ISO/IEC FDIS 17065
(Main)Conformity assessment — Requirements for bodies certifying products, processes and services
General Information
- Abstract
- Status
- Not Published
- Technical Committee
- ISO/CASCO - Committee on conformity assessment
- Drafting Committee
- ISO/CASCO - Committee on conformity assessment
- Current Stage
- 5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
- Start Date
- 04-Aug-2026
- Completion Date
- 04-Aug-2026
Buy Documents
ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services
REDLINE ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services
Overview
ISO/IEC FDIS 17065 is an international standard developed by ISO and IEC that outlines requirements for bodies certifying products, processes, and services. This standard is essential for certification bodies to demonstrate competence, consistency, and impartiality in their certification activities. Through third-party conformity assessment, ISO/IEC FDIS 17065 aims to establish confidence among all interested parties-including clients, regulators, customers, and the public-that certified products, processes, or services meet specified requirements.
Adhering to ISO/IEC FDIS 17065 helps certification bodies operate in accordance with recognized principles, facilitating acceptance in both national and international markets and supporting global trade. The requirements foster trust in certifications by ensuring transparent, impartial, and reliable evaluation.
Key Topics
- Impartiality and Independence: Certification activities must remain free from commercial, financial, or other pressures that could compromise objectivity. Risks to impartiality are identified and addressed on an ongoing basis.
- Confidentiality and Transparency: Certification bodies are responsible for safeguarding client information, making only the necessary details public as required by law or agreement.
- Legal and Contractual Obligations: Bodies must be legally responsible entities capable of entering enforceable agreements and maintaining appropriate liability coverage.
- Resource Management: Competence of personnel, availability of resources for evaluation, and ongoing training are required to ensure high-quality certification.
- Certification Process: Standardized procedures guide application review, evaluation, decision making, documentation, surveillance, and handling of complaints or appeals.
- Non-Discriminatory Conditions: Access to certification is not restricted based on client size, group membership, or number of certifications. Requirements are related solely to the scope of certification.
- Management Systems: Certification bodies must maintain effective management system documentation, conduct internal audits, perform management reviews, and take corrective actions to address risks and opportunities.
Applications
ISO/IEC FDIS 17065 is widely applied by:
- Product Certification Bodies: Organizations certifying hardware, software, processed materials, or services under an established certification scheme.
- Process and Service Certification: Ensuring that industrial, manufacturing, or service processes fulfill defined quality or regulatory requirements.
- Regulatory Authorities: Governments or agencies referencing this standard when designating or recognizing certification bodies.
- Scheme Owners: Entities (e.g., trade associations, industry groups) developing specific certification schemes based on ISO/IEC FDIS 17065 requirements.
- International Trade Facilitation: Supporting mutual recognition of certifications, thus streamlining market access and compliance with international regulations.
This standard is relevant across industries such as manufacturing, agriculture, food safety, information technology, and more. By providing a consistent framework, it ensures certifications issued by accredited bodies are accepted internationally, helping organizations demonstrate compliance and build stakeholder trust.
Related Standards
- ISO/IEC 17000: Conformity assessment - Vocabulary and general principles.
- ISO/IEC 17020: Requirements for bodies performing inspection.
- ISO/IEC 17021-1: Requirements for bodies providing audit and certification of management systems.
- ISO/IEC 17025: General requirements for competence of testing and calibration laboratories.
- ISO/IEC 17029: General principles and requirements for validation and verification bodies.
- ISO/IEC 17067: Guidance on product certification schemes.
- ISO/IEC 17030: Requirements for third-party marks of conformity.
Each of these standards supports the implementation of robust conformity assessment frameworks and is frequently referenced to ensure harmonized, reliable certification processes worldwide.
By aligning with ISO/IEC FDIS 17065, certification bodies greatly enhance their operational credibility, ensure seamless international cooperation, and deliver confidence to clients and end-users regarding the quality and compliance of certified products, processes, or services.
Relations
- Effective Date
- 09-May-2026
Buy Documents
ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services
REDLINE ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

Bureau Veritas
Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

DNV
DNV is an independent assurance and risk management provider.
Sponsored listings
Frequently Asked Questions
ISO/IEC FDIS 17065 is a draft published by the International Organization for Standardization (ISO). Its full title is "Conformity assessment — Requirements for bodies certifying products, processes and services". This standard covers: L'ISO/IEC 17065:2012 comporte des exigences portant sur les compétences, la cohérence des activités et l'impartialité des organismes de certification de produits, processus et services. Les organismes de certification exerçant selon l'ISO/IEC 17065:2012 ne sont pas tenus de proposer tous les types de certification de produits, processus et services.
L'ISO/IEC 17065:2012 comporte des exigences portant sur les compétences, la cohérence des activités et l'impartialité des organismes de certification de produits, processus et services. Les organismes de certification exerçant selon l'ISO/IEC 17065:2012 ne sont pas tenus de proposer tous les types de certification de produits, processus et services.
ISO/IEC FDIS 17065 is classified under the following ICS (International Classification for Standards) categories: 03.120.20 - Product and company certification. Conformity assessment. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC FDIS 17065 has the following relationships with other standards: It is inter standard links to ISO/IEC 17065:2012. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.
ISO/IEC FDIS 17065 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
FINAL DRAFT
International
Standard
ISO/CASCO
Conformity assessment —
Secretariat: ISO
Requirements for bodies certifying
Voting begins on:
products, processes and services
2026-08-04
Évaluation de la conformité — Exigences pour les organismes
Voting terminates on:
certifiant les produits, les procédés et les services
2026-10-27
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
ISO/CEN PARALLEL PROCESSING LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/CASCO
Conformity assessment —
Secretariat: ISO
Requirements for bodies certifying
Voting begins on:
products, processes and services
Évaluation de la conformité — Exigences pour les organismes
Voting terminates on:
certifiant les produits, les procédés et les services
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
ISO/CEN PARALLEL PROCESSING
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 General requirements . 4
4.1 Legal and contractual matters .4
4.1.1 Legal responsibility .4
4.1.2 Certification agreement .4
4.1.3 Use of license, certificates and marks of conformity .5
4.2 Management of impartiality .5
4.3 Liability and financing .7
4.4 Non-discriminatory conditions .7
4.5 Confidentiality .7
4.6 Publicly available information . .8
5 Structural requirements . 8
5.1 Organizational structure and top management .8
5.2 Mechanism for safeguarding impartiality .9
6 Resource requirements .10
6.1 Certification body personnel .10
6.1.1 General .10
6.1.2 Management of competence for personnel involved in the certification process .10
6.1.3 Contract with the personnel .11
6.2 Resources for evaluation .11
6.2.1 Internal resources .11
6.2.2 External resources (outsourcing) .11
7 Process requirements .12
7.1 General . 12
7.2 Application . 13
7.3 Application review . 13
7.4 Evaluation .14
7.5 Review . 15
7.6 Certification decision . . . 15
7.7 Certification documentation .16
7.8 Directory of certified products .17
7.9 Surveillance .17
7.10 Changes affecting certification .17
7.11 Termination, reduction, suspension or withdrawal of certification .18
7.12 Records .19
7.13 Complaints and appeals.19
8 Management system requirements .20
8.1 Options. 20
8.1.1 General . 20
8.1.2 Option A . 20
8.1.3 Option B . 20
8.2 General management system documentation (Option A) . 20
8.3 Control of documents (Option A) .21
8.4 Control of records (Option A) .21
8.5 Management review (Option A) .21
8.5.1 General .21
8.5.2 Review inputs .21
8.5.3 Review outputs . 22
© ISO/IEC 2026 – All rights reserved
iii
8.6 Internal audits (Option A) . . 22
8.7 Corrective actions (Option A) . . 22
8.8 Actions to address risks and opportunities (Option A) . 23
Annex A (informative) Principles for product certification bodies and their certification
activities .24
Annex B (informative) Application of this document for processes and services .26
Annex ZA (informative) Relationship between this European Standard and the requirements
of Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July
2008 setting out the requirements for accreditation and repealing Regulation (EEC) No
339/93 aimed to be covered .27
Bibliography .29
© ISO/IEC 2026 – All rights reserved
iv
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by the ISO Committee on Conformity Assessment (CASCO), in collaboration
with the European Committee for Standardization (CEN) Technical Committee CEN/CLC/JTC 1, Criteria for
conformity assessment bodies, in accordance with the Agreement on technical cooperation between ISO and
CEN (Vienna Agreement).
