Blog
Compliance
ISO 27001
ISO 9001
Cyber Essentials
September 7, 2026
Approx min read

Your public certification status: what a buyer can see without asking you

Accredited ISO 27001 and ISO 9001 certification, Cyber Essentials and the NHS Data Security and Protection Toolkit all have public registers a buyer can search. Your public certification status is one of the fields those registers carry, along with its dates and its scope. Looking you up costs a procurement team nothing and needs no permission.

The duty to keep those records current sits with your certification body, and it runs to the database. Nothing in the governing document requires anyone to tell you when your entry changes, and the upload happens on a monthly cycle set by the certification body. The record is accurate only to the extent that the thing behind it is accurate.

What your certification body has to publish about your certificate

The rule is IAF MD 28:2023, Issue 1, the mandatory document on the upload and maintenance of data on the IAF Database. The International Accreditation Forum issued it on 26 October 2023, with an application date of 26 October 2024. It applies to accreditation bodies that are IAF MLA signatories providing accreditation under "main scope ISO/IEC 17021-1" and to "their accredited Certification Bodies (CB) under this scope", so accredited certification is what it covers. That Forum ceased operations on 1 January 2026. MD 28 is on the Global Accreditation Cooperation Incorporated list of documents continuing in use under Global ACI Resolutions 2025-25 and 2025-29, until equivalent Global ACI documents are adopted.

Clause 4.2.1 requires a certification body to upload data on "all Certified Entities that it certifies under ISO/IEC 17021-1". The same clause names the fields. They include the geographical location of each certified client, or of the headquarters and all sites inside a multi-site scope. The scope of certification is a field, worded "without being misleading or ambiguous", and so are the certification issue dates and the expiry date. The last field is the certification status, which carries one of three values: active, suspended or withdrawn.

A note under the status item sets how long it stays there. "This information shall be maintained on the IAF Database for at least three years after the corresponding decision."

Clause 4.2.4 sets the cadence at "at least once a month", so a change reaches the database on the certification body's schedule and not on yours.

The same duty covers accredited ISO 9001 certification as it covers ISO 27001, and what moves a status is the ordinary business of surveillance and recertification, covered in certification status between audits.

Where a buyer looks to check your public certification status

Clause 1.3 says the database exists to verify "the validity of accredited MS certifications" for the global industry and regulators who rely on them. It is IAF CertSearch, at iafcertsearch.org, and Global ACI links to it from its homepage as its verification route. Its support documentation says the database carries the validity and status of a certificate, its standard, scope and certified locations, and that a public user can "search and validate up to 3 certifications per day and 30 verifications for free" with an account.

UKAS runs a second route in the UK. CertCheck launched on 16 June 2022, "free to use and open to all", and a search by company name or certificate number returns every UKAS accredited certification that company holds, giving "a simple confirmation whether a certification is both genuine and current". Working out how to check if a company is ISO 27001 certified takes a company name and about a minute.

Registration is free too, and CertCheck account holders can set alerts for changes in the accredited status of certifications they track. They are under no obligation to tell you that yours is one of them.

The exceptions, and how narrow they are

A certification body can be excused from the upload duty, and clause 5.2.2 sets out the grounds in full: regulatory or government requirements, data privacy or data security laws, and the absence of a mandate in the case of a government agency. Commercial preference is absent from that list. The certification body does not decide the question about itself. Clause 5.2.4 puts the review with the accreditation body, and clause 5.2.5 adds a second layer, quoted as printed: "The AB review and decision regarding CB justifications will be subject to examination though the peer evaluation process."

An accepted exclusion is itself published. Under clause 5.2.8 an excluded certification body "will be indicated in the IAF Database as 'non-participating'", so that a searcher knows to contact it directly.

Confidentiality works differently from opting out. Clause 6.1 requires a certification body to participate even where data "may not be suitable for, or capable of, publication to third parties", marking the sensitive parts confidential. Clause 6.2 limits that to national security activities, a significant safety risk, or a government or regulatory requirement, with supporting evidence required under clause 6.3. Where the certification body has said the name or the certificate number can be searched, a confidential record still returns a result: the certification body's name, a statement that the information is confidential, and an enquiry form.

Certification issued by a body with no accreditation sits outside all of this, and its absence means something different from a lapse.

Cyber Essentials and the NHS DSPT, with different tells

A Cyber Essentials certificate check runs through IASME, the NCSC's Cyber Essentials Delivery Partner, whose search the NCSC points buyers to for "all current Cyber Essentials certificates". Certificates run for twelve months from the date of submission, per IASME's renewal guidance read on 20 August 2026, so what a buyer finds after a lapse is an absence. That gap is covered in Cyber Essentials renewal and lapse.

The DSPT public register puts more on show, returning the ODS code, organisation name, status and publication date of "an organisation's most recent Data Security and Protection Toolkit self-assessment", refreshed every ten minutes. The live cycle is DSPT 2026-27 version 9, published on 4 September 2026 with a submission deadline of 30 June 2027. The cycle before it, DSPT 2025-26 version 8, closed on 30 June 2026. Guidance names the outcomes as Standards Met and Standards Exceeded, with Approaching Standards for social care organisations, and requires "at least one assessment by the deadline of 30 June every year".

On 4 September 2026 a search of that register returned organisations whose most recent published assessment was DSPT 2024-25 version 7, published on 30 June 2025. That is fourteen months old and one full cycle behind. The register carries the edition and the date and leaves the buyer to read them.

What a procurement team does with it, and what it cannot see

UKAS tells buyers to check that a certificate came from a body "accredited by an internationally recognised accreditation body", which its directory of accredited organisations answers. CertCheck covers the certificate itself.

Nothing about the audit is published. Clause 4.2.1 is a closed list of fields carrying no nonconformity, no audit report, no auditor's name, no corrective action, no closure evidence and no opportunity for improvement. Grade makes no difference, because no finding of any kind is a field on that list.

NHS England is equally direct on the DSPT: "No information on the content within your toolkit is available publicly." A buyer sees the edition, the outcome and the date. Your evidence, your improvement plan and the assertions that gave you trouble stay inside the toolkit.

What travels is the state change and its date. A suspended or withdrawn status carries no explanation of the circumstances, and it stays for at least three years after the decision. The fact moves and the context stays behind, which is the practical argument for handling a maintenance problem while it is still an internal one.

A suspension also closes one obvious response, because under IAF MD 2:2023, Issue 2, Version 2, clause 2.1.2, certification "known to be suspended shall not be accepted for transfer". For a group that is one more reason to run compliance across multiple entities and products on one system.

What to check this week, and where the record comes from

Search your own organisation on UKAS CertCheck and IAF CertSearch, and read the result against what your sales team says.

Check the DSPT public register for every organisation and ODS code you are responsible for, and confirm the edition showing is the one you expect.

Confirm the expiry date, sites and scope wording on every accredited certificate you hold, because those are the uploaded fields.

The register is downstream of your management system, so the work that keeps it right is internal. ISO 27001 and ISO 9001 certificates come from a certification body accredited by UKAS, and Naq's job is getting an organisation audit-ready and keeping it there between audits. The platform runs UK GDPR, Cyber Essentials, ISO 27001, ISO 9001 and the NHS DSPT against one library of controls and evidence, and a parent and a subsidiary holding separate certificates each get their own framework instance, scoped and scheduled on its own terms, so the two records never merge. Every meaningful action lands in the record's activity stream, in the order it happened.

That gives you a dated internal record to answer with, and it keeps true the thing the registers report, which is the part of your public certification status you control. If you want to walk through your certificate list and the dates behind it, book a fifteen-minute demo.