Trust centers for ISO 27001 companies
An ISO 27001 certificate is public by nature. The Statement of Applicability is where a reviewer looks next, and it is the document to gate.
A company certified to ISO 27001 can publish its certificate openly on its trust centre, with the certification body, the accreditation body, the scope statement and the expiry date. It should gate the Statement of Applicability, which lists the 93 Annex A controls of ISO 27001:2022 and which apply. It should also show the date of the last surveillance audit, because certificates run for three years with annual surveillance in between.
What should be public?
- The certificate, with certificate number and expiry.
- The scope statement, word for word. A narrow scope a reviewer discovers later reads as concealment.
- The certification body and its accreditation, so the reviewer can verify it. A certificate from an unaccredited body carries little weight.
- The last surveillance audit date and the next recertification date.
What should be gated?
The Statement of Applicability, internal audit summaries, and the risk treatment plan if you share it at all. The SoA shows which controls you excluded and why, which a reviewer needs and an attacker would like.
What if we hold ISO 27001 and SOC 2?
Show both, and one controls summary that both support. North American buyers usually want the SOC 2 report; European and UK buyers usually want ISO 27001. ISO27K compares the two.
How do reviewers verify an ISO 27001 certificate?
They check the certification body named on the certificate, whether that body is accredited by a recognised accreditation body such as the Standards Council of Canada or another member of the International Accreditation Forum, and whether the certificate appears in the body's register. Publish all three facts so the reviewer does not have to ask. A certificate from an unaccredited body is a red flag that ends reviews badly.
Why does scope matter so much?
An ISO 27001 certificate covers the scope written on it and nothing else. If the scope covers one office and not the product a buyer uses, the certificate does not help them. Publish the scope statement verbatim and, if it excludes something a buyer may assume is covered, say so. More on ISO 27001 in Canada is on ISO27K.
Common questions
Can we publish our ISO 27001 certificate openly?
Yes. The certificate is designed to be shown. Many certification bodies also list certified organizations in a public register, which a reviewer may check.
Should we publish the Statement of Applicability?
Gate it. It is the most useful document for a reviewer after the certificate, and it describes which controls are in place in detail.
Build your trust centre around ISO 27001
Providers set up the certificate, scope and gated SoA for you.
Get matched