Skip to main content
Category: Certification and Accreditation

UKAS Accreditation

Also known as: UKAS, United Kingdom Accreditation Service accreditation
Simply put

UKAS accreditation is formal recognition, granted by the United Kingdom Accreditation Service, that an organisation is competent to perform specific tasks such as certification, testing, inspection, or calibration. In the compliance world, this matters because a certification body that issues ISO/IEC 27001 certificates typically operates under accreditation from a national accreditation body like UKAS, which lends credibility to the certificates it issues. UKAS is the sole National Accreditation Body for the United Kingdom.

Formal definition

UKAS (the United Kingdom Accreditation Service) is the UK's sole National Accreditation Body, recognised by government to assess and accredit organisations that provide conformity assessment services, including certification, testing, inspection, and calibration. Accreditation is defined as formal, third-party recognition of competence to perform specific tasks, issued by an authoritative body; UKAS derives its authority through government recognition. In the context of ISO/IEC 27001, a certification body accredited by UKAS (or another equivalent national accreditation body) is assessed as competent to issue certifications against the standard, and its accredited scope determines the activities it is recognised to perform. Note that UKAS accreditation applies to the certification body's competence, not directly to the organisation seeking an ISO 27001 certificate; the certificate itself covers only the defined scope of the client's ISMS. This concept is distinct from the SOC 2 model, where examinations are performed by licensed CPA firms under AICPA standards rather than by accredited certification bodies.

Why it matters

In the ISO/IEC 27001 ecosystem, the credibility of a certificate depends heavily on the competence of the body that issued it. UKAS accreditation provides formal, third-party recognition that a certification body is competent to perform specific conformity assessment tasks, which helps assure buyers, regulators, and partners that a certificate carries weight rather than merely reflecting the judgement of an unaccredited issuer. Because UKAS is the sole National Accreditation Body for the United Kingdom and is recognised by government, its accreditation acts as a trust anchor in the chain that runs from the accreditation body, to the certification body, to the certified organisation.

Who it's relevant to

Compliance and GRC managers
When selecting a certification body for ISO/IEC 27001, compliance managers should consider whether the body operates under accreditation from a recognised national accreditation body such as UKAS. Accreditation lends credibility to the resulting certificate, though the certificate itself still only attests to the defined scope of the organisation's ISMS.
Auditors and certification bodies
Certification bodies that issue ISO/IEC 27001 certificates are the direct subjects of UKAS accreditation, which recognises their competence to perform specific conformity assessment tasks. The accredited scope defines the activities the body is recognised to perform, making it central to how these organisations operate and market their services.
Procurement and vendor risk teams
Teams evaluating suppliers' ISO/IEC 27001 certificates can use accreditation status as one indicator of a certificate's credibility, since an accredited certification body has been assessed as competent to issue certifications. They should remember that accreditation applies to the certification body, not the vendor, and that the certificate covers only the vendor's defined ISMS scope.

Inside UKAS

Accreditation Body
UKAS (the United Kingdom Accreditation Service) is the national accreditation body for the UK, recognised to assess and accredit organisations that provide certification, testing, inspection, and calibration services.
Certification Body Oversight
In the ISO/IEC 27001 context, UKAS accredits certification bodies against standards such as ISO/IEC 17021-1, confirming that a certification body is competent to audit and issue ISMS certifications. UKAS itself does not certify individual organisations' ISMS.
Accredited vs. Non-Accredited Certification
An ISO 27001 certificate issued by a UKAS-accredited certification body typically carries the accreditation mark, indicating that the certification body's competence and impartiality have been independently assessed. Certificates from non-accredited bodies may carry less assurance.
Scope of Accreditation
UKAS accreditation applies to the defined scope of the certification body's activities. It confirms competence to certify within stated sectors or standards and does not extend beyond that defined scope.
Relationship to ISO 27001 Certification
UKAS accreditation underpins the credibility of the ISO/IEC 27001 certification chain but is distinct from the certification itself. The certification is issued by the accredited certification body against clauses 4 through 10 of ISO 27001, with Annex A reference controls selected via a Statement of Applicability.

Common questions

Answers to the questions practitioners most commonly ask about UKAS.