This second edition cancels and replaces the first edition (ISO/IEC 17065:2012), which has been technically
revised.
The main changes are as follows:
— updated to reflect terminology in ISO/IEC 17000;
— in subclause 8.8, replaced of “Preventive actions” with a new clause “Actions to address risks and
opportunities”;
— updated and corrected bibliographic references.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
© ISO/IEC 2026 – All rights reserved
v
Introduction
The overall aim of certifying products, processes or services is to give confidence to all interested parties
that a product, process or service fulfils specified requirements. The value of certification is the degree
of confidence and trust that is established by an impartial and competent demonstration of fulfilment of
specified requirements through third-party attestation. Parties that have an interest in certification include,
but are not limited to:
a) the clients of the certification bodies;
b) the customers of the organizations whose products, processes or services are certified;
c) governmental authorities;
d) non-governmental organizations; and
e) consumers and other members of the public.
Interested parties can expect or require the certification body to meet all the requirements of this document
and perform certification in accordance with a certification scheme.
Certification of products, processes or services is a means of providing assurance that they comply with
specified requirements in standards and other normative documents. Some product, process or service
certification schemes can include initial testing or inspection and assessment of its suppliers' quality
management systems, followed by surveillance that takes into account the quality management system and
the testing or inspection of samples from the production and the open market. Other schemes rely on initial
testing and surveillance testing, while still others comprise type testing only.
This document specifies requirements, the observance of which is intended to ensure that certification
bodies operate certification schemes in a competent, consistent and impartial manner, thereby facilitating
the recognition of such bodies and the acceptance of certified products, processes and services on a national
and international basis and so furthering international trade. This document can be used as a criteria
document for accreditation or peer assessment or designation by governmental authorities, scheme owners
and others.
The requirements contained in this document are written, above all, to be considered as general criteria
for certification bodies operating product, process or service certification schemes; they can have to be
amplified when specific industrial or other sectors make use of them, or when particular requirements
such as health and safety have to be taken into account. Annex A contains principles relating to certification
bodies and certification activities that they provide.
This document does not set requirements for schemes and how they are developed and is not intended
to restrict the role or choice of scheme owners, however scheme rules and procedures, including those
identifying the certification requirements, should not contradict or exclude any of the requirements of this
document.
Statements of conformity to the applicable standards or other normative documents can be in the form
of certificates and/or marks of conformity. Schemes for certifying particular products or product groups,
processes and services to specified standards or other normative documents can, in many cases, necessitate
their own explanatory documentation.
While this document is concerned with bodies providing certification (third party attestation) for a product,
process or service, many of its provisions can also be useful for bodies performing first- and second-party
product, process or service conformity assessment activities.
In this document, the following verbal forms are used:
— “shall” indicates a requirement;
— “should” indicates a recommendation;
— “may” indicates a permission;
© ISO/IEC 2026 – All rights reserved
vi
— “can” indicates a possibility or a capability.
Further details can be found in the ISO/IEC Directives, Part 2.
© ISO/IEC 2026 – All rights reserved
vii
FINAL DRAFT International Standard ISO/IEC FDIS 17065:2026(en)
Conformity assessment — Requirements for bodies certifying
products, processes and services
1 Scope
This document contains requirements for the competence, consistent operation and impartiality of product,
process and service certification bodies. Certification bodies operating to this document need not offer all
types of products, processes and services certification. Certification of products, processes and services is a
third-party conformity assessment activity (see ISO/IEC 17000:2020, 4.5).
In this document, the term “product” can be read as “process” or “service”, except in those instances where
separate provisions are stated for “processes” or “services” (see Annex B).
2 Normative references
The following referenced documents are indispensable for the application of this document. For dated
references, only the edition cited applies. For undated references, the latest edition of the referenced
document (including any amendments) applies.
ISO/IEC 17000, Conformity assessment — Vocabulary and general principles
ISO/IEC 17020, Conformity assessment — Requirements for bodies performing inspection
ISO/IEC 17021-1, Conformity assessment — Requirements for bodies providing audit and certification of
management systems — Part 1: Requirements
ISO/IEC 17025, General requirements for the competence of testing and calibration laboratories
ISO/IEC 17029, Conformity assessment — General principles and requirements for validation and verification
bodies
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 17000 and the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
client
organization or person responsible to a certification body for ensuring that certification requirements (3.7),
including product requirements (3.8), are fulfilled
Note 1 to entry: Whenever the term “client” is used in this document, it applies to both the “applicant” and the “client”,
unless otherwise specified.
3.2
consultancy
participation in
© ISO/IEC 2026 – All rights reserved
a) the designing, manufacturing, installing, maintaining or distributing of a certified product or a product
to be certified, or
b) the designing, implementing, operating or maintaining of a certified process or a process to be certified,
or
c) the designing, implementing, providing or maintaining of a certified service or a service to be certified
Note 1 to entry: In this document, the term “consultancy” is used in relation to activities of certification bodies,
personnel of certification bodies and organizations related or linked to certification bodies.
3.3
evaluation
combination of the selection and determination functions of conformity assessment activities
Note 1 to entry: The selection and determination functions are specified in ISO/IEC 17000:2020, Clauses A.2 and A.3.
3.4
product
result of a process
1)
Note 1 to entry: Four generic product categories are noted in ISO 9000:2005 :
— services (e.g. transport) (see 3.6);
— software (e.g. computer program, dictionary);
— hardware (e.g. engine, mechanical part);
— processed materials (e.g. lubricant).
