certifications7 min read

How to Check an ISO Certificate: Validity, Scope and Accreditation

An ISO certificate travels as a PDF. It is emailed, stapled to a tender response, uploaded to a supplier portal — and most of the time, nobody really reads it. Someone spots a logo, a standard, a date that does not look expired, and the document goes into the file.

That is a shame: an ISO certificate is a structured document, containing a limited number of items, all of them checkable. Here is how to read one in a few minutes.

First clarification: ISO certifies nobody

This is the most widespread misunderstanding, and it distorts everything else. The International Organization for Standardization develops and publishes the standards, but performs no certification and issues no certificates. It states explicitly that no company can be “certified by ISO”, and that it permits nobody to use its logo in connection with certification.

Certification is carried out by independent certification bodies, whose own rules are themselves set by a standard: ISO/IEC 17021-1, which lays down the requirements for bodies providing audit and certification of management systems.

The immediate consequence: a certificate displaying the ISO logo instead of a certification body’s mark and an accreditation mark is suspect. A genuine certificate carries the name, mark and number of an identifiable certification body.

The items to check, one by one

A compliant certificate always carries the same information.

Item What it states What you should check
Legal name and address The certified legal entity That it matches exactly the entity that invoices you — not the parent or a sister company
Scope The activities covered by the management system That the service you are buying appears explicitly
Sites covered The audited establishments That the site delivering the work is listed, or that a multi-site arrangement is stated
Standard and version The standard and its edition That the version is the one in force (ISO 9001:2015, ISO 14001:2015, ISO 45001:2018, ISO/IEC 27001:2022)
Issue date The starting point That it is consistent with the cycle claimed
Expiry date End of validity That it has not passed on the day you read the document
Certificate number The unique identifier That it lets you retrieve the certificate from a database or from the body
Certification body Who audited and signed That it exists, is contactable, and does claim this certificate
Accreditation mark Who accredited the certification body The single most important point — see below

Two rows do most of the work: scope and accreditation mark. The rest takes thirty seconds.

Accredited or not: the point that settles everything

A certification body may issue certificates without being accredited; nothing forbids it. But the certificate then rests on nothing but its own word, since nobody has verified its competence, its impartiality or the rigour of its audits.

Accreditation is exactly that verification. A national accreditation body assesses the certification body against ISO/IEC 17021-1, defines its scope of accreditation — the standards and sectors for which it is recognised as competent — and reassesses it periodically. Hence the question to ask of any certificate: who checked the checker?

The role of Cofrac in France

In France a single actor performs this function: the Comité français d’accréditation (Cofrac), designated sole national accreditation body by decree no. 2008-1401 of 19 December 2008, under European Regulation (EC) No 765/2008, which requires each member state to designate only one.

Cofrac provides a search engine for accredited bodies — by name, accreditation number, programme number or SIREN company number. Two cautions are set out there:

  • an accreditation attestation is valid only together with its technical annex, which sets out the real scope; a body may be accredited for ISO 9001 without being accredited for ISO/IEC 27001;
  • an accreditation may be suspended, amended or withdrawn at any time. Cofrac publishes the list of suspensions, terminations and withdrawals. A certification body that loses its accreditation leaves its clients in an awkward position, as we explain in our article on a certification body losing its accreditation.

International recognition: EA, and a reshaped global arrangement

Is a certificate issued in Milan or Osaka worth anything where you are? That is what multilateral recognition arrangements are for. Cofrac is a member of the European co-operation for Accreditation (EA) and a signatory to its arrangements, which organise mutual recognition between European accreditation bodies and, by extension, of the certificates issued under their authority.

Globally, the landscape has just changed. The International Accreditation Forum (IAF) ceased operations on 1 January 2026: IAF and the International Laboratory Accreditation Cooperation (ILAC) were replaced by a single organisation, the Global Accreditation Cooperation Incorporated (Global ACI), operational from that date. The former IAF MLA and ILAC MRA were consolidated into a single mutual recognition arrangement held by the new body. So if a certificate still mentions “IAF MLA”, that does not make it a forgery — the wording appears on countless documents issued before 2026 — but your checks should rely on current sources.

