United Kingdom Accreditation Service (UKAS)
The United Kingdom Accreditation Service (UKAS) is the national accreditation body for the United Kingdom, appointed and recognised by the British government. It assesses and accredits organisations that provide services such as certification, testing, inspection, and calibration. In practice, this means UKAS does not certify companies directly against standards like ISO/IEC 27001; instead, it evaluates and accredits the certification bodies that issue such certificates.
UKAS is the sole national accreditation body for the United Kingdom, appointed by government to assess organisations against recognised standards. It accredits conformity assessment bodies, including certification bodies, testing laboratories, inspection bodies, and calibration providers, thereby underpinning the credibility of the certificates, test results, and measurements those bodies produce. In an ISO/IEC 27001 context, a certification body may hold UKAS accreditation to demonstrate its competence to issue ISO 27001 certifications; the accreditation attests to the certification body's competence rather than to any individual organisation's ISMS. Note that UKAS accreditation applies to the accredited bodies within its scope and does not itself constitute certification of an end organisation. SOC 2, by contrast, is an AICPA attestation examination performed by a licensed CPA firm and does not involve accreditation bodies such as UKAS.
Why it matters
UKAS accreditation sits at the top of the assurance chain that gives an ISO/IEC 27001 certificate its credibility. When an organisation seeks ISO 27001 certification, it engages a certification body, not UKAS directly. The value of the resulting certificate depends in part on whether the certification body itself has been assessed as competent by a recognised national accreditation body such as UKAS. Without this layer of oversight, a certificate would rest only on the issuing body's own assertions of competence, which is why buyers, regulators, and procurement teams often distinguish between accredited and unaccredited certifications.
For compliance managers and GRC professionals selecting a certification body, checking for UKAS accreditation (or accreditation from an equivalent recognised body in another jurisdiction) is a practical due diligence step. It provides independent confirmation that the certification body has been evaluated against recognised standards for how it conducts audits and issues certificates. This matters most in contractual and supply-chain contexts, where a customer may require not just an ISO 27001 certificate but one issued under a recognised accreditation.
It is important to keep the boundaries clear: UKAS accreditation attests to the competence of the certification body, not to the security posture of any individual organisation's information security management system. A UKAS-accredited certification body issuing an ISO 27001 certificate does not guarantee freedom from breaches, and the certificate still covers only the defined scope of that organisation's ISMS.
Who it's relevant to
Inside UKAS
Common questions
Answers to the questions practitioners most commonly ask about UKAS.