Many products comprise elements belonging to different generic product categories. Whether the product is then
called service, software, hardware or processed material depends on the dominant element.
Note 2 to entry: Products include results of natural processes, such as growth of plants and formation of other natural
resources.
3.5
process
set of interrelated or interacting activities which transforms inputs into outputs
EXAMPLE Welding engineering processes; heat treatment processes; manufacturing processes requiring
confirmation of process capability (e.g. operating or producing product within specified tolerances); food production
processes; plant growth processes.
Note 1 to entry: Adapted from ISO 9000:2005, 3.4.1.
3.6
service
result of at least one activity necessarily performed at the interface between the supplier and the customer,
which is generally intangible
Note 1 to entry: Provision of a service can involve, for example, the following:
— an activity performed on a customer-supplied tangible product (e.g. automobile to be repaired);
— an activity performed on a customer-supplied intangible product (e.g. the income statement needed to prepare a
tax return);
— the delivery of an intangible product (e.g. the delivery of information in the context of knowledge transmission);
— the creation of ambience for the customer (e.g. in hotels and restaurants).
Note 2 to entry: Adapted from ISO 9000:2005, 3.4.2.
1) Withdrawn.
© ISO/IEC 2026 – All rights reserved
3.7
certification requirement
requirement, including product requirements (3.8), that is fulfilled by the client (3.1) as a condition of
establishing or maintaining certification
EXAMPLE The following are certification requirements that are not product requirements:
— completing the certification agreement;
— paying fees;
— providing information about changes to the certified product;
— providing access to certified products for surveillance activities.
Note 1 to entry: Certification requirements include requirements imposed on the client by the certification body
[usually via the certification agreement (see 4.1.2)] to meet this document, and can also include requirements
imposed on the client by the certification scheme. Certification requirements, as used in this document, do not include
requirements imposed on the certification body by the certification scheme.
3.8
product requirement
specified requirement that relates directly to a product, stated in standards or in other normative documents
identified by the certification scheme
Note 1 to entry: Product requirements can be stated in normative documents such as regulations, standards and
technical specifications.
3.9
certification scheme
set of rules and procedures that describes the object of conformity assessment, identifies the specified
requirements and provides the methodology for performing certification and the related conformity
assessment activities
Note 1 to entry: The object of conformity assessment in this document is a product, process or service.
Note 2 to entry: General guidance on conformity assessment schemes which include product, process or services
certification is given in ISO/IEC 17067.
[SOURCE: ISO/IEC 17000:2020, 4.9, modified — "Conformity assessment" has been replaced by "certification
and the related conformity assessment activities"; the original notes to entry have been replaced by new
ones.]
3.10
scope of certification
— information identifying the product(s), process(es) or service(s) for which the certification is granted,
— the applicable certification scheme, and
— the standard(s) and other normative document(s), including their date of publication, to which it is judged
that the product(s), process(es) or service(s) comply
3.11
scheme owner
person or organization responsible for developing and maintaining a specific certification scheme (3.9)
Note 1 to entry: The scheme owner can be the certification body itself, a governmental authority, a trade association, a
group of certification bodies or others.
© ISO/IEC 2026 – All rights reserved
3.12
certification body
third-party conformity assessment body operating certification schemes
Note 1 to entry: A certification body can be non-governmental or governmental (with or without regulatory authority).
3.13
impartiality
objectivity with regard to the outcome of a conformity assessment activity
Note 1 to entry: Objectivity can be understood as freedom from bias or freedom from conflicts of interest.
[SOURCE: ISO/IEC 17000:2020, 5.3]
4 General requirements
4.1 Legal and contractual matters
4.1.1 Legal responsibility
The certification body shall be a legal entity, or a defined part of a legal entity, such that the legal entity can
be held legally responsible for all its certification activities.
NOTE A governmental certification body is deemed to be a legal entity on the basis of its governmental status.
4.1.2 Certification agreement
4.1.2.1 The certification body shall have a legally enforceable agreement for the provision of certification
activities to its clients. Certification agreements shall take into account the responsibilities of the
certification body and its clients.
4.1.2.2 The certification body shall ensure its certification agreement requires that the client comply at
least, with the following:
a) the client always fulfils the certification requirements (see 3.7), including implementing appropriate
changes when they are communicated by the certification body (see 7.10);
b) if the certification applies to ongoing production, the certified product continues to fulfil the product
requirements (see 3.8);
c) the client makes all necessary arrangements for
1) the conduct of the evaluation (see 3.3) and surveillance (if required), including provision for
examining documentation and records, and access to the relevant equipment, location(s), area(s),
personnel, and client's subcontractors;
2) investigation of complaints;
3) the participation of observers, if applicable;
d) the client makes claims regarding certification consistent with the scope of certification (see 3.10);
e) the client does not use its product certification in such a manner as to bring the certification body into
disrepute and does not make any statement regarding its product certification that the certification
body can consider misleading or unauthorized;
f) upon suspension, withdrawal, or termination of certification, the client discontinues its use of all
advertising matter that contains any reference thereto and takes action as required by the certification
scheme (e.g. the return of certification documents) and takes any other required measure;
© ISO/IEC 2026 – All rights reserved
g) if the client provides copies of the certification documents to others, the documents shall be reproduced
in their entirety or as specified in the certification scheme;
h) in making reference to its product certification in communication media such as documents, brochures
or advertising, the client complies with the requirements of the certification body or as specified by the
certification scheme;
i) the client complies with any rules and procedures that may be prescribed in the certification scheme
relating to the use of marks of conformity, and on information related to the product;
NOTE See also ISO/IEC 17030
j) the client keeps a record of all complaints made known to it relating to compliance with certification
requirements and makes these records available to the certification body when requested, and
1) takes appropriate action with respect to such complaints and any deficiencies found in products
that affect compliance with the requirements for certification;
2) documents the actions taken;
NOTE Verification of item j) by the certification body can be specified in the certification scheme.
k) the client informs the certification body, without delay, of changes that can affect its ability to conform
with the certification requirements.
NOTE Examples of changes can include the following:
— the legal, commercial, organizational status or ownership;
— organization and management (e.g. key managerial, decision-making or technical staff);
— modifications to the product or the production method;
— contact address and production sites;
— major changes to the quality management system.
4.1.3 Use of license, certificates and marks of conformity
4.1.3.1 The certification body shall exercise the control as specified by the certification scheme over
ownership, use and display of licenses, certificates, marks of conformity, and any other mechanisms for
indicating a product is certified.
NOTE ISO/IEC 17030 provides requirements for the use of third-party marks.
4.1.3.2 Incorrect references to the certification scheme, or misleading use of licenses, certificates, marks,
or any other mechanism for indicating a product is certified, found in documentation or other publicity, shall
be dealt with by suitable action.
