
The workload
A founder evaluating a vendor's 'ISO 27001 certified' claim has a specific check to run, per ISO's own certification page: verify the certificate through the certification body that issued it, or through the International Accreditation Forum's CertSearch database, rather than take a logo at face value. That page states, verified and quoted directly: 'ISO does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification. Certification is performed by external certification bodies, thus a company or organization cannot be certified by ISO.' The workload, in other words, is naming and checking the actual certification body, not ISO.
What the documents show
Verified, from ISO's own catalogue page for the standard: ISO/IEC 27001:2022 carries a publication date of '2022-10' and is listed as 'Edition: 3,' a 19-page document under ISO/IEC JTC 1/SC 27. The catalogue page does not itself list what changed from the prior edition, and this entry did not purchase or open the full standard text — it is sold, not published in full on iso.org — so no specific clause-by-clause or control-count change is stated here as verified fact. Separately verified, from the certification page: accreditation of a certification body 'is not compulsory, and non-accreditation does not necessarily mean the certification body is not reputable,' which matters directly to anyone trying to weigh how much a specific certificate is worth.
The operating cost
Neither ISO page retrieved lists a certification fee or a price for the standard document itself; both are set independently — the audit fee by the certification body a company chooses, and the standard's purchase price by ISO's own store, which this entry did not check out to confirm a figure. Finding an actual cost requires requesting quotes from certification bodies directly; nothing on iso.org states one.
The stop condition
A certificate covers only the scope a specific certification body actually audited — which systems, which offices, which product line — and ISO's own materials retrieved here did not spell out how that scope gets documented, though the principle that certification is a bounded, external act (not something ISO itself grants wholesale) follows directly from the verified 'cannot be certified by ISO' language above. Editorially: when a vendor's certification is more than a year or two old, or when its product line has visibly changed since, the reasonable next step is asking the certification body or CertSearch what the current certificate actually covers, rather than assuming the original scope still applies.
- Which certification body issued a given vendor's ISO 27001 certificate, and is that body itself accredited?
- Does the certificate's scope cover the specific product or data flow this decision depends on, or a different part of the vendor's business?
- Is the certificate current against the 2022 edition, or against the superseded 2013 edition?
ISO writes the standard; it does not audit anyone against it. That distinction, stated on ISO's own site, is the single most useful fact for reading any vendor's certification claim, more useful than the edition number itself.
Sources & reading trail
States the standard's edition number (3), 19-page length and October 2022 publication date.
Source published: 1 October 2022 · Retrieved: 16 September 2026
States that ISO itself does not certify organizations, that external certification bodies do, and that accreditation of those bodies is optional and separately verifiable.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.