Choosing
Choosing a certification body, once you have checked accreditation
Accreditation is the first filter and a separate question. Once two or three bodies have cleared it, the things that decide which one you should actually use are commercial and rarely appear in the proposal.
Facts checked — 2026-09-11
How do you choose between accredited bodies?
Price the cycle rather than the certificate. A certification audit is year one of three, followed by two surveillance audits and then recertification, and quotes that look close in year one can diverge considerably across the cycle. Ask for the full three-year schedule of fees, including what a transfer or a scope change would cost.
Ask about the lead auditor rather than the firm. Someone who has audited your kind of business asks sharper questions, wastes less of your time on explaining what you do, and is less likely to mistake an unfamiliar architecture for a finding. Ask whether you get the same auditor across the cycle, because continuity is worth a great deal by the second surveillance visit.
Then availability, which is the one that quietly sets your date. Certification body calendars are theirs, they lengthen towards the end of the year, and an audit slot you cannot book is a customer commitment you cannot meet. Ask for realistic lead times at the first conversation rather than when you are ready.
The bottom line
Get the three-year fee schedule and the lead auditor’s background in writing, and ask what their next available slot actually is. Those three answers differentiate bodies far more than the headline price does.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.
Choosing
SOC 2 or ISO 27001 first? A commercial question wearing a technical costume
Your pipeline decides this, not the frameworks — and the two produce very different things to hand a customer.
Choosing
Accredited and unaccredited certification are not the same product
Both produce a certificate. Only one carries independent oversight of the auditor — and it is checkable.