4.2 Management of impartiality
4.2.1 Certification activities shall be undertaken impartially.
4.2.2 The certification body shall be responsible for the impartiality of its certification activities and shall
not allow commercial, financial or other pressures to compromise impartiality.
4.2.3 The certification body shall identify risks to its impartiality on an ongoing basis. This shall include
those risks that arise from its activities, from its relationships, or from the relationships of its personnel
(see 4.2.12). However, such relationships may not necessarily present a certification body with a risk to
impartiality.
© ISO/IEC 2026 – All rights reserved
NOTE 1 A relationship presenting a risk to impartiality of the certification body can be based on ownership,
governance, management, personnel, shared resources, finances, contracts, marketing (including branding), and
payment of a sales commission or other inducement for the referral of new clients, etc.
NOTE 2 Identifying risks does not imply risk assessments as stated in ISO 31000.
4.2.4 If a risk to impartiality is identified, the certification body shall be able to demonstrate how it
eliminates or minimizes such risk. This information shall be made available to the mechanism specified in
5.2.
4.2.5 The certification body shall have top management commitment to impartiality.
4.2.6 The certification body and any part of the same legal entity and entities under its organizational
control (see 7.6.4) shall not:
a) be the designer, manufacturer, installer, distributer or maintainer of the certified product;
b) be the designer, implementer, operator or maintainer of the certified process;
c) be the designer, implementer, provider or maintainer of the certified service;
d) offer or provide consultancy (see 3.2) to its clients;
e) offer or provide management system consultancy or internal auditing to its clients where the
certification scheme requires the evaluation of the client’s management system.
NOTE 1 This does not preclude the following:
— the possibility of exchange of information (e.g. explanations of findings or clarifying requirements) between the
certification body and its clients;
— the use, installing and maintaining of certified products which are necessary for the operations of the certification
body.
NOTE 2 “Management system consultancy” is defined in ISO/IEC 17021-1:2015, 3.3.
4.2.7 The certification body shall ensure that activities of separate legal entities, with which the
certification body or the legal entity of which it forms a part has relationships, do not compromise the
impartiality of its certification activities.
NOTE See 4.2.3, NOTE 1.
4.2.8 When the separate legal entity in 4.2.7 offers or produces the certified product (including products to
be certified) or offers or provides consultancy (see 3.2), the certification body's management personnel and
personnel in the review and certification decision-making process shall not be involved in the activities of
the separate legal entity. The personnel of the separate legal entity shall not be involved in the management
of the certification body, the review, or the certification decision.
NOTE For the evaluation personnel, impartiality requirements are stipulated in Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.1 and 6.2.2.1.
4.2.9 The certification body's activities shall not be marketed or offered as linked with the activities
of an organization that provides consultancy (see 3.2). A certification body shall not state or imply that
certification would be simpler, easier, faster or less expensive if a specified consultancy organization were
used.
4.2.10 Within a period specified by the certification body, personnel shall not be used to review or make a
certification decision for a product for which they have provided consultancy (see 3.2).
© ISO/IEC 2026 – All rights reserved
NOTE 1 The period can be specified in the certification scheme or, if specified by the certification body, it reflects a
period that is long enough to ensure that the review or decision does not compromise impartiality. A specified period
of two years is often used.
NOTE 2 For the evaluation personnel, impartiality requirements are stipulated in Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.1 and 6.2.2.1.
4.2.11 The certification body shall take action to respond to any risks to its impartiality, arising from the
actions of other persons, bodies or organizations, of which it becomes aware.
4.2.12 All certification body personnel (either internal or external) or committees who could influence the
certification activities shall act impartially.
4.3 Liability and financing
4.3.1 The certification body shall have adequate arrangements (e.g. insurance or reserves) to cover
liabilities arising from its operations.
4.3.2 The certification body shall have the financial stability and resources required for its operations.
4.4 Non-discriminatory conditions
4.4.1 The policies and procedures under which the certification body operates, and the administration of
them, shall be non-discriminatory. Procedures shall not be used to impede or inhibit access by applicants,
other than as provided for in this document.
4.4.2 The certification body shall make its services accessible to all applicants whose activities fall within
the scope of its operations.
4.4.3 Access to the certification process shall not be conditional upon the size of the client or membership
of any association or group, nor shall certification be conditional upon the number of certifications already
issued. There shall not be undue financial or other conditions.
NOTE A certification body can decline to accept an application or maintain a contract for certification from a
client when fundamental or demonstrated reasons exist, such as the client participating in illegal activities, having a
history of repeated non-compliances with certification/product requirements, or similar client-related issues.
4.4.4 The certification body shall confine its requirements, evaluation, review, decision and surveillance
(if any) to those matters specifically related to the scope of certification.
4.5 Confidentiality
4.5.1 The certification body shall be responsible, through legally enforceable commitments, for the
management of all information obtained or created during the performance of certification activities. Except
for information that the client makes publicly available, or when agreed between the certification body and
the client (e.g. for the purpose of responding to complaints), all other information is considered proprietary
information and shall be regarded as confidential. The certification body shall inform the client, in advance,
of the information it intends to place in the public domain.
4.5.2 When the certification body is required by law or authorized by contractual arrangements to release
confidential information, the client or person concerned shall, unless prohibited by law, be notified of the
information provided.
4.5.3 Information about the client obtained from sources other than the client (e.g. from the complainant
or from regulators) shall be treated as confidential.
© ISO/IEC 2026 – All rights reserved
4.6 Publicly available information
The certification body shall maintain (through publications, electronic media or other means), and make
available upon request, the following:
a) information about (or reference to) the certification scheme(s), including evaluation procedures, rules
and procedures for granting, for maintaining, for extending or reducing the scope of, for suspending, for
withdrawing or for refusing certification;
b) a description of the means by which the certification body obtains financial support and general
information on the fees charged to applicants and to clients;
c) a description of the rights and duties of applicants and clients, including requirements, restrictions
or limitations on the use of the certification body's name and certification mark and on the ways of
referring to the certification granted;
d) information about procedures for handling complaints and appeals.
5 Structural requirements
5.1 Organizational structure and top management
5.1.1 Certification activities shall be structured and managed so as to safeguard impartiality.
5.1.2 The certification body shall document its organizational structure, showing duties, responsibilities
and authorities of management and other certification personnel and any committees. When the certification
body is a defined part of a legal entity, the structure shall include the line of authority and the relationship to
other parts within the same legal entity.
5.1.3 The management of the certification body shall identify the board, group of persons, or person
having overall authority and responsibility for each of the following:
a) development of policies relating to the operation of the certification body;
b) supervision of the implementation of the policies and procedures;
c) supervision of the finances of the certification body;
d) development of certification activities;
e) development of certification requirements;
f) evaluation (see 7.4);
g) review (see 7.5);
h) decisions on certification (see 7.6);
i) delegation of authority to committees or personnel, as required, to undertake defined activities on its
behalf;
j) contractual arrangements;
k) provision of adequate resources for ce
...
