Skip to main content
Back to research

Open research, August 2026

Nobody Can Check an ISO 27001 Certificate, and the Registers Are Built That Way

We set out to build an ISO/IEC 27001 ontology that reproduces no ISO text, which turned out to be the easy part. The hard part was discovering that the assurance chain a buyer would use to check a certification claim is broken at every link, and that two of those breaks are deliberate design decisions rather than oversights. This page reports what we measured, publishes the vocabulary and the evidence, and explains the one modelling idea that makes the difference: a register that cannot be asked a question is not the same thing as a register that answers no.

The short version

  • The copyright problem is not where people think it is. ISO cannot stop you modelling control addresses, because an address is not expression. The licences that actually bite are the ones everyone reaches for first: the Secure Controls Framework is CC BY-ND and explicitly forbids using AI to generate derivative content from its material, and CIS Controls v8.1 is CC BY-NC-ND. We dropped 1,137 reference lines from those sources rather than argue about them.
  • The global certificate register cannot be enumerated. IAF CertSearch states that no user may view or download a list of certificates issued by a certification body and that all verification must be of known entities. You can confirm a certificate you were handed. You can never discover one, and you can never establish that a supplier has none.
  • 0 of 2,921 UKAS-accredited organisations declare a standard in the public register. UKAS publishes the organisations, publishes a vocabulary of standards, and does not publish the relation between them. ISO/IEC 27001 is absent from that vocabulary entirely.
  • 21.6 per cent of the UKAS scope vocabulary is duplication. 3,336 terms carry 2,617 distinct names. Sampling exists as 15 separate terms, metals as 14, microbiology as 13.
  • The public domain crosswalk has been withdrawn. NIST's SP 800-53 to ISO/IEC 27001 mapping returns 404, and its last archived form addressed the 2013 edition, superseded in 2022.
  • 70 of the 93 Annex A controls have a NIST CSF 2.0 informative reference. Twenty three do not, and nothing published says which.
  • The artefact is an OWL 2 vocabulary with a SKOS registry and three SHACL layers, one of which mechanically proves the graph contains no standard text. Code MIT, ontology CC BY 4.0, no API keys required.

0 / 2,921

UKAS-accredited organisations declaring a standard

21.6%

of the UKAS scope vocabulary is duplicated terms

70 / 93

Annex A controls with a CSF 2.0 reference

404

status of the NIST SP 800-53 to ISO 27001 mapping

The question that starts this work

A buyer writes ISO/IEC 27001 into a contract. A supplier says it is certified. Some months later somebody in procurement or in a second line assurance function has to decide whether that sentence is true, and whether it covers the service actually being bought. That is a small, ordinary, entirely reasonable question, and there is a whole industry selling software that implies it can be answered continuously and at scale.

It cannot, and the reasons are structural rather than commercial. We went looking for them because we wanted to build the ontology, and an ontology of a domain whose registers do not work is a different artefact from an ontology of a domain whose registers do.

Break one: the register is not enumerable, on purpose

IAF CertSearch is the global database of accredited management system certificates, bringing together the International Accreditation Forum, the accreditation bodies and roughly 2,500 certification bodies, and holding on the order of two million certificates. It is the correct place to check a certificate, and for that job it works.

Its published guidance also states, in terms, that no user is able to download or view a list of certifications issued by a certification body, and that all certification verification must be of known entities. Access sits behind an account, with a fair use policy, one free account per organisation, and programmatic access reserved for paid enterprise subscriptions.

The operational consequence is precise. A certificate can be confirmed if you already hold its number. It can never be discovered. Absence cannot be observed at all. This means a buyer cannot audit a supply chain for suppliers who claim certification and do not hold it, because the only party able to produce the identifier needed to run the check is the party whose claim is in question. Every published warning about certificate mills tells buyers to check the IAF database, and that advice is sound for a certificate in hand and useless for the population level question.

We are not arguing this policy is wrong. There are good commercial and data protection reasons for it. We are arguing that any product built on top of it inherits the limit, and that almost none of them say so.

Break two: UKAS publishes who is accredited, but not what for

UKAS is the United Kingdom's national accreditation body, and unlike IAF it publishes a genuinely open register. There is a public WordPress REST endpoint, no key and no account, and we harvested every collection to its declared total: 2,921 accredited organisations, of which 251 are certification bodies, alongside 2,986 schedules, 3,024 schedule instances and two taxonomies.

