Skip to main content
Category: Certification and Accreditation

United Kingdom Accreditation Service (UKAS)

Also known as: UKAS, UK Accreditation Service
Simply put

The United Kingdom Accreditation Service (UKAS) is the national accreditation body for the United Kingdom, appointed and recognised by the British government. It assesses and accredits organisations that provide services such as certification, testing, inspection, and calibration. In practice, this means UKAS does not certify companies directly against standards like ISO/IEC 27001; instead, it evaluates and accredits the certification bodies that issue such certificates.

Formal definition

UKAS is the sole national accreditation body for the United Kingdom, appointed by government to assess organisations against recognised standards. It accredits conformity assessment bodies, including certification bodies, testing laboratories, inspection bodies, and calibration providers, thereby underpinning the credibility of the certificates, test results, and measurements those bodies produce. In an ISO/IEC 27001 context, a certification body may hold UKAS accreditation to demonstrate its competence to issue ISO 27001 certifications; the accreditation attests to the certification body's competence rather than to any individual organisation's ISMS. Note that UKAS accreditation applies to the accredited bodies within its scope and does not itself constitute certification of an end organisation. SOC 2, by contrast, is an AICPA attestation examination performed by a licensed CPA firm and does not involve accreditation bodies such as UKAS.

Why it matters

UKAS accreditation sits at the top of the assurance chain that gives an ISO/IEC 27001 certificate its credibility. When an organisation seeks ISO 27001 certification, it engages a certification body, not UKAS directly. The value of the resulting certificate depends in part on whether the certification body itself has been assessed as competent by a recognised national accreditation body such as UKAS. Without this layer of oversight, a certificate would rest only on the issuing body's own assertions of competence, which is why buyers, regulators, and procurement teams often distinguish between accredited and unaccredited certifications.

For compliance managers and GRC professionals selecting a certification body, checking for UKAS accreditation (or accreditation from an equivalent recognised body in another jurisdiction) is a practical due diligence step. It provides independent confirmation that the certification body has been evaluated against recognised standards for how it conducts audits and issues certificates. This matters most in contractual and supply-chain contexts, where a customer may require not just an ISO 27001 certificate but one issued under a recognised accreditation.

It is important to keep the boundaries clear: UKAS accreditation attests to the competence of the certification body, not to the security posture of any individual organisation's information security management system. A UKAS-accredited certification body issuing an ISO 27001 certificate does not guarantee freedom from breaches, and the certificate still covers only the defined scope of that organisation's ISMS.

Who it's relevant to

Compliance managers selecting a certification body
When choosing who will perform an ISO/IEC 27001 certification, compliance managers can use UKAS accreditation (or equivalent recognised accreditation) as a due diligence signal that the certification body has been independently assessed as competent to issue certificates.
GRC and procurement teams evaluating supplier certificates
Teams reviewing a vendor's ISO 27001 certificate may distinguish between accredited and unaccredited certifications. Confirming the issuing body holds UKAS accreditation helps establish confidence in the certificate, while remembering the certificate covers only the vendor's defined ISMS scope.
Auditors and certification body staff
For certification bodies themselves, UKAS accreditation is the mechanism by which their competence to issue ISO 27001 certifications is assessed and recognised in the United Kingdom, underpinning the credibility of the certificates they produce.
Professionals comparing SOC 2 and ISO 27001
Those working across both frameworks should note that UKAS-style accreditation applies to the ISO certification model but not to SOC 2, which is an AICPA attestation performed by a licensed CPA firm and does not rely on accreditation bodies such as UKAS.

Inside UKAS

National Accreditation Body
UKAS is the recognised national accreditation body for the United Kingdom, responsible for assessing and accrediting the competence of certification bodies, testing laboratories, and inspection bodies against internationally recognised standards.
Accreditation of Certification Bodies
In the context of ISO/IEC 27001, UKAS accredits the certification bodies that issue ISO 27001 certificates, evaluating whether those bodies operate competently and impartially. It does not itself certify individual organisations' ISMS implementations.
Conformity Assessment Standards
UKAS assesses certification bodies against recognised conformity assessment requirements applicable to bodies that certify management systems, providing assurance that an accredited certificate carries consistent meaning.
Accreditation Marks
A UKAS accreditation mark may appear alongside a certification body's mark on an ISO 27001 certificate, indicating the certificate was issued under an accredited scheme rather than through an unaccredited process.
International Recognition
UKAS accreditation is recognised through international arrangements among national accreditation bodies, which supports mutual recognition of accredited certifications across jurisdictions, though the extent of recognition depends on the applicable arrangements.