ISO/CASCO
Secretariat: ISO
Date: 2026-06-22
Conformity assessment — Requirements for bodies certifying
products, processes and services
Évaluation de la conformité — Exigences pour les organismes certifiant les produits, les procédés et les services
FDIS stage
TThhiiss d drraftaft i iss s suubbmmiitttteded t too a pa pararallel vallel vootte e iinn I ISSOO,, I IECEC && C CENEN.
© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
E-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword . v
Introduction . vii
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 General requirements . 4
4.1 Legal and contractual matters . 4
4.2 Management of impartiality . 6
4.3 Liability and financing . 7
4.4 Non-discriminatory conditions. 7
4.5 Confidentiality . 8
4.6 Publicly available information . 8
5 Structural requirements . 8
5.1 Organizational structure and top management . 8
5.2 Mechanism for safeguarding impartiality . 9
6 Resource requirements . 10
6.1 Certification body personnel . 10
6.2 Resources for evaluation . 12
7 Process requirements . 13
7.1 General. 13
7.2 Application . 14
7.3 Application review . 14
7.4 Evaluation . 15
7.5 Review . 16
7.6 Certification decision . 16
7.7 Certification documentation . 17
7.8 Directory of certified products . 17
7.9 Surveillance . 18
7.10 Changes affecting certification . 18
7.11 Termination, reduction, suspension or withdrawal of certification . 19
7.12 Records . 20
7.13 Complaints and appeals. 20
8 Management system requirements . 21
8.1 Options . 21
8.2 General management system documentation (Option A) . 21
8.3 Control of documents (Option A) . 22
8.4 Control of records (Option A) . 22
8.5 Management review (Option A) . 22
8.6 Internal audits (Option A) . 23
8.7 Corrective actions (Option A) . 24
8.8 Actions to address risks and opportunities (Option A) . 24
Annex A (informative) Principles for product certification bodies and their certification
activities . 25
Annex B (informative) Application of this document for processes and services . 27
Annex ZA (informative) Relationship between this European Standard and the requirements of
Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July
© ISO/IEC 2026 – All rights reserved
iii
2008 setting out the requirements for accreditation and repealing Regulation (EEC) No
339/93 aimed to be covered . 28
Bibliography . 30
© ISO/IEC 2026 – All rights reserved
iv
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of conformity
assessment, the ISO Committee on conformity assessment (CASCO) is responsible for the development of
International Standards and Guides.
International Standards are The procedures used to develop this document and those intended for its further
maintenance are described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria
needed for the different types of document should be noted. This document was drafted in accordance with
the editorial rules given inof the ISO/IEC Directives, Part 2 (see www.iso.org/directives or
www.iec.ch/members_experts/refdocs.).
Draft International Standards are circulated to the national bodies for voting. Publication as an International
Standard requires approval by at least 75 % of the national bodies casting a vote.
Attention is drawnISO and IEC draw attention to the possibility that some of the elementsimplementation of
this document may beinvolve the subjectuse of (a) patent(s). ISO and IEC take no position concerning the
evidence, validity or applicability of any claimed patent rights in respect thereof. As of the date of publication
of this document, ISO and IEC had not received notice of (a) patent(s) which may be required to implement
this document. However, implementers are cautioned that this may not represent the latest information,
which may be obtained from the patent database available at www.iso.org/patents and https://patents.iec.ch.
ISO. ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html/.
In the IEC, see www.iec.ch/understanding-standards 17065.
This document was prepared by the ISO Committee on conformity assessmentConformity Assessment
(CASCO), in collaboration with the European Committee for Standardization (CEN) Technical Committee
CEN/CLC/JTC 1, Criteria for conformity assessment bodies, in accordance with the Agreement on technical
cooperation between ISO and CEN (Vienna Agreement).
It was circulated for voting to the national bodies of both ISO and IEC, and was approved by both organizations.
This second edition of ISO/IEC 17065 cancels and replaces the first edition (ISO/IEC 17065:2012,), which has
been technically revised.
The following majormain changes have been made compared with ISO/IEC 17065:2012are as follows:
— updateupdated to reflect terminology in ISO/IEC 17000:2020;
— in subclause 8.8in clause of Clause 8.8, replacement, replaced of “Preventive actions” with a new clause
“Actions to address risks and opportunities””;
— updated alland corrected bibliographic references of ISO/IEC 17021 with ISO/IEC 17021-1 and
references.
© ISO/IEC 2026 – All rights reserved
v
Any feedback or questions on this document should be directed to Guides no longer publishedthe user’s
national standards body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committeesthe Bibliography.
© ISO/IEC 2026 – All rights reserved
vi
Introduction
The overall aim of certifying products, processes or services is to give confidence to all interested parties that
a product, process or service fulfils specified requirements. The value of certification is the degree of
confidence and trust that is established by an impartial and competent demonstration of fulfilment of specified
requirements through third-party attestation. Parties that have an interest in certification include, but are not
limited to:
a) the clients of the certification bodies;
b) the customers of the organizations whose products, processes or services are certified;
c) governmental authorities;
d) non-governmental organizations; and
e) consumers and other members of the public.
Interested parties can expect or require the certification body to meet all the requirements of this
International Standarddocument and perform certification in accordance with a certification scheme.
Certification of products, processes or services is a means of providing assurance that they comply with
specified requirements in standards and other normative documents. Some product, process or service
certification schemes maycan include initial testing or inspection and assessment of its suppliers' quality
management systems, followed by surveillance that takes into account the quality management system and
the testing or inspection of samples from the production and the open market. Other schemes rely on initial
testing and surveillance testing, while still others comprise type testing only.
This International Standarddocument specifies requirements, the observance of which is intended to ensure
that certification bodies operate certification schemes in a competent, consistent and impartial manner,
thereby facilitating the recognition of such bodies and the acceptance of certified products, processes and
services on a national and international basis and so furthering international trade. This International
Standarddocument can be used as a criteria document for accreditation or peer assessment or designation by
governmental authorities, scheme owners and others.
The requirements contained in this International Standarddocument are written, above all, to be considered
as general criteria for certification bodies operating product, process or service certification schemes; they
maycan have to be amplified when specific industrial or other sectors make use of them, or when particular
requirements such as health and safety have to be taken into account. Annex AAnnex A contains principles
relating to certification bodies and certification activities that they provide.
This International Standarddocument does not set requirements for schemes and how they are developed and
is not intended to restrict the role or choice of scheme owners, however scheme rules and procedures,
including those identifying the certification requirements, should not contradict or exclude any of the
requirements of this International Standarddocument.
Statements of conformity to the applicable standards or other normative documents can be in the form of
certificates and/or marks of conformity. Schemes for certifying particular products or product groups,
processes and services to specified standards or other normative documents willcan, in many cases,
requirenecessitate their own explanatory documentation.
While this document is concerned with bodies providing certification (third party attestation) for a product,
process or service, many of its provisions can also be useful for bodies performing first- and second-party
product, process or service conformity assessment activities.
