General Information

Abstract

Status
Not Published
Current Stage
5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
Start Date
04-Aug-2026
Completion Date
04-Aug-2026

Buy Documents

Draft

ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services

Release Date:21-Jul-2026
English language (29 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services

Release Date:21-Jul-2026
English language (29 pages)
sale 15% off
sale 15% off
Draft

ISO/IEC FDIS 17065 - Évaluation de la conformité — Exigences pour les organismes certifiant les produits, les processus et les services

Release Date:07-Sep-2026
French language (32 pages)
sale 15% off
sale 15% off

Overview

ISO/IEC FDIS 17065 is an international standard developed by ISO and IEC that outlines requirements for bodies certifying products, processes, and services. This standard is essential for certification bodies to demonstrate competence, consistency, and impartiality in their certification activities. Through third-party conformity assessment, ISO/IEC FDIS 17065 aims to establish confidence among all interested parties-including clients, regulators, customers, and the public-that certified products, processes, or services meet specified requirements.

Adhering to ISO/IEC FDIS 17065 helps certification bodies operate in accordance with recognized principles, facilitating acceptance in both national and international markets and supporting global trade. The requirements foster trust in certifications by ensuring transparent, impartial, and reliable evaluation.

Key Topics

  • Impartiality and Independence: Certification activities must remain free from commercial, financial, or other pressures that could compromise objectivity. Risks to impartiality are identified and addressed on an ongoing basis.
  • Confidentiality and Transparency: Certification bodies are responsible for safeguarding client information, making only the necessary details public as required by law or agreement.
  • Legal and Contractual Obligations: Bodies must be legally responsible entities capable of entering enforceable agreements and maintaining appropriate liability coverage.
  • Resource Management: Competence of personnel, availability of resources for evaluation, and ongoing training are required to ensure high-quality certification.
  • Certification Process: Standardized procedures guide application review, evaluation, decision making, documentation, surveillance, and handling of complaints or appeals.
  • Non-Discriminatory Conditions: Access to certification is not restricted based on client size, group membership, or number of certifications. Requirements are related solely to the scope of certification.
  • Management Systems: Certification bodies must maintain effective management system documentation, conduct internal audits, perform management reviews, and take corrective actions to address risks and opportunities.

Applications

ISO/IEC FDIS 17065 is widely applied by:

  • Product Certification Bodies: Organizations certifying hardware, software, processed materials, or services under an established certification scheme.
  • Process and Service Certification: Ensuring that industrial, manufacturing, or service processes fulfill defined quality or regulatory requirements.
  • Regulatory Authorities: Governments or agencies referencing this standard when designating or recognizing certification bodies.
  • Scheme Owners: Entities (e.g., trade associations, industry groups) developing specific certification schemes based on ISO/IEC FDIS 17065 requirements.
  • International Trade Facilitation: Supporting mutual recognition of certifications, thus streamlining market access and compliance with international regulations.

This standard is relevant across industries such as manufacturing, agriculture, food safety, information technology, and more. By providing a consistent framework, it ensures certifications issued by accredited bodies are accepted internationally, helping organizations demonstrate compliance and build stakeholder trust.

Related Standards

  • ISO/IEC 17000: Conformity assessment - Vocabulary and general principles.
  • ISO/IEC 17020: Requirements for bodies performing inspection.
  • ISO/IEC 17021-1: Requirements for bodies providing audit and certification of management systems.
  • ISO/IEC 17025: General requirements for competence of testing and calibration laboratories.
  • ISO/IEC 17029: General principles and requirements for validation and verification bodies.
  • ISO/IEC 17067: Guidance on product certification schemes.
  • ISO/IEC 17030: Requirements for third-party marks of conformity.

Each of these standards supports the implementation of robust conformity assessment frameworks and is frequently referenced to ensure harmonized, reliable certification processes worldwide.


By aligning with ISO/IEC FDIS 17065, certification bodies greatly enhance their operational credibility, ensure seamless international cooperation, and deliver confidence to clients and end-users regarding the quality and compliance of certified products, processes, or services.

Relations

Effective Date
23-May-2026
Effective Date
09-May-2026

Buy Documents

Draft

ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services

Release Date:21-Jul-2026
English language (29 pages)
sale 15% off
sale 15% off
Draft

REDLINE ISO/IEC FDIS 17065 - Conformity assessment — Requirements for bodies certifying products, processes and services

Release Date:21-Jul-2026
English language (29 pages)
sale 15% off
sale 15% off
Draft

ISO/IEC FDIS 17065 - Évaluation de la conformité — Exigences pour les organismes certifiant les produits, les processus et les services

Release Date:07-Sep-2026
French language (32 pages)
sale 15% off
sale 15% off

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

Bureau Veritas

Bureau Veritas is a world leader in laboratory testing, inspection and certification services.

COFRAC France Verified

DNV

DNV is an independent assurance and risk management provider.

NA Norway Verified

Sponsored listings

Frequently Asked Questions

ISO/IEC FDIS 17065 is a draft published by the International Organization for Standardization (ISO). Its full title is "Conformity assessment — Requirements for bodies certifying products, processes and services". This standard covers: L'ISO/IEC 17065:2012 comporte des exigences portant sur les compétences, la cohérence des activités et l'impartialité des organismes de certification de produits, processus et services. Les organismes de certification exerçant selon l'ISO/IEC 17065:2012 ne sont pas tenus de proposer tous les types de certification de produits, processus et services.

L'ISO/IEC 17065:2012 comporte des exigences portant sur les compétences, la cohérence des activités et l'impartialité des organismes de certification de produits, processus et services. Les organismes de certification exerçant selon l'ISO/IEC 17065:2012 ne sont pas tenus de proposer tous les types de certification de produits, processus et services.

