ISO certifications and independent assessments
Have your management system, controls or processes independently assessed by Brand Compliance.
Certification, verification and other conformity assessment activities enable your organization to demonstrate how applicable requirements and controls have been implemented. The appropriate assessment depends on your activities, risks, objectives and the requirements of customers, contracting parties or regulators.
Brand Compliance performs independent certification audits, verifications, assurance engagements and compliance audits in the areas of information security, privacy, cybersecurity, healthcare, IT asset management, quality, environmental management and internal control.
Certification, verification or assurance?
During a certification audit, a certification body assesses whether a management system meets the requirements of a standard. Verification assesses information or implemented measures against specified verification criteria. During an assurance engagement, an independent auditor examines specified information, processes or internal controls and documents the outcome in an assurance report.
Which certification or assessment suits your organization?
Select the subject that matches your requirements and go directly to the relevant certification, verification or independent assessment.
Information security |
Cybersecurity and NIS2Have your cybersecurity measures under the CyberFundamentals Framework independently verified. |
Privacy and data protection |
Other management systems |
Assurance |
Other independent assessments |
Not sure which standard or assessment suits your organization? Schedule an introductory meeting.
Information security certifications
These standards and frameworks help organizations demonstrate that they systematically manage risks relating to information, systems, cloud environments and health information.
ISO 27001 certification
ISO 27001 specifies requirements for an Information Security Management System. The standard helps organizations systematically identify, assess and treat risks to the confidentiality, integrity and availability of information.
Learn more about ISO 27001 certificationNEN 7510 certification
NEN 7510 is the Dutch standard for information security in healthcare. It is relevant to healthcare providers and other organizations that process personal health information in the Netherlands.
Learn more about NEN 7510 certificationISO 27799 certification
ISO 27799 provides additional controls and implementation guidance for protecting health information. The standard is relevant to healthcare organizations and service providers that process health information.
Learn more about ISO 27799 certificationISO 27017 en ISO 27018
ISO 27017 and ISO 27018 provide additional controls and implementation guidance for information security and privacy in cloud environments. The assessment is generally performed in conjunction with an Information Security Management System based on ISO 27001.
Learn more about ISO 27017 and ISO 27018BIO2 certification
The Baseline Informatiebeveiliging Overheid 2 is the information security framework used by Dutch government organizations. An independent assessment enables an organization to demonstrate how the applicable requirements have been implemented.
Learn more about BIO2 certificationCyFun verification for cybersecurity and NIS2
CyFun
The CyberFundamentals Framework, also known as CyFun, helps organizations select and implement appropriate cybersecurity measures. For organizations operating in Belgium, the framework can play an important role in demonstrating measures implemented in the context of NIS2.
Learn more about CyFunCyFun verification
During an independent CyFun verification, Brand Compliance assesses the extent to which the measures associated with the selected assurance level have been implemented.
Depending on the organization’s situation, the verification may cover the Basic, Important or Essential level. CyFun verification is not ISO certification. It is a separate conformity assessment based on the CyberFundamentals Framework and the applicable verification requirements.
Learn more about CyFun verificationCertifications for privacy and data protection
Privacy certification enables your organization to demonstrate how responsibilities, processes and controls relating to privacy and personal data have been established. Brand Compliance provides different certification processes, each with its own purpose and scope.
BC 5701 certification
BC 5701 contains certification criteria for assessing the processing and protection of personal data. Certification focuses on how an organization has demonstrably established its responsibilities relating to data protection.
Learn more about BC 5701 certificationISO 27701 certification
ISO 27701 specifies requirements for a Privacy Information Management System, or PIMS. It enables an organization to systematically manage privacy risks, responsibilities, processes and controls relating to personal data.
Learn more about ISO 27701 certificationCertifications for IT asset management and business continuity
ISO 19770-1 certification
ISO 19770-1 specifies requirements for an IT asset management system. The standard helps organizations manage IT assets systematically and demonstrably throughout their lifecycle.
Learn more about ISO 19770-1 certificationISO 22301 certification
ISO 22301 specifies requirements for a Business Continuity Management System. The standard helps organizations prepare for disruption and restore critical activities within the required timeframe.
