Sooner or later every certified organisation considers switching to another certification body (CB) — because of price, better knowledge of your sector, or because a customer requires a specifically accredited CB. That is well provided for: fixed transfer rules exist. But a poorly timed switch can create an ISO 27001 gap in your certification or lead to a duplicate audit. With the right sequence you avoid that.
Why companies switch CB
The most common reasons: rates rise, the auditor does not understand your industry well enough, scheduling is tight, or a large client sets requirements for your CB’s accreditation. Important to know: your certificate stays valid as long as the switch follows the international transfer rules (IAF) properly. You do not start over — you transfer your existing certification.
The steps in the right order
- Inform your current CB and ask about the transfer conditions. Under the IAF transfer rules a new CB may take over a valid certificate without a full reassessment.
- Plan the surveillance with the new CB before your current certificate expires. This is the critical point: do not let your certificate lapse before the new CB has assessed you, or a gap appears.
- Transfer your file: the Statement of Applicability (SoA), the recent audit reports and all open corrective actions (CAPs). A clean handover prevents the new CB wanting to see things again.
- Communicate to your customers: the certificate number and the CB change, your scope does not. A short proactive notice prevents questions and doubt.
The timing risk in detail
The biggest danger is a surveillance gap: the period in which your old certificate has expired but the new one has not yet been issued. For customers who check your certificate in a supplier portal, you are briefly “uncertified” — with all the questions that brings. So plan back from the expiry date: allow at least a few weeks for the transfer assessment and the administrative issuance, and start well in advance.
What you hand over
A smooth handover stands or falls with a complete file. Have ready: the current SoA, the reports of your last (re)certification and surveillance audits, the status of open findings and how you resolved them, and your scope description. The more complete this package, the less the new CB wants to re-assess — and the faster and cheaper the transfer.
What customers check in 2026
Enterprise buyers increasingly look beyond just “do you have a certificate”. They check the accreditation of your CB (is it affiliated with a recognised accreditation body) and whether your scope on the certificate actually covers the service they buy. So keep your transfer letter and the new certificate PDF in your evidence folder, so that in a supplier audit you can immediately show the switch was done correctly.
Common mistakes
- Starting too late — engaging the new CB when the old certificate is nearly expired causes a gap.
- File not in order — a missing SoA or open CAPs delay the transfer and can trigger an extra audit.
- Not informing customers — a changed certificate number without explanation raises unnecessary doubt.
- Ignoring accreditation — a cheap, non-accredited CB can actually cost you customers.
Getting started
Considering a switch? Start with your current certificate’s expiry date and plan back. Ask both CBs about their transfer process and make sure your file is complete. That way you switch without an audit gap. Want to know more about the certification route? See ISO 27001 certification or take the free readiness scan.
