Ask certification bodies for quotes and the proposals come back sprinkled with "ISMS-AC accredited," "UKAS accredited." This is where most project owners stumble. What is the difference between accreditation and certification? Does a different accreditation body mean a different certificate?
The short answer: the standard is the same ISO/IEC 27001 in every case. What differs is who vouches for the competence of the certification body — and that difference shapes how your counterparties read your certificate.
This article covers the two-tier structure, the differences between the main accreditation bodies, what accreditation actually guarantees, and how to choose based on who your customers are. For the overall picture, see What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The handling of accreditation and certification, and each body's accredited scope, are governed by the publications of the accreditation and certification bodies themselves. Always verify current status at source.
Who Vouches for Whom
ISMS certification has three tiers.
| Tier | Name | Role | Examples |
|---|---|---|---|
| 1 | Accreditation body | Assesses the competence of certification bodies and accredits them; does not audit organisations itself | ISMS-AC (Japan), UKAS (UK), ANAB (US) |
| 2 | Certification body | Audits an organisation's ISMS and issues the certificate | BSI, JQA, Bureau Veritas, SGS, DQS |
| 3 | The certified organisation | Builds and operates the ISMS | You |
You contract with a certification body. You never deal with the accreditation body directly. The accreditation body's job is to check that the certification body audits properly.
The structure exists to prevent a certification body vouching for its own audit quality. Certificates issued by unaccredited bodies can physically exist, but nobody independent stands behind the audit that produced them. To a customer, an unaccredited certificate is one they have no way to verify.
Accreditation bodies are not isolated from one another either. The International Accreditation Forum (IAF) provides a mutual recognition framework under which participating bodies' accreditations are, in principle, treated as equivalent. ISMS-AC, UKAS, and ANAB all sit inside it.
How the Main Bodies Differ
| Body | Base | Character | Where it is read |
|---|---|---|---|
| ISMS-AC (Information Management System Accreditation Center) | Japan | Operates Japan's ISMS conformity assessment scheme; publishes a searchable register of certified organisations in Japanese | Procurement by Japanese hospitals, pharma, local government |
| UKAS | United Kingdom | The UK national accreditation body; well recognised across Europe and the Commonwealth | European customers, global SaaS vendor assessments |
| ANAB | United States | The US accreditation body; well recognised in North America | US counterparties, US investor due diligence |
The requirements are the same ISO/IEC 27001 in all three cases. What the audit looks at does not change materially by accreditation body. Two things do differ:
- Verifiability of the register. ISMS-AC publishes certified organisations in Japanese, so a Japanese buyer can check you easily
- Familiarity of the mark. A UKAS mark needs no explanation to a British or European reviewer; ISMS-AC does. And the reverse is equally true
So the criterion is not the content of the standard but who reads the certificate.
On choosing the certification body itself, see Choosing a Certification Body and Comparing the Major Certification Bodies.
What Accreditation Actually Guarantees
"If an unaccredited certificate is cheaper, why not?" is a fair question. Here is what accreditation underwrites.
- Auditor competence requirements. Accredited bodies are externally checked on auditor qualifications, experience, and continuing development
- Reasonableness of audit effort. The framework sets expectations for auditor-days relative to headcount and scope, making implausibly short audits hard to sustain
- Independence of the certification body. Requirements exist to avoid conflicts of interest, such as the same party doing consulting and certification
- An appeals route. If you dispute an audit outcome, there is a tier above the certification body
In practice the second point bites harder than the fourth. A certificate obtained through an unaccredited audit at a fraction of the usual effort tends to get picked apart during a customer's security review. Auditor-days and scope statements on a certificate are exactly what a reader inspects.
And the most overlooked item is the scope written on the certificate. Whatever the accreditation body, a scope that diverges from reality will not persuade anyone. Does it say "whole company," or is it confined to one service? Customers read that line. See Defining ISMS Scope.
Choosing by Who Your Customers Are
Count the people who will read the certificate.
| Customer mix | Recommendation | Why |
|---|---|---|
| Mostly Japanese hospitals, pharma, government | A body accredited by ISMS-AC | Easiest for domestic buyers to verify from public records |
| Domestic now, overseas planned | ISMS-AC primarily, but choose a body that can also issue under an overseas accreditation | Switching certification bodies later is costly |
| Real European customers | A UKAS-accredited certificate alongside | No explaining required to European procurement |
| US counterparties or investors | An ANAB-accredited certificate alongside | Smoother North American due diligence |
"Alongside" is the operative word: internationally active certification bodies often hold multiple accreditations. Which accreditations a given body can issue under varies, so ask at the quotation stage — it belongs on the must-ask list for competitive quotes.
If overseas expansion is the driver, note that some counterparties will ask for SOC 2 rather than ISMS — see ISMS vs SOC 2. And if cloud add-ons (ISO 27017 and 27018) or the privacy extension (ISO 27701) are on the roadmap, check that the body can audit those too, to avoid having to switch later.
For how hospitals read supplier certifications, see Security Check Sheets for Vendors and The Three-Ministry Guidelines.
Conclusion
- ISMS certification is three tiers: accreditation body → certification body → your organisation. You contract with the middle one
- ISMS-AC, UKAS, and ANAB all certify against the same ISO/IEC 27001; recognition and verifiability are what differ
- Accreditation underwrites auditor competence, plausible audit effort, independence, and an appeals route
- Customers read more than the accreditation name — the scope on the certificate must match reality
- Choose by who reads the certificate: ISMS-AC domestically, UKAS for Europe, ANAB for North America
- In competitive quotes, always confirm which accreditations a body can issue under and whether it can audit future add-ons (27017/27018/27701)
Pottech supports ISMS certification with a focus on healthcare. For certification body selection we obtain and compare competitive quotes — including from JUSE, JSA-SOL, and ICMS — and lead the project from scope design through the audit itself.
See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- United Kingdom Accreditation Service (UKAS)
- ANSI National Accreditation Board (ANAB)
- International Accreditation Forum (IAF)
- ISO/IEC 27001 Information security management systems | ISO
Note: accredited scopes and scheme rules change. Always confirm what a certification body can issue against its own published material and its quotation.