Read More

ISO Services

ISO Certification Services That Open Global Markets

Everything you need to know about how Decrypt Compliance audits, certifies, and maintains your management system certification, published openly under ISO/IEC 17021-1.

ISO/IEC 27001:2022

ISO/IEC 27701:2019

ISO 42001:2023

Overview

An Accredited ISO 27001 Certification Body Built for SaaS

Decrypt Compliance is accredited by the International Accreditation Service (IAS) as a Management Systems Certification Body for ISO/IEC 27001:2022. We also provide certification services for ISO/IEC 27701 and ISO/IEC 42001 outside the scope of our IAS accreditation.

We conduct your Stage 1 and Stage 2 audits, issue your certification, and manage your ongoing surveillance cycle, all under one roof. No handoffs to a separate certification body. 
One team from audit kickoff through certification and beyond.
Our current ISO/IEC 27001 accreditation status and scope can be independently verified through the IAS public directory at iasonline.org or provided upon request.

ISO Security Benefits:

Implement a clear and globally recognized framework for information security, privacy, and AI governance

Build trust across global markets

Demonstrate commitment to responsible management of customer data

Our ISO Services

ISO 27001 - Information Security Management

The global benchmark for information security. ISO 27001 certification shows enterprise buyers and partners that your organization manages security risks to a recognized international standard.
A digital illustration of a secure network diagram with interconnected nodes, a shield with a lock symbol, and an ISO 27001 ISO Certification label, representing information security management.

ISO 27701 - Privacy Information Management

An extension of ISO 27001 that covers how your organization collects, processes, and protects personal data. The right credentials for companies handling customer data across multiple jurisdictions.
A futuristic digital interface displaying the ISO 27701 label and icons, with a shield symbol featuring a lock, representing information security and privacy management technology with ISO Certification.

ISO 42001 - AI Management System

The first international standard for AI governance. ISO 42001 certifies that your organization manages AI systems with accountability and transparency – a credential few audit firms can issue.

Futuristic digital interface with neural network diagrams, circuit patterns, and a highlighted ISO 42001 label on the upper left, suggesting artificial intelligence standards or ISO certification in advanced technology concepts.

OUR AUDIT PROCESS

A two-stage model, then an ongoing cycle

Certification audits follow a two-stage model, then continue through surveillance and recertification across a three-year cycle. Audits may be combined, joint, or integrated for clients holding or pursuing multiple standards.
Stage 1

Readiness review

Review of your management system documentation and site readiness to confirm preparedness for Stage 2.

Stage 2

Certification audit

An evaluation of implementation and effectiveness against the applicable standard.

Years 1 & 2

Surveillance audits

Conducted annually to confirm your system stays conformant between full audits.

Year 3

Recertification audit

Conducted before expiry to renew your certification and start a fresh three-year cycle.

Want the detail? Explore every step from first application to a live certificate, with who owns each stage and how long it takes.

View the Full ISO Process →

CERTIFICATION DECISIONS

How Certification decisions are made

Every decision is based on the complete audit record and confirmed by an independent decision-making authority. No rubber stamps, ever.

Certification is granted only once our decision-making authority confirms full conformance based on the complete audit record.

Refused where unresolved non-conformities remain. Exceeding the remediation timeframe requires a re-audit.
Continued through required surveillance audits and timely resolution of non-conformities.
Recertification audits are conducted before expiry of each three-year cycle.
May occur for unresolved major non-conformities, breach of agreement, or refusal to permit required audits.
Restored once an independent review confirms all issues are resolved.
May occur for failure to conduct audits, misrepresentation, unresolved corrective actions, failed appeals, or client request.
Requires a formal application, supporting documentation, and an on-site audit.
Applied where part of a scope no longer meets requirements. Never used solely to avoid recording a non-conformity.

USE OF OUR NAME & MARKS

Using our name, marks, and logos

Certified clients may reference their certification and use our marks, subject to the following rules.

Download Decrypt's Acceptable Use of the Certification Mark Policy here.

Our Commitment to Impartiality

Decrypt Compliance is committed to independence across all certification activities. We do not provide management system consultancy, and we identify, evaluate, and mitigate any relationship (financial, contractual, personnel-based, or otherwise) that could compromise our objectivity.

This commitment is reviewed at least annually by top management and is a condition of every certification decision we make.

Appeals

If you disagree with a certification decision made by Decrypt, you may submit a formal appeal to appeals@decrypt.cpa. Appeals are acknowledged, investigated and decided by competent persons who were not involved in the audit or certification decision being appealed. You will be informed of the progress and formally notified of the outcome.

Complaints

Complaints concerning Decrypt’s certification activities, personnel, auditors, or a Decrypt-certified client may be submitted to complaints@decrypt.cpa. Complaints are acknowledged, evaluated and investigated objectively, with appropriate confidentiality maintained. Where a complaint concerns a certified client, Decrypt will assess the matter in relation to the effectiveness of the client’s certified management system and take appropriate action.

Submitting an appeal or complaint will not result in discriminatory action against the person or organization making the submission.

Decrypt maintains documented records of appeals and complaints and takes appropriate correction and corrective action where required.

Processing Timeline

  • Acknowledgement: Within 5 business days of receipt.
  • Resolution: Normally within 30 calendar days.
  • Extensions: If additional investigation is required, the complainant or appellant will be informed of the progress and any extension.
  • Outcome: Formal notification will be provided upon conclusion.

Accreditations

Decrypt Compliance is accredited by the International Accreditation Service (IAS) to provide ISO/IEC 27001 certification services, operating in accordance with the applicable requirements of ISO/IEC 17021-1 and ISO/IEC 27006. Decrypt operates in full conformance with ISO 17021, ISO 27006, and the standards established by the International Accreditation Service (IAS).

Information requests

Certification-related information is available upon request at info@decrypt.cpa, including the geographical areas in which Decrypt operates and verification of a client’s certification status, including the organization’s name, applicable standard, certification scope and location, subject to applicable confidentiality requirements.

Get Started

Ready to Get Certified and Close More Deals?

Tell us about your company and we’ll get back to you with a clear path to certification – including timeline and pricing.

Consultation form

This field is for validation purposes and should be left unchanged.
Name(Required)