Skip to main content
Category: Certification and Accreditation

ISO/IEC 27006

Also known as: ISO/IEC 27006-1, ISO/IEC 27006-1:2024, ISO/IEC TS 27006-2
Simply put

ISO/IEC 27006 is a standard that sets the rules for the organizations that audit and certify other companies' information security management systems. In other words, it governs the certification bodies themselves rather than the companies seeking certification, helping ensure those bodies operate competently and consistently. It works alongside ISO/IEC 27001, which defines the requirements that a company's management system must meet.

Formal definition

ISO/IEC 27006 specifies additional requirements and provides guidance for bodies that provide audit and certification of an information security management system (ISMS) in accordance with ISO/IEC 27001. Its current base document, ISO/IEC 27006-1:2024, supplements the general accreditation requirements applicable to certification bodies with ISMS-specific provisions governing the competence, impartiality, and conduct of the certification process. A related document, ISO/IEC TS 27006-2:2021, specifies requirements and guidance for bodies auditing and certifying a privacy information management system (PIMS). ISO/IEC 27006 is directed at accredited certification bodies and their accreditation, not at organizations pursuing ISO/IEC 27001 certification themselves; it does not define ISMS requirements (which reside in ISO/IEC 27001 clauses 4 through 10) nor the reference controls of Annex A. Specific edition details and provisions vary by version, and the standard should be cited by its full designation and year for precision.

Why it matters

ISO/IEC 27006 underpins the credibility of the entire ISO/IEC 27001 certification ecosystem. When an organization presents an ISO/IEC 27001 certificate, its value depends on the assumption that the certification body issuing it operated competently, impartially, and consistently. ISO/IEC 27006 sets the requirements that govern those bodies, so that a certificate from one accredited body carries comparable weight to one from another. Without such governing rules, certification outcomes could vary widely and the assurance conveyed by a certificate would be difficult to trust.

For organizations pursuing or relying on ISO/IEC 27001 certification, the standard matters indirectly but meaningfully. It is directed at certification bodies and their accreditation rather than at the organizations being certified, but it shapes how audits are conducted, how auditor competence is assessed, and how impartiality is maintained throughout the certification process. Buyers, partners, and regulators who accept an ISO/IEC 27001 certificate as evidence of a functioning ISMS are, in effect, relying on the discipline that ISO/IEC 27006 imposes on the bodies performing the audits.

It is important to keep the boundaries clear. ISO/IEC 27006 does not define ISMS requirements, those reside in ISO/IEC 27001 clauses 4 through 10, nor does it define the reference controls in Annex A. Its provisions vary by edition, so it should be cited by its full designation and year. The current base document is ISO/IEC 27006-1:2024, while ISO/IEC TS 27006-2:2021 addresses bodies auditing and certifying a privacy information management system (PIMS) rather than an ISMS.

Who it's relevant to

Certification Bodies
ISO/IEC 27006-1 is directed primarily at bodies that audit and certify information security management systems. These organizations must meet its requirements, covering competence, impartiality, and the conduct of the certification process, to obtain and maintain accreditation to issue ISO/IEC 27001 certificates.
Accreditation Bodies
Accreditation bodies use ISO/IEC 27006 as the benchmark against which they assess certification bodies. The standard provides the ISMS-specific criteria that supplement general accreditation requirements, enabling consistent evaluation of whether a certification body is fit to certify ISO/IEC 27001 conformance.
Organizations Pursuing ISO/IEC 27001 Certification
While ISO/IEC 27006 does not apply to organizations seeking certification directly, it shapes the audit process they will experience and helps assure that the certificate they earn is issued by a competent, impartial body. Selecting a body accredited against these requirements can support the credibility of the resulting certification.
GRC and Compliance Professionals
Those who rely on ISO/IEC 27001 certificates as evidence of a functioning ISMS, whether evaluating vendors or presenting their own certification, benefit from understanding that ISO/IEC 27006 governs the bodies behind those certificates. It clarifies where certification credibility comes from and where it does not, including that a certificate covers only the defined scope of the ISMS.
Privacy Program Stakeholders
Teams working with privacy information management systems should note ISO/IEC TS 27006-2:2021, which specifies requirements and guidance for bodies auditing and certifying a PIMS. This is a distinct scope from the ISMS-focused ISO/IEC 27006-1 and should be referenced by its full designation.

Inside ISO/IEC 27006

Accreditation Requirements for Certification Bodies
ISO/IEC 27006 specifies requirements and provides guidance for bodies that provide audit and certification of information security management systems (ISMS). It supplements the general requirements in the applicable conformity assessment standard as they apply specifically to ISO/IEC 27001 certification.
Competence and Auditor Requirements
It addresses the competence expectations for personnel involved in ISMS certification activities, helping ensure that auditors and certification bodies conducting ISO/IEC 27001 audits meet consistent qualification and impartiality expectations. Specific criteria may vary depending on the accreditation body applying the standard.
Audit Time and Resourcing Guidance
The standard offers guidance intended to promote consistency in how certification bodies determine audit effort and resourcing for ISMS certification engagements. The exact application typically depends on the scope, complexity, and risk profile of the ISMS being certified.
Support for the Certification Chain
ISO/IEC 27006 operates within the accreditation and certification ecosystem, underpinning the credibility of an ISO/IEC 27001 certificate. It applies to the certification body rather than to the organization seeking certification, and it does not itself define the ISMS requirements found in clauses 4 through 10 of ISO/IEC 27001 or the reference controls in Annex A.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27006.

