An organisation can work in accordance with ISO 9001 or ISO/IEC 27001 without having a certificate under accreditation. A certifying party may also issue a certificate without being accredited itself.
This does not mean that every certificate is automatically accepted everywhere. The value and usability depends on the purpose for which the certificate is used, the expertise and independence of the auditor and the requirements imposed by a sponsor, supervisor or contracting authority.
An unaccredited ISO certificate is not automatically invalid or worthless. It is just not the same as a certificate issued under accreditation and is therefore not accepted in every situation.
Certification and accreditation are not the same
ISO develops international standards but does not carry out audits itself and does not issue certificates itself.
In the case of certification, an external party shall assess whether a management system meets the requirements of a standard. In the case of accreditation, the certification body itself is then assessed. In the Netherlands this is usually done by the Accreditation Board.
Accreditation thus gives an additional layer of certainty about among others:
- the expertise of the certification body;
- independence and impartiality;
- the audit methodology used;
- the qualifications of auditors;
- the certification decision;
- the supervision of certificates issued.
ISO explicitly states that accreditation is not mandatory and that lack of accreditation does not automatically mean that a certification body is not reliable. However, accreditation offers an independent confirmation of the expertise of the certification body. See the explanation of ISO →
A certification body issuing certificates for the ISO 9001 is therefore not obliged to be accredited.
Accreditation Board, Explanation Policy Rule Accreditations
This explanation is contained in the official accreditation policy of the RvA. Read the policy interpretation of the RvA →
What does an unaccredited certificate prove?
An unaccredited certificate can demonstrate that an organisation has been examined by an external party and that its management system has been found to comply with the ISO standard during the audit.
The requirements of ISO 9001 or ISO/IEC 27001 do not change. The difference lies mainly in the supervision of the party conducting the audit and issuing the certificate.
Therefore, when assessing an unaccredited certificate, the following questions are relevant:
- Has the full standard been proven?
- Is the scope of the certification clearly defined?
- Does the auditor have proven knowledge and experience?
- Has a documented audit methodology been used?
- Have any anomalies been recorded and demonstrably resolved?
- Has the certification decision been carefully and independently taken?
- Is it clear who issued the certificate?
- Is the validity of the certificate verifiable?
- Are periodic audit audits carried out?
- Is it clearly stated that the certificate was not issued under accreditation?
An unaccredited certificate can therefore still have significant evidentiary value. The recipient ultimately decides whether that evidence is sufficient for its intended purpose.
What does justice say?
There is little Dutch case law dealing directly with an unaccredited certification of an ISO 9001 or ISO/IEC 27001 management system. However, clear starting points can be drawn from the available case law.
Accreditation is not always a legal condition
The Oberlandesgericht Köln dealt with a case in 2015 concerning a certificate according to DIN EN ISO/IEC 17024 issued after the accreditation of the certifying party had expired.
The court ruled that the legal validity of the certificate was not automatically dependent on accreditation. There was no legal provision requiring accreditation for that specific certification. The claim for damages was therefore rejected.
This German judgment concerns personal certification and is not binding on Dutch judges. However, it illustrates an important starting point: where the law or agreement does not require accreditation, a certificate shall not be invalid solely because of the lack of accreditation. OLG Köln 30 September 2015, 26 U 9/15 →
Contractual requirements can be decisive
A contracting authority may require in a contract or procurement that a certificate is issued under accreditation. If this is clearly included as a condition, an unaccredited certificate may be insufficient.
In February 2026 the Rechtbank Rotterdam ruled on a tender containing an ISO 9001 certificate as a fitness requirement. The successful tenderer did not have the required certificate. The court concluded that this tenderer did not meet the suitability requirement and that the registration should have been declared invalid. Rb. Rotterdam 13 February 2026, ECLI:EN:RBROT:2026:1466 →
Equivalent measures are not always sufficient
Article 2.96 of the Dutch Public Procurement Act allows other evidence of equivalent quality-assurance measures under specific conditions. Among other things, a tenderer must show that it could not obtain the requested certificate in time for reasons beyond its control.
