Back to Columns
ISMS & Certification10 min read

Comparing the Main Certification Bodies: BSI, JQA, BV, SGS, DQS

September 14, 2026

Comparing the Main Certification Bodies: BSI, JQA, BV, SGS, DQS
Share this article

Once you reach the point of choosing a certification body, the first thing you want is a list of candidates. Several bodies audit to ISO/IEC 27001 in Japan, each with its own typical client size and audit style. Comparing their websites, however, rarely surfaces the differences that actually matter to a decision.

This article sets out the accreditations and distinguishing characteristics of five bodies commonly shortlisted, then shows how to narrow the field from your own requirements. It does not quote prices. Audit fees depend on in-scope headcount, number of sites, and business complexity, so "this body is cheap" is not a statement that can hold generally. Confirm figures through comparative quotes.

For the selection procedure itself see How to Choose a Certification Body; for the cost structure, The Full Cost of ISMS Certification.

Disclaimer: This article is general information. Each body's accreditation status, services, and fees are subject to change, and the bodies' own publications and those of the accreditation bodies are authoritative.

The Premise: An Accredited Certificate Is an Accredited Certificate

Where a body holds accreditation, the certificate it issues carries the same force as any other. It is not normal for a customer to say a particular body's certificate is insufficient.

In Japan the accreditation body for ISMS certification is ISMS-AC (Information Management System Accreditation Center). Some certification bodies also hold overseas accreditations such as UKAS (UK) or ANAB (US). That combination matters mainly when presenting the certificate to an overseas customer or parent company — see ISMS-AC, UKAS and ANAB.

The comparison below is therefore not about which body is better. It is about which fits your circumstances.

The Five Bodies at a Glance

Certification bodyAccreditationCharacteristics
BSI Group JapanISMS-AC & ANABThe world's oldest national standards body; originator of the draft that became ISO 27001, with extensive experience
JQA (Japan Quality Assurance Organisation)ISMS-AC & UKASA major domestic body; over 70% of its registrations are organisations of 100 people or fewer, giving it startup familiarity
Bureau Veritas JapanISMS-ACSpecial pricing for referred companies; flexible on compressed timelines and scheduling
SGS JapanISMS-ACAround 140 years of history; a track record across all sizes, centred on startups
DQS JapanISMS-ACAuditors who are practising IT engineers; audits weighted toward how work actually flows

These are the bodies Pottech obtains comparative quotes from as part of its ISMS support. Other strong options exist (see below).

Reading the Characteristics

Each line in that table points at a different selection criterion.

BSI Group Japan (ISMS-AC & ANAB)

The world's oldest national standards body, and the originator of the draft that became ISO 27001. Having been involved in how the standard came about is reassuring where interpretation of requirements becomes the point of discussion.

Its accreditation combines ISMS-AC and ANAB. Since ANAB is the US accreditation body, this combination is easier to explain where you trade with, or expand into, the United States.

JQA (ISMS-AC & UKAS)

A major domestic body. Its notable characteristic is that more than 70% of its registered organisations have 100 people or fewer — small organisations are the norm for it, not the exception, which implies accumulated familiarity with startups and small teams.

Few people, roles held concurrently, no dedicated security hire: these are ordinary conditions in a small organisation. A body that treats them as the starting point reduces how much you must explain on the day. See ISMS for Small Organisations.

Its accreditation combines ISMS-AC and UKAS, the UK accreditation body — relevant where you have European counterparties.

Bureau Veritas Japan (ISMS-AC)

Its noted characteristic is flexibility on compressed timelines and scheduling. Because audit slots fill first-come, where your certification date is fixed by a commercial deadline, scheduling flexibility becomes the effective selection criterion.

It also offers special pricing for referred companies, meaning terms can differ when applying via a support partner — worth raising when you request quotes.

SGS Japan (ISMS-AC)

A body with around 140 years of history and a track record across organisation sizes, centred on startups. Covering a wide range of sizes matters if your scope and headcount will grow: you can stay with the same body as you scale.

