
If you need an accredited ISO/IEC 27001 certification body operating in the United States, the shortlist below covers the most widely recognized options. Each holds accreditation from ANAB (ANSI National Accreditation Board) or another IAF-member body, which is the baseline requirement for any certificate enterprise procurement teams and regulated buyers will actually accept.
Your immediate shortlist of ANAB-recognized ISO 27001 certification bodies in the USA:
- Schellman & Co. — ANAB-accredited, US-headquartered, strong in cloud/SaaS and FedRAMP-adjacent scopes
- A-LIGN — ANAB-accredited, US-based, known for bundling ISO 27001 with SOC 2 and HITRUST
- Coalfire — ANAB-accredited, US-headquartered, deep experience in government, FedRAMP, and financial services
- BSI Group — UKAS-accredited (IAF MLA signatory), global network with strong US presence and multi-site scope capability
- Bureau Veritas — COFRAC/UKAS-accredited (IAF member), broad industry coverage, US offices nationwide
- DNV — ANAB-accredited, strong in energy, maritime, and critical infrastructure sectors
- SGS — ANAB-accredited, global reach, competitive pricing for mid-market organizations
- Intertek — ANAB-accredited, US presence, particularly active in manufacturing and consumer goods
- TÜV Rheinland — DAkkS-accredited (IAF member), US operations, documented impartiality and conflict-of-interest safeguards
- Lloyd’s Register — UKAS-accredited (IAF member), strong in regulated industries and critical infrastructure
Recommended next step: Look up each shortlisted body in the ANAB directory, confirm the scope of accreditation matches your planned certification scope, then request quotes from two or three of them. Before you contact any CB, run a free 2-minute readiness check with Ismscalculator so you know where your ISMS gaps are before the auditor does.
Key Takeaways
Choosing an accredited ISO 27001 certification body in the US requires verifying ANAB or IAF-member accreditation, confirming the scope matches your planned certification, and checking the lead auditor’s sector experience before signing any contract.
| Point | Details |
|---|---|
| ANAB accreditation is the baseline | Only use CBs listed in the ANAB directory or accredited by another IAF MLA-signatory body. |
| Auditor experience beats brand name | Always request the lead auditor’s CV and sector references before committing to a CB. |
| Conflict-of-interest policy matters | Confirm the CB separates consulting from certification; ask for the policy in writing. |
| Three-year certificate with annual surveillance | Certificates are valid for three years; plan for surveillance audits at years one and two. |
| Ismscalculator for pre-audit budgeting | Run a readiness assessment on Ismscalculator to estimate scope, cost, and gaps before contacting CBs. |
Table of Contents
- Which ISO 27001 certification bodies serve US organizations?
- How do you choose the right certification body for your organization?
- What does the ISO 27001 certification process look like in the US?
- How do you verify a certification body’s accreditation and a company’s certificate?
- How we vetted this shortlist
- What actually matters when picking a certification body
- Plan your ISO 27001 budget before you contact a certification body
- Primary sources and directories for accreditation verification
- Sources
Which ISO 27001 certification bodies serve US organizations?
The table below compares each provider across the criteria that matter most when selecting an ISO 27001 certifying organization in the USA. Only accredited certification bodies can issue valid ISO 27001 certificates, so accreditation body and scope appear first.
