A supplier sends a PDF with a logo and the words "ISO 9001:2015 certified". Whether that PDF means anything depends on two things it may or may not say: who issued it, and who accredits the issuer. ISO, the International Organization for Standardization, writes the standard and certifies nobody; it keeps no register of certified companies, and a certificate with the ISO logo on it is a warning sign rather than a proof. Certification is done by certification bodies, private companies, and the only thing that separates a certification body from a company that sells PDFs is accreditation by the national accreditation body of an EU member state, of which Regulation (EC) 765/2008 requires exactly one per state. This article is what a real certificate shows, the three checks that establish it, and the 27 registers to check against.

What a real certificate shows

ISO/IEC 17021-1, the standard that accreditation bodies hold certification bodies to, requires the certification document to identify the client and where it is, the standard and its edition, the scope of the certification, the certification body, the dates it was granted and expires, and a unique identification. On an accredited certificate the accreditation body's mark appears next to the certifier's, with the certifier's accreditation number. So a certificate that means something shows:

  1. The name of the certified organisation and the sites covered.
  2. "ISO 9001:2015", the edition, not "ISO 9001" alone and never "ISO 9001:2008", whose certificates all expired in September 2018 at the end of the transition.
  3. A scope statement in words: what the organisation does that the certificate covers, for example "design and support of accounting software", not the company name repeated.
  4. The certification body's name, and the accreditation body's mark with an accreditation number.
  5. The dates: an issue date, an expiry date three years after the initial certification, and often the date of the current cycle; certification is a three-year cycle with a surveillance audit each year in between.
  6. A certificate number that the certifier can look up.

A certificate missing the scope, the accreditation mark or the edition is not necessarily false, but each is a question to ask before relying on it.

Three checks that take ten minutes

The certifier is accredited, for ISO 9001, by a national accreditation body. Take the certifier's name and the accreditation body named on the certificate to that body's register, linked in the table below, and look the certifier up. The register says whether the accreditation is current, suspended or withdrawn, and for which standards: accreditation for ISO 9001 is separate from accreditation for ISO 27001 or ISO 14001, and a body accredited for one is not thereby accredited for another. A certifier that appears in no national register is not accredited, whatever its website says.

The certificate is current. Most certifiers publish a directory of the certificates they have issued, searchable by company name or certificate number, and many also upload to IAF CertSearch, the database run by the International Accreditation Forum, where a certificate can be looked up across certifiers. A certificate that the certifier's own directory does not show, or shows as withdrawn or suspended, is not one to rely on, and a certificate three years past its issue date with no recertification has lapsed.

The scope covers what you are buying. The scope statement is the certificate's limit: a company certified for "provision of IT support services" is not certified for the software it also develops, and a certificate for one site does not cover another. Read the scope against the contract.

If the three checks pass, the certificate is real, current and relevant. If the supplier cannot name the accreditation body, cannot give a certificate number, or explains that the certifier is "internationally recognised" without being in any national register, you are looking at an unaccredited certificate: identical to the eye, roughly 40 to 50% cheaper to buy, and routinely rejected by public and enterprise buyers, which is why the supplier that bought one usually buys an accredited one afterwards, at full price, because an unaccredited certificate cannot be transferred.

The 27 registers

One body per member state, alphabetical, from EA's directory of members; each publishes the register of the certifiers it accredits, with scope. Checked against EA's directory on 11 August 2026.

Country Accreditation body Register
Austria AA, Akkreditierung Austria bmwet.gv.at/akkreditierung
Belgium BELAC, Belgian Accreditation Council belac.fgov.be
Bulgaria BAS, Bulgarian Accreditation Service nab-bas.bg
Croatia HAA, Croatian Accreditation Agency akreditacija.hr
Cyprus CYS-CYSAB, Cyprus Organization for the Promotion of Quality www.gov.cy/meci-cysab/en/
Czechia CAI, Czech Accreditation Institute cai.cz
Denmark DANAK, Den Danske Akkrediteringsfond english.danak.dk
Estonia EAK, Estonian Accreditation Centre eak.ee
Finland FINAS, Finnish Accreditation Service finas.fi
France COFRAC, Comité français d'accréditation cofrac.fr
Germany DAkkS, Deutsche Akkreditierungsstelle dakks.de
Greece ESYD, Hellenic Accreditation System esyd.gr
Hungary NAH, National Accreditation Authority nah.gov.hu
Ireland INAB, Irish National Accreditation Board inab.ie
Italy ACCREDIA, Ente Italiano di Accreditamento accredia.it
Latvia LATAK, Latvian National Accreditation Bureau latak.gov.lv
Lithuania LA, Lithuanian Accreditation and Standardization Agency lasa.lrv.lt
Luxembourg OLAS, Office Luxembourgeois d'Accréditation et de Surveillance portail-qualite.public.lu
Malta NAB-Malta, National Accreditation Board nabmalta.org.mt
Netherlands RvA, Raad voor Accreditatie rva.nl
Poland PCA, Polskie Centrum Akredytacji pca.gov.pl
Portugal IPAC, Instituto Português de Acreditação www.ipac.pt
Romania RENAR, Romanian Accreditation Association renar.ro
Slovakia SNAS, Slovak National Accreditation Service snas.sk
Slovenia SA, Slovenian Accreditation slo-akreditacija.si
Spain ENAC, Entidad Nacional de Acreditación www.enac.es
Sweden SWEDAC, Swedish Board for Accreditation and Conformity Assessment swedac.se

You do not need a certifier in your own country

A certificate from a body accredited by any signatory of the European co-operation for Accreditation's multilateral agreement is recognised across all of them, so a certifier accredited by DAkkS is as good in Spain as one accredited by ENAC, and a buyer asking for "a national certificate" is asking for something they do not need. Outside Europe the equivalent is the IAF multilateral arrangement. The one thing that does not travel is scope: check it in the register of the state that accredited the certifier, not the state where the supplier is.

What this has to do with us

StandardOS does not issue certificates and cannot: ISO/IEC 17021-1 requires the certifier to be independent of whoever helped the organisation prepare, and the same separation is why this page sends you to a register rather than to a partner. What we build is the management system a certifier audits, for ISO 9001 as a clause register and for ISO 27001, and the records it produces carry a hash that anyone can verify without us. The equivalent checks for an ISO 27001 certificate, with the same registers, are on the certification bodies page; why a buyer asks for the certificate at all, by country, is in the count of EU tenders naming ISO 9001.

Sources

  • Regulation (EC) No 765/2008, Article 4, one national accreditation body per member state.
  • ISO/IEC 17021-1:2015, the requirements for bodies certifying management systems, for the content of certification documents, the three-year cycle and the independence requirement, cited by number; the text is ISO's.
  • The European co-operation for Accreditation, directory of members and MLA signatories, read 11 August 2026.
  • IAF CertSearch, the International Accreditation Forum's certificate database.

This is not procurement or legal advice. A register entry read today is the fact today; read it again before you sign.