Does UKAS accreditation mean UKAS certifies my organization's ISO 27001 ISMS?
No. UKAS accredits certification bodies; it does not certify organizations directly. UKAS assesses and accredits the certification body against the relevant requirements, and that accredited certification body is the entity that issues an ISO 27001 certificate covering the defined scope of your ISMS. Your organization's relationship is with the accredited certification body, not with UKAS.
Is a certificate from a UKAS-accredited body somehow 'more valid' than the ISO 27001 standard itself requires?
Accreditation and certification are distinct concepts. ISO 27001 defines the ISMS requirements in clauses 4 through 10, with reference controls in Annex A selected via a Statement of Applicability. Accreditation of the certification body speaks to the credibility and competence of the body performing the certification, not to the content of the standard. A certificate from a UKAS-accredited body is typically viewed as carrying recognized independent oversight, but the underlying certifiable requirements remain those of the standard regardless of who accredits the certification body.
How do I verify that a certification body offering ISO 27001 certification is UKAS-accredited?
In most cases you can confirm a certification body's accreditation status and its accredited scope through the accreditation body's published register and the certification body's own documentation. It is worth confirming that the accreditation specifically covers ISO 27001 certification, since a body's accredited scope can vary by standard. Verify the details directly rather than relying solely on marketing claims, as scope and status can change over time.
Does choosing a UKAS-accredited certification body affect how our ISO 27001 audit is conducted?
The certification process typically follows the structure defined by the applicable audit and certification requirements the body operates under, which usually includes a two-stage initial audit followed by surveillance activities across the certification cycle. The specific approach, duration, and scheduling depend on the certification body, your ISMS scope, and other scoping decisions, so confirm expectations with your chosen body during engagement planning.
If we already have a SOC 2 report, does a UKAS-accredited ISO 27001 certification add anything?
The two outcomes are different in kind. A SOC 2 report is an attestation examination performed by a licensed CPA firm under SSAE 18 that attests only to the controls and period covered, while ISO 27001 certification is issued by an accredited certification body against the ISMS management system standard and covers only the defined ISMS scope. Mapping between the frameworks is possible but partial, and holding one does not automatically satisfy the other, so an accredited ISO 27001 certification may address stakeholder expectations that a SOC 2 report does not, depending on your requirements.
What should we consider when selecting an accredited certification body for ISO 27001?
Practical considerations typically include confirming that the body's accredited scope covers ISO 27001, that the accreditation is current, and that the body has relevant sector experience for your ISMS scope. You may also weigh the body's approach to the initial audit and surveillance cycle, resourcing, and scheduling. Because these factors vary by body and by your defined scope, it is advisable to clarify them directly before engagement rather than assuming a single standard approach.

Common misconceptions

UKAS issues ISO 27001 certificates to organisations.
UKAS accredits the certification bodies that issue ISO/IEC 27001 certificates; it does not itself certify an organisation's ISMS. The certificate is issued by the accredited certification body, not by UKAS.
UKAS accreditation applies to SOC 2 in the same way it applies to ISO 27001.
SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report, not a certification. UKAS accreditation relates to the certification-body model used for ISO/IEC 27001 and comparable standards, not to the SOC 2 attestation model.
Any ISO 27001 certificate provides the same level of assurance regardless of who issued it.
A certificate issued by a UKAS-accredited certification body typically carries independent assurance that the certification body's competence and impartiality have been assessed, whereas a certificate from a non-accredited body may not carry the same level of recognised assurance.

Best practices

When evaluating a vendor's ISO/IEC 27001 certificate, confirm whether it was issued by a UKAS-accredited certification body and look for the accreditation mark rather than accepting the certificate at face value.
Verify that the certification body's scope of accreditation covers the relevant standard and sector before relying on its certificates.
Review the defined scope of the certified ISMS on the certificate, since a UKAS-accredited certificate covers only the boundaries stated and does not extend to activities outside that scope.
Keep the roles clear in internal documentation: UKAS accredits certification bodies, certification bodies certify ISMSs, and neither guarantees freedom from breaches.
Do not treat a UKAS-accredited ISO 27001 certificate as equivalent to a SOC 2 report; recognise that mapping between the frameworks is possible but partial and that satisfying one does not automatically satisfy the other.
Where accreditation status cannot be confirmed with confidence, describe it qualitatively to stakeholders and request supporting evidence rather than assuming accredited status.