Insights · 6 min read

Accredited vs non-accredited ISO certificates: the difference in one line

An accredited certificate leaves a trace in a public register. A non-accredited one leaves nothing.

Published by CAS — Conformity Assessment Services · 4 September 2026

An accredited certificate leaves a trace in a public register. A non-accredited one leaves nothing.

That is the whole distinction, and everything below is an elaboration of it. If you are evaluating a supplier's ISO certificate right now and have three minutes, the short version is: find the certification body's accreditation number on the certificate, look that body up on its accreditation body's public register, then look the certificate itself up. If all three exist, you are holding an accredited certificate. If any step comes back empty, you are holding a document.

What "accredited" actually means

Certification has three layers, and the words for them get used interchangeably in the market even though they mean different things.

Your organization implements a management system and is audited against a standard — ISO 9001, for example.

A certification body does that audit and issues the certificate. CAS is one.

An accreditation body audits the certification body. It checks that the certification body is competent, impartial, and follows ISO/IEC 17021-1 — the standard that governs how certification bodies must operate. In Egypt that body is EGAC, the Egyptian Accreditation Council.

A certificate is accredited when the body that issued it was itself assessed and approved to issue that particular type of certificate. Not approved in general — approved for that scheme, in those technical sectors, within a defined scope.

This is why the word "accredited" cannot be self-applied. A certification body cannot accredit itself, any more than an auditor can audit their own work. Somebody outside had to check.

The three registers

Accreditation produces public records. That is not a courtesy; ISO/IEC 17021-1 clause 4.5 sets openness as a principle of certification, and clause 8.1.2 requires a certification body to provide the status of a given certificate on request. The records exist so that the person relying on the certificate can check it without asking the person who benefits from it.

The accreditation body's register. Every national accreditation body publishes the bodies it has accredited, with the scope of each. For CAS that entry reads: CAB #012418, accredited under ISO/IEC 17021-1:2015, certificate 012418A, schedule 012418B, valid to 27 November 2029.

IAF CertSearch. The global registry operated by the International Accreditation Forum. Accredited management system certificates from participating bodies are published there, searchable by the certified organization's name.

The certification body's own verification page. Ours is at cas.com.eg/certsearch.

Three independent routes. A genuine accredited certificate appears in all of them. A fabricated one appears in none.

What a non-accredited certificate is — and is not

It is not automatically fraudulent. A certification body can lawfully issue certificates outside its accredited scope, under its own authority, as long as it says so plainly and does not carry accreditation marks on them.

CAS does exactly that for a number of schemes. They are labelled "By CAS", they carry only the CAS mark, and they appear in our services catalogue — because ISO/IEC 17021-1 clause 8.1.1 c) requires a certification body to publish the schemes it operates. What they do not carry is the EGAC accreditation mark or the IAF MLA mark, and they are not published to IAF CertSearch as accredited certificates.

The problem is not that non-accredited certificates exist. The problem is when nobody tells you which one you are holding.

So the honest question to ask a certification body is not "are you accredited?" — almost everyone says yes. It is: "is this specific certificate, for this specific standard, within your accredited scope?" That question has a checkable answer.

Why the distinction exists at all

Consider what a certificate is supposed to do. Your buyer in Milan cannot visit your factory in Alexandria. They need someone competent and impartial to have looked, and they need to trust that judgement without knowing the person who made it.

Accreditation is the mechanism that makes that possible. The certification body is audited by the accreditation body. The accreditation body is peer-evaluated by its counterparts through the International Accreditation Forum's Multilateral Recognition Arrangement. Each link is checked by someone with no stake in the outcome.

Break any link and the chain stops carrying weight. A certificate from a body nobody assessed is a private opinion, formatted like a public fact.

The International Accreditation Forum published an entire document on this in 2025 — IAF ID 17, on the risk of counterfeit certificates — precisely because the formatting has become very good and the checking has not kept pace.

Checking a certificate in three steps

One — read the certificate. Look for the certification body's name, its accreditation body, and an accreditation number. A certificate that names no accreditation body has already answered your question.

Two — check the body. Search that accreditation number on the accreditation body's public register. Confirm the scope covers the standard on the certificate. A body accredited for ISO 9001 is not thereby accredited for ISO 22000; scopes are granular.

Three — check the certificate. Search the organization's name on IAF CertSearch and on the certification body's own verification page. Confirm the status reads valid, and read the scope statement — not just the standard number.

The uncomfortable part is that a certificate you cannot verify looks identical to one you can. Same paper, same seals, often better design. The difference only appears when you check.

Three things that catch people out

Scope. A certificate can be entirely genuine and still not cover what you are buying. The scope statement names the activities, processes and products the certification applies to, at which sites. If you are buying a product line that is not in the scope, the certificate does not speak to it.

Status. Certificates are living records. They can be suspended — under ISO/IEC 17021-1 clause 9.6.5.3, a suspended certification is temporarily invalid — and reduced in scope, and withdrawn. A PDF sent to you in March tells you nothing about September. The register does.

Coverage of recognition. Not every accredited scheme is covered by the same international arrangement. CAS is EGAC-accredited for six standards; five of them — ISO 9001, 14001, 45001, 22000 and 50001 — fall within EGAC's IAF MLA scope. ISO 22301 is EGAC-accredited and sits outside that scope, so its certificates carry the EGAC accreditation mark without the IAF MLA mark. That is a precise fact, and precision here is the point.

What this means for you

If you are a buyer: make verification a step in supplier onboarding, not a formality. Ask for the certificate number and check it yourself. It takes three minutes and it is the only part of the process that cannot be faked.

If you are certified: know which of your certificates are accredited and which are not, and be able to say so. A supplier who can explain the difference is a supplier who has been paying attention.

If you are choosing a certification body: ask which of your intended standards are inside its accredited scope, and ask to see the schedule of accreditation — not the certificate, the schedule. That is where the scope actually lives.

Apply for certification →Verify a certificate

Read next

A programme shaped by its inputs leaves a trailTwo of Stage 1's seven objectives are not about youThe accreditation number checked out. That is not the same as the certificate being real.
Accredited vs non-accredited ISO certificates: the difference in one line — CAS · CAS