Certification Body
A certification body is an independent, third-party organization that reviews whether a business meets the requirements of a particular standard, such as an ISO standard, and issues a certificate when it does. It conducts the audits and manages the certification process rather than the company certifying itself. Choosing a certification body that is itself accredited generally makes the resulting certificate more credible and more widely trusted.
A certification body (CB), also called a certifying body, is an independent third-party organization that administers a certification process, provides guidance on the applicable standard and process, and conducts certification audits against defined requirements (for example, ISO standards). An accredited certification body has had its competence, impartiality, and adherence to the certification program assessed by an accreditation body; within the IAF framework, accreditation bodies conduct and administer programmes by which they accredit certification, validation, or verification bodies. Practitioners should distinguish the certification body (which performs conformity assessment and issues certificates) from the accreditation body (which assesses and accredits the certification body). Note that a virtual CISO or advisory engagement may support certification readiness and audit preparation, but it is the certification body, not the vCISO, that issues certification; the plain fact of certification does not itself guarantee ongoing security or breach prevention.
Why it matters
Certification is a common way for organizations to demonstrate to customers, partners, and regulators that their practices conform to a recognized standard such as an ISO standard. The credibility of that demonstration, however, depends heavily on who issued the certificate. A certification body that has itself been accredited has had its competence, impartiality, and adherence to the certification programme assessed by an accreditation body, which generally makes the resulting certificate more credible and more widely trusted. For security leaders, this distinction matters because a certificate from a non-accredited or self-declared source may carry far less weight with the very stakeholders it is meant to reassure.
A frequent point of confusion is the difference between the certification body and the accreditation body. The certification body performs the conformity assessment and issues the certificate; the accreditation body assesses and accredits the certification body itself. Within the IAF framework, accreditation bodies conduct and administer the programmes by which they accredit certification, validation, or verification bodies. Treating these two roles as the same, or assuming any organization calling itself a certification body carries equivalent authority, is a mistake an experienced buyer would want corrected before committing to an engagement.
Just as important is understanding what certification does and does not represent. The plain fact of certification does not itself guarantee ongoing security or prevent breaches; it attests that defined requirements were met at the point of assessment. Organizations that treat a certificate as a permanent security guarantee rather than a snapshot of conformity against a specific standard tend to underinvest in the continuous work that security governance actually requires. Certification should be read as evidence of conformity, not as proof of immunity from risk.
Who it's relevant to
Inside CB
Common questions
Answers to the questions practitioners most commonly ask about CB.