ISO certifications and independent assessments

Have your management system, controls or processes independently assessed by Brand Compliance.

Certification, verification and other conformity assessment activities enable your organization to demonstrate how applicable requirements and controls have been implemented. The appropriate assessment depends on your activities, risks, objectives and the requirements of customers, contracting parties or regulators.

Brand Compliance performs independent certification audits, verifications, assurance engagements and compliance audits in the areas of information security, privacy, cybersecurity, healthcare, IT asset management, quality, environmental management and internal control.

Certification, verification or assurance?

During a certification audit, a certification body assesses whether a management system meets the requirements of a standard. Verification assesses information or implemented measures against specified verification criteria. During an assurance engagement, an independent auditor examines specified information, processes or internal controls and documents the outcome in an assurance report.

Which certification or assessment suits your organization?

Select the subject that matches your requirements and go directly to the relevant certification, verification or independent assessment.

Information security

Cybersecurity and NIS2

Have your cybersecurity measures under the CyberFundamentals Framework independently verified.

Privacy and data protection

Other management systems

Assurance

Other independent assessments

Not sure which standard or assessment suits your organization? Schedule an introductory meeting.

Information security certifications

These standards and frameworks help organizations demonstrate that they systematically manage risks relating to information, systems, cloud environments and health information.

ISO 27001 certification

ISO 27001 specifies requirements for an Information Security Management System. The standard helps organizations systematically identify, assess and treat risks to the confidentiality, integrity and availability of information.

Learn more about ISO 27001 certification

NEN 7510 certification

NEN 7510 is the Dutch standard for information security in healthcare. It is relevant to healthcare providers and other organizations that process personal health information in the Netherlands.

Learn more about NEN 7510 certification

ISO 27799 certification

ISO 27799 provides additional controls and implementation guidance for protecting health information. The standard is relevant to healthcare organizations and service providers that process health information.

Learn more about ISO 27799 certification

ISO 27017 en ISO 27018

ISO 27017 and ISO 27018 provide additional controls and implementation guidance for information security and privacy in cloud environments. The assessment is generally performed in conjunction with an Information Security Management System based on ISO 27001.

Learn more about ISO 27017 and ISO 27018

BIO2 certification

The Baseline Informatiebeveiliging Overheid 2 is the information security framework used by Dutch government organizations. An independent assessment enables an organization to demonstrate how the applicable requirements have been implemented.

Learn more about BIO2 certification

CyFun verification for cybersecurity and NIS2

CyFun

The CyberFundamentals Framework, also known as CyFun, helps organizations select and implement appropriate cybersecurity measures. For organizations operating in Belgium, the framework can play an important role in demonstrating measures implemented in the context of NIS2.

Learn more about CyFun

CyFun verification

During an independent CyFun verification, Brand Compliance assesses the extent to which the measures associated with the selected assurance level have been implemented.

Depending on the organization’s situation, the verification may cover the Basic, Important or Essential level. CyFun verification is not ISO certification. It is a separate conformity assessment based on the CyberFundamentals Framework and the applicable verification requirements.

Learn more about CyFun verification

Certifications for privacy and data protection

Privacy certification enables your organization to demonstrate how responsibilities, processes and controls relating to privacy and personal data have been established. Brand Compliance provides different certification processes, each with its own purpose and scope.

BC 5701 certification

BC 5701 contains certification criteria for assessing the processing and protection of personal data. Certification focuses on how an organization has demonstrably established its responsibilities relating to data protection.

Learn more about BC 5701 certification

ISO 27701 certification

ISO 27701 specifies requirements for a Privacy Information Management System, or PIMS. It enables an organization to systematically manage privacy risks, responsibilities, processes and controls relating to personal data.

Learn more about ISO 27701 certification

Certifications for IT asset management and business continuity

ISO 19770-1 certification

ISO 19770-1 specifies requirements for an IT asset management system. The standard helps organizations manage IT assets systematically and demonstrably throughout their lifecycle.

Learn more about ISO 19770-1 certification

ISO 22301 certification

ISO 22301 specifies requirements for a Business Continuity Management System. The standard helps organizations prepare for disruption and restore critical activities within the required timeframe.