ISO/IEC FDIS 17065 is classified under the following ICS (International Classification for Standards) categories: 03.120.20 - Product and company certification. Conformity assessment. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/IEC FDIS 17065 has the following relationships with other standards: It is inter standard links to prEN ISO/IEC 17065, ISO/IEC 17065:2012. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/IEC FDIS 17065 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


FINAL DRAFT
International
Standard
ISO/CASCO
Conformity assessment —
Secretariat: ISO
Requirements for bodies certifying
Voting begins on:
products, processes and services
2026-08-04
Évaluation de la conformité — Exigences pour les organismes
Voting terminates on:
certifiant les produits, les procédés et les services
2026-10-27
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
ISO/CEN PARALLEL PROCESSING LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/CASCO
Conformity assessment —
Secretariat: ISO
Requirements for bodies certifying
Voting begins on:
products, processes and services
Évaluation de la conformité — Exigences pour les organismes
Voting terminates on:
certifiant les produits, les procédés et les services
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO/IEC 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO­
ISO/CEN PARALLEL PROCESSING
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 General requirements . 4
4.1 Legal and contractual matters .4
4.1.1 Legal responsibility .4
4.1.2 Certification agreement .4
4.1.3 Use of license, certificates and marks of conformity .5
4.2 Management of impartiality .5
4.3 Liability and financing .7
4.4 Non-discriminatory conditions .7
4.5 Confidentiality .7
4.6 Publicly available information . .8
5 Structural requirements . 8
5.1 Organizational structure and top management .8
5.2 Mechanism for safeguarding impartiality .9
6 Resource requirements .10
6.1 Certification body personnel .10
6.1.1 General .10
6.1.2 Management of competence for personnel involved in the certification process .10
6.1.3 Contract with the personnel .11
6.2 Resources for evaluation .11
6.2.1 Internal resources .11
6.2.2 External resources (outsourcing) .11
7 Process requirements .12
7.1 General . 12
7.2 Application . 13
7.3 Application review . 13
7.4 Evaluation .14
7.5 Review . 15
7.6 Certification decision . . . 15
7.7 Certification documentation .16
7.8 Directory of certified products .17
7.9 Surveillance .17
7.10 Changes affecting certification .17
7.11 Termination, reduction, suspension or withdrawal of certification .18
7.12 Records .19
7.13 Complaints and appeals.19
8 Management system requirements .20
8.1 Options. 20
8.1.1 General . 20
8.1.2 Option A . 20
8.1.3 Option B . 20
8.2 General management system documentation (Option A) . 20
8.3 Control of documents (Option A) .21
8.4 Control of records (Option A) .21
8.5 Management review (Option A) .21
8.5.1 General .21
8.5.2 Review inputs .21
8.5.3 Review outputs . 22

© ISO/IEC 2026 – All rights reserved
iii
8.6 Internal audits (Option A) . . 22
8.7 Corrective actions (Option A) . . 22
8.8 Actions to address risks and opportunities (Option A) . 23
Annex A (informative) Principles for product certification bodies and their certification
activities .24
Annex B (informative) Application of this document for processes and services .26
Annex ZA (informative) Relationship between this European Standard and the requirements
of Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July
2008 setting out the requirements for accreditation and repealing Regulation (EEC) No
339/93 aimed to be covered .27
Bibliography .29

© ISO/IEC 2026 – All rights reserved
iv
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by the ISO Committee on Conformity Assessment (CASCO), in collaboration
with the European Committee for Standardization (CEN) Technical Committee CEN/CLC/JTC 1, Criteria for
conformity assessment bodies, in accordance with the Agreement on technical cooperation between ISO and
CEN (Vienna Agreement).
This second edition cancels and replaces the first edition (ISO/IEC 17065:2012), which has been technically
revised.
The main changes are as follows:
— updated to reflect terminology in ISO/IEC 17000;
— in subclause 8.8, replaced of “Preventive actions” with a new clause “Actions to address risks and
opportunities”;
— updated and corrected bibliographic references.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2026 – All rights reserved
v
Introduction
The overall aim of certifying products, processes or services is to give confidence to all interested parties
that a product, process or service fulfils specified requirements. The value of certification is the degree
of confidence and trust that is established by an impartial and competent demonstration of fulfilment of
specified requirements through third-party attestation. Parties that have an interest in certification include,
but are not limited to:
a) the clients of the certification bodies;
b) the customers of the organizations whose products, processes or services are certified;
c) governmental authorities;
d) non-governmental organizations; and
e) consumers and other members of the public.
Interested parties can expect or require the certification body to meet all the requirements of this document
and perform certification in accordance with a certification scheme.
Certification of products, processes or services is a means of providing assurance that they comply with
specified requirements in standards and other normative documents. Some product, process or service
certification schemes can include initial testing or inspection and assessment of its suppliers' quality
management systems, followed by surveillance that takes into account the quality management system and
the testing or inspection of samples from the production and the open market. Other schemes rely on initial
testing and surveillance testing, while still others comprise type testing only.
This document specifies requirements, the observance of which is intended to ensure that certification
bodies operate certification schemes in a competent, consistent and impartial manner, thereby facilitating
the recognition of such bodies and the acceptance of certified products, processes and services on a national
and international basis and so furthering international trade. This document can be used as a criteria
document for accreditation or peer assessment or designation by governmental authorities, scheme owners
and others.
The requirements contained in this document are written, above all, to be considered as general criteria
for certification bodies operating product, process or service certification schemes; they can have to be
amplified when specific industrial or other sectors make use of them, or when particular requirements
such as health and safety have to be taken into account. Annex A contains principles relating to certification
bodies and certification activities that they provide.
This document does not set requirements for schemes and how they are developed and is not intended
to restrict the role or choice of scheme owners, however scheme rules and procedures, including those
identifying the certification requirements, should not contradict or exclude any of the requirements of this
document.
Statements of conformity to the applicable standards or other normative documents can be in the form
of certificates and/or marks of conformity. Schemes for certifying particular products or product groups,
processes and services to specified standards or other normative documents can, in many cases, necessitate
their own explanatory documentation.
While this document is concerned with bodies providing certification (third party attestation) for a product,
process or service, many of its provisions can also be useful for bodies performing first- and second-party
product, process or service conformity assessment activities.
In this document, the following verbal forms are used:
— “shall” indicates a requirement;
— “should” indicates a recommendation;
— “may” indicates a permission;

© ISO/IEC 2026 – All rights reserved
vi
— “can” indicates a possibility or a capability.
Further details can be found in the ISO/IEC Directives, Part 2.

