) specifying requirements for the competence, consistent operation, and impartiality of bodies that certify products, processes, and services. It can be used as a criteria document for accreditation, peer assessment, or designation by governmental authorities and scheme owners. Practitioners should note it addresses product/process/service certification bodies and is distinct from management system standards such as ISO/IEC 27001; a revised edition was progressing through the ISO development process (an FDIS stage was noted in the evidence), so the applicable edition should be confirmed when citing specific requirements.
Why it matters
ISO/IEC 17065 matters because it governs the credibility of the organizations that issue product, process, and service certifications. When a certification body operates against a recognized standard for competence, consistent operation, and impartiality, the certifications it issues carry weight with regulators, scheme owners, and buyers. Without such a baseline, a certificate would mean only what the issuing body chose it to mean, which would undermine trust across markets that rely on independent conformity assessment.
For GRC professionals, the significance is largely indirect but important to understand. ISO/IEC 17065 sits in the accreditation and conformity assessment layer of the standards ecosystem, addressing how certification bodies themselves must be structured and operate rather than the specific requirements a product or service must meet. According to the evidence, the standard can be used as a criteria document for accreditation, peer assessment, or designation by governmental authorities and scheme owners, which is what allows a certificate to be recognized as trustworthy beyond the relationship between the body and its client.
It is worth noting the boundaries of this standard to avoid confusion in a security compliance context. ISO/IEC 17065 addresses bodies that certify products, processes, and services and is distinct from management system standards such as ISO/IEC 27001. It is also separate from the requirements applying to bodies that certify management systems. As a result, ISO/IEC 17065 does not itself establish that any particular product is secure; it establishes conditions under which the body issuing a certification is expected to be competent and impartial.
Who it's relevant to
Inside ISO/IEC 17065
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 17065.