Skip to main content
Category: Certification and Accreditation

ISO/IEC 17065

Also known as: ISO/IEC 17065:2012, ISO/IEC 17065 Product Certification Standard
Simply put

ISO/IEC 17065 is an international standard that sets out the requirements a certification body must meet in order to certify products, processes, and services. It defines how such bodies should operate so that their certifications are competent, consistent, and impartial. It focuses on the certification bodies themselves rather than on the products being certified.

Formal definition

ISO/IEC 17065:2012, titled 'Conformity assessment, Requirements for bodies certifying products, processes and services,' is an International Standard (Edition 1, published 2012) specifying requirements for the competence, consistent operation, and impartiality of bodies that certify products, processes, and services. It can be used as a criteria document for accreditation, peer assessment, or designation by governmental authorities and scheme owners. Practitioners should note it addresses product/process/service certification bodies and is distinct from management system standards such as ISO/IEC 27001; a revised edition was progressing through the ISO development process (an FDIS stage was noted in the evidence), so the applicable edition should be confirmed when citing specific requirements.

Why it matters

ISO/IEC 17065 matters because it governs the credibility of the organizations that issue product, process, and service certifications. When a certification body operates against a recognized standard for competence, consistent operation, and impartiality, the certifications it issues carry weight with regulators, scheme owners, and buyers. Without such a baseline, a certificate would mean only what the issuing body chose it to mean, which would undermine trust across markets that rely on independent conformity assessment.

For GRC professionals, the significance is largely indirect but important to understand. ISO/IEC 17065 sits in the accreditation and conformity assessment layer of the standards ecosystem, addressing how certification bodies themselves must be structured and operate rather than the specific requirements a product or service must meet. According to the evidence, the standard can be used as a criteria document for accreditation, peer assessment, or designation by governmental authorities and scheme owners, which is what allows a certificate to be recognized as trustworthy beyond the relationship between the body and its client.

It is worth noting the boundaries of this standard to avoid confusion in a security compliance context. ISO/IEC 17065 addresses bodies that certify products, processes, and services and is distinct from management system standards such as ISO/IEC 27001. It is also separate from the requirements applying to bodies that certify management systems. As a result, ISO/IEC 17065 does not itself establish that any particular product is secure; it establishes conditions under which the body issuing a certification is expected to be competent and impartial.

Who it's relevant to

Certification bodies
Organizations that certify products, processes, or services are the direct audience for ISO/IEC 17065, since the standard specifies the requirements they must meet for competence, consistent operation, and impartiality. Bodies seeking accreditation, peer assessment, or governmental designation typically need to demonstrate conformity with these requirements.
Accreditation bodies and scheme owners
The evidence indicates the standard can be used as a criteria document for accreditation, peer assessment, or designation. Accreditation bodies and scheme owners therefore use ISO/IEC 17065 as the benchmark for evaluating and recognizing the certification bodies operating within their schemes.
Governmental authorities
Governmental authorities may rely on ISO/IEC 17065 when designating or recognizing certification bodies, as noted in the evidence. This makes the standard relevant to those responsible for establishing which bodies are authorized to issue certifications in a given regulatory or market context.
GRC and compliance professionals
For compliance managers and auditors working primarily with SOC 2 and ISO/IEC 27001, ISO/IEC 17065 is relevant contextually. It helps clarify the distinction between product/process/service certification bodies and management system standards, and reinforces that the trustworthiness of a certification depends in part on how the issuing body is accredited and governed. Because it is distinct from ISO/IEC 27001, satisfying one does not imply satisfying the other.

Inside ISO/IEC 17065

Product, Process, and Service Certification Scope
ISO/IEC 17065 sets requirements for bodies that certify products, processes, and services. This distinguishes it from ISO/IEC 17021-1, which governs bodies certifying management systems such as ISO 27001. Because of this difference in scope, ISO/IEC 17065 is not typically the accreditation basis for an ISO 27001 certification body.
Impartiality and Independence Requirements
The standard establishes requirements intended to safeguard the impartiality of the certification body, including managing conflicts of interest between certification activities and other services offered. The specific arrangements depend on the certification body and the accreditation arrangements in place.
Competence of Personnel
It addresses the competence, evaluation, and management of personnel involved in certification decisions, so that certification outcomes are based on qualified assessment rather than subjective judgment. The exact competence criteria vary by certification scheme.
Certification Process Structure
The standard describes the elements of a certification process, such as application, evaluation, review, and the certification decision. The detailed steps depend on the particular certification scheme being operated under the standard.
Relationship to Accreditation
Certification bodies operating under ISO/IEC 17065 are typically accredited by a recognized accreditation body that assesses conformity to the standard. This creates a chain of oversight, though the specific accreditation body and arrangements vary by jurisdiction and scheme.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 17065.