© ISO/IEC 2026 – All rights reserved
vii
In this International Standarddocument, the following verbal forms are used:
— “shall” indicates a requirement;
— “should” indicates a recommendation;
— “may” indicates a permission;
— “can” indicates a possibility or a capability.
Further details can be found in the ISO/IEC Directives, Part 2.
© ISO/IEC 2026 – All rights reserved
viii
Conformity assessment — Requirements for bodies certifying
products, processes and services
1 Scope
This International Standarddocument contains requirements for the competence, consistent operation and
impartiality of product, process and service certification bodies. Certification bodies operating to this
International Standarddocument need not offer all types of products, processes and services certification.
Certification of products, processes and services is a third-party conformity assessment activity (see ISO/IEC
17000:2020, 4.5).
In this International Standarddocument, the term “product” can be read as “process” or “service”, except in
those instances where separate provisions are stated for “processes” or “services” (see Annex BAnnex B).).
2 Normative references
The following referenced documents are indispensable for the application of this document. For dated
references, only the edition cited applies. For undated references, the latest edition of the referenced
document (including any amendments) applies.
ISO/IEC 17000, Conformity assessment — Vocabulary and general principles
ISO/IEC 17020, Conformity assessment — Requirements for bodies performing inspection
ISO/IEC 17021-1, Conformity assessment — Requirements for bodies providing audit and certification of
management systems — Part 1: Requirements
ISO/IEC 17025, General requirements for the competence of testing and calibration laboratories
ISO/IEC 17029 -, Conformity assessment — General principles and requirements for validation and verification
bodies,
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 17000 and the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp3.1
— IEC Electropedia: available at https://www.electropedia.org/
3.1
client
organization or person responsible to a certification body for ensuring that certification requirements
(3.7(3.7),), including product requirements (3.8(3.8),), are fulfilled
NOTE Note 1 to entry: Whenever the term “client” is used in this International Standarddocument, it applies to both
the “applicant” and the “client”, unless otherwise specified.
3.2 3.2
consultancy
participation in
© ISO/IEC 2026 – All rights reserved
a) the designing, manufacturing, installing, maintaining or distributing of a certified product or a product to
be certified, or
b) the designing, implementing, operating or maintaining of a certified process or a process to be certified,
or
c) the designing, implementing, providing or maintaining of a certified service or a service to be certified
NOTE Note 1 to entry: In this International Standarddocument, the term “consultancy” is used in relation to
activities of certification bodies, personnel of certification bodies and organizations related or linked to certification
bodies.
3.3 3.3
evaluation
combination of the selection and determination functions of conformity assessment activities
NOTE Note 1 to entry: The selection and determination functions are specified in ISO/IEC 17000:2020, Clauses A.2
and A.3.
3.4 3.4
product
result of a process
1)
NOTENote 1 to entry: Four generic product categories are noted in ISO 9000:2005: :
— services (e.g. transport) (see 3.6definition in 3.6); );
— software (e.g. computer program, dictionary);
— hardware (e.g. engine, mechanical part);
— processed materials (e.g. lubricant).
Many products comprise elements belonging to different generic product categories. Whether the product is then called
service, software, hardware or processed material depends on the dominant element.
NOTE 2 Note 2 to entry: Products include results of natural processes, such as growth of plants and formation of other
natural resources.
3.5 3.5
process
set of interrelated or interacting activities which transforms inputs into outputs
EXAMPLESEXAMPLE Welding engineering processes; heat treatment processes; manufacturing processes
requiring confirmation of process capability (e.g. operating or producing product within specified tolerances); food
production processes; plant growth processes.
NOTE Note 1 to entry: Adapted from ISO 9000:2005, definition 3.4.1.
3.6 3.6
service
result of at least one activity necessarily performed at the interface between the supplier and the customer,
which is generally intangible
1)
Withdrawn.
© ISO/IEC 2026 – All rights reserved
NOTE 1 Note 1 to entry: Provision of a service can involve, for example, the following:
— an activity performed on a customer-supplied tangible product (e.g. automobile to be repaired);
— an activity performed on a customer-supplied intangible product (e.g. the income statement needed to prepare a tax
return);
— the delivery of an intangible product (e.g. the delivery of information in the context of knowledge transmission);
— the creation of ambience for the customer (e.g. in hotels and restaurants).
NOTE Note 2 to entry: Adapted from ISO 9000:2005, definition 3.4.2.
3.7 3.7
certification requirement
requirement, including product requirements (3.8(3.8),), that is fulfilled by the client (3.1(3.1)) as a condition
of establishing or maintaining certification
NOTE Certification requirements include requirements imposed on the client by the certification body [usually via
the certification agreement (see 4.1.2)] to meet this International Standard, and can also include requirements imposed
on the client by the certification scheme. “Certification requirements”, as used in this International Standard, do not
include requirements imposed on the certification body by the certification scheme.
EXAMPLE The following are certification requirements that are not product requirements:
— completing the certification agreement;
— paying fees;
— providing information about changes to the certified product;
— providing access to certified products for surveillance activities.
Note 1 to entry: Certification requirements include requirements imposed on the client by the
certification body [usually via the certification agreement (see 4.1.23.8
)] to meet this document, and can also include requirements imposed on the client by the certification scheme.
Certification requirements, as used in this document, do not include requirements imposed on the certification body by
the certification scheme.
3.8
product requirement
specified requirement that relates directly to a product, stated in standards or in other normative documents
identified by the certification scheme
NOTE Note 1 to entry: Product requirements can be stated in normative documents such as regulations, standards
and technical specifications.
3.83.9 3.9
certification scheme
set of rules and procedures that describes the object of conformity assessment, identifies the specified
requirements and provides the methodology for performing certification and the related conformity
assessment activities
Note 1 to entry: The object of conformity assessment in this document is a product, process or service.
Note 2 to entry: General guidance on conformity assessment schemes which include product, process or services
certification is given in ISO/IEC 17067.
© ISO/IEC 2026 – All rights reserved
[SOURCE: ISO/IEC 17000:2020, 4.9, modified — At the end of the definition, "conformity"Conformity
assessment" has been replaced by "certification and the related conformity assessment activities"; the original
notes to entry have been replaced by new ones.]
3.93.10 3.10
scope of certification
— information identifying the product(s), process(es) or service(s) for which the certification is granted,
— the applicable certification scheme, and
— the standard(s) and other normative document(s), including their date of publication, to which it is judged
that the product(s), process(es) or service(s) comply
3.103.11 3.11
scheme owner
person or organization responsible for developing and maintaining a specific certification scheme (3.9(3.9))
NOTE Note 1 to entry: The scheme owner can be the certification body itself, a governmental authority, a trade
association, a group of certification bodies or others.
3.113.12 3.12
certification body
third-party conformity assessment body operating certification schemes
NOTE Note 1 to entry: A certification body can be non-governmental or governmental (with or without regulatory
authority).