Learn more about ISO 22301 certification

Certifications for quality and environmental management

ISO 9001 certification

ISO 9001 specifies requirements for a Quality Management System. The standard helps organizations control their processes, meet applicable requirements and continually improve the quality of products and services.

Learn more about ISO 9001 certification

ISO 14001 certification

ISO 14001 specifies requirements for an Environmental Management System. The standard helps organizations manage environmental impacts, meet compliance obligations and continually improve environmental performance.

Learn more about ISO 14001 certification

Assurance over internal controls

An assurance engagement differs from a certification audit. During an assurance engagement, an independent auditor examines specified information, processes or internal controls. The outcome is documented in an assurance report rather than an ISO certificate. Brand Compliance performs assurance engagements in accordance with ISAE 3000, ISAE 3402 and SOC 2.

ISAE 3000

ISAE 3000 is an international standard for assurance engagements other than audits or reviews of historical financial information. It can be applied to a range of non-financial subjects and reporting information.

Learn more about ISAE 3000

ISAE 3402

ISAE 3402 focuses on controls at service organizations that are relevant to their customers’ financial reporting.

Learn more about ISAE 3402

SOC 2

SOC 2 focuses on internal controls relating to security, availability, confidentiality, processing integrity and privacy. The outcome is documented in an independent SOC 2 report.

Learn more about SOC 2

Other independent assessments

In addition to certification audits, verifications and assurance engagements, Brand Compliance performs other independent assessments. These may focus on legislation, contractual requirements, quality mark criteria or preparation for a future certification process.

Compliance audits

A compliance audit independently assesses the extent to which an organization meets predefined requirements. These may include legal requirements, contractual agreements, sector-specific conditions or internal frameworks.

The scope, assessment criteria and reporting format are agreed in advance. The outcome provides insight into the level of compliance and any identified nonconformities or areas for attention.

Learn more about compliance audits

Keurmerk Private Lease

Het Keurmerk Private Lease stelt eisen aan onder meer transparantie, consumentenbescherming en de kwaliteit van privateleaseproducten en dienstverlening. Brand Compliance voert onafhankelijke beoordelingen uit aan de hand van de toepasselijke keurmerkcriteria.

Private Lease Quality Mark

Gap analysis

A gap analysis provides independent insight into the differences between your organization’s current situation and the requirements of a standard or framework. It can be performed in preparation for certification but does not form part of the certification audit.

Brand Compliance reports which elements already align with the requirements and where gaps remain. The gap analysis does not include management system consultancy and does not result in a certification decision.

Learn more about gap analysis

Can different certifications be combined?

Several ISO management system standards follow a harmonized structure. This enables an organization to integrate different management systems. Where scopes and processes are sufficiently aligned, parts of the certification audits may also be combined.

Common combinations include:

  • ISO 27001 and ISO 27701 for information security and privacy.
  • ISO 27001 and NEN 7510 for information security in healthcare.
  • ISO 27001 and ISO 27799 for the protection of health information.
  • ISO 27001 combined with ISO 27017 and ISO 27018 for cloud security and privacy.
  • ISO 9001 and ISO 14001 for quality and environmental management.

The possibility of combining audits depends on the standards, the certification scopes and the extent to which the management systems have been integrated.

How does the certification process work?

A certification process consists of six steps. Based on information about your organization, Brand Compliance determines the certification scope, audit method and required audit time.


1

Application review

We review information about your organization, activities, locations and intended certification scope.


2

Initial audit stage 1

The auditor assesses the design and documented elements of the management system.


3

Initial audit stage 2

The auditor assesses the implementation and effectiveness of the management system.


4

Certification decision

An independent person reviews the audit results and makes the certification decision.


5

Surveillance audits

Periodic surveillance audits are performed during the certification cycle.


6

Recertification

A recertification audit is performed before the end of the certification cycle.

Learn more about the certification cycle.

Certification under accreditation

Accreditation is the formal recognition that a conformity assessment body is competent, independent and impartial to perform specified conformity assessment activities.

The applicable accreditation depends on the standard, country and certification scope.

View our accreditations

Start your certification process

Would you like to know which standard suits your organization’s activities, risks and objectives? Discuss your situation with a Brand Compliance certification specialist or submit an application for certification.

Request a certification process