| Provider | Accreditation | US Presence | Industry Specialisms | Services Beyond ISO 27001 | Conflict-of-Interest Policy |
|---|---|---|---|---|---|
| Schellman & Co. | ANAB | HQ: Tampa, FL | Cloud/SaaS, FedRAMP, financial services | SOC 2, FedRAMP, PCI DSS | Published separation policy |
| A-LIGN | ANAB | HQ: Tampa, FL | Healthcare, SaaS, fintech | SOC 2, HITRUST, PCI DSS | Published separation policy |
| Coalfire | ANAB | HQ: Westminster, CO | Government, FedRAMP, financial services | FedRAMP, PCI DSS, CMMC | Published separation policy |
| BSI Group | UKAS (IAF MLA) | Multiple US offices | Manufacturing, finance, healthcare | ISO 27701, ISO 9001 | Documented impartiality policy |
| Bureau Veritas | COFRAC/UKAS (IAF) | US offices nationwide | Manufacturing, energy, logistics | ISO 9001, ISO 14001 | Documented impartiality policy |
| DNV | ANAB | US offices, Houston TX hub | Energy, maritime, critical infrastructure | ISO 9001, ISO 14001 | Documented impartiality policy |
| SGS | ANAB | US offices nationwide | Mid-market, manufacturing, food | ISO 9001, ISO 14001 | Documented impartiality policy |
| Intertek | ANAB | US offices nationwide | Manufacturing, consumer goods, retail | ISO 9001, ISO 14001 | Documented impartiality policy |
| TÜV Rheinland | DAkkS (IAF MLA) | US HQ: Newtown, CT | Automotive, IT, healthcare | ISO 27701, ISO 9001, functional safety | Minimum interval rules between consulting and certification |
| Lloyd’s Register | UKAS (IAF MLA) | US offices, Houston TX hub | Energy, marine, rail, regulated industries | ISO 9001, ISO 14001 | Documented impartiality policy |
Provider profiles
Schellman & Co. is one of the few US-headquartered firms that built its entire practice around cybersecurity and privacy assessments. Its auditors typically carry deep cloud architecture knowledge, which matters when your ISMS scope covers AWS, Azure, or GCP environments. ANAB-accredited for ISO/IEC 27001:2022.
A-LIGN built its reputation on combining ISO 27001 with SOC 2 in a single engagement, cutting audit fatigue for SaaS companies that need both. If your customers ask for SOC 2 Type II and ISO 27001 simultaneously, A-LIGN’s bundled approach is worth pricing out. ANAB-accredited.
Coalfire is the go-to for organizations pursuing FedRAMP authorization alongside ISO 27001. Its auditor bench has significant federal compliance depth, and it handles multi-framework programs without treating each standard as a separate silo. ANAB-accredited.
BSI Group brings the widest global footprint of any body on this list. For organizations with operations in Europe or Asia-Pacific, BSI’s UKAS accreditation (an IAF MLA signatory) is recognized across those markets without requiring a separate local certification. Multi-site scopes are a particular strength.
Bureau Veritas covers the broadest industry range. If your organization needs ISO 27001 alongside ISO 9001 or ISO 14001, Bureau Veritas can run integrated audits, which reduces scheduling complexity and often lowers total cost.
DNV is the strongest choice for energy, utilities, and maritime organizations. Its US hub in Houston reflects where its client base sits. Less relevant for pure-play SaaS companies, but hard to beat for critical infrastructure scopes.
SGS tends to offer competitive pricing for mid-market organizations and has the geographic spread to cover multi-site US operations. Auditor experience varies by region, so ask specifically for a lead auditor CV during the RFP.
Intertek is active in manufacturing, consumer goods, and retail. Its integrated assurance model works well for organizations that already use Intertek for product testing or quality audits and want to consolidate vendor relationships.
TÜV Rheinland publishes specific rules on the minimum interval required between any consulting engagement and a certification audit for the same client, which is one of the clearest conflict-of-interest policies on this list. DAkkS-accredited (IAF MLA), so certificates are recognized across the EU and beyond.
Lloyd’s Register has a long track record in regulated industries where auditor credibility carries weight with regulators. Its UKAS accreditation and sector depth in energy and rail make it a natural fit for organizations in those verticals.
Pro Tip: If you need ISO 27701 (privacy information management) alongside ISO 27001, ask each CB whether they can run both audits concurrently. BSI, TÜV Rheinland, and A-LIGN all offer bundled ISO 27001 + ISO 27701 programs, which can save several audit days and weeks of scheduling overhead.

How do you choose the right certification body for your organization?
Accreditation is the non-negotiable starting point. A certificate from an unaccredited body is not recognized by enterprise procurement teams or regulated buyers, and industry practitioners consistently flag this as the primary market risk. Once you confirm ANAB or equivalent IAF-member accreditation, the decision comes down to five factors.
1. Accreditation scope matches your planned scope. A CB’s accreditation certificate covers specific activities and, in some cases, specific industry sectors. If your ISMS scope includes cloud services or healthcare data, confirm the CB’s accreditation explicitly covers those activities. A mismatch means the certificate may not be recognized for your intended use case.