Certification runs on a three-year cycle, so it is worth asking whether a body has experience at the size you expect to be in three or six years.

DQS Japan (ISMS-AC)

Its characteristic is the auditors: practising IT engineers, running audits weighted toward how work actually flows.

That matters if your development organisation is in scope. CI/CD pipelines, cloud permission design, logging practice — these are areas where documentation alone conveys little of the reality. Auditors with a technical background spend less time on background and tend to return findings at an implementable level of detail. See Reading the 34 Technological Controls.

Other Bodies

The five above are examples. Other bodies audit to ISO/IEC 27001 in Japan, and you can also obtain and compare quotes from JUSE (Union of Japanese Scientists and Engineers), JSA-SOL, and ICMS, among others.

There is no need to limit yourself to five. Widen the field if:

  • You want a body strong in a particular sector or technology area
  • Your site locations mean travel costs differ materially between bodies
  • You want to consolidate with the body already handling another certification (ISO 9001, for example)
  • Slot availability in your target month is the binding constraint

In practice, requesting from about three bodies, mixing different accreditation combinations, is a manageable size of exercise.

Narrowing From Your Own Conditions

Your situationWhat to weight
Showing the certificate to a US customer or parentWhether US accreditation (ANAB) is also held
European counterpartiesWhether European accreditation (UKAS) is also held
Domestic business onlyISMS-AC is sufficient; prioritise other factors
Fewer than 50 peopleExperience with small organisations; understanding of concurrent roles
Certification date fixed by a commercial deadlineSlot availability, support for compressed timelines
Development organisation in scopeTechnical background of the auditors
Headcount or sites growing significantlyBreadth of experience at larger sizes
Handling medical informationFamiliarity with healthcare and the three-ministry guidelines

The last row is specific to healthcare. Hospital customers may ask about three-ministry guideline compliance alongside ISMS certification, and the handling of medical information comes up during the audit itself. See Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Guidelines.

You do not need a body that satisfies every row. If your top two conditions are met, deciding on cost and scheduling from there is perfectly reasonable.

Why No Prices Appear Here

Everyone wants to know which body is cheapest, and no general figure can be given, because audit fees follow:

  • In-scope headcount
  • Number of sites in scope
  • Complexity of activities (development, operations, data centre management)
  • Whether the audit is integrated with other certifications

Within the same body, a 30-person single-site company and a 200-person three-site company differ by an order of magnitude. Conversely, request quotes from several bodies on identical assumptions and the relative levels for your conditions become perfectly clear. Fees are not something to look up; they are something to have quoted.

Application and registration fees, travel, and annual maintenance fees may also be billed separately. See How to Choose a Certification Body and Audit Fee Benchmarks and What Moves Them.

Conclusion

  1. An accredited body's certificate has the same force as any other — compare for fit, not for rank
  2. What differs in accreditation is ISMS-AC alone versus ISMS-AC plus UKAS or ANAB, which matters according to your overseas exposure
  3. The five characteristics can be read as standards heritage (BSI), small-organisation familiarity (JQA), scheduling flexibility (BV), experience across sizes (SGS), and technically grounded auditors (DQS)
  4. JUSE, JSA-SOL, ICMS and others are also candidates — five is not a closed list
  5. Narrow from your own conditions: overseas exposure, organisation size, timing constraints, whether development is in scope
  6. Actual fees emerge only from comparative quotes — request from about three bodies on identical assumptions

Pottech obtains comparative quotes from the bodies above as part of its ISMS certification support and helps you choose one that fits your size and priorities (fees vary with headcount and other factors). We can also obtain and compare quotes from other bodies including JUSE, JSA-SOL, and ICMS.

See ISMS Certification Support for scope and pricing, or contact us. For the wider picture, see What Is an ISMS (ISO/IEC 27001)?.

References and Sources

Note: each body's accreditation status and services are subject to change; confirm current details in their own publications and those of the accreditation bodies. Fees vary substantially with organisation size, scope, and body.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.