In a judgment of 2024 a tenderer did not have the required ISO 9001 certificate and had not yet applied for certification. The court did not accept the alternative evidence. It was not enough to say that a certification process is long. Rb. Limburg 28 March 2024, ECLI:EN:RBLIM:2024:1434 →
The Limburg Court confirmed this line in June 2026. A quality manual did not need to be assessed as an equivalent alternative, since it was not demonstrated that the lack of the ISO 9001 certificate could not be attributed to the tenderer. Rb. Limburg 4 June 2026, ECLI:EN:RBLIM:2026:5449 →
Working by an ISO standard.
Provide the specific certificate required.
An organisation can have a good management system in substance and still be excluded if it does not have the formally required certificate.
When can an unaccredited certificate be appropriate?
An unaccredited certificate may be a practical choice when:
- to have an organisation independently assess how mature its management system is;
- Customers require a demonstrable application of ISO 9001 or ISO/IEC 27001 but do not require accreditation;
- the organisation first wishes to gain experience with certification;
- a certificate is used as an intermediate step towards accredited certification;
- a client accepts the certificate after transparent explanation;
- the cost and extent of accredited certification are at that time disproportionate to the purpose of use.
The certificate may then provide insight into the standard, scope and Declaration of Applicability assessed and the date on which the audit took place.
When is certification under accreditation more sensible?
Certification under accreditation is more obvious when:
- an explicit procurement requirement;
- a customer contract requires an accredited certificate;
- international recognition is important;
- accept large customers only certificates from a recognised accreditation system;
- sets specific requirements for sectoral legislation or regulation;
- the certificate must be capable of being verified through an international certificate register;
- the organisation wishes to discuss the status of the certificate as little as possible.
Therefore, always check the exact customer, contract or procurement requirement first.
Transparency prevents wrong expectations
An organisation with an unaccredited certificate must clearly communicate its status. Only when asking questions that the certificate was not issued under accreditation is less careful than making this information directly available.
An appropriate wording is, for example:
Our management system has been tested and certified by De Compliance Afdeling against ISO/IEC 27001:2022. The certificate was not issued under accreditation from the Accreditation Board.
It is necessary to avoid the use of logo dressings or declarations that give the impression that ISO itself, the RvA or any other accreditation body has issued or approved the certificate.
Furthermore, ISO does not allow its own logo to be used to communicate certification. An organisation is therefore not an ISO-certified organisation. Read ISO Certification Explanation →
How De Compliance Afdeling works
De Compliance Afdeling carries out audits assessing the management system of an organisation against the requirements of, for example, ISO 9001 or ISO/IEC 27001.
If sufficient objective evidence is obtained during the audit and any deficiencies have been resolved, De Compliance Afdeling may issue a certificate. This certificate shall not be issued under accreditation.
We are transparent about this in advance. Organisations should also clearly communicate this status to their own customers and clients. A DCA certificate is not intended to apply an accredited certificate.
Does an organisation need an accreditation certificate because of a tender, customer contract or international recognition? Then we can guide the organisation towards an accredited certification institution. We work with EIK Certification, which is registered with the Accreditation Board under number C669. Check the registration of EIK →
Conclusion
An ISO certificate without accreditation is not automatically invalid. ISO and the Accreditation Board confirm that accreditation is not mandatory in all situations.
The difference lies mainly in the extra security and market acceptance. In the case of accredited certification, the certification body has also been independently assessed. In the case of an unaccredited certificate, the recipient must assess how much trust he has in the auditor, the audit methodology and the certifying party.
For many organisations, a carefully executed and transparently presented unaccredited certificate can be a valuable confirmation of their management system. Where a contracting authority or procurement specifically requires an accredited certificate, that route shall be chosen.
First check which form of certification suits your purpose.
We help assess the requirements and clarify in advance which route and certification status are appropriate.