© ISO/IEC 2026 – All rights reserved
vii
FINAL DRAFT International Standard ISO/IEC FDIS 17065:2026(en)
Conformity assessment — Requirements for bodies certifying
products, processes and services
1 Scope
This document contains requirements for the competence, consistent operation and impartiality of product,
process and service certification bodies. Certification bodies operating to this document need not offer all
types of products, processes and services certification. Certification of products, processes and services is a
third-party conformity assessment activity (see ISO/IEC 17000:2020, 4.5).
In this document, the term “product” can be read as “process” or “service”, except in those instances where
separate provisions are stated for “processes” or “services” (see Annex B).
2 Normative references
The following referenced documents are indispensable for the application of this document. For dated
references, only the edition cited applies. For undated references, the latest edition of the referenced
document (including any amendments) applies.
ISO/IEC 17000, Conformity assessment — Vocabulary and general principles
ISO/IEC 17020, Conformity assessment — Requirements for bodies performing inspection
ISO/IEC 17021-1, Conformity assessment — Requirements for bodies providing audit and certification of
management systems — Part 1: Requirements
ISO/IEC 17025, General requirements for the competence of testing and calibration laboratories
ISO/IEC 17029, Conformity assessment — General principles and requirements for validation and verification
bodies
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 17000 and the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
client
organization or person responsible to a certification body for ensuring that certification requirements (3.7),
including product requirements (3.8), are fulfilled
Note 1 to entry: Whenever the term “client” is used in this document, it applies to both the “applicant” and the “client”,
unless otherwise specified.
3.2
consultancy
participation in
© ISO/IEC 2026 – All rights reserved
a) the designing, manufacturing, installing, maintaining or distributing of a certified product or a product
to be certified, or
b) the designing, implementing, operating or maintaining of a certified process or a process to be certified,
or
c) the designing, implementing, providing or maintaining of a certified service or a service to be certified
Note 1 to entry: In this document, the term “consultancy” is used in relation to activities of certification bodies,
personnel of certification bodies and organizations related or linked to certification bodies.
3.3
evaluation
combination of the selection and determination functions of conformity assessment activities
Note 1 to entry: The selection and determination functions are specified in ISO/IEC 17000:2020, Clauses A.2 and A.3.
3.4
product
result of a process
1)
Note 1 to entry: Four generic product categories are noted in ISO 9000:2005 :
— services (e.g. transport) (see 3.6);
— software (e.g. computer program, dictionary);
— hardware (e.g. engine, mechanical part);
— processed materials (e.g. lubricant).
Many products comprise elements belonging to different generic product categories. Whether the product is then
called service, software, hardware or processed material depends on the dominant element.
Note 2 to entry: Products include results of natural processes, such as growth of plants and formation of other natural
resources.
3.5
process
set of interrelated or interacting activities which transforms inputs into outputs
EXAMPLE Welding engineering processes; heat treatment processes; manufacturing processes requiring
confirmation of process capability (e.g. operating or producing product within specified tolerances); food production
processes; plant growth processes.
Note 1 to entry: Adapted from ISO 9000:2005, 3.4.1.
3.6
service
result of at least one activity necessarily performed at the interface between the supplier and the customer,
which is generally intangible
Note 1 to entry: Provision of a service can involve, for example, the following:
— an activity performed on a customer-supplied tangible product (e.g. automobile to be repaired);
— an activity performed on a customer-supplied intangible product (e.g. the income statement needed to prepare a
tax return);
— the delivery of an intangible product (e.g. the delivery of information in the context of knowledge transmission);
— the creation of ambience for the customer (e.g. in hotels and restaurants).
Note 2 to entry: Adapted from ISO 9000:2005, 3.4.2.
1) Withdrawn.
© ISO/IEC 2026 – All rights reserved
3.7
certification requirement
requirement, including product requirements (3.8), that is fulfilled by the client (3.1) as a condition of
establishing or maintaining certification
EXAMPLE The following are certification requirements that are not product requirements:
— completing the certification agreement;
— paying fees;
— providing information about changes to the certified product;
— providing access to certified products for surveillance activities.
Note 1 to entry: Certification requirements include requirements imposed on the client by the certification body
[usually via the certification agreement (see 4.1.2)] to meet this document, and can also include requirements
imposed on the client by the certification scheme. Certification requirements, as used in this document, do not include
requirements imposed on the certification body by the certification scheme.
3.8
product requirement
specified requirement that relates directly to a product, stated in standards or in other normative documents
identified by the certification scheme
Note 1 to entry: Product requirements can be stated in normative documents such as regulations, standards and
technical specifications.
3.9
certification scheme
set of rules and procedures that describes the object of conformity assessment, identifies the specified
requirements and provides the methodology for performing certification and the related conformity
assessment activities
Note 1 to entry: The object of conformity assessment in this document is a product, process or service.
Note 2 to entry: General guidance on conformity assessment schemes which include product, process or services
certification is given in ISO/IEC 17067.
[SOURCE: ISO/IEC 17000:2020, 4.9, modified — "Conformity assessment" has been replaced by "certification
and the related conformity assessment activities"; the original notes to entry have been replaced by new
ones.]
3.10
scope of certification
— information identifying the product(s), process(es) or service(s) for which the certification is granted,
— the applicable certification scheme, and
— the standard(s) and other normative document(s), including their date of publication, to which it is judged
that the product(s), process(es) or service(s) comply
3.11
scheme owner
person or organization responsible for developing and maintaining a specific certification scheme (3.9)
Note 1 to entry: The scheme owner can be the certification body itself, a governmental authority, a trade association, a
group of certification bodies or others.