Is ISO/IEC 17065 the standard my organization gets certified against for information security?
No. ISO/IEC 17065 is not the standard an organization implements or is certified against for its management system. It is a conformity assessment standard that sets requirements for the bodies that certify products, processes, and services. For information security management system certification, the certifiable standard is ISO/IEC 27001, and organizations are certified by an accredited certification body. ISO/IEC 17065 operates at a different level in the certification ecosystem: it governs certain certification bodies rather than the organizations seeking certification.
Does an ISO/IEC 17065 accreditation of a certification body mean my certificate is more credible than a SOC 2 report?
Accreditation and attestation are different mechanisms, so they should not be ranked against one another as if they were interchangeable. ISO/IEC 17065 relates to the accreditation and competence of certain certification bodies, which supports confidence in the certifications those bodies issue. A SOC 2 report, by contrast, is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report rather than a certificate. The credibility of each depends on its own governing framework, scope, and the assurance it is designed to provide, not on a direct comparison between the two.
How do I confirm that a certification body is operating under ISO/IEC 17065?
Confirmation is typically obtained by checking the accreditation status of the certification body, which is usually documented by the relevant accreditation authority and reflected on the certificate or accompanying documentation. Because the applicable accreditation standard depends on what is being certified, verify that the standard cited matches the type of certification in question. When the goal is information security management system certification, confirm which standard the certification body is accredited under for that specific scheme, as this can vary by body and by the type of certification offered.
What should I look for in the scope statement when engaging a certification body?
Review the scope statement to confirm that it covers the specific service, process, or product certification you require, and that it aligns with the boundaries of your intended engagement. Scope determines what the certification actually covers, so any certificate speaks only to the defined scope and not to the organization as a whole. Depending on the arrangement, clarify how the scope is described, what is excluded, and how the certification body defines the assessed subject matter before proceeding.
Where does ISO/IEC 17065 fit relative to the other standards I encounter, such as ISO/IEC 27001 and SOC 2?
It helps to separate the layers. ISO/IEC 27001 is the certifiable management system standard an organization implements, with requirements in clauses 4 through 10 and reference controls in Annex A selected via a Statement of Applicability. SOC 2 is a separate attestation examination under AICPA SSAE 18 that results in a report addressing the Trust Services Criteria. Conformity assessment standards such as ISO/IEC 17065 sit at the level of the bodies performing certain certifications. Keeping these layers distinct helps avoid conflating the organization being assessed, the framework it is assessed against, and the requirements placed on the assessing body.
Does relying on an accredited certification body remove the need for our own due diligence?
No. Accreditation of a certification body supports confidence in the certifications issued, but it does not replace your own due diligence over scope, applicability, and the specific assurance you need. In most engagements, you should still confirm what the certification or report covers, its boundaries, and its limitations, since outcomes depend on scope and the applicable criteria. A certification or report attests only to what is defined within its stated scope and does not, on its own, guarantee broader outcomes such as freedom from incidents.

Common misconceptions

ISO/IEC 17065 is the standard accreditation body certification bodies use to issue ISO 27001 certificates.
ISO/IEC 17065 governs bodies certifying products, processes, and services. Certification bodies issuing ISO/IEC 27001 certificates are generally accredited against the management-system certification standard (ISO/IEC 17021-1 and related documents), not ISO/IEC 17065. The two address different types of conformity assessment.
A body accredited under ISO/IEC 17065 can perform a SOC 2 examination.
A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, not a certification. ISO/IEC 17065 concerns certification bodies and does not govern or authorize SOC 2 attestation work, which sits under an entirely separate professional framework.
Any ISO/IEC 17065 certification confirms an organization's overall security posture.
Conformity assessed under ISO/IEC 17065 is limited to the defined product, process, or service and the specific certification scheme applied. It does not, on its own, attest to an information security management system or guarantee freedom from breaches, and it should not be conflated with an ISO 27001 certificate or a SOC 2 report.

Best practices

Confirm which accreditation standard applies to your intended certification: use ISO/IEC 17065 for product, process, and service certification, and verify that ISO 27001 work is conducted by a body accredited under the appropriate management-system certification standard instead.
When evaluating a certification body, check the exact scope and scheme covered by its accreditation rather than assuming broad coverage, since accreditation is scheme-specific.
Do not treat an ISO/IEC 17065-based certificate as interchangeable with an ISO 27001 certificate or a SOC 2 report; clarify to stakeholders what each conformity assessment actually covers.
Verify the certification body's accreditation status with the relevant accreditation body before relying on its certificates, as recognition varies by jurisdiction and scheme.
Review impartiality and conflict-of-interest arrangements when selecting a certification body, since these safeguards can differ between bodies operating under the standard.
Document the precise boundaries of any certification you obtain or accept, noting the specific product, process, or service and scheme covered so it is not overstated in customer or audit communications.