Credit where it is due, because this is far better than most national registers manage, and our first hypothesis, that UKAS published scopes only as PDFs, was simply wrong and died on contact with the data.

What is missing is the link. Zero of the 2,921 organisation records carry a standard term. Sixteen carry any scope category. None carry a populated custom field. The register publishes the organisations, and separately publishes the vocabulary, and does not publish the relation between the two, so the question the register exists to answer cannot be asked of it.

ISO/IEC 27001 is not in the standard taxonomy at all. Its 35 terms are overwhelmingly conformity assessment standards, the ones that govern assessors rather than the assessed: ISO/IEC 17021-1, 17025, 17020, 17024, 17029, 17043, 17065. That distinction is real and correct, since an accreditation body accredits against ISO/IEC 17021-1 and 27006, not against 27001 itself. It is also exactly the distinction that procurement text collapses when it asks for an ISO 27001 accredited supplier. The only occurrences of 27001 anywhere in the UKAS taxonomies are two scope terms, 27001 Lead Auditors and 27001 Lead Implementers, each classifying one record, and both about certifying people rather than management systems.

We had to introduce a status for this, because neither open nor closed describes it. In the vocabulary it is published but unlinked.

Break three: the controlled vocabularies are not controlled

UKAS standard taxonomy: 35 terms, 26 distinct standards
ISO 37001
3 terms
ISO 14066
3 terms, all lower case
ISO 14065
2 terms
ISO/IEC 17029
2 terms
ISO/TS 23406
2 terms
ISO 55001
2 terms
PAS 2031
2 terms

Seven standards are entered under more than one term, differing by edition suffix or by case.

ISO 14066 appears three times and is lower case in all three, where every other term is upper case. Four terms classify nothing at all: 9001, EMAS, ISO 22870 and QSI. The bare number 9001 is also the only term written without a publisher prefix.

UKAS scope vocabulary: 3,336 terms, 2,617 distinct names
sampling
15 separate terms
metals
14
microbiology
13
pesticides
12
chemical analysis
12
polyaromatic hydrocarbons
11

356 names are carried by more than one term id. 719 term ids are surplus, which is 21.6 per cent of the vocabulary.

The operational consequence for anyone building on this register is that scope comparison is unreliable in a way that is invisible from the outside. Two certification bodies whose schedules both mention sampling may be classified under two different term ids, so any grouping, filtering or coverage count computed on term identity is wrong by an unknown margin.

Break four: the public domain crosswalk has been withdrawn, and was already stale

If you cannot check the certificate, the next best thing is to reason about the controls directly, and for that you need a crosswalk from a control catalogue you are allowed to redistribute. The obvious one is NIST SP 800-53, a United States Government work in the public domain.

The mapping document from SP 800-53 Revision 5 to ISO/IEC 27001 returns 404 at its published address on csrc.nist.gov. The Wayback Machine holds a 200 capture dated 16 March 2023, so it was published and has since been removed. It survives on an unofficial mirror.

Its content matters as much as its absence, and in a way that cuts both ways. The mapping table is identifier only, which is precisely why it would have been usable in a copyright clean build. But it maps to ISO/IEC 27001:2013, superseded in 2022 when Annex A was restructured from 114 controls in 14 clauses to 93 controls in 4 themes. The single most widely cited public domain bridge between the US federal control catalogue and ISO/IEC 27001 is therefore one full revision out of date and no longer served by its publisher.

What is maintained is the NIST CSF 2.0 informative reference catalogue, which does address ISO/IEC 27001:2022 and does so as identifiers only. It is a good dataset and it is the spine of our crosswalk. It also has limits nobody states.

ISO/IEC 27001:2022 Annex A coverage by the NIST CSF 2.0 informative references
People (6.x)
8 of 8, 100%
Organizational (5.x)
29 of 37, 78.4%
Physical (7.x)
10 of 14, 71.4%
Technological (8.x)
23 of 34, 67.6%
All Annex A
70 of 93, 75.3%

70 of 93 controls referenced. 23 have no reference path.

The unreferenced controls are 5.5, 5.6, 5.11, 5.23, 5.30, 5.32, 5.34, 5.37, 7.6, 7.8, 7.9, 7.11, 8.1, 8.10, 8.11, 8.12, 8.23, 8.24, 8.29, 8.30, 8.31, 8.33 and 8.34. Some of those may genuinely have no counterpart worth asserting, and we are not claiming the mapping is deficient. The practitioner point is narrower and still sharp: if CSF 2.0 is your bridge to ISO/IEC 27001, you have no reference path for about a quarter of Annex A, and nothing published tells you which quarter.

