ISO/IEC 27006
ISO/IEC 27006 is a standard that sets the rules for the organizations that audit and certify other companies' information security management systems. In other words, it governs the certification bodies themselves rather than the companies seeking certification, helping ensure those bodies operate competently and consistently. It works alongside ISO/IEC 27001, which defines the requirements that a company's management system must meet.
ISO/IEC 27006 specifies additional requirements and provides guidance for bodies that provide audit and certification of an information security management system (ISMS) in accordance with ISO/IEC 27001. Its current base document, ISO/IEC 27006-1:2024, supplements the general accreditation requirements applicable to certification bodies with ISMS-specific provisions governing the competence, impartiality, and conduct of the certification process. A related document, ISO/IEC TS 27006-2:2021, specifies requirements and guidance for bodies auditing and certifying a privacy information management system (PIMS). ISO/IEC 27006 is directed at accredited certification bodies and their accreditation, not at organizations pursuing ISO/IEC 27001 certification themselves; it does not define ISMS requirements (which reside in ISO/IEC 27001 clauses 4 through 10) nor the reference controls of Annex A. Specific edition details and provisions vary by version, and the standard should be cited by its full designation and year for precision.
Why it matters
ISO/IEC 27006 underpins the credibility of the entire ISO/IEC 27001 certification ecosystem. When an organization presents an ISO/IEC 27001 certificate, its value depends on the assumption that the certification body issuing it operated competently, impartially, and consistently. ISO/IEC 27006 sets the requirements that govern those bodies, so that a certificate from one accredited body carries comparable weight to one from another. Without such governing rules, certification outcomes could vary widely and the assurance conveyed by a certificate would be difficult to trust.
For organizations pursuing or relying on ISO/IEC 27001 certification, the standard matters indirectly but meaningfully. It is directed at certification bodies and their accreditation rather than at the organizations being certified, but it shapes how audits are conducted, how auditor competence is assessed, and how impartiality is maintained throughout the certification process. Buyers, partners, and regulators who accept an ISO/IEC 27001 certificate as evidence of a functioning ISMS are, in effect, relying on the discipline that ISO/IEC 27006 imposes on the bodies performing the audits.
It is important to keep the boundaries clear. ISO/IEC 27006 does not define ISMS requirements, those reside in ISO/IEC 27001 clauses 4 through 10, nor does it define the reference controls in Annex A. Its provisions vary by edition, so it should be cited by its full designation and year. The current base document is ISO/IEC 27006-1:2024, while ISO/IEC TS 27006-2:2021 addresses bodies auditing and certifying a privacy information management system (PIMS) rather than an ISMS.
Who it's relevant to
Inside ISO/IEC 27006
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27006.