© ISO/IEC 2026 – All rights reserved
3.12
certification body
third-party conformity assessment body operating certification schemes
Note 1 to entry: A certification body can be non-governmental or governmental (with or without regulatory authority).
3.13
impartiality
objectivity with regard to the outcome of a conformity assessment activity
Note 1 to entry: Objectivity can be understood as freedom from bias or freedom from conflicts of interest.
[SOURCE: ISO/IEC 17000:2020, 5.3]
4 General requirements
4.1 Legal and contractual matters
4.1.1 Legal responsibility
The certification body shall be a legal entity, or a defined part of a legal entity, such that the legal entity can
be held legally responsible for all its certification activities.
NOTE A governmental certification body is deemed to be a legal entity on the basis of its governmental status.
4.1.2 Certification agreement
4.1.2.1 The certification body shall have a legally enforceable agreement for the provision of certification
activities to its clients. Certification agreements shall take into account the responsibilities of the
certification body and its clients.
4.1.2.2 The certification body shall ensure its certification agreement requires that the client comply at
least, with the following:
a) the client always fulfils the certification requirements (see 3.7), including implementing appropriate
changes when they are communicated by the certification body (see 7.10);
b) if the certification applies to ongoing production, the certified product continues to fulfil the product
requirements (see 3.8);
c) the client makes all necessary arrangements for
1) the conduct of the evaluation (see 3.3) and surveillance (if required), including provision for
examining documentation and records, and access to the relevant equipment, location(s), area(s),
personnel, and client's subcontractors;
2) investigation of complaints;
3) the participation of observers, if applicable;
d) the client makes claims regarding certification consistent with the scope of certification (see 3.10);
e) the client does not use its product certification in such a manner as to bring the certification body into
disrepute and does not make any statement regarding its product certification that the certification
body can consider misleading or unauthorized;
f) upon suspension, withdrawal, or termination of certification, the client discontinues its use of all
advertising matter that contains any reference thereto and takes action as required by the certification
scheme (e.g. the return of certification documents) and takes any other required measure;

© ISO/IEC 2026 – All rights reserved
g) if the client provides copies of the certification documents to others, the documents shall be reproduced
in their entirety or as specified in the certification scheme;
h) in making reference to its product certification in communication media such as documents, brochures
or advertising, the client complies with the requirements of the certification body or as specified by the
certification scheme;
i) the client complies with any rules and procedures that may be prescribed in the certification scheme
relating to the use of marks of conformity, and on information related to the product;
NOTE See also ISO/IEC 17030
j) the client keeps a record of all complaints made known to it relating to compliance with certification
requirements and makes these records available to the certification body when requested, and
1) takes appropriate action with respect to such complaints and any deficiencies found in products
that affect compliance with the requirements for certification;
2) documents the actions taken;
NOTE Verification of item j) by the certification body can be specified in the certification scheme.
k) the client informs the certification body, without delay, of changes that can affect its ability to conform
with the certification requirements.
NOTE Examples of changes can include the following:
— the legal, commercial, organizational status or ownership;
— organization and management (e.g. key managerial, decision-making or technical staff);
— modifications to the product or the production method;
— contact address and production sites;
— major changes to the quality management system.
4.1.3 Use of license, certificates and marks of conformity
4.1.3.1 The certification body shall exercise the control as specified by the certification scheme over
ownership, use and display of licenses, certificates, marks of conformity, and any other mechanisms for
indicating a product is certified.
NOTE ISO/IEC 17030 provides requirements for the use of third-party marks.
4.1.3.2 Incorrect references to the certification scheme, or misleading use of licenses, certificates, marks,
or any other mechanism for indicating a product is certified, found in documentation or other publicity, shall
be dealt with by suitable action.
4.2 Management of impartiality
4.2.1 Certification activities shall be undertaken impartially.
4.2.2 The certification body shall be responsible for the impartiality of its certification activities and shall
not allow commercial, financial or other pressures to compromise impartiality.
4.2.3 The certification body shall identify risks to its impartiality on an ongoing basis. This shall include
those risks that arise from its activities, from its relationships, or from the relationships of its personnel
(see 4.2.12). However, such relationships may not necessarily present a certification body with a risk to
impartiality.
© ISO/IEC 2026 – All rights reserved
NOTE 1 A relationship presenting a risk to impartiality of the certification body can be based on ownership,
governance, management, personnel, shared resources, finances, contracts, marketing (including branding), and
payment of a sales commission or other inducement for the referral of new clients, etc.
NOTE 2 Identifying risks does not imply risk assessments as stated in ISO 31000.
4.2.4 If a risk to impartiality is identified, the certification body shall be able to demonstrate how it
eliminates or minimizes such risk. This information shall be made available to the mechanism specified in
5.2.
4.2.5 The certification body shall have top management commitment to impartiality.
4.2.6 The certification body and any part of the same legal entity and entities under its organizational
control (see 7.6.4) shall not:
a) be the designer, manufacturer, installer, distributer or maintainer of the certified product;
b) be the designer, implementer, operator or maintainer of the certified process;
c) be the designer, implementer, provider or maintainer of the certified service;
d) offer or provide consultancy (see 3.2) to its clients;
e) offer or provide management system consultancy or internal auditing to its clients where the
certification scheme requires the evaluation of the client’s management system.
NOTE 1 This does not preclude the following:
— the possibility of exchange of information (e.g. explanations of findings or clarifying requirements) between the
certification body and its clients;
— the use, installing and maintaining of certified products which are necessary for the operations of the certification
body.
NOTE 2 “Management system consultancy” is defined in ISO/IEC 17021-1:2015, 3.3.
4.2.7 The certification body shall ensure that activities of separate legal entities, with which the
certification body or the legal entity of which it forms a part has relationships, do not compromise the
impartiality of its certification activities.
NOTE See 4.2.3, NOTE 1.
4.2.8 When the separate legal entity in 4.2.7 offers or produces the certified product (including products to
be certified) or offers or provides consultancy (see 3.2), the certification body's management personnel and
personnel in the review and certification decision-making process shall not be involved in the activities of
the separate legal entity. The personnel of the separate legal entity shall not be involved in the management
of the certification body, the review, or the certification decision.
NOTE For the evaluation personnel, impartiality requirements are stipulated in Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.1 and 6.2.2.1.
4.2.9 The certification body's activities shall not be marketed or offered as linked with the activities
of an organization that provides consultancy (see 3.2). A certification body shall not state or imply that
certification would be simpler, easier, faster or less expensive if a specified consultancy organization were
used.
4.2.10 Within a period specified by the certification body, personnel shall not be used to review or make a
certification decision for a product for which they have provided consultancy (see 3.2).