We also found five identifier defects in the live crosswalk, out of 412 accepted mappings across 106 subcategories. Two are substantive. GV.RM-07 references Mandatory Clause 6.11 and ID.RA-06 references Mandatory Clause 6.13, and neither names a clause that exists in ISO/IEC 27001:2022, whose clause 6 holds 6.1 with 6.1.1 to 6.1.3, plus 6.2 and 6.3. Both look like 6.1.1 and 6.1.3 with a lost separator, which is the class of error a pattern based validator waves through because both are well formed dotted addresses. The other three are a trailing comma, two identifiers on a single line, and a reference reading All applicable controls, which names no resolvable element and so can never be machine checked.

Five defects in a dataset this size is a good ratio and we report them in that spirit. NIST's OLIR programme also does something most crosswalk publishers do not, which is to record 75 explicit no relationship assertions. That is a claim rather than silence, and it is the right way to publish a mapping.

Break five: the search that would find the requirement ignores you

We wanted to measure how often UK public buyers require certification and how often they require it to be accredited. Contracts Finder is the right corpus and it is Open Government Licence v3.0, so we harvested it.

Its search silently ignores keyword filters. Searching for ISO 27001 returns 694 notices. Searching for UKAS returns 694. Searching for a string of nonsense returns 694. Searching for nothing at all returns 694, because 694 is the unfiltered total. The OCDS API behaves identically: a keyword parameter produces a byte identical result set to no keyword, and the size parameter is discarded in favour of a forced limit. There is no error and no warning.

A silently ignored filter is worse than a rejected one, because the pipeline that trusts it concludes there are no matching notices while looking at an unfiltered feed. That 694 was very nearly a headline in this write up, and the only thing that killed it was running the same query with a deliberately meaningless keyword.

The cursor also drops the early end of whatever window you ask for. Request the whole of April and page to exhaustion and you get 1,432 releases, the earliest dated 20 April, with the chain ending normally and no error. Run it again from scratch and you get the identical count and the identical boundary, so it is deterministic rather than flaky. Then request 1 to 10 April directly and the first page comes back full of releases dated 9 April, inside the window the previous request claimed to have exhausted.

At scale this halves the corpus. January to August as a single window yields 13,271 distinct notices spanning 20 April to 29 August. The same period run as eight separate one-month windows yields 22,678, of which 9,819 are absent from the single-window result. The long walk recovers 56.7 per cent of what the month walks find.

Neither strategy is complete, which is the part worth dwelling on. The month walks in turn miss 412 notices that the long walk found, so one-month windows truncate as well, just less. The union of both is the best retrieval we could achieve, there is no reason to think even that is exhaustive, and the API offers no completeness signal to check against. Every Contracts Finder count in this work is therefore stated as a lower bound.

Both defects reproduce in a browser in under a minute, and both are being reported to the publisher.

The measurement we could not make

The number we wanted was the proportion of public buyers requiring ISO 27001 who also require the certificate to be accredited. We did not get it. Of the 13,271 releases in the first harvest, exactly two mention ISO 27001 in the notice title or description, a rate of 0.02 per cent, and neither requires accreditation. Certification requirements live in attached tender documents, not in notice text, so this source cannot answer the question. No figure for it appears anywhere in the repository, and the hypothesis is recorded as dead in the build report alongside four others.

We mention it because a null result is a result, and because the alternative was to quietly compute the number on n equals two and present it as a finding.

Building an ISO 27001 ontology that contains no ISO text

The copyright analysis is short. The normative text of ISO/IEC 27001 is sold and is protected expression. Its control addresses are not. A.8.23 is a reference in the way a page number is a reference, and reference addresses, document structure, control counts and publication metadata are facts rather than authorship. Case law has moved on standards incorporated into law, and the Court of Justice held in March 2024 that harmonised standards form part of EU law, but none of that currently reaches ISO/IEC 27001, so the safe design is simply not to store the text.

So the vocabulary models standards as addresses and never as text. A standard element carries a notation and an edition link. It carries no title, no definition and no paraphrase, because a systematic paraphrase of ninety three controls is an abridgement of the annex whatever you call it. Meaning is attached by crosswalk to catalogues that are genuinely free to redistribute.