Common questions

Answers to the questions practitioners most commonly ask about UKAS.

Does a UKAS accreditation mean that UKAS itself certifies my organization's ISO 27001 ISMS?
No. UKAS does not certify organizations against ISO/IEC 27001. UKAS is a national accreditation body that assesses and accredits certification bodies. It is those accredited certification bodies, not UKAS, that audit your information security management system and issue the ISO 27001 certificate covering the defined scope of your ISMS.
Is a certificate from a UKAS-accredited body somehow more valid than one from a body accredited elsewhere?
Not in the sense that one is legitimate and the other is not. UKAS is one national accreditation body among several that operate internationally, and accreditation bodies typically participate in mutual recognition arrangements. A certificate from a body accredited by another recognized national accreditation body is generally still a valid ISO 27001 certification. In most cases, the relevant question is whether the certification body is accredited by a recognized accreditation body at all, and which one may matter for specific customer or market expectations rather than for underlying validity.
How do I confirm that the certification body I plan to use is UKAS-accredited for ISO 27001?
You can typically verify a certification body's accreditation status and scope through the accreditation body's published directory of accredited organizations. Because accreditation is granted for specific scopes, confirm that the body's accreditation covers ISO/IEC 27001 certification and that the scope is relevant to your sector or activities. If you cannot confirm this with confidence, request evidence directly from the certification body.
Does using a UKAS-accredited certification body change how the ISO 27001 audit itself is conducted?
The core audit process, evaluating your ISMS against the requirements in clauses 4 through 10 and your selected Annex A reference controls via the Statement of Applicability, is driven by the ISO 27001 standard and the certification body's procedures. Accreditation provides oversight of the certification body's competence and impartiality rather than dictating the specifics of each engagement, so the exact scope, sampling, and stage structure will still depend on your organization and the certification body's methodology.
If we already have a SOC 2 report, does engaging a UKAS-accredited certification body let us reuse that work for ISO 27001?
Some evidence and control activities may be relevant to both, since mapping between SOC 2 and ISO 27001 is possible but only partial, and satisfying one does not automatically satisfy the other. A UKAS-accredited certification body assesses your ISMS against the ISO 27001 requirements regardless of any existing SOC 2 report, which is an attestation examination performed by a licensed CPA firm rather than a certification. In most engagements you should expect the certification body to evaluate ISO 27001 requirements on their own terms, even where prior work reduces some duplication.
What should we look for when confirming that an accredited certification body's scope fits our needs?
Check that the accreditation explicitly covers ISO/IEC 27001 certification and, where relevant, that any sector or technology scope aligns with your organization's activities. Keep in mind that the resulting certificate will cover only the defined scope of your ISMS, so both the accreditation scope of the body and the certification scope you agree with them matter. If any element is unclear, it is reasonable to ask the certification body to provide documentation rather than assume coverage.

Common misconceptions

UKAS certifies organisations' ISO 27001 information security management systems directly.
UKAS accredits the certification bodies that perform ISO 27001 certification; it does not audit or certify individual organisations. An organisation seeking certification engages an accredited certification body, not UKAS directly.
A UKAS mark on a document indicates the organisation has passed a SOC 2 examination or holds a SOC 2 report.
UKAS accreditation relates to certification schemes such as ISO/IEC 27001. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA's SSAE 18 standard and results in a report rather than an accredited certificate, so UKAS accreditation is not relevant to it.
Any ISO 27001 certificate is equivalent regardless of whether the certification body is accredited by UKAS or another body.
Certificates issued under an accredited scheme carry assurance about the competence and impartiality of the certification body, whereas unaccredited certificates do not carry that same assurance. Recognition of a given accreditation body typically depends on the applicable international arrangements and the assessing party's requirements.

Best practices

When evaluating a vendor's ISO 27001 certificate, confirm whether it was issued by a certification body accredited by UKAS or another recognised national accreditation body, rather than relying on the certificate alone.
Verify the accreditation status of a certification body directly, since accreditation applies to the certification body and not to the certified organisation.
Check that the ISO 27001 certificate specifies the defined scope of the ISMS, and remember that accreditation does not extend assurance beyond that stated scope.
Do not treat a UKAS-accredited ISO 27001 certificate as equivalent to a SOC 2 report; request the appropriate deliverable for the framework relevant to your assurance needs, as satisfying one does not automatically satisfy the other.
Where cross-border recognition matters, confirm that the relevant international accreditation arrangements apply, as the extent of mutual recognition depends on those arrangements.
Retain evidence of accreditation verification within your vendor risk or GRC records so that reliance on a certificate can be substantiated during your own audits.