Choosing
Compliant, certified, aligned: which claim you can actually make
Nobody sets out to overclaim. What happens is that a sentence written for a website in month three survives into a contract in month eighteen, by which point somebody is checking it. The distinctions here take two minutes to learn and remove a category of problem entirely.
Facts checked — 2026-09-11
What each claim actually carries
| Claim | What it means | Who can check it |
|---|---|---|
| Certified | An accredited certification body audited your management system and issued a certificate with a scope, dates and a number. | Anyone — the certification body, its accreditation body, and IAF CertSearch. |
| Aligned with | You have built to the standard and have not been audited against it. Honest, and defensible. | Nobody, and it does not claim otherwise. |
| Compliant | Ambiguous. Usually means aligned, but reads to a buyer as certified. | Nobody — which is the problem, because it sounds checkable. |
| SOC 2 certified | Nothing. SOC 2 is an attestation report from a CPA firm; there is no certificate and no certifying body. | Not applicable — the claim describes something that does not exist. |
The same logic applies to statutes. There is no GDPR or DPDP certificate, so "GDPR certified" is not a thing either — compliance with a law is a legal conclusion, not an issued document.
The difference in one sentence
Certified means somebody independent looked and issued a document you did not write. Compliant means you looked and reached a favourable conclusion about yourself.
Both can be true. Only one is evidence, and the gap between them is exactly the thing a customer is trying to close when they ask for your certificate.
A certificate carries specifics that make it checkable: the standard and its edition, a scope statement, issue and expiry dates, a certificate number, the certification body, and the accreditation symbol of the body that accredits them. "We are compliant" carries none of those, which is why it cannot do the same commercial work however sincerely it is meant.
Why "compliant" causes trouble specifically
Because it is ambiguous in a way that resolves in your favour to a casual reader and against you to a careful one.
Written honestly, it usually means "we have implemented the standard and believe we meet it". Read by a procurement reviewer, it lands somewhere very close to certified — and when they ask for the certificate and there is none, the conversation is no longer about security. It is about whether your claims can be relied on, which is a much worse conversation to be having with someone mid-way through a vendor assessment.
The risk compounds when the phrase migrates. A line on a website is marketing; the same line in a questionnaire response is a representation; the same line in a contract is a warranty. Nobody plans that progression, and it happens by copy-paste.
What to say instead
"Aligned with ISO/IEC 27001" is the honest and entirely respectable phrasing for an organisation that has built the management system and not yet certified. It says what you did, claims no external assessment, and nobody has ever been caught out by it.
Better still, be specific about where you are, because specificity reads as confidence rather than hedging. "We operate an ISMS aligned to ISO/IEC 27001 and are in our Stage 1 audit in November" tells a buyer far more than either "compliant" or "certified" would, and it gives them a date to plan around. Procurement teams deal with in-progress suppliers constantly; what they cannot work with is a claim that turns out to be softer than it sounded.
If you have controls but no management system, say that too. "We have implemented controls mapped to Annex A; we have not built a certifiable management system" is a real answer, and it is the answer a competent reviewer will reach anyway once they ask for your Statement of Applicability.
Claims that do not exist
Four appear regularly and all of them signal to an informed reader that the writer has not checked.
"SOC 2 certified" — SOC 2 is an attestation examination performed by a licensed CPA firm, producing a report containing an opinion. There is no certificate and no certification body.
"GDPR certified" or "DPDP certified" — compliance with a statute is a legal conclusion reached against the law, not a document anyone issues. You can be certified to ISO/IEC 27701, which builds the records that make demonstrating compliance straightforward, but that is a different sentence and worth writing as one.
"IAF certified" or "IAF approved" — the International Accreditation Forum neither certifies organisations nor accredits certification bodies. It runs the arrangement between accreditation bodies.
And "ISO certified", unqualified. ISO publishes many standards and certifies nothing itself. Name the standard, the edition and the certification body; the unqualified version is the phrasing used by people who bought a certificate without asking who stood behind it.
What a buyer does with your claim
Worth knowing, because it is more than most suppliers assume. A certificate number and a certification body are checkable in minutes through the body itself, its accreditation body’s register, or IAF CertSearch. Enterprise procurement teams do this routinely, and increasingly do it before the first call rather than during contracting.
They also read the scope statement, which is where most overclaiming actually unravels — not through a false certificate, but through a real one that covers a different part of the business from the service being bought.
So the practical advice is narrower than "be honest". It is: make the claim you can support, name the standard and edition, publish the scope, and if you are not certified say aligned and give a date. All four of those are easier than managing the alternative.
Common questions
What is the difference between ISO 27001 compliant and certified?
Certified means an accredited certification body audited your management system and issued a verifiable certificate with a scope and dates. Compliant means you have assessed yourself and concluded you meet the standard. Only the first is independent evidence.
Is it wrong to say we are ISO 27001 compliant?
Not dishonest if you genuinely meet the standard, but it is ambiguous — it reads to a buyer as certified. "Aligned with ISO/IEC 27001" says what you actually did and cannot be misread, which makes it the safer and equally respectable phrasing.
Can we say we are SOC 2 certified?
No. SOC 2 is an attestation examination by a licensed CPA firm and the output is a report with an opinion. There is no SOC 2 certificate or certification body, so the phrase describes something that does not exist and signals to informed readers that it was not checked.
Is there such a thing as GDPR certification?
No certificate establishes compliance with a statute — that is a legal conclusion reached against the law. ISO/IEC 27701 certification demonstrates a privacy management system and is recognised by customers asking, but it is not a finding of compliance with the GDPR or the DPDP Act.
What should we say while certification is in progress?
Be specific: an ISMS aligned to ISO/IEC 27001, with the audit stage and month you are booked for. Buyers handle in-progress suppliers routinely; what they cannot work with is a claim that turns out softer than it sounded.
How do buyers verify a certificate?
Through the certification body, the accreditation body’s public register, or IAF CertSearch, using the company name or certificate number. They also read the scope statement — which is where overclaiming usually unravels, via a real certificate covering a different part of the business.
The bottom line
Say certified only if you hold a certificate, and say aligned otherwise — it is honest, defensible and costs you nothing. Then name the standard, the edition and the certification body, and publish your scope, because the scope is what a careful buyer reads after the claim.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.
Choosing
SOC 2 or ISO 27001 first? A commercial question wearing a technical costume
Your pipeline decides this, not the frameworks — and the two produce very different things to hand a customer.
Choosing
Accredited and unaccredited certification are not the same product
Both produce a certificate. Only one carries independent oversight of the auditor — and it is checkable.