The five traps that come up most often

  1. Scope too narrow. A company certified to ISO 14001 for its logistics, but not for the workshop that makes what you are buying. The certificate is genuine, valid, accredited — and beside the point. This is by far the most frequent error, particularly in public procurement: see our analysis of ISO 14001 in tenders.
  2. Site not covered. The group is certified, but the plant or branch that will deliver the work is not in the list of sites. Check the address, not the group logo.
  3. Expired certificate. Certification runs on a three-year cycle punctuated by annual surveillance audits; we set out that mechanism in our article on surveillance and renewal.
  4. Obsolete version of the standard. An ISO/IEC 27001:2013 certificate is no longer valid: the transition period to the 2022 version ended on 31 October 2025. The same reflex will apply to ISO 9001, for which a new edition has been announced by committee ISO/TC 176/SC 2.
  5. Suspension between two audits. A printed certificate still looks handsome after being suspended or withdrawn. Only an online check, on today’s date, gives the real status.

Where to check, in practice

Four routes, from fastest to most robust:

  • IAF CertSearch (iafcertsearch.org), the global database of accredited management system certifications, still accessible and linked from Global ACI. By company name or certificate number it gives the validity and status of the certificate, the standard, the scope, the certified sites, the certification body and its accreditation body. Not every certification is loaded into it: an absence is not proof of fraud, but a prompt to dig further.
  • The certification body’s own directory, which most of them publish online.
  • The Cofrac website for the certification body’s accreditation: scope, technical annex, and the list of suspensions and withdrawals.
  • A direct request to the certification body, by email, quoting the certificate number: the slowest and most reliable check, to be kept for the cases that warrant it.

What the research says about auditor independence

Why insist so much on accreditation? Because an independent third party is only reliable if its independence is itself supervised — and economic research has measured this. Esther Duflo, Michael Greenstone, Rohini Pande and Nicholas Ryan published in 2013 in The Quarterly Journal of Economics the results of a two-year field experiment run in the Indian state of Gujarat (Truth-telling by Third-party Auditors and the Response of Polluting Firms, vol. 128, no. 4, pp. 1499-1545). Under the original arrangement, environmental auditors were chosen and paid by the plants they inspected: they systematically reported emissions just below the regulatory threshold, while actual emissions were higher. The researchers altered the structure of the audit market — random assignment of auditors, payment from a central pool, back-checking. Reports became markedly more accurate, and pollution at the audited plants fell within six months.

The study says nothing about French certification bodies, and it would be improper to make it carry such a judgement. What it establishes is a general mechanism: audit quality depends on the incentive structure in which the audit takes place. That is precisely what accreditation is for — imposing impartiality rules, having the certification body assessed by a third party, and making sanction possible. An unaccredited certificate leaves that mechanism entirely to the goodwill of whoever signs.

Take action

Take the next certificate that lands in your inbox and run the test: does the scope cover what you are buying, is the site listed, is the accreditation mark there, and can the number be found online? Four questions, five minutes. To understand what sits behind these documents, see our guides to ISO 14001, ISO 9001, ISO 45001 and ISO/IEC 27001 — and if you are the one who has to supply the certificate, our guide to the steps to obtain ISO 14001 certification.

FAQ

Frequently asked questions

+Does ISO itself issue ISO 9001 or ISO 14001 certificates?

No. ISO develops and publishes the standards, but it performs no certification and issues no certificates. Certification is carried out by independent certification bodies. ISO also states that it does not permit anyone to use its logo in connection with certification: a certificate bearing the ISO logo is a warning sign, not a guarantee.

+How do I know whether an ISO certificate is accredited?

An accredited certificate carries the mark of the national accreditation body that assessed the certification body — in France, Cofrac — together with the accreditation number. You can check that number and the exact scope of accreditation on the Cofrac website, and look up the certificate itself in the IAF CertSearch database. A certificate with no accreditation mark rests on nothing but the word of the body that signed it.

+What if the certificate scope does not cover the service I am buying?

Then the certificate is worthless for your purchase: it attests to a management system over specific activities and sites, not over the whole company. Ask the supplier for a certificate whose scope explicitly covers the activity and the site concerned, or treat the gap as a finding in your assessment. This is the most common defect and the easiest to miss.

Read next