2. Auditor experience in your sector. Ask for the lead auditor’s CV before you sign anything. A lead auditor who has certified ten SaaS companies understands the control environment; one who primarily audits manufacturing plants may struggle with your cloud-native architecture. The CB’s brand name does not guarantee the individual auditor’s depth.
3. Conflict-of-interest policy. Accreditation bodies prohibit CBs from certifying clients they have also consulted for. Ask directly: “Has any entity within your organization provided ISO 27001 consulting to us or to a related entity?” Some firms, like CBIZ, publish explicit rules stating that one business unit will not certify a client that received consulting from another CBIZ unit. That level of transparency is a good sign.
4. Geographic coverage. If you have multiple US sites or international offices in scope, confirm the CB can staff auditors at each location without subcontracting to an unaccredited partner. Multi-site audits require careful scoping, and the CB’s accreditation must cover all sites.

5. Pricing model and audit day estimates. Most CBs price by audit days, which scale with scope complexity, number of employees, and number of sites. Get a written estimate of audit days for Stage 1 and Stage 2 separately, not a blended total. That breakdown lets you compare quotes accurately.
Questions to ask during the RFP
- What is your ANAB (or equivalent) accreditation ID, and can you send the scope of accreditation document?
- Who will be the lead auditor, and can I see their CV and sector experience?
- Can you provide references from clients in our industry who completed certification in the past 18 months?
- How do you handle major non-conformances found during Stage 2, and what is the typical remediation timeline?
- What is your surveillance audit cadence, and are surveillance audits conducted on-site or remotely?
- Do any entities within your group provide ISO 27001 consulting services, and how is that conflict managed?
Red flags to avoid
- No ANAB listing or inability to provide an accreditation ID on request
- Offering to provide both implementation consulting and the certification audit for the same engagement
- Vague scope of accreditation that does not match your industry or activities
- Unusually short audit timelines that do not align with your organization’s size and complexity
- Pressure to sign before you have reviewed the lead auditor’s qualifications
For SaaS and tech companies specifically, the ISO 27001 for SaaS guide on Ismscalculator covers the control areas where cloud-native organizations typically face the most scrutiny during Stage 2.
What does the ISO 27001 certification process look like in the US?
The ISO 27001 certification process follows a two-stage audit sequence, after which the certificate is valid for three years with annual surveillance audits. Here is how the stages break down and what drives the timeline.
The two audit stages
Stage 1 (documentation review): The auditor reviews your ISMS documentation, including the scope statement, risk assessment methodology, Statement of Applicability, and key policies. This stage is typically conducted remotely and takes one to three days depending on scope complexity. The auditor issues a Stage 1 report identifying gaps before Stage 2 begins. Most organizations need four to eight weeks between Stage 1 and Stage 2 to close documentation gaps.
Stage 2 (implementation audit): The auditor tests whether your controls are actually implemented and operating effectively, not just documented. This involves interviews with staff, evidence review, and observation. Stage 2 typically runs two to five days on-site. A successful Stage 2 results in a certification decision; major non-conformances require remediation and a follow-up audit before the certificate is issued.
Certificate lifecycle
| Phase | Timing | What happens |
|---|---|---|
| Stage 1 audit | Early in the audit process | Documentation review; gap report issued |
| Stage 2 audit | Weeks after Stage 1 | Implementation audit; certification decision |
| Certificate issued | Shortly after Stage 2 pass | Certificate valid for a multi-year period |
| Surveillance audits | Annual intervals | Spot-checks and broader controls review |
| Recertification audit | At the end of the certification cycle | Full re-audit; resets the certification period |
Cost drivers and typical ranges
Audit cost scales primarily with audit days, and audit days scale with scope. The main variables are:
- Number of employees in scope (more people means more interviews and evidence)
- Number of sites (each site adds audit days)
- Scope complexity (cloud services, regulated data, and multi-framework requirements all add days)
- Auditor day rate (varies by CB and auditor seniority)
- Travel costs for on-site stages
For a detailed breakdown of what drives ISO 27001 certification cost, Ismscalculator’s cost guide covers the typical ranges by company size and industry. Book your CB slot early: most reputable bodies have lead times of eight to sixteen weeks for Stage 1 scheduling, and aligning audit dates with your implementation timeline matters more than most organizations expect. The ISO 27001 implementation timeline guide on Ismscalculator walks through how to sequence implementation phases against audit windows.