© ISO/IEC 2026 – All rights reserved
NOTE 1 The period can be specified in the certification scheme or, if specified by the certification body, it reflects a
period that is long enough to ensure that the review or decision does not compromise impartiality. A specified period
of two years is often used.
NOTE 2 For the evaluation personnel, impartiality requirements are stipulated in Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.1 and 6.2.2.1.
4.2.11 The certification body shall take action to respond to any risks to its impartiality, arising from the
actions of other persons, bodies or organizations, of which it becomes aware.
4.2.12 All certification body personnel (either internal or external) or committees who could influence the
certification activities shall act impartially.
4.3 Liability and financing
4.3.1 The certification body shall have adequate arrangements (e.g. insurance or reserves) to cover
liabilities arising from its operations.
4.3.2 The certification body shall have the financial stability and resources required for its operations.
4.4 Non-discriminatory conditions
4.4.1 The policies and procedures under which the certification body operates, and the administration of
them, shall be non-discriminatory. Procedures shall not be used to impede or inhibit access by applicants,
other than as provided for in this document.
4.4.2 The certification body shall make its services accessible to all applicants whose activities fall within
the scope of its operations.
4.4.3 Access to the certification process shall not be conditional upon the size of the client or membership
of any association or group, nor shall certification be conditional upon the number of certifications already
issued. There shall not be undue financial or other conditions.
NOTE A certification body can decline to accept an application or maintain a contract for certification from a
client when fundamental or demonstrated reasons exist, such as the client participating in illegal activities, having a
history of repeated non-compliances with certification/product requirements, or similar client-related issues.
4.4.4 The certification body shall confine its requirements, evaluation, review, decision and surveillance
(if any) to those matters specifically related to the scope of certification.
4.5 Confidentiality
4.5.1 The certification body shall be responsible, through legally enforceable commitments, for the
management of all information obtained or created during the performance of certification activities. Except
for information that the client makes publicly available, or when agreed between the certification body and
the client (e.g. for the purpose of responding to complaints), all other information is considered proprietary
information and shall be regarded as confidential. The certification body shall inform the client, in advance,
of the information it intends to place in the public domain.
4.5.2 When the certification body is required by law or authorized by contractual arrangements to release
confidential information, the client or person concerned shall, unless prohibited by law, be notified of the
information provided.
4.5.3 Information about the client obtained from sources other than the client (e.g. from the complainant
or from regulators) shall be treated as confidential.

© ISO/IEC 2026 – All rights reserved
4.6 Publicly available information
The certification body shall maintain (through publications, electronic media or other means), and make
available upon request, the following:
a) information about (or reference to) the certification scheme(s), including evaluation procedures, rules
and procedures for granting, for maintaining, for extending or reducing the scope of, for suspending, for
withdrawing or for refusing certification;
b) a description of the means by which the certification body obtains financial support and general
information on the fees charged to applicants and to clients;
c) a description of the rights and duties of applicants and clients, including requirements, restrictions
or limitations on the use of the certification body's name and certification mark and on the ways of
referring to the certification granted;
d) information about procedures for handling complaints and appeals.
5 Structural requirements
5.1 Organizational structure and top management
5.1.1 Certification activities shall be structured and managed so as to safeguard impartiality.
5.1.2 The certification body shall document its organizational structure, showing duties, responsibilities
and authorities of management and other certification personnel and any committees. When the certification
body is a defined part of a legal entity, the structure shall include the line of authority and the relationship to
other parts within the same legal entity.
5.1.3 The management of the certification body shall identify the board, group of persons, or person
having overall authority and responsibility for each of the following:
a) development of policies relating to the operation of the certification body;
b) supervision of the implementation of the policies and procedures;
c) supervision of the finances of the certification body;
d) development of certification activities;
e) development of certification requirements;
f) evaluation (see 7.4);
g) review (see 7.5);
h) decisions on certification (see 7.6);
i) delegation of authority to committees or personnel, as required, to undertake defined activities on its
behalf;
j) contractual arrangements;
k) provision of adequate resources for ce
...


ISO/CASCO
Secretariat: ISO
Date: 2026-06-22
Conformity assessment — Requirements for bodies certifying
products, processes and services
Évaluation de la conformité — Exigences pour les organismes certifiant les produits, les procédés et les services
FDIS stage
TThhiiss d drraftaft i iss s suubbmmiitttteded t too a pa pararallel vallel vootte e iinn I ISSOO,, I IECEC && C CENEN.

© ISO/IEC 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
E-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2026 – All rights reserved
ii
Contents Page
Foreword . v
Introduction . vii
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 General requirements . 4
4.1 Legal and contractual matters . 4
4.2 Management of impartiality . 6
4.3 Liability and financing . 7
4.4 Non-discriminatory conditions. 7
4.5 Confidentiality . 8
4.6 Publicly available information . 8
5 Structural requirements . 8
5.1 Organizational structure and top management . 8
5.2 Mechanism for safeguarding impartiality . 9
6 Resource requirements . 10
6.1 Certification body personnel . 10
6.2 Resources for evaluation . 12
7 Process requirements . 13
7.1 General. 13
7.2 Application . 14
7.3 Application review . 14
7.4 Evaluation . 15
7.5 Review . 16
7.6 Certification decision . 16
7.7 Certification documentation . 17
7.8 Directory of certified products . 17
7.9 Surveillance . 18
7.10 Changes affecting certification . 18
7.11 Termination, reduction, suspension or withdrawal of certification . 19
7.12 Records . 20
7.13 Complaints and appeals. 20
8 Management system requirements . 21
8.1 Options . 21
8.2 General management system documentation (Option A) . 21
8.3 Control of documents (Option A) . 22
8.4 Control of records (Option A) . 22
8.5 Management review (Option A) . 22
8.6 Internal audits (Option A) . 23
8.7 Corrective actions (Option A) . 24
8.8 Actions to address risks and opportunities (Option A) . 24
Annex A (informative) Principles for product certification bodies and their certification
activities . 25
Annex B (informative) Application of this document for processes and services . 27
Annex ZA (informative) Relationship between this European Standard and the requirements of
Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July
© ISO/IEC 2026 – All rights reserved
iii
2008 setting out the requirements for accreditation and repealing Regulation (EEC) No
339/93 aimed to be covered . 28
Bibliography . 30