3.123.13
3.13 impartiality
objectivity with regard to the outcome of a conformity assessment activity
Note 1 to entry: Objectivity can be understood as freedom from bias or freedom from conflicts of interest.
Source[SOURCE: ISO/IEC 17000:2020, 5.3]
4 General requirements
4.1 Legal and contractual matters
4.1.1 Legal responsibility
The certification body shall be a legal entity, or a defined part of a legal entity, such that the legal entity can be
held legally responsible for all its certification activities.
NOTE A governmental certification body is deemed to be a legal entity on the basis of its governmental status.
4.1.2 Certification agreement
4.1.2.1 4.1.2.1 The certification body shall have a legally enforceable agreement for the
provision of certification activities to its clients. Certification agreements shall take into account the
responsibilities of the certification body and its clients.
© ISO/IEC 2026 – All rights reserved
4.1.2.2 4.1.2.2 The certification body shall ensure its certification agreement requires that the
client comply at least, with the following:
a) the client always fulfils the certification requirements (see 3.73.7),), including implementing appropriate
changes when they are communicated by the certification body (see 7.107.10););
b) if the certification applies to ongoing production, the certified product continues to fulfil the product
requirements (see 3.83.8););
c) the client makes all necessary arrangements for
1) the conduct of the evaluation (see 3.33.3)) and surveillance (if required), including provision for
examining documentation and records, and access to the relevant equipment, location(s), area(s),
personnel, and client's subcontractors;
2) investigation of complaints;
3) the participation of observers, if applicable;
d) the client makes claims regarding certification consistent with the scope of certification (see 3.103.10););
e) the client does not use its product certification in such a manner as to bring the certification body into
disrepute and does not make any statement regarding its product certification that the certification body
maycan consider misleading or unauthorized;
f) upon suspension, withdrawal, or termination of certification, the client discontinues its use of all
advertising matter that contains any reference thereto and takes action as required by the certification
scheme (e.g. the return of certification documents) and takes any other required measure;
g) if the client provides copies of the certification documents to others, the documents shall be reproduced
in their entirety or as specified in the certification scheme;
h) in making reference to its product certification in communication media such as documents, brochures or
advertising, the client complies with the requirements of the certification body or as specified by the
certification scheme;
i) the client complies with any rules and procedures that may be prescribed in the certification scheme
relating to the use of marks of conformity, and on information related to the product;
NOTE See also ISO/IEC 17030
j) the client keeps a record of all complaints made known to it relating to compliance with certification
requirements and makes these records available to the certification body when requested, and
1) takes appropriate action with respect to such complaints and any deficiencies found in products that
affect compliance with the requirements for certification;
2) documents the actions taken;
NOTE Verification of item j) by the certification body can be specified in the certification scheme.
k) the client informs the certification body, without delay, of changes that maycan affect its ability to conform
with the certification requirements.
NOTE Examples of changes can include the following:
© ISO/IEC 2026 – All rights reserved
— the legal, commercial, organizational status or ownership,;
— organization and management (e.g. key managerial, decision-making or technical staff),);
— modifications to the product or the production method,;
— contact address and production sites,;
— major changes to the quality management system.
4.1.3 Use of license, certificates and marks of conformity
4.1.3.1 4.1.3.1 The certification body shall exercise the control as specified by the certification
scheme over ownership, use and display of licenses, certificates, marks of conformity, and any other
mechanisms for indicating a product is certified.
NOTE 2 ISO/IEC 17030 provides requirements for the use of third-party marks.
4.1.3.2 4.1.3.2 Incorrect references to the certification scheme, or misleading use of licenses,
certificates, marks, or any other mechanism for indicating a product is certified, found in
documentation or other publicity, shall be dealt with by suitable action.
4.2 Management of impartiality
4.2.1 4.2.1 Certification activities shall be undertaken impartially.
4.2.2 4.2.2 The certification body shall be responsible for the impartiality of its certification activities and
shall not allow commercial, financial or other pressures to compromise impartiality.
4.2.3 4.2.3 The certification body shall identify risks to its impartiality on an ongoing basis. This shall
include those risks that arise from its activities, from its relationships, or from the relationships of its
personnel (see 4.2.124.2.12).). However, such relationships may not necessarily present a
certification body with a risk to impartiality.
NOTE 1 A relationship presenting a risk to impartiality of the certification body can be based on ownership,
governance, management, personnel, shared resources, finances, contracts, marketing (including branding), and
payment of a sales commission or other inducement for the referral of new clients, etc.
NOTE 2 Identifying risks does not imply risk assessments as stated in ISO 31000.
4.2.4 4.2.4 If a risk to impartiality is identified, the certification body shall be able to demonstrate how it
eliminates or minimizes such risk. This information shall be made available to the mechanism
specified in 5.25.2.
4.2.5 4.2.5 The certification body shall have top management commitment to impartiality.
4.2.6 4.2.6 The certification body and any part of the same legal entity and entities under its organizational
control (see 7.6.47.6.4)) shall not:
a) be the designer, manufacturer, installer, distributer or maintainer of the certified product;
b) be the designer, implementer, operator or maintainer of the certified process;
c) be the designer, implementer, provider or maintainer of the certified service;
d) offer or provide consultancy (see 3.23.2)) to its clients;
e) offer or provide management system consultancy or internal auditing to its clients where the certification
scheme requires the evaluation of the client’s management system.
© ISO/IEC 2026 – All rights reserved
NOTE 1 This does not preclude the following:
— the possibility of exchange of information (e.g. explanations of findings or clarifying requirements) between the
certification body and its clients;
— the use, installing and maintaining of certified products which are necessary for the operations of the certification
body.
NOTE 2 “Management system consultancy” is defined in ISO/IEC 17021-1:2015, 3.3.
4.2.7 4.2.7 The certification body shall ensure that activities of separate legal entities, with which the
certification body or the legal entity of which it forms a part has relationships, do not compromise the
impartiality of its certification activities.
NOTE See 4.2.34.2.3, Note, NOTE 1.
4.2.8 4.2.8 When the separate legal entity in 4.2.74.2.7 offers or produces the certified product (including
products to be certified) or offers or provides consultancy (see 3.23.2),), the certification body's
management personnel and personnel in the review and certification decision-making process shall
not be involved in the activities of the separate legal entity. The personnel of the separate legal entity
shall not be involved in the management of the certification body, the review, or the certification
decision.
NOTE For the evaluation personnel, impartiality requirements are stipulated in Clause 6Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.16.2.1 and 6.2.2.16.2.2.1.
4.2.9 4.2.9 The certification body's activities shall not be marketed or offered as linked with the activities
of an organization that provides consultancy (see 3.23.2).). A certification body shall not state or imply
that certification would be simpler, easier, faster or less expensive if a specified consultancy
organization were used.
4.2.10 4.2.10 Within a period specified by the certification body, personnel shall not be used to review or
make a certification decision for a product for which they have provided consultancy (see 3.23.2). ).
