Accredited vs Non-Accredited ISO 27001 Certificates: The Expensive Mistake
Why the cheaper certificate costs more in the end: procurement rejection, what accreditation actually checks, and how to verify a CB.
What accreditation is
An accredited CB has been assessed by a national accreditation body (UKAS, ANAB, DAkkS, RvA, …) against ISO/IEC 17021 — the standard for bodies auditing management systems. Accreditation checks auditor competence, impartiality, audit-day calculations, and decision-making independence. A non-accredited "certification" skips all of that: it's a private opinion with a certificate-shaped wrapper.
Why buyers reject unaccredited certificates
Enterprise procurement and government tenders specify accredited ISO 27001 certification because it's the only form they can trust without re-auditing you themselves. An unaccredited certificate fails the checkbox it was bought to tick — the deal stalls, and you pay for a second, accredited audit anyway.
The cost math
Published UK data puts an accredited small-org audit at £6,250+ versus cheaper non-accredited options. The "saving" evaporates the first time a customer asks for the accreditation behind the certificate. Budget for an accredited CB from the start — it's the cheapest path to a certificate that works.
How to verify
- Search the accreditation body's directory (UKAS, ANAB, DAkkS, RvA) for the CB's name and confirm ISO 27001 is in its accredited scope.
- Check issued certificates on IAF CertSearch (iafcertsearch.org).
- Ask the CB for its accreditation certificate — accredited bodies provide it routinely.
- Beware lookalike "accreditation" from private bodies with official-sounding names.
Frequently asked
Is a non-accredited certificate ever acceptable?
For internal improvement or marketing to unsophisticated buyers, maybe. For B2B procurement, tenders, or regulated customers — no. Get the accredited one.
Does accreditation make audits better?
It makes them consistent and trustworthy: auditor competence, impartiality, and audit-day minimums are all overseen. That's what buyers are paying for when they require it.
Related reading
Get quotes from accredited CBs
One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.
More guides
How to Choose an ISO 27001 Certification Body: 8 Questions to Ask
The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.
ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different
Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.
ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?
Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.