How to verify an ISO certificate

Published 3 September 2026 · Reviewed 4 September 2026 · By Steven MoreySteven Morey has spent 27 years in digital, leading marketing and sales for technology businesses in Australia and the US. Through Opollo, his MSP marketing agency, he's run thousands of campaigns for hundreds of managed service providers. That's where the pricing questions in these guides come from.

A certification badge or logo on a website proves nothing by itself. Verifying an ISO certificate means checking three things: that the certificate is currently valid, that it was issued by a body with real accreditation, and that its scope actually covers the service you're buying.

What each standard actually proves

ISO/IEC 27001:2022 proves an audited information security management system: how the provider identifies, treats and monitors information security risk. It's the one security questionnaires, cyber insurance applications and government or enterprise procurement usually ask for by name. ISO 9001:2015 proves an audited quality management system across service delivery, not a security control on its own; it shows up in procurement processes assessing a supplier's overall process maturity. ISO 14001:2015 proves an audited environmental management system, relevant to procurement with a sustainability requirement. ISO 42001:2023, published December 2023 and still rare, proves an audited management system for how a provider governs the AI systems it builds or deploys. ISO 45001:2018 proves an audited occupational health and safety management system, relevant to clients with on-site work, and unrelated to information security.

Essential Eight is a framework, not a certificate

The Australian Cyber Security Centre publishes eight mitigation strategies and rates maturity against them on a 0-3 scale per strategy. There's no accreditation body behind it and no expiry date to check, because it isn't a certificate at all; a provider can only self-assess against it, so verifying an Essential Eight claim means asking for that self-assessment directly rather than looking for a certificate number.

How the same standard can mean different things

Two real, current scope statements from this register show the range. One reads: "Managed Services Provider catering to small-medium businesses, government entities, and large enterprises offering services including Managed IT Services, Cloud and Infrastructure Services including maintenance & support, Project Deployment services, Network Solutions, Cyber Security, Business Continuity & Disaster Recovery, ISP Services: Voice/Data solutions, Data Centre Services, Unified Communications, Hardware Procurement and Management, Managed Print Services in accordance with Statement of Applicability v1.0." That covers a managed IT relationship broadly. Another, for a different provider and a different standard, reads: "Cloud-based hosting services in data centers across Australia." That covers one service line only. Both are genuine, current certificates; only one of them would cover a buyer assessing that provider for a full managed IT relationship rather than hosting specifically.

What to ask the provider for

Ask for the certificate number, the name of the issuing certification body, the issue and expiry dates, and the scope statement in writing. A provider with a genuine, current certificate has all of this on hand immediately; hesitation or a vague answer is itself useful information.

What an accreditation body actually accredits

JAS-ANZ does not certify businesses. It accredits certification bodies, the organisations that audit a business's management system and issue the certificate itself. A provider's certificate is issued by one of these certification bodies, not by JAS-ANZ directly, and a genuine certificate names that body alongside JAS-ANZ's own accreditation mark (or another IAF member body's, outside Australia and New Zealand). In the certificate data behind this register, the field held consistently is the accreditor: JAS-ANZ on the large majority, with a small number accredited instead through ANAB or IAS. The certifying body itself, the specific firm that ran the audit, is the detail a genuine certificate document always states but that doesn't always survive being passed on secondhand. When you're checking a certificate directly, look for both names on it: the certification body that issued it, and the accreditation body that stands behind that certification body's own competence to do so.

What to check independently

Confirm the issuing body is itself accredited, in Australia typically by JAS-ANZ (the Joint Accreditation System of Australia and New Zealand) or another IAF (International Accreditation Forum) member body.

Many certification bodies publish a public register of current certificate holders; ask the provider to point you to their own listing rather than only supplying a PDF. Check the expiry date against today's date, and check the scope statement names the actual service you're buying, not just the business in general.

What a register lookup actually shows

A certification body's public register returns more than a yes or no. A real entry shows the certificate number, the standard, the scope statement, the issue date, and a current status: current, suspended, or withdrawn. Status is the part a PDF sitting on a provider's website can't show you, because it doesn't update itself. One certificate in this register's own data is a working example: identifier 5301-3257-01, ISO 9001:2015, expiring 2026-09-29, carrying a status of expiring soon rather than current. That distinction only exists because someone checked the date against today rather than trusting that a certificate once issued stays valid indefinitely. A certification body's register is the only place that status is authoritative; the provider's own marketing page is not.

When a provider can't produce the number

A provider who genuinely holds a certificate can produce the number immediately, because it's on the certificate document, the audit report and every renewal notice the certification body has sent them. Hesitation, an offer to "send it through later", or an answer that only points back at the logo on their website are signs the claim isn't ready to be checked yet, not proof the claim is false. Being partway through certification is common and isn't disqualifying on its own; a business in that position can still tell you which certification body is running the audit and roughly when it expects to finish. The distinction worth asking for directly is between "we are certified" and "we are being audited for certification", because those are two different claims and only one of them a register lookup can confirm today.

Reading a scope statement against what you're buying

The scope statement names the specific activity a certificate covers, and matching its wording to the service you're buying is the step most buyers skip. Two real scope statements from this register show the range: one reads "Managed Services, Cloud & Infrastructure, Cyber Security, Business Continuity & Disaster Recovery, Collaboration, Business Internet & Networking", covering a managed IT relationship broadly. Another reads "Configuration, deployment, and use of AI systems and AI agents to support the delivery of Managed IT Services", covering AI governance specifically and saying nothing about that provider's help desk or its core managed services. A provider can hold both statements as genuinely current certificates and still have neither one cover the exact line you're assessing them for. Read the scope statement for the words that name your service, not for the standard's name alone.

The four-step check

  • Get the certificate number, issuing body and expiry date in writing.
  • Confirm the issuing body is itself accredited (in Australia, typically by JAS-ANZ or another IAF member body).
  • Look the certificate up on the issuing body's own public register, not only the PDF the provider sent you.
  • Read the scope statement and check it actually names the service you're buying, not just the business in general.

Answering an auditor or insurer

If you need to record what you checked, a short note covering all four points is enough: "Provider holds [standard], certificate [number], accredited by [body], expiring [date]. Scope: [scope statement]. Verified against the accreditation body's public register on [date checked]."