ISO 27001 and ENS certification bodies in Spain: how to choose

By Kike Gandia · Co-Founder & CEO, OSCP

Consulting prepares your ISMS; certification is issued by an independent third party. In Spain, that certification audit — for both ISO 27001 and the ENS — is only valid if carried out by a body accredited by ENAC (Spain's National Accreditation Body). Choosing among the available certification bodies — AENOR, Bureau Veritas, DNV, SGS and others — has more practical implications than it seems.

What it means for a body to be "ENAC-accredited"

ENAC doesn't certify companies: it accredits the bodies that certify, verifying they meet the competence, impartiality and independence requirements to issue valid certificates (ISO/IEC 17021-1 for management systems). An ISO 27001 certificate or ENS certification issued by a body without that accreditation doesn't carry the same recognition with clients, public tenders or second-party auditors.

The most common certification bodies in Spain

AENOR is the Spanish certification body par excellence, with strong local recognition and a specific track record in the ENS scheme. Bureau Veritas, DNV, SGS, TÜV Rheinland, NQA, LRQA and BSI are international certification bodies with a presence in Spain, common for ISO 27001 and especially useful if your company also operates outside Spain or has a foreign parent company. The list of ENAC-accredited bodies for each scheme is published and public.

What to ask before choosing a certification body

Is it ENAC-accredited specifically for the scheme you need (ISO 27001, ENS, or both)? Does it have experience auditing companies in your sector and size? How many audit days does it estimate based on employee count and ISMS scope (duration is calculated using standardized formulas, not negotiable downward without justification)? Does the same auditor cover Stage 1 and Stage 2, or are they different people? What response time does it offer for nonconformities found during the audit?

How the consultant fits with the certification body

A point that causes confusion: the consultant who helps you implement the ISMS cannot, due to conflict of interest, be the one who certifies it — the standard requires independence between whoever builds the system and whoever audits it for certification. The consultant's role is to get the ISMS ready and, often, support the external audit technically, but the decision to certify always belongs to the accredited body.

Stage 1 and Stage 2: what happens at each visit

The certification audit is not one visit, it is two, and arriving without knowing what each involves is the most common reason a first certification slips by a whole cycle.

Stage 1Stage 2
What it reviewsWhether the ISMS is documented and mature enough to be auditedWhether the documented system actually works
Where it focusesScope, policy, risk assessment, SoA, internal audit and management reviewEvidence of operation: records, interviews, control sampling
How it is runOften remote, or as a short visitOn site at the in-scope locations, over more days
What comes out of itA readiness report listing what to resolve before Stage 2Classified findings and a recommendation to certify, or not
Typical riskDiscovering the internal audit or management review minutes are missingRecords not covering a long enough period of operation

A gap of several weeks is usually left between the two stages to close whatever the first one surfaces. That gap cannot be compressed to zero: if Stage 1 concludes the system has not been running long enough, there is no way around it, because what is missing is track record, not documents.

What happens after the certificate: the full cycle

The price to compare when choosing a certification body is not the initial audit but the whole cycle, because switching bodies mid-cycle has a cost. In ISO 27001 the cycle runs three years: initial certification (Stage 1 and Stage 2), a surveillance audit the following year, another in the second, and recertification in the third — shorter than the initial one but with a full system review. For the ENS the certification cycle is two years. Surveillance audits do not repeat the whole scope: they sample controls, check that previous findings were closed, and review the period's changes. So when requesting a quote, ask for the estimated days across all three or four visits in the cycle, not just the first: that is where the real differences between bodies show up.

FAQ

Can I switch certification bodies at renewal?

Yes. At the end of the certification cycle (3 years for ISO 27001, 2 for the ENS) you can choose a different accredited body. It is common to compare price and availability at that point, although switching means the new auditor starts with no history of your organization.

Do all certification bodies cost the same?

No. Price depends on the number of audit days (calculated using standards like IAF MD 5 based on employee count and scope complexity) and each body's day rate, which does vary between certifiers. It's worth requesting quotes from 2-3 accredited bodies before deciding.

Can a certification body refuse the certificate even after I've paid for the audit?

Yes, and that is exactly what gives the certificate its value: if the audit reveals unresolved major nonconformities, the body won't issue the certificate until they're fixed. Paying for the audit buys the process, not the outcome.

How far in advance do we need to book the audit?

Further ahead than most teams expect. Accredited auditor availability is limited and saturates around financial year-end, so contact the body as soon as you have a target date, even if the ISMS is still being implemented: the booking is confirmed before the system is finished. When a client commitment or a tender is involved, this is the variable that most often causes a missed deadline — more so than the technical work.

Can the audit be done remotely, or does it have to be on site?

Partly. Stage 1 and certain documentation review activities are routinely handled remotely, while Stage 2 includes on-site work at the in-scope locations. The permissible proportion of remote auditing is governed by accreditation rules, so it is not something the client negotiates: ask about it when requesting quotes, because it affects travel costs if you have several sites.

What if a major nonconformity is raised in Stage 2?

The certificate is not issued at that point. A window opens to submit the root cause analysis, the correction and the evidence, and the body verifies closure — on documentation if the finding allows, or with an additional visit if it is substantial — before recommending certification. The project slips by weeks, not months, provided the root cause is genuinely addressed rather than patched.

Is the certificate valid outside Spain?

An ISO 27001 certificate issued by an ENAC-accredited body carries international recognition through the multilateral agreements between accreditation bodies, so it is generally valid with foreign clients. The ENS is a Spanish framework and its conformity has no automatic equivalence abroad. If your buyer is outside the EU and does not know the certification body, what usually settles the question is supplying the accreditation reference alongside the certificate, not changing bodies.

Related service

ISO 27001 implementation consulting

Related content

Sources

Ask which certification body fits my project