© ISO/IEC 2026 – All rights reserved
iv
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are members
of ISO or IEC participate in the development of International Standards through technical committees
established by the respective organization to deal with particular fields of technical activity. ISO and IEC
technical committees collaborate in fields of mutual interest. Other international organizations, governmental
and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of conformity
assessment, the ISO Committee on conformity assessment (CASCO) is responsible for the development of
International Standards and Guides.
International Standards are The procedures used to develop this document and those intended for its further
maintenance are described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria
needed for the different types of document should be noted. This document was drafted in accordance with
the editorial rules given inof the ISO/IEC Directives, Part 2 (see www.iso.org/directives or
www.iec.ch/members_experts/refdocs.).
Draft International Standards are circulated to the national bodies for voting. Publication as an International
Standard requires approval by at least 75 % of the national bodies casting a vote.
Attention is drawnISO and IEC draw attention to the possibility that some of the elementsimplementation of
this document may beinvolve the subjectuse of (a) patent(s). ISO and IEC take no position concerning the
evidence, validity or applicability of any claimed patent rights in respect thereof. As of the date of publication
of this document, ISO and IEC had not received notice of (a) patent(s) which may be required to implement
this document. However, implementers are cautioned that this may not represent the latest information,
which may be obtained from the patent database available at www.iso.org/patents and https://patents.iec.ch.
ISO. ISO and IEC shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html/.
In the IEC, see www.iec.ch/understanding-standards 17065.
This document was prepared by the ISO Committee on conformity assessmentConformity Assessment
(CASCO), in collaboration with the European Committee for Standardization (CEN) Technical Committee
CEN/CLC/JTC 1, Criteria for conformity assessment bodies, in accordance with the Agreement on technical
cooperation between ISO and CEN (Vienna Agreement).
It was circulated for voting to the national bodies of both ISO and IEC, and was approved by both organizations.
This second edition of ISO/IEC 17065 cancels and replaces the first edition (ISO/IEC 17065:2012,), which has
been technically revised.
The following majormain changes have been made compared with ISO/IEC 17065:2012are as follows:
— updateupdated to reflect terminology in ISO/IEC 17000:2020;
— in subclause 8.8in clause of Clause 8.8, replacement, replaced of “Preventive actions” with a new clause
“Actions to address risks and opportunities””;
— updated alland corrected bibliographic references of ISO/IEC 17021 with ISO/IEC 17021-1 and
references.
© ISO/IEC 2026 – All rights reserved
v
Any feedback or questions on this document should be directed to Guides no longer publishedthe user’s
national standards body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committeesthe Bibliography.
© ISO/IEC 2026 – All rights reserved
vi
Introduction
The overall aim of certifying products, processes or services is to give confidence to all interested parties that
a product, process or service fulfils specified requirements. The value of certification is the degree of
confidence and trust that is established by an impartial and competent demonstration of fulfilment of specified
requirements through third-party attestation. Parties that have an interest in certification include, but are not
limited to:
a) the clients of the certification bodies;
b) the customers of the organizations whose products, processes or services are certified;
c) governmental authorities;
d) non-governmental organizations; and
e) consumers and other members of the public.
Interested parties can expect or require the certification body to meet all the requirements of this
International Standarddocument and perform certification in accordance with a certification scheme.
Certification of products, processes or services is a means of providing assurance that they comply with
specified requirements in standards and other normative documents. Some product, process or service
certification schemes maycan include initial testing or inspection and assessment of its suppliers' quality
management systems, followed by surveillance that takes into account the quality management system and
the testing or inspection of samples from the production and the open market. Other schemes rely on initial
testing and surveillance testing, while still others comprise type testing only.
This International Standarddocument specifies requirements, the observance of which is intended to ensure
that certification bodies operate certification schemes in a competent, consistent and impartial manner,
thereby facilitating the recognition of such bodies and the acceptance of certified products, processes and
services on a national and international basis and so furthering international trade. This International
Standarddocument can be used as a criteria document for accreditation or peer assessment or designation by
governmental authorities, scheme owners and others.
The requirements contained in this International Standarddocument are written, above all, to be considered
as general criteria for certification bodies operating product, process or service certification schemes; they
maycan have to be amplified when specific industrial or other sectors make use of them, or when particular
requirements such as health and safety have to be taken into account. Annex AAnnex A contains principles
relating to certification bodies and certification activities that they provide.
This International Standarddocument does not set requirements for schemes and how they are developed and
is not intended to restrict the role or choice of scheme owners, however scheme rules and procedures,
including those identifying the certification requirements, should not contradict or exclude any of the
requirements of this International Standarddocument.
Statements of conformity to the applicable standards or other normative documents can be in the form of
certificates and/or marks of conformity. Schemes for certifying particular products or product groups,
processes and services to specified standards or other normative documents willcan, in many cases,
requirenecessitate their own explanatory documentation.
While this document is concerned with bodies providing certification (third party attestation) for a product,
process or service, many of its provisions can also be useful for bodies performing first- and second-party
product, process or service conformity assessment activities.
© ISO/IEC 2026 – All rights reserved
vii
In this International Standarddocument, the following verbal forms are used:
— “shall” indicates a requirement;
— “should” indicates a recommendation;
— “may” indicates a permission;
— “can” indicates a possibility or a capability.
Further details can be found in the ISO/IEC Directives, Part 2.
© ISO/IEC 2026 – All rights reserved
