Information Security Management
ISO 27001 Certification UK: Options Explained
Achieving ISO 27001 certification demonstrates that your organisation takes information security seriously. ISO 27001 is an international standard for information security management systems (ISMS).
But before you start the audit process, you’ll need to decide what type of ISO 27001 certificate you actually want and which certification route is right for you.
In the UK, there are three main routes to claiming compliance with ISO 27001 (these routes relate to how organisations demonstrate alignment with ISO standards):
- UKAS-accredited certification
- Non-accredited certification
- Self-declared conformity
Each has a different level of credibility and recognition, and the choice can influence how customers, partners and regulators view your business. Read on to learn more.
Includes all the mandatory document templates — free, no commitment

What Is UKAS-Accredited ISO 27001 Certification?
UKAS (the United Kingdom Accreditation Service) is the government-appointed body responsible for accrediting certification bodies in the UK.
When a certification body is UKAS-accredited, it means they’ve been independently assessed to confirm they operate to recognised standards such as ISO/IEC 17021-1 — the global standard for auditing and certifying management systems. UKAS accreditation is an important factor in the credibility of ISO certification.
If you choose a UKAS-accredited certification body (for example, BSI, LRQA, NQA, Alcumus ISOQAR or BAB), your final ISO 27001 certificate will carry the UKAS crown and tick logo. That mark tells customers and regulators that:
- A competent, impartial auditor performed the audit.
- UKAS regularly assesses the certification body itself.
- Your certificate is recognised internationally under the IAF Multilateral Recognition Arrangement (MLA).
Why UKAS is important
For some organisations with very stringent client onboarding / due diligence, businesses working in regulated or supply-chain environments, or in government procurement, UKAS-accredited ISO 27001 certification is the only type accepted during procurement or due diligence reviews.
UKAS accreditation enhances the recognition of certifications and is crucial for organisations seeking certification to ISO standards. ISO 27001 certification applies specifically to an organisation’s information security management system, ensuring it meets internationally recognised ISO standards. UKAS-accredited certifications are often required in the public sector.
Accreditations Outside the UK
In the UK, ISO 27001 certificates issued by a UKAS-accredited certification body are widely accepted, including by larger customers and in formal procurement.
Outside the UK, UKAS itself matters less, but the same idea applies: buyers generally expect your auditor to be accredited by a recognised national accreditation body (for example, ANAB in the US, DAkkS in Germany, ENAC in Spain) that is part of the International Accreditation Forum (IAF).
Auditors Should Consult and Consultants Shouldn’t Audit.
Sadly, I’ve found over the years an increasing tendancy – even by UKAS auditors – to audit their own consultancy work. They’ll do this by saying ‘it’s another team’, but 27001 is very clear that independance should be maintained in audits, and therefore if you have a vested interest in the outcome, you should not be involved in the audit.
If you value a robust approach, and a certificate that means something to you, then I stronlgy suggest you find seperate auditors and consultants.
Non-Accredited ISO 27001 Certification

A non-accredited ISO 27001 certificate is issued by a certification body that isn’t accredited by UKAS (or any other national accreditation service).
These providers still conduct a certification process, including a certification audit and assessment, but without oversight by an accreditation body. So, the auditors aren’t getting audited.
In my experience, many, if not most, organisations function quite happily with non-accredited ISO 27001 auditors.
Why some organisations choose non-accredited certification
There are several good reasons to go down the non-accredited route, which include;
- Speed and cost: Non-accredited bodies can be substantially cheaper and more flexible with scheduling. The audit could be done in just one day.
- Historical data: The demand for historical data to evidence the operation of the ISMS can be lower. UKAS, for example, demands 3 months, minimum. Non-accredited auditors may say ‘if the mandatory components are there, then we’ll certify you, but need to see the data at the end of your first year’.
- Internal or contractual drivers: Some smaller companies want external validation without the need for formal UKAS recognition.
- Low regulatory pressure: If you don’t handle sensitive data or work with enterprise clients, a non-accredited certificate may be enough.
- Flexible services: Non-accredited providers may offer a range of services tailored to the needs of smaller organisations.
The risks:
- Some procurement teams won’t recognise a non-accredited certificate as evidence of compliance.
- Some clients will explicitly ask for a “UKAS-accredited certificate”.
- Certificates from non-accredited bodies can be perceived as “lightweight” or “unverified” — even if the audit work was of high quality.
When it’s acceptable:
Non-accredited certification can be a reasonable, quick option for startups or internal assurance exercises. These organisations have a reputation to maintain, so they don’t just give away certification.
ISO 27001 Coaching Programme
Get ISO 27001 certified in 90 days.
Fully remote. Fixed fee. Working with SMEs across the UK, EU and USA.
✔ Audit-ready plan with structured checkpoints
✔ Full toolkit + templates included
✔ Expert support throughout
Cancel any time
Pro-rata refund on unused sessions
✔ Defined scope, SoA and risk treatment
✔ Plain-English — no jargon
✔ Trusted auditor recommendations
First-pass guarantee
If you don’t pass, I fix it for free
“..no-nonsense help in achieving our UKAS-accredited ISO 27001 certification…”
– Periculum Security Group (UK)
Self-Declared Conformity
The third option is to simply declare that your organisation complies with ISO 27001 — without engaging an external auditor. This is quite acceptable in many circumstances, but it is also likely that your client will then ask for additional evidence of your ISMS (policies, write-ups, etc).
You can perform your own internal audit, document the results, and state publicly that you meet the requirements of the standard.
This is not a certification.
It’s essentially a self-assessment. A recognised body issues no independent verification or certificate. Organisations can use internal audits and gap analysis to identify areas for improvement and ensure their practices are aligned with ISO 27001.
