You Cannot Be Certified to ISO 26000
ISO has published a statement on this specifically, because the misuse is widespread. ISO 26000 is not a management system standard, and it is not intended or appropriate for certification purposes or for regulatory or contractual use. Any offer to certify, or claim to be certified to ISO 26000, is a misrepresentation of the standard's intent and a misuse of it.
The reason is structural, not bureaucratic. ISO 26000 is written in "should", not "shall". It offers guidance rather than requirements. There is nothing to audit an organization against and no pass or fail line to draw, which is exactly what a certifiable standard needs.
We are saying this on a page that could more easily have sold you a certificate, because a document with no authority behind it fails the moment a procurement team checks — and they increasingly do.
What You Can Actually Get
| Exists? | What it proves | |
|---|---|---|
| ISO 26000 certificate | No | Nothing — no accreditation stands behind it |
| Gap assessment | Yes | Where you stand against the seven core subjects |
| Independent attestation | Yes | A third-party opinion on your alignment, with methodology stated |
| Self-declaration | Yes | Your own claim, unverified |
| SA8000 certification | Yes | An accredited certificate for labour and workplace practices |
Most organizations arriving here want the last two rows without realising it. See whether any company is ISO 26000 certified for what the firms claiming it actually hold.
The Attestation
An independent attestation is a signed statement from an assessor describing what was examined, how, and what was found. It is a legitimate assurance document with a long history in other domains — it is simply not a certificate, and the difference matters.
What ours contains:
Scope. Which entity, which sites, which of the seven core subjects were examined.
Methodology. Documents reviewed, people interviewed, evidence sampled and over what period.
Findings by core subject. Where practice aligns with the guidance and where it does not, with the evidence.
An opinion. Our assessment of overall alignment, stated plainly.
Explicit limitations. Including a statement that ISO 26000 is not certifiable and that this document is not a certificate. That sentence protects you — it is what stops a customer later claiming you presented it as one.
The Gap Audit
The assessment that produces the attestation, and the more useful half if you intend to act on it.
1. Scoping. Which core subjects are relevant. Not all seven apply meaningfully to every organization, and pretending otherwise wastes your money.
2. Documentation review. Policies, codes of conduct, supplier terms, grievance procedures, reporting.
3. Interviews. Management and, where relevant, worker representatives.
4. Evidence sampling. Whether stated practice matches actual practice — the part a self-assessment cannot do for itself.
5. Findings and roadmap. Gaps rated and sequenced, with the work attached to each.
6. Attestation. Issued once findings are agreed.
Work through the ISO 26000 checklist first if you want to see what the assessment covers before committing.
The Seven Core Subjects We Assess
| Core subject | What it covers | Certifiable elsewhere? |
|---|---|---|
| Organizational governance | Decision-making structures and accountability | Partly, via management system standards |
| Human rights | Due diligence, complicity, discrimination, civil rights | Yes — SA8000 |
| Labour practices | Employment, conditions, dialogue, health and safety | Yes — SA8000, ISO 45001 |
| The environment | Pollution, resources, climate, ecosystems | Yes — ISO 14001 |
| Fair operating practices | Anti-corruption, fair competition, supply chain | Partly |
| Consumer issues | Fair marketing, health and safety, data protection | Partly |
| Community involvement | Local development, education, employment creation | No |
Notice the third column. Much of ISO 26000's ground is covered by standards that are certifiable. That is usually the more useful answer for an organization being asked to prove something — see below.
If You Genuinely Need a Certificate
Sometimes the attestation is not enough — a supplier programme requires a certificate, a contract names one, or a buyer will only accept an accredited mark.
For social responsibility, the certifiable standard is SA8000. It is auditable, it is certified by accredited bodies, and it covers the human rights and labour practices core subjects of ISO 26000 in enforceable detail — child labour, forced labour, health and safety, freedom of association, discrimination, disciplinary practices, working hours, remuneration, and the management system holding it together.
| ISO 26000 | SA8000 | |
|---|---|---|
| Nature | Guidance | Auditable standard |
| Certifiable | No | Yes, by accredited bodies |
| Scope | Seven broad core subjects | Labour and workplace practices |
| What you receive | Attestation and report | A certificate |
| Accepted in supplier programmes | Sometimes | Widely |
A common and sensible sequence: use the ISO 26000 gap assessment to understand your overall position, then pursue SA8000 where a certificate is actually required. See ISO 26000 vs SA8000.
Book an ISO 26000 Gap Assessment
Tell us your organization size, sites, and which core subjects matter to whoever is asking. Scoped proposal within 24 hours.
Our form could not load. Email your organization size and what your customer is asking for, and you'll get the same proposal within 24 hours.
Email your requirements Open the full quote formISO 26000 Attestation FAQs
Can you get ISO 26000 certified?
No. ISO states directly that ISO 26000 is not a management system standard and is not intended or appropriate for certification purposes, and that any offer to certify or claim to be certified to ISO 26000 is a misrepresentation and a misuse of the standard. It provides guidance using "should", not requirements using "shall", so there is nothing auditable to certify against.
What can you get instead of ISO 26000 certification?
A gap assessment against the seven core subjects and an independent attestation statement describing what was assessed, the methodology used, and the findings. It is a third-party opinion on your alignment with the guidance, which is a legitimate and verifiable document — it is simply not a certificate, and it should never be presented as one.
Why do some companies advertise ISO 26000 certification?
Because buyers search for it, and selling it is easier than explaining why it does not exist. ISO has published a specific statement addressing this. A certificate issued against ISO 26000 carries no accreditation and no recognised authority behind it, and a procurement team that checks will find that out.
My customer asked for ISO 26000 certification. What do I send them?
Usually they want assurance about your social responsibility practices rather than that specific document. An independent attestation with a findings report answers the underlying question. If they need something certifiable — for a supplier programme or a contractual clause — SA8000 is the recognised certifiable standard covering the same ground, and we can take you there.
What is the difference between ISO 26000 and SA8000?
ISO 26000 is guidance on social responsibility, covering seven broad core subjects, and is not certifiable. SA8000 is an auditable standard focused on labour conditions and workplace practices, and it is certifiable by accredited bodies. Organizations often use ISO 26000 to structure their thinking and SA8000 to prove it to a customer.
How long does an ISO 26000 gap assessment take?
Typically two to four weeks for a single-site organization, depending on how much documentation already exists and how many of the seven core subjects are in scope. The attestation follows once findings are agreed.
Related Reading
See the ISO 26000 overview, ISO 26000 vs SA8000, whether any company is actually certified, or SA8000 certification if you need a certificate.
Official reference: ISO — No certification to ISO 26000.
Get the document that actually stands up
A gap assessment, a findings report, and an attestation you can defend.