viii
Conformity assessment — Requirements for bodies certifying
products, processes and services
1 Scope
This International Standarddocument contains requirements for the competence, consistent operation and
impartiality of product, process and service certification bodies. Certification bodies operating to this
International Standarddocument need not offer all types of products, processes and services certification.
Certification of products, processes and services is a third-party conformity assessment activity (see ISO/IEC
17000:2020, 4.5).
In this International Standarddocument, the term “product” can be read as “process” or “service”, except in
those instances where separate provisions are stated for “processes” or “services” (see Annex BAnnex B).).
2 Normative references
The following referenced documents are indispensable for the application of this document. For dated
references, only the edition cited applies. For undated references, the latest edition of the referenced
document (including any amendments) applies.
ISO/IEC 17000, Conformity assessment — Vocabulary and general principles
ISO/IEC 17020, Conformity assessment — Requirements for bodies performing inspection
ISO/IEC 17021-1, Conformity assessment — Requirements for bodies providing audit and certification of
management systems — Part 1: Requirements
ISO/IEC 17025, General requirements for the competence of testing and calibration laboratories
ISO/IEC 17029 -, Conformity assessment — General principles and requirements for validation and verification
bodies,
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 17000 and the following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp3.1
— IEC Electropedia: available at https://www.electropedia.org/
3.1
client
organization or person responsible to a certification body for ensuring that certification requirements
(3.7(3.7),), including product requirements (3.8(3.8),), are fulfilled
NOTE Note 1 to entry: Whenever the term “client” is used in this International Standarddocument, it applies to both
the “applicant” and the “client”, unless otherwise specified.
3.2 3.2
consultancy
participation in
© ISO/IEC 2026 – All rights reserved
a) the designing, manufacturing, installing, maintaining or distributing of a certified product or a product to
be certified, or
b) the designing, implementing, operating or maintaining of a certified process or a process to be certified,
or
c) the designing, implementing, providing or maintaining of a certified service or a service to be certified
NOTE Note 1 to entry: In this International Standarddocument, the term “consultancy” is used in relation to
activities of certification bodies, personnel of certification bodies and organizations related or linked to certification
bodies.
3.3 3.3
evaluation
combination of the selection and determination functions of conformity assessment activities
NOTE Note 1 to entry: The selection and determination functions are specified in ISO/IEC 17000:2020, Clauses A.2
and A.3.
3.4 3.4
product
result of a process
1)
NOTENote 1 to entry: Four generic product categories are noted in ISO 9000:2005: :
— services (e.g. transport) (see 3.6definition in 3.6); );
— software (e.g. computer program, dictionary);
— hardware (e.g. engine, mechanical part);
— processed materials (e.g. lubricant).
Many products comprise elements belonging to different generic product categories. Whether the product is then called
service, software, hardware or processed material depends on the dominant element.
NOTE 2 Note 2 to entry: Products include results of natural processes, such as growth of plants and formation of other
natural resources.
3.5 3.5
process
set of interrelated or interacting activities which transforms inputs into outputs
EXAMPLESEXAMPLE Welding engineering processes; heat treatment processes; manufacturing processes
requiring confirmation of process capability (e.g. operating or producing product within specified tolerances); food
production processes; plant growth processes.
NOTE Note 1 to entry: Adapted from ISO 9000:2005, definition 3.4.1.
3.6 3.6
service
result of at least one activity necessarily performed at the interface between the supplier and the customer,
which is generally intangible
1)
Withdrawn.
© ISO/IEC 2026 – All rights reserved
NOTE 1 Note 1 to entry: Provision of a service can involve, for example, the following:
— an activity performed on a customer-supplied tangible product (e.g. automobile to be repaired);
— an activity performed on a customer-supplied intangible product (e.g. the income statement needed to prepare a tax
return);
— the delivery of an intangible product (e.g. the delivery of information in the context of knowledge transmission);
— the creation of ambience for the customer (e.g. in hotels and restaurants).
NOTE Note 2 to entry: Adapted from ISO 9000:2005, definition 3.4.2.
3.7 3.7
certification requirement
requirement, including product requirements (3.8(3.8),), that is fulfilled by the client (3.1(3.1)) as a condition
of establishing or maintaining certification
NOTE Certification requirements include requirements imposed on the client by the certification body [usually via
the certification agreement (see 4.1.2)] to meet this International Standard, and can also include requirements imposed
on the client by the certification scheme. “Certification requirements”, as used in this International Standard, do not
include requirements imposed on the certification body by the certification scheme.
EXAMPLE The following are certification requirements that are not product requirements:
— completing the certification agreement;
— paying fees;
— providing information about changes to the certified product;
— providing access to certified products for surveillance activities.
Note 1 to entry: Certification requirements include requirements imposed on the client by the
certification body [usually via the certification agreement (see 4.1.23.8
)] to meet this document, and can also include requirements imposed on the client by the certification scheme.
Certification requirements, as used in this document, do not include requirements imposed on the certification body by
the certification scheme.
3.8
product requirement
specified requirement that relates directly to a product, stated in standards or in other normative documents
identified by the certification scheme
NOTE Note 1 to entry: Product requirements can be stated in normative documents such as regulations, standards
and technical specifications.
3.83.9 3.9
certification scheme
set of rules and procedures that describes the object of conformity assessment, identifies the specified
requirements and provides the methodology for performing certification and the related conformity
assessment activities
Note 1 to entry: The object of conformity assessment in this document is a product, process or service.
Note 2 to entry: General guidance on conformity assessment schemes which include product, process or services
certification is given in ISO/IEC 17067.
© ISO/IEC 2026 – All rights reserved
[SOURCE: ISO/IEC 17000:2020, 4.9, modified — At the end of the definition, "conformity"Conformity
assessment" has been replaced by "certification and the related conformity assessment activities"; the original
notes to entry have been replaced by new ones.]

