ISO 27001 and ENS certification bodies in Spain: how to choose

By the QuantumSec team

Consulting prepares your ISMS; certification is issued by an independent third party. In Spain, that certification audit — for both ISO 27001 and the ENS — is only valid if carried out by a body accredited by ENAC (Spain's National Accreditation Body). Choosing among the available certification bodies — AENOR, Bureau Veritas, DNV, SGS and others — has more practical implications than it seems.

What it means for a body to be "ENAC-accredited"

ENAC doesn't certify companies: it accredits the bodies that certify, verifying they meet the competence, impartiality and independence requirements to issue valid certificates (ISO/IEC 17021-1 for management systems). An ISO 27001 certificate or ENS certification issued by a body without that accreditation doesn't carry the same recognition with clients, public tenders or second-party auditors.

The most common certification bodies in Spain

AENOR is the Spanish certification body par excellence, with strong local recognition and a specific track record in the ENS scheme. Bureau Veritas, DNV, SGS, TÜV Rheinland, NQA, LRQA and BSI are international certification bodies with a presence in Spain, common for ISO 27001 and especially useful if your company also operates outside Spain or has a foreign parent company. The list of ENAC-accredited bodies for each scheme is published and public.

What to ask before choosing a certification body

Is it ENAC-accredited specifically for the scheme you need (ISO 27001, ENS, or both)? Does it have experience auditing companies in your sector and size? How many audit days does it estimate based on employee count and ISMS scope (duration is calculated using standardized formulas, not negotiable downward without justification)? Does the same auditor cover Stage 1 and Stage 2, or are they different people? What response time does it offer for nonconformities found during the audit?

How the consultant fits with the certification body

A point that causes confusion: the consultant who helps you implement the ISMS cannot, due to conflict of interest, be the one who certifies it — the standard requires independence between whoever builds the system and whoever audits it for certification. The consultant's role is to get the ISMS ready and, often, support the external audit technically, but the decision to certify always belongs to the accredited body.

FAQ

Can I switch certification bodies at renewal?

Yes. At the end of the certification cycle (3 years for ISO 27001, 2 for the ENS) you can choose a different accredited body. It is common to compare price and availability at that point, although switching means the new auditor starts with no history of your organization.

Do all certification bodies cost the same?

No. Price depends on the number of audit days (calculated using standards like IAF MD 5 based on employee count and scope complexity) and each body's day rate, which does vary between certifiers. It's worth requesting quotes from 2-3 accredited bodies before deciding.

Can a certification body refuse the certificate even after I've paid for the audit?

Yes, and that is exactly what gives the certificate its value: if the audit reveals unresolved major nonconformities, the body won't issue the certificate until they're fixed. Paying for the audit buys the process, not the outcome.