The part worth stealing is that the commitment is mechanical. A SHACL layer rejects any graph in which a standard element carries a label, a definition, a note, a comment, a description, or any literal longer than 24 characters. That layer conforms on every build, which means the absence of protected text is demonstrated rather than asserted. Running the shapes is the audit, and anyone can run them.

The licences that actually constrained the work belonged to nobody's standards body. The Secure Controls Framework is CC BY-ND 4.0 and its terms explicitly prohibit using artificial intelligence to generate derivative content from SCF material. CIS Controls v8.1 is CC BY-NC-ND 4.0. Both forbid exactly what a crosswalk repository does. We dropped 1,137 reference lines from those sources and from the CSA Cloud Controls Matrix on ingest, and the spine of ISO plus NIST lost nothing.

The modelling idea, which transfers to any register

Registers are usually modelled as though they contain facts. They contain claims, made by someone, on a date, through a particular query. So nothing in this vocabulary is a property of a thing. A crosswalk is an assertion with a source, a target, a relationship type drawn from NIST's own vocabulary, an asserter and a date. An accreditation is an assertion. A certification claim is an assertion, and is carefully not the same class as a certificate.

The load bearing class is the register observation: a dated record of what a register did and did not disclose when it was queried, and how it was queried. That is what lets the graph distinguish the register says this supplier has no certificate from the register cannot be asked whether this supplier has a certificate. Almost every compliance tool on the market collapses those two sentences into one, and the difference between them is the entire subject of this page. Here the second is a first class status, and a SHACL rule enforces that you may not record a not found outcome against a register carrying it.

The same discipline applies to our own numbers. Every headline figure is computed twice, once set based in Python and once by SPARQL over the emitted graph, by a script that exits non zero if the two disagree. It earned its place immediately: Annex A control 5.2 and mandatory clause 5.2 are different elements of the same edition, our first URI scheme dropped the part and collapsed them, and nine elements vanished. Python said 93 and SPARQL said 84. Nothing else would have caught it.

What this means if you are buying, or if you are a register

If you write ISO/IEC 27001 into contracts, three things follow directly. Require the certificate number, the certification body and the accreditation body in the response itself, because without those the claim cannot be checked at all and the register will not help you form the query. Require the Statement of Applicability, or at least the list of excluded controls, because a certificate tells you nothing about which of the ninety three controls the holder declared out of scope. Ask whether the certified scope covers the specific service, in writing, because scope statements are free text and two certificates naming the same standard are not comparable.

If you run a register, the finding is more encouraging than it sounds. UKAS already publishes the organisations and the vocabulary openly. Publishing the relation between them is a data change rather than a policy change, and it would make the UK the only jurisdiction where a buyer can determine from open data which bodies are accredited to certify what.

Prior art

NIST's OLIR programme defined the relationship vocabulary reused here rather than reinvented, and is the only body publishing a maintained, public domain, identifier only crosswalk to ISO/IEC 27001. NIST also publishes OSCAL, which is the right machine readable format for control catalogues and which this work aligns to rather than competing with. The reification and evidence pattern comes from our own Chain Control Ontology, and the Specification Conformance Ontology asks a closely related question one layer down, about whether a data exchange specification contradicts itself.

The artefact

The repository is at github.com/fabio-rovai/certification-register-ontology. It contains the OWL 2 vocabulary, the SKOS identifier registry in which each scheme declares whether its register can be enumerated at all, three SHACL layers including the copyright layer, resumable harvesters for UKAS and Contracts Finder, the dual computation script, 28 offline known answer tests, and a build report that records every source that could not be obtained, five hypotheses that died, and three bugs we found in our own work. Code MIT, ontology and documentation CC BY 4.0. No API keys are needed to reproduce any of it.

Where to start

A bounded first engagement is a two week certification claim audit on one supplier population. We take your supplier list, extract every certification claim, classify each one by whether it is checkable at all, run the checks that can be run, and hand back the register observations with the evidence and the method. The deliverable is a defensible statement of what you can and cannot establish about your own supply chain, which is a different and more useful thing than a dashboard that implies you can establish all of it.

If you run one of the registers described here, the specific rows behind any figure above are available and the pipeline is reproducible end to end. Corrections are published on this page rather than applied silently.

Fabio Rovai, fabio@thetesseractacademy.com.