Learn more about ISO 22301 certificationCertifications for quality and environmental management
ISO 9001 certification
ISO 9001 specifies requirements for a Quality Management System. The standard helps organizations control their processes, meet applicable requirements and continually improve the quality of products and services.
Learn more about ISO 9001 certificationISO 14001 certification
ISO 14001 specifies requirements for an Environmental Management System. The standard helps organizations manage environmental impacts, meet compliance obligations and continually improve environmental performance.
Learn more about ISO 14001 certificationAssurance over internal controls
An assurance engagement differs from a certification audit. During an assurance engagement, an independent auditor examines specified information, processes or internal controls. The outcome is documented in an assurance report rather than an ISO certificate. Brand Compliance performs assurance engagements in accordance with ISAE 3000, ISAE 3402 and SOC 2.
ISAE 3000
ISAE 3000 is an international standard for assurance engagements other than audits or reviews of historical financial information. It can be applied to a range of non-financial subjects and reporting information.
Learn more about ISAE 3000ISAE 3402
ISAE 3402 focuses on controls at service organizations that are relevant to their customers’ financial reporting.
Learn more about ISAE 3402SOC 2
SOC 2 focuses on internal controls relating to security, availability, confidentiality, processing integrity and privacy. The outcome is documented in an independent SOC 2 report.
Learn more about SOC 2Other independent assessments
In addition to certification audits, verifications and assurance engagements, Brand Compliance performs other independent assessments. These may focus on legislation, contractual requirements, quality mark criteria or preparation for a future certification process.
Compliance audits
A compliance audit independently assesses the extent to which an organization meets predefined requirements. These may include legal requirements, contractual agreements, sector-specific conditions or internal frameworks.
The scope, assessment criteria and reporting format are agreed in advance. The outcome provides insight into the level of compliance and any identified nonconformities or areas for attention.
Learn more about compliance auditsKeurmerk Private Lease
Het Keurmerk Private Lease stelt eisen aan onder meer transparantie, consumentenbescherming en de kwaliteit van privateleaseproducten en dienstverlening. Brand Compliance voert onafhankelijke beoordelingen uit aan de hand van de toepasselijke keurmerkcriteria.
Private Lease Quality MarkGap analysis
A gap analysis provides independent insight into the differences between your organization’s current situation and the requirements of a standard or framework. It can be performed in preparation for certification but does not form part of the certification audit.
Brand Compliance reports which elements already align with the requirements and where gaps remain. The gap analysis does not include management system consultancy and does not result in a certification decision.
Learn more about gap analysisCan different certifications be combined?
Several ISO management system standards follow a harmonized structure. This enables an organization to integrate different management systems. Where scopes and processes are sufficiently aligned, parts of the certification audits may also be combined.
Common combinations include:
- ISO 27001 and ISO 27701 for information security and privacy.
- ISO 27001 and NEN 7510 for information security in healthcare.
- ISO 27001 and ISO 27799 for the protection of health information.
- ISO 27001 combined with ISO 27017 and ISO 27018 for cloud security and privacy.
- ISO 9001 and ISO 14001 for quality and environmental management.
The possibility of combining audits depends on the standards, the certification scopes and the extent to which the management systems have been integrated.
How does the certification process work?
A certification process consists of six steps. Based on information about your organization, Brand Compliance determines the certification scope, audit method and required audit time.
1 Application reviewWe review information about your organization, activities, locations and intended certification scope. |
2 Initial audit stage 1The auditor assesses the design and documented elements of the management system. |
3 Initial audit stage 2The auditor assesses the implementation and effectiveness of the management system. |
4 Certification decisionAn independent person reviews the audit results and makes the certification decision. |
5 Surveillance auditsPeriodic surveillance audits are performed during the certification cycle. |
6 RecertificationA recertification audit is performed before the end of the certification cycle. |
Learn more about the certification cycle.
Certification under accreditation
Accreditation is the formal recognition that a conformity assessment body is competent, independent and impartial to perform specified conformity assessment activities.
The applicable accreditation depends on the standard, country and certification scope.
View our accreditationsStart your certification process
Would you like to know which standard suits your organization’s activities, risks and objectives? Discuss your situation with a Brand Compliance certification specialist or submit an application for certification.
Request a certification process