How to Verify an ISO 27001 Certificate Is Genuine
The short answer: a genuine ISO 27001 certificate names an accredited certification body, carries a certificate number, states an ISMS scope, shows issue and expiry dates, and can be found on the certification body’s public register or in IAF CertSearch. If any one of those is missing, you are not looking at a certificate you can rely on — you are looking at a PDF.
ISO does not certify anyone. It writes the standard. Certificates are issued by certification bodies, and what makes a certification body’s output mean anything is accreditation — oversight by a national accreditation body that is itself a signatory to the International Accreditation Forum’s Multilateral Recognition Arrangement. Anyone can register a company, call it a certification body, and sell a certificate. Nothing stops them. The accreditation chain is the only thing that separates a real certificate from a printed one, and it is checkable in about five minutes.
The four checks, in order
1. Read the certificate itself
Before going anywhere online, confirm the document contains all of the following. A real certificate always does:
- The certification body’s name and the accreditation body’s mark. Two different organisations. The accreditation mark usually appears alongside the certification body’s logo, with an accreditation number.
- A certificate number. This is what you will search on.
- The standard and its version — it should read ISO/IEC 27001:2022.
- A scope statement. Specific: the activities, services and sites the ISMS covers. A certificate with no scope statement, or a scope that reads only “information security management,” is not usable in due diligence.
- Issue date, expiry date, and the certification cycle. ISO 27001 certificates run a three-year cycle with annual surveillance audits.
- The certified legal entity’s name and address — matching the entity you are actually contracting with, not a parent or sister company.
2. Confirm the certification body is accredited
The claim to test is not “is this company certified” but “is whoever issued this certificate accountable to anyone.” Check the accreditation body named on the certificate against its own published register:
- India: NABCB, the National Accreditation Board for Certification Bodies, under the Quality Council of India. Its directory lists accredited bodies and, importantly, bodies whose accreditation has been suspended or withdrawn.
- United Kingdom: UKAS. United States: ANAB. UAE: EIAC or ENAS. Each publishes a searchable register.
- Anywhere: IAF CertSearch aggregates accredited certificates from IAF member accreditation bodies worldwide. Free searching is capped at a few lookups a day without an account.
Two failure modes to name explicitly. An unaccredited certificate comes from a body no accreditation board oversees — it is not recognised in supplier due diligence and will not satisfy a customer’s security questionnaire. A lapsed accreditation is worse and easier to miss: the body was accredited when the certificate was issued and has since been suspended or withdrawn. This is exactly what the “withdrawn” and “suspended” lists on an accreditation register are for. Check them, not just the active list.
3. Verify the certificate number at source
Search the certificate number on the certification body’s own public register, and separately in IAF CertSearch. You are confirming four things: the certificate exists, it is current rather than expired or withdrawn, the certified entity name matches, and the scope on the register matches the scope on the PDF you were sent. Registers are the authoritative record; a PDF is not.
If the certificate does not appear, that is not automatically fraud — a certification body may publish on a delay, and not every accredited body pushes data to IAF CertSearch. It is a reason to stop and ask the certification body directly for written confirmation. Contact the certification body using details from the accreditation register, never the contact details printed on the certificate you are verifying.
4. Match the scope to what you are buying
This is the check that gets skipped, and it is the one that most often turns a valid certificate into a useless one. A certificate covering a single development office does not cover the managed service you are contracting for. A certificate covering “corporate IT” does not cover the SaaS platform your customer data will sit in. The scope statement is the whole assurance: outside it, the certificate says nothing at all. Read it against the service, the systems, and the physical sites actually involved in your contract.
Red flags worth acting on
- Still certified to ISO/IEC 27001:2013. The transition deadline was 31 October 2025. Certificates against the 2013 version are no longer valid, and an organisation that missed it needs a full certification audit, not a transition audit. A 2013 certificate presented in 2026 is either stale paperwork or an ISMS nobody has maintained.
- No accreditation mark, or an accreditation body you cannot find on the IAF member list.
- A vague or missing scope statement.
- Certification turned around in days. A real Stage 1 / Stage 2 audit cycle cannot be compressed to a week, and an ISMS needs operating evidence — internal audit, management review, risk treatment — before Stage 2 can even be attempted.
- The certification body also did the consulting. Impartiality rules prohibit a certification body from certifying an ISMS it built. If the same firm wrote your policies and issued your certificate, the accreditation is at risk.
- Certificate supplied only as an image, or the entity name differs from the contracting entity.
What to do when a supplier’s certificate does not check out
Treat it as a vendor risk finding, not a paperwork problem, and keep it factual. Record what you verified and what failed. Ask the supplier for the accredited certification body’s current status letter, addressed to you. Give a deadline.
Meanwhile, re-run your own due diligence on the controls the certificate was standing in for — access management, encryption and key handling, logging and incident response, sub-processor and data-location disclosure, and business continuity. A certificate was only ever a shortcut for asking those questions; if the shortcut fails, ask them directly. Where the supplier processes personal data, obligations under the DPDP Act 2023 sit with you as the data fiduciary regardless of what the supplier’s certificate claimed, so document the compensating controls you accepted and the date you accepted them.
If you conclude a certificate was issued improperly, the route is the accreditation body’s complaints process against the certification body — NABCB in India, or the relevant IAF member elsewhere. Report what you can evidence: the certificate number, the register result, and the dates.
Getting your own certificate to pass this test
The same list, applied inward. Choose a certification body accredited by an IAF MLA signatory and confirm its accreditation is current before you sign, not after. Write a scope statement your customers can read and match to what they are buying — narrow enough to be true, broad enough to be useful. Keep the certificate current on the register and be able to produce the accreditation chain on request. And run the ISMS between audits: surveillance audits are annual, but the controls have to hold on the other 363 days, which is where most post-certification incidents originate.
Praxis-Q runs certificate verification and third-party risk review as part of supplier due diligence engagements, and prepares organisations for accredited ISO 27001 certification with a defensible scope. If you are holding a certificate you cannot verify — yours or a supplier’s — talk to us.
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Sahil Dubey
Compliance & Security Expert
Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.