How do you verify a certification body’s accreditation and a company’s certificate?
Checking accreditation takes about ten minutes and protects you from a costly mistake. Here is the exact sequence.
Step-by-step verification checklist
- Get the CB’s ANAB accreditation ID. Ask the CB directly for their ANAB accreditation number. Any legitimate CB will provide this without hesitation.
- Search the ANAB directory. Go to the ANAB ISO/IEC 27001 CB directory and search by the CB’s name or accreditation ID. Confirm the CB appears as currently accredited, not suspended or withdrawn.
- Download the scope of accreditation. The ANAB listing includes a downloadable scope document. Confirm it covers ISO/IEC 27001 (not just ISO 9001 or another standard) and that the scope of activities matches your planned certification scope.
- Confirm ISO/IEC 27006 compliance. CBs performing ISO 27001 certification must comply with ISO/IEC 27006, which sets the requirements for bodies providing audit and certification of information security management systems. Ask the CB to confirm this in writing.
- Check the certificate itself. A valid ISO 27001 certificate should show: the full standard reference ISO/IEC 27001:2022, the CB’s name and accreditation mark, the certified organization’s name and scope statement, issue date and expiry date, and a unique certificate number.
- Cross-reference the accreditation mark. The certificate should carry the accreditation body’s mark (ANAB, UKAS, DAkkS, etc.) alongside the CB’s own mark. A certificate with only the CB’s logo and no accreditation mark is a warning sign.
What to watch for in certificates
- Scope statements that are vague (“all information security activities”) rather than specific to the organization’s actual services and locations
- Expiry dates that have passed or surveillance audit dates that were missed
- A standard reference that reads “ISO 27001” without the “IEC” designation or without the “:2022” version number
- No accreditation body mark on the certificate face
Pro Tip: Ask the CB for their ANAB accreditation ID before your first call, then verify it yourself in the ANAB directory before the meeting. It takes three minutes and immediately tells you whether you are dealing with a legitimate body. If a CB hesitates or cannot provide the ID, that is your answer.
Frank, Rimerman is an example of a US firm that publicly cites its ANAB accreditation in its ISO/IEC 27001 service materials, treating accreditation as evidence of independent assessment competence rather than a footnote. That transparency is the standard to hold every CB to.
How we vetted this shortlist
Every body on this list was evaluated against the same criteria before inclusion.
Data sources checked:
- ANAB’s searchable directory of accredited management systems certification bodies
- National accreditation body directories for IAF MLA signatories (UKAS, DAkkS, COFRAC, JAS-ANZ)
- Each CB’s publicly available scope of accreditation document
- Each CB’s published conflict-of-interest and impartiality policies
- Provider websites for US office locations and stated industry specialisms
Inclusion rules:
- Accreditation by ANAB or another IAF MLA-signatory national accreditation body is required; no exceptions
- The CB must operate in the United States with the ability to staff US-based auditors
- The CB must publish or provide on request a conflict-of-interest policy that separates consulting from certification
- The CB must reference ISO/IEC 27001:2022 (not an outdated version) in its current service materials
- CBs that both consult and certify the same client without documented separation controls are excluded
Limitations: Accreditation status can change. ANAB may suspend or withdraw accreditation between our checks. Always verify current accreditation status in the ANAB directory before signing a contract, regardless of what any article states. This list was verified against publicly available accreditation records; it is not a real-time feed.
What actually matters when picking a certification body
The market for ISO 27001 certification bodies in the US has grown significantly, and the range of options can make the decision feel more complicated than it needs to be. Here is the honest version.
Accreditation is the floor, not the differentiator. Every body on this list clears that bar. The real decision happens at the auditor level, not the brand level. A well-known global CB with an inexperienced lead auditor will give you a worse audit than a smaller regional body with a seasoned practitioner who has certified twenty companies in your sector. Ask for the lead auditor’s CV every time, without exception.
