Choosing a certification body is a decision that gets left late and then rushed. It matters more than most organisations realise. The certification body affects audit cost, audit timeline, auditor interpretation of the standard, and whether your certificate is accepted in the procurement frameworks you actually need it for.
This article sets out the UKAS accreditation question, the major UK certification bodies, the factors that should drive your shortlist, and what to ask in initial conversations.
The UKAS question
The single most important decision is whether to use a UKAS-accredited certification body or a non-accredited one. The difference matters and is easy to miss.
UKAS, the United Kingdom Accreditation Service, is the national accreditation body for the UK, appointed by the UK government. UKAS independently assesses certification bodies against the international standard for certification bodies, ISO/IEC 17021-1. A certification body holding UKAS accreditation has been independently verified for auditor competence, process integrity, and impartiality. Their certificates carry the UKAS crown and tick mark alongside the certification body's own logo.
A UKAS-accredited certificate is recognised internationally through the IAF Multilateral Recognition Arrangement, meaning it is accepted as equivalent to certificates issued by accredited bodies in other countries.
A non-UKAS-accredited certificate is issued by a certification body that has not been independently assessed. The audit may have been conducted competently, but there is no independent oversight of the certification body itself. Non-accredited certification is significantly cheaper and faster, sometimes a one-day audit instead of two-stage Stage 1 and Stage 2.
The acceptance pattern is the practical question. Several procurement frameworks specifically require UKAS-accredited certification.
UK government contracts typically require UKAS-accredited certification. Government procurement frameworks generally expect this baseline.
NHS procurement requires UKAS-accredited certification for ISO 27001. The Data Security and Protection Toolkit assumes accredited certification.
Defence supply chain procurement, particularly for organisations bidding into prime contractors, expects UKAS-accredited certification. Non-accredited certificates may not satisfy JOSCAR-driven assurance requirements.
Financial services and regulated enterprise customers increasingly specify UKAS-accredited certification in supplier security questionnaires.
If you are pursuing ISO 27001 to satisfy a customer or procurement requirement, the question is not whether UKAS accreditation matters in general; it is whether your specific buyers require it. Read their procurement specifications carefully. The cost of getting non-UKAS certification only to discover it does not satisfy the buyer is meaningfully higher than the cost difference between UKAS and non-UKAS certification.
The major UK UKAS-accredited certification bodies
The UKAS register at ukas.com is the authoritative source. Several bodies are well-established and worth shortlisting depending on your sector and scale.
BSI (British Standards Institution). The largest UK body and the body that wrote much of the foundational work that became ISO 27001. BSI's certification carries strong recognition in regulated sectors and government supply chains. Pricing is at the higher end, but the brand recognition matters in some procurement contexts.
LRQA (formerly Lloyd's Register Quality Assurance). Internationally recognised with roots in marine and industrial inspection and substantial information security practice. Strong fit for safety-critical sectors, energy, maritime, and engineering.
Bureau Veritas. International certification body with significant UK presence and sector depth in manufacturing, energy, and infrastructure.
NQA. UK-focused certification body with a large SME customer base and competitive pricing. Strong in IT services and professional services sectors.
Alcumus ISOQAR. Established UK body serving a broad range of sectors including professional services, healthcare, and technology. Often a good fit for SMEs and mid-market organisations.
British Assessment Bureau (BAB). UK-focused mid-market body with a digital-first audit experience and SME-friendly pricing.
SGS. One of the world's largest inspection and certification companies with UKAS accreditation for ISO 27001. International recognition strong, although audit approach can be more formal.
Intertek. Global certification body with UKAS accreditation, often a fit for organisations with international operations.
QMS International and Amtivo (formerly Socotec). Mid-market UK options worth shortlisting for SMEs.
This list is not exhaustive and the landscape changes. Always verify current accreditation against the UKAS register.
What to compare
Once you have a UKAS-accredited shortlist, the differentiators are audit approach, sector depth, pricing, and commercial terms. Five comparison factors are worth working through.
Audit fees. Get quotes from two or three bodies. Certification body audit fees are quoted per engagement rather than published, so the only reliable number is the one on a written quote. Compare what is included. Some quotes include corrective action verification, others charge for it separately.
Sector expertise. Does the body have auditors with experience in your sector? A defence supply chain SME and a fintech have different control environments. An auditor familiar with the sector will produce a more useful audit and waste less time on contextual onboarding.
Auditor continuity. Will you get the same lead auditor across Stage 1, Stage 2, and surveillance? Continuity reduces friction in subsequent audits. Some bodies rotate auditors more aggressively than others.
Audit flexibility. How does the body handle minor nonconformity closure? What is their process for disputes? What happens if your business changes scope mid-cycle? Ask before committing.
Surveillance approach. Years 2 and 3 surveillance audits and the year 3 recertification audit cost more in total than Stage 1 plus Stage 2 combined. The full three-year cost matters more than the initial fee.
A practical approach: shortlist three UKAS-accredited bodies that fit your sector and scale, request fee quotes covering the three-year cycle from each, and have a 30-minute conversation with each before deciding. The conversation itself is informative. A body that is responsive, clear, and substantive in pre-engagement is usually responsive, clear, and substantive in audit.
When to engage your certification body
Senior practitioners engage their certification body earlier than most organisations expect. The reasoning is practical. Certification bodies are sometimes booked four to eight weeks ahead, particularly for Stage 1 audits at year-end or quarter-end. An organisation that completes its implementation in 16 weeks but cannot get a Stage 1 slot for another 8 weeks has effectively added 50% to its certification timeline.
Engaging the certification body in week 6 to 8 of a 16-week implementation, before the implementation is complete but with a clear timeline, locks in a Stage 1 date that aligns with implementation completion. Most certification bodies are comfortable with this approach, and several offer pre-Stage 1 engagement support that can identify issues earlier.
Verifying accreditation
Two checks before signing.
Visit ukas.com and use the organisation search. Confirm the body holds UKAS accreditation specifically for ISO/IEC 27001 management system certification. Some bodies hold UKAS accreditation for quality management (ISO 9001) but not for information security management. The scope of accreditation matters.
Check the certification body's own register of issued certificates. Most accredited bodies maintain a publicly searchable register. Searching by company name confirms a specific certificate is live and not suspended or withdrawn.
A common procurement mistake is accepting a certificate without verifying current status. Certificates that were valid when last provided may have lapsed or been suspended. Always verify through the UKAS register or the certification body's own register rather than relying on a copy of a certificate provided by a supplier.
Closing thought
The certification body is not the most important decision you will make in your ISO 27001 journey. The implementation work matters more. But it is a decision that affects cost, timeline, and certificate acceptance, and the wrong choice can add months to your certification programme.
Take the decision seriously. Shortlist UKAS-accredited bodies. Verify accreditation against UKAS. Get quotes covering the three-year cycle. Have a substantive conversation with each before deciding.
Goldline Consultancy is led by an ISO 27001 Lead Implementer (PECB) and ISO 42001 Lead Implementer and Lead Auditor (PECB), SC-cleared, and delivers ISO 27001 implementation as a fixed-scope engagement. We work with all major UKAS-accredited certification bodies and can advise on certification body selection alongside implementation. Take our free ISMS maturity self-assessment or book an ISO 27001 diagnostic call.