NOTE 1 The period can be specified in the certification scheme or, if specified by the certification body, it reflects a
period that is long enough to ensure that the review or decision does not compromise impartiality. A specified period of
two years is often used.
NOTE 2 For the evaluation personnel, impartiality requirements are stipulated in Clause 6Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.16.2.1 and 6.2.2.16.2.2.1.
4.2.11 4.2.11 The certification body shall take action to respond to any risks to its impartiality, arising from
the actions of other persons, bodies or organizations, of which it becomes aware.
4.2.12 4.2.12 All certification body personnel (either internal or external) or committees who could
influence the certification activities shall act impartially.
4.3 Liability and financing
4.3.1 4.3.1 The certification body shall have adequate arrangements (e.g. insurance or reserves) to cover
liabilities arising from its operations.
4.3.2 4.3.2 The certification body shall have the financial stability and resources required for its
operations.
4.4 Non-discriminatory conditions
4.4.1 4.4.1 The policies and procedures under which the certification body operates, and the
administration of them, shall be non-discriminatory. Procedures shall not be used to impede or inhibit
access by applicants, other than as provided for in this International Standarddocument.
© ISO/IEC 2026 – All rights reserved
4.4.2 4.4.2 The certification body shall make its services accessible to all applicants whose activities fall
within the scope of its operations.
4.4.3 4.4.3 Access to the certification process shall not be conditional upon the size of the client or
membership of any association or group, nor shall certification be conditional upon the number of
certifications already issued. There shall not be undue financial or other conditions.
NOTE A certification body can decline to accept an application or maintain a contract for certification from a client
when fundamental or demonstrated reasons exist, such as the client participating in illegal activities, having a history of
repeated non-compliances with certification/product requirements, or similar client-related issues.
4.4.4 4.4.4 The certification body shall confine its requirements, evaluation, review, decision and
surveillance (if any) to those matters specifically related to the scope of certification.
4.5 Confidentiality
4.5.1 4.5.1 The certification body shall be responsible, through legally enforceable commitments, for the
management of all information obtained or created during the performance of certification activities.
Except for information that the client makes publicly available, or when agreed between the
certification body and the client (e.g. for the purpose of responding to complaints), all other
information is considered proprietary information and shall be regarded as confidential. The
certification body shall inform the client, in advance, of the information it intends to place in the public
domain.
4.5.2 4.5.2 When the certification body is required by law or authorized by contractual arrangements to
release confidential information, the client or person concerned shall, unless prohibited by law, be
notified of the information provided.
4.5.3 4.5.3 Information about the client obtained from sources other than the client (e.g. from the
complainant or from regulators) shall be treated as confidential.
4.6 Publicly available information
The certification body shall maintain (through publications, electronic media or other means), and make
available upon request, the following:
a) information about (or reference to) the certification scheme(s), including evaluation procedures, rules
and procedures for granting, for maintaining, for extending or reducing the scope of, for suspending, for
withdrawing or for refusing certification;
b) a description of the means by which the certification body obtains financial support and general
information on the fees charged to applicants and to clients;
c) a description of the rights and duties of applicants and clients, including requirements, restrictions or
limitations on the use of the certification body's name and certification mark and on the ways of referring
to the certification granted;
d) information about procedures for handling complaints and appeals.
5 Structural requirements
5.1 Organizational structure and top management
5.1.1 5.1.1 Certification activities shall be structured and managed so as to safeguard impartiality.
5.1.2 5.1.2 The certification body shall document its organizational structure, showing duties,
responsibilities and authorities of management and other certification personnel and any committees.
© ISO/IEC 2026 – All rights reserved
When the certification body is a defined part of a legal entity, the structure shall include the line of
authority and the relationship to other parts within the same legal entity.
5.1.3 5.1.3 The management of the certification body shall identify the board, group of persons, or person
having overall authority and responsibility for each of the following:
a) development of policies relating to the operation of the certification body;
b) supervision of the implementation of the policies and procedures;
c) supervision of the finances of the certification body;
d) development of certification activities;
e) development of certification requirements;
f) evaluation (see 7.47.4););
g) review (see 7.57.5););
h) decisions on certification (see 7.67.6););
i) delegation of authority to committees or personnel, as required, to undertake defined activities on its
behalf;
j) contractual arrangements;
k) provision of adequate resources for certification activities;
l) responsiveness to complaints and appeals;
m) personnel competence requirements;
n) management system of the certification body (see Clause 8Clause 8).).
5.1.4 5.1.4 The certification body shall have formal rules for the appointment, terms of reference and
operation of any committees that are involved in the certification process (see Clause 7Clause 7).).
Such committees shall be free from any commercial, financial and other pressures that might influence
decisions. The certification body shall retain authority to appoint and withdraw members of such
committees.
5.2 Mechanism for safeguarding impartiality
5.2.1 5.2.1 The certification body shall have a mechanism for safeguarding its impartiality. The
mechanism shall provide input on the following:
a) the policies and principles relating to the impartiality of its certification activities;
b) any tendency on the part of a certification body to allow commercial or other considerations to prevent
the consistent impartial provision of certification activities;
c) matters affecting impartiality and confidence in certification, including openness.
NOTE 1 Other tasks or duties (e.g. taking part in the decision-making process) can be assigned to the mechanism,
provided these additional tasks or duties do not compromise its essential role of ensuring impartiality.
© ISO/IEC 2026 – All rights reserved
NOTE 2 A possible mechanism can be a committee established by one or more certification bodies, a committee
implemented by a scheme owner, a governmental authority or an equivalent party.
NOTE 3 A single mechanism for several certification schemes can satisfy this requirement.
5.2.2 5.2.2 The mechanism shall be formally documented to ensure the following:
a) a balanced representation of significantly interested parties, such that no single interest predominates
(internal or external personnel of the certification body are considered to be a single interest, and shall
not predominate);
b) access to all the information necessary to enable it to fulfil all its functions.
5.2.3 5.2.3 If the top management of the certification body does not follow the input of this mechanism,
the mechanism shall have the right to take independent action (e.g. informing authorities,
accreditation bodies, stakeholders). In taking appropriate action, the confidentiality requirements of
4.54.5 relating to the client and certification body shall be respected.
Input that is in conflict with the operating procedures of the certification body or other mandatory
requirements should not be followed. Management should document the reasoning behind the decision to not
follow the input and maintain the document for review by appropriate personnel.
5.2.4 5.2.4 Although every interest cannot be represented in the mechanism, a certification body shall
identify and invite significantly interested parties.
NOTE 1 Such interested parties can include clients of the certification body, customers of clients, manufacturers,
suppliers, users, conformity assessment experts, representatives of industry trade associations, representatives of
governmental regulatory bodies or other governmental services, and representatives of non-governmental
organizations, including consumer organizations. It can be sufficient to have one representative of each interested party
in the mechanism.
NOTE 2 These interests can be limited, depending on the nature of the certification scheme.
6 Re
...