The second thing most organizations underweight is the conflict-of-interest question. It sounds procedural, but it has real consequences. A CB that also sells consulting services has a financial incentive to find fewer non-conformances during the audit, because a clean audit protects the consulting relationship. The firms that publish explicit separation rules, like TÜV Rheinland’s documented minimum intervals, are telling you something meaningful about how they manage that tension.
For enterprise buyers, the accreditation body’s IAF membership matters more than which specific national body issued the accreditation. ANAB, UKAS, and DAkkS certificates are all mutually recognized under the IAF Multilateral Recognition Arrangement. Choosing ANAB-accredited is the natural default for a US-headquartered organization, but if your European parent company already works with a UKAS-accredited CB, there is no technical reason to run a separate US certification.
One tradeoff worth naming: the largest global CBs offer capacity and international coverage, but smaller US-focused bodies often move faster, charge less per audit day, and assign more senior auditors to mid-market clients rather than routing them to junior staff. If your organization has fewer than 500 employees and a single-site scope, a mid-sized ANAB-accredited body may serve you better than a household name.
Plan your ISO 27001 budget before you contact a certification body
Before you request quotes from the CBs on this list, knowing your organization’s readiness level and likely implementation effort changes the conversation. A CB will quote audit days based on scope; Ismscalculator tells you what that scope should realistically look like given your company size, industry, and current security maturity.

Ismscalculator gives compliance officers and IT managers a real-time cost and effort estimate tailored to their specific situation, not a generic range copied from a blog post. The platform covers maturity assessments across all 14 ISO 27001 domains, customizable implementation timelines, and industry benchmarks so you can see how your planned scope compares to sector averages.
- Free 2-minute readiness check: Identify your biggest ISMS gaps before the auditor does, using the instant self-assessment
- Implementation cost and effort estimator: Get a tailored estimate by company size, industry, and maturity level before you request CB quotes
- Vetted consultant introductions: Connect with independent ISO 27001 implementers through Ismscalculator’s consultant directory when you need hands-on help before the audit
Run the full readiness assessment now to get a detailed picture of where your ISMS stands, what it will take to close the gaps, and what a realistic audit scope looks like before you put a CB on the phone.
Primary sources and directories for accreditation verification
Use these authoritative sources to verify CB accreditation and confirm certificate details independently.
- ANAB ISO/IEC 27001 CB directory — Search by CB name or accreditation ID; download the scope of accreditation document to confirm coverage of your planned scope. ANAB is the primary US national accreditation body for management systems CBs.
- ISO/IEC 27001:2022 standard page — Confirms the correct full standard designation (ISO/IEC 27001:2022) and the scope of the standard. Use this to verify that a certificate references the current version, not a superseded edition.
- UKAS directory — For CBs accredited by the UK national accreditation body; relevant for BSI Group, Lloyd’s Register, and Bureau Veritas certificates issued under UKAS accreditation.
- DAkkS accreditation database — For TÜV Rheinland and other German-accredited CBs; confirms DAkkS accreditation status and scope.
- IAF MLA signatories list — Confirms which national accreditation bodies participate in the multilateral recognition arrangement, meaning their certificates are accepted across member economies.
- NQA ISO 27001 guidance — Explains what accreditation means for certificate validity and what to check when reviewing a certificate.
Sources
- Information Security Management Systems | ISO/IEC 27001 CBs | ANAB
- ISO/IEC 27001 — Information security, cybersecurity and privacy protection
- ISO 27001 Certification: Complete Guide
- LBMC certification services
- ISO 27001 - NQA
- ISO 27001 - TÜV Rheinland
- Frank, Rimerman — ISO certification services
Recommended
- ISO 27001 Certification: What Organizations Need to Know | ISMS Calculator
- Top 5 iSecureData.com Alternatives for ISO 27001 2026 | ISMS Calculator
- ISO 27001 Certification Checklist: 80 Steps to Certification | ISMS Calculator
- Find an ISO 27001 Consultant — Vetted Implementers & Lead Auditors | ISMS Calculator