When self-declaration can make sense:
- As a stepping stone before formal certification, to test readiness.
- For small internal teams or projects that don’t need a formal certificate but still want to follow ISO 27001 principles and best practices.
- When you simply want to communicate alignment without implying third-party validation.
- Maintaining alignment by conducting regular internal audits and following established practices is sufficient for your needs.
However, for tenders, contracts, or customer assurance processes, a self-declared ISMS will often not meet formal compliance requirements.
Which Type of ISO 27001 Certification Is Right for You?
| Type | Recognition | Cost | Typical Use Case | Accepted in Procurement? |
|---|---|---|---|---|
| UKAS-accredited certification | Highest (UK and international recognition) | Medium to high | Organisations handling sensitive data or working with enterprise clients | ✅ Yes |
| Non-accredited certification | Moderate (depends on provider reputation) | Lower | Small businesses seeking quick external validation | ⚠️ Sometimes |
| Self-declared conformity | Low (internal only) | Minimal | Early-stage businesses or pilot ISMS projects | ❌ No |
If your goal is to demonstrate compliance to customers, win new major contracts, or meet supply-chain requirements, UKAS-accredited certification is the safest choice. Choosing UKAS-accredited certification can provide a significant competitive advantage by simplifying regulatory compliance, helping your organisation attract and secure new business, and delivering long-term benefits through sustained trust and credibility with stakeholders.
However, for rapid certification, cost savings, and minimal disruption, a non-UKAS certificate can be very valuable. You can always move over to UKAS later.
UK-Based (UKAS-Accredited) ISO 27001 Certification Bodies
These organisations are UKAS-accredited, meaning their ISO 27001 certifications carry formal recognition under international accreditation standards.
| Certification Body | Accreditation | Website |
|---|---|---|
| BSI Group (British Standards Institution) | UKAS | https://www.bsigroup.com |
| LRQA (Lloyd’s Register Quality Assurance) | UKAS | https://www.lrqa.com |
| SGS UK | UKAS | https://www.sgs.co.uk |
| Alcumus ISOQAR | UKAS | https://www.alcumus.com/en-gb/ |
| NQA | UKAS | https://www.nqa.com |
| QMS International | UKAS (for some services) | https://www.qmsuk.com |
US-Based ISO 27001 Certification Bodies
In the US, certification bodies may be accredited by ANAB (ANSI National Accreditation Board) or similar. Some bodies also offer non-accredited ISO 27001 certifications for cost-sensitive or internal use cases.
| Certification Body | Accreditation | Website |
|---|---|---|
| BSI Group America | ANAB | https://www.bsigroup.com/en-US |
| Perry Johnson Registrars (PJR) | ANAB | https://www.pjr.com |
| TÜV SÜD America | ANAB | https://www.tuvsud.com/en-us |
| DNV (Det Norske Veritas) | ANAB | https://www.dnv.com |
| Intertek | ANAB | https://www.intertek.com |
| Schellman & Co. | ANAB (also known for SOC 2 audits) | https://www.schellman.com |
Tips When Choosing a Certification Body
- Check the UKAS website (ukas.com) to confirm your chosen body is genuinely accredited for ISO/IEC 27001.
- Ask for the accreditation scope — it should list ISO/IEC 27001 specifically.
- Compare audit proposals carefully; the cheapest quote isn’t always the most credible.
- Avoid “guaranteed pass” claims — a genuine audit should be impartial.
- Ask about auditor competence and industry experience — especially if you operate in a specialised sector.
- Ask about the level of support and training offered — find out how the certification body is experienced in helping organisations, supporting them throughout the certification process, and whether they provide accredited training or ongoing support to ensure a smooth journey.
Final Thoughts
There’s no single “right” way to demonstrate ISO 27001 compliance — but there is a right level of assurance for your audience.
If customers, regulators, or partners expect evidence of independent oversight, choose a UKAS-accredited certificate. It’s recognised internationally and will stand up to due diligence.
If you’re testing the waters or building internal confidence, a non-accredited or self-declared approach can be a useful interim step — just be transparent about what it represents.
To achieve certification and maintain certification, it is important to follow best practices and continuous improvement, and to familiarise yourself with the ISO 27001 certification process, including the required audits and ongoing compliance activities.
For guidance on selecting the right route or preparing for certification, explore my related ISO 27001 certification guides below.
Is UKAS certification a legal requirement for ISO 27001?
No, UKAS certification is not legally required. However, many clients—particularly in regulated sectors or government supply chains—will expect or require it. It’s more about market expectations and credibility than legal obligation.
Can I start with general certification and upgrade to UKAS later?
Yes, many organisations begin with a general certification to get the benefits of an ISO-aligned ISMS quickly, and then transition to a UKAS-accredited certification once they have more evidence and resources. However, you’ll need to undergo a full audit again when switching providers.
Will clients care if I don’t use a UKAS-accredited body?
That depends on your clients. Some will be satisfied with any form of ISO 27001 certification, while others—especially those in finance, healthcare, or government—may require UKAS or equivalent accreditation. Always check what your target market expects.
Does a non-UKAS certification mean I’m not compliant with ISO 27001?
Not necessarily. The certification process still follows ISO 27001 requirements, but without the added assurance that comes from an accredited certification body being regularly assessed by a national authority like UKAS. It’s still compliance—but with less external validation.
What’s the biggest risk of choosing the cheaper route?
The main risk is perception. If a potential client or partner checks your certificate and sees an accredited body didn’t issue it, they may question its legitimacy—even if your actual controls are solid. It can create a credibility gap in certain markets.
Includes all the mandatory document templates — free, no commitment