Does ISO/IEC 27006 apply to organizations seeking ISO 27001 certification?
No. ISO/IEC 27006 is directed at certification bodies rather than at the organizations pursuing certification. It sets out requirements for the bodies that audit and certify information security management systems, so its primary audience is the certification providers and their accreditation bodies. An organization implementing an ISMS follows ISO/IEC 27001 for the certifiable requirements; it typically encounters ISO/IEC 27006 only indirectly, through the way an accredited certification body conducts its audit. Depending on scope, understanding this standard can help an organization anticipate how its auditor is expected to operate, but the standard itself does not impose requirements on the certified organization.
Is ISO/IEC 27006 a standard that a company can be certified against?
No. ISO/IEC 27006 is not a certifiable standard for organizations. Certification against a management system is achieved under ISO/IEC 27001, whose ISMS requirements are the certifiable content. ISO/IEC 27006 instead supports the accreditation and consistent operation of the certification bodies that issue those certifications. Treating it as something a company "gets certified to" conflates the role of the certification body with the role of the certified organization. The two are distinct participants in the certification process, and ISO/IEC 27006 governs the former.
How does ISO/IEC 27006 relate to the audit our certification body performs?
ISO/IEC 27006 informs how an accredited certification body is expected to plan, staff, and conduct its ISMS audits, which in turn shapes the experience an organization has during certification. In most engagements this influences matters such as auditor competence expectations and how audit activity is organized. The specifics of any individual audit still depend on the certification body, the agreed scope of the ISMS, and the risk profile of the organization, so the standard sets a framework for the body rather than a fixed script for every audit.
Should we consider a certification body's alignment with ISO/IEC 27006 when selecting a provider?
When choosing a certification body, organizations typically look for one that is accredited, since accreditation is intended to demonstrate that the body operates consistently with the requirements applicable to certification bodies. Confirming a provider's accreditation status is a common part of due diligence. Because outcomes depend on the certification body and the defined scope of the ISMS, verifying accreditation helps set expectations for how the audit will be conducted, though it does not by itself guarantee any particular result.
Does ISO/IEC 27006 change the requirements we must meet for ISO 27001 certification?
No. The requirements an organization must meet for certification come from ISO/IEC 27001, specifically its ISMS requirements, with Annex A reference controls selected through a Statement of Applicability informed by risk assessment. ISO/IEC 27006 addresses the certification body's operations rather than the substance of what an organization must implement. Depending on scope, an organization prepares its ISMS against ISO/IEC 27001, and the certification body applies its own governing requirements when assessing that ISMS.
How does ISO/IEC 27006 fit alongside other standards in the ISO 27000 family?
ISO/IEC 27006 occupies a distinct role from the standards an organization implements directly. ISO/IEC 27001 contains the certifiable ISMS requirements, ISO/IEC 27002 provides guidance on the reference controls, and sector- or topic-specific standards such as ISO/IEC 27017 and ISO/IEC 27018 address particular contexts. ISO/IEC 27006, by contrast, supports the certification bodies that assess conformity. Keeping these boundaries clear helps a compliance team direct its own implementation effort toward the standards that impose requirements on the organization rather than on its auditor.

Common misconceptions

Organizations seeking ISO 27001 certification must comply with ISO/IEC 27006.
ISO/IEC 27006 is directed at certification bodies and accreditation activities, not at the organization implementing an ISMS. An organization pursuing certification builds its ISMS against ISO/IEC 27001; the certification body it engages is the party to which ISO/IEC 27006 requirements typically apply.
ISO/IEC 27006 is an alternative or replacement standard for ISO/IEC 27001.
The two serve different purposes. ISO/IEC 27001 defines the certifiable ISMS requirements, while ISO/IEC 27006 sets requirements and guidance for the bodies that audit and certify against ISO/IEC 27001. It supplements rather than replaces the certification framework.
ISO/IEC 27006 is relevant to SOC 2 examinations.
ISO/IEC 27006 belongs to the ISO/IEC 27001 certification ecosystem. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and does not use ISO/IEC 27006; the two frameworks and their oversight structures are distinct.

Best practices

When selecting a certification body for ISO/IEC 27001, confirm it is accredited by a recognized accreditation body, since that accreditation typically reflects conformity with ISO/IEC 27006-related requirements.
Treat ISO/IEC 27006 as context for evaluating the credibility of a certification body rather than as a compliance obligation for your own ISMS.
Focus your organization's implementation effort on the ISO/IEC 27001 ISMS requirements (clauses 4 through 10) and the Annex A reference controls selected via your Statement of Applicability, leaving ISO/IEC 27006 conformance to the certification body.
Ask prospective certification bodies how they determine audit time and resourcing for your engagement, recognizing that this typically depends on the scope, complexity, and risk profile of your ISMS.
Verify the version of any standard cited in accreditation or certification documentation, since requirements and referenced editions can change over time.
Do not assume that a certification body's ISO/IEC 27006 alignment guarantees any particular audit outcome; certification depends on the defined scope of your ISMS and the auditor's assessment against ISO/IEC 27001.