3.93.10 3.10
scope of certification
— information identifying the product(s), process(es) or service(s) for which the certification is granted,
— the applicable certification scheme, and
— the standard(s) and other normative document(s), including their date of publication, to which it is judged
that the product(s), process(es) or service(s) comply
3.103.11 3.11
scheme owner
person or organization responsible for developing and maintaining a specific certification scheme (3.9(3.9))
NOTE Note 1 to entry: The scheme owner can be the certification body itself, a governmental authority, a trade
association, a group of certification bodies or others.
3.113.12 3.12
certification body
third-party conformity assessment body operating certification schemes
NOTE Note 1 to entry: A certification body can be non-governmental or governmental (with or without regulatory
authority).
3.123.13
3.13 impartiality
objectivity with regard to the outcome of a conformity assessment activity
Note 1 to entry: Objectivity can be understood as freedom from bias or freedom from conflicts of interest.
Source[SOURCE: ISO/IEC 17000:2020, 5.3]
4 General requirements
4.1 Legal and contractual matters
4.1.1 Legal responsibility
The certification body shall be a legal entity, or a defined part of a legal entity, such that the legal entity can be
held legally responsible for all its certification activities.
NOTE A governmental certification body is deemed to be a legal entity on the basis of its governmental status.
4.1.2 Certification agreement
4.1.2.1 4.1.2.1 The certification body shall have a legally enforceable agreement for the
provision of certification activities to its clients. Certification agreements shall take into account the
responsibilities of the certification body and its clients.
© ISO/IEC 2026 – All rights reserved
4.1.2.2 4.1.2.2 The certification body shall ensure its certification agreement requires that the
client comply at least, with the following:
a) the client always fulfils the certification requirements (see 3.73.7),), including implementing appropriate
changes when they are communicated by the certification body (see 7.107.10););
b) if the certification applies to ongoing production, the certified product continues to fulfil the product
requirements (see 3.83.8););
c) the client makes all necessary arrangements for
1) the conduct of the evaluation (see 3.33.3)) and surveillance (if required), including provision for
examining documentation and records, and access to the relevant equipment, location(s), area(s),
personnel, and client's subcontractors;
2) investigation of complaints;
3) the participation of observers, if applicable;
d) the client makes claims regarding certification consistent with the scope of certification (see 3.103.10););
e) the client does not use its product certification in such a manner as to bring the certification body into
disrepute and does not make any statement regarding its product certification that the certification body
maycan consider misleading or unauthorized;
f) upon suspension, withdrawal, or termination of certification, the client discontinues its use of all
advertising matter that contains any reference thereto and takes action as required by the certification
scheme (e.g. the return of certification documents) and takes any other required measure;
g) if the client provides copies of the certification documents to others, the documents shall be reproduced
in their entirety or as specified in the certification scheme;
h) in making reference to its product certification in communication media such as documents, brochures or
advertising, the client complies with the requirements of the certification body or as specified by the
certification scheme;
i) the client complies with any rules and procedures that may be prescribed in the certification scheme
relating to the use of marks of conformity, and on information related to the product;
NOTE See also ISO/IEC 17030
j) the client keeps a record of all complaints made known to it relating to compliance with certification
requirements and makes these records available to the certification body when requested, and
1) takes appropriate action with respect to such complaints and any deficiencies found in products that
affect compliance with the requirements for certification;
2) documents the actions taken;
NOTE Verification of item j) by the certification body can be specified in the certification scheme.
k) the client informs the certification body, without delay, of changes that maycan affect its ability to conform
with the certification requirements.
NOTE Examples of changes can include the following:
© ISO/IEC 2026 – All rights reserved
— the legal, commercial, organizational status or ownership,;
— organization and management (e.g. key managerial, decision-making or technical staff),);
— modifications to the product or the production method,;
— contact address and production sites,;
— major changes to the quality management system.
4.1.3 Use of license, certificates and marks of conformity
4.1.3.1 4.1.3.1 The certification body shall exercise the control as specified by the certification
scheme over ownership, use and display of licenses, certificates, marks of conformity, and any other
mechanisms for indicating a product is certified.
NOTE 2 ISO/IEC 17030 provides requirements for the use of third-party marks.
4.1.3.2 4.1.3.2 Incorrect references to the certification scheme, or misleading use of licenses,
certificates, marks, or any other mechanism for indicating a product is certified, found in
documentation or other publicity, shall be dealt with by suitable action.
4.2 Management of impartiality
4.2.1 4.2.1 Certification activities shall be undertaken impartially.
4.2.2 4.2.2 The certification body shall be responsible for the impartiality of its certification activities and
shall not allow commercial, financial or other pressures to compromise impartiality.
4.2.3 4.2.3 The certification body shall identify risks to its impartiality on an ongoing basis. This shall
include those risks that arise from its activities, from its relationships, or from the relationships of its
personnel (see 4.2.124.2.12).). However, such relationships may not necessarily present a
certification body with a risk to impartiality.
NOTE 1 A relationship presenting a risk to impartiality of the certification body can be based on ownership,
governance, management, personnel, shared resources, finances, contracts, marketing (including branding), and
payment of a sales commission or other inducement for the referral of new clients, etc.
NOTE 2 Identifying risks does not imply risk assessments as stated in ISO 31000.
4.2.4 4.2.4 If a risk to impartiality is identified, the certification body shall be able to demonstrate how it
eliminates or minimizes such risk. This information shall be made available to the mechanism
specified in 5.25.2.
4.2.5 4.2.5 The certification body shall have top management commitment to impartiality.
4.2.6 4.2.6 The certification body and any part of the same legal entity and entities under its organizational
control (see 7.6.47.6.4)) shall not:
a) be the designer, manufacturer, installer, distributer or maintainer of the certified product;
b) be the designer, implementer, operator or maintainer of the certified process;
c) be the designer, implementer, provider or maintainer of the certified service;
d) offer or provide consultancy (see 3.23.2)) to its clients;
e) offer or provide management system consultancy or internal auditing to its clients where the certification
scheme requires the evaluation of the client’s management system.
© ISO/IEC 2026 – All rights reserved
NOTE 1 This does not preclude the following:
— the possibility of exchange of information (e.g. explanations of findings or clarifying requirements) between the
certification body and its clients;
— the use, installing and maintaining of certified products which are necessary for the operations of the certification
body.
NOTE 2 “Management system consultancy” is defined in ISO/IEC 17021-1:2015, 3.3.
4.2.7 4.2.7 The certification body shall ensure that activities of separate legal entities, with which the
certification body or the legal entity of which it forms a part has relationships, do not compromise the
impartiality of its certification activities.
NOTE See 4.2.34.2.3, Note, NOTE 1.
4.2.8 4.2.8 When the separate legal entity in 4.2.74.2.7 offers or produces the certified product (including
products to be certified) or offers or provides consultancy (see 3.23.2),), the certification body's
management personnel and personnel in the review and certification decision-making process shall
not be involved in the activities of the separate legal entity. The personnel of the separate legal entity
shall not be involved in the management of the certification body, the review, or the certification
decision.
NOTE For the evaluation personnel, impartiality requirements are stipulated in Clause 6Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.16.2.1 and 6.2.2.16.2.2.1.
4.2.9 4.2.9 The certification body's activities shall not be marketed or offered as linked with the activities
of an organization that provides consultancy (see 3.23.2).). A certification body shall not state or imply
that certification would be simpler, easier, faster or less expensive if a specified consultancy
organization were used.
4.2.10 4.2.10 Within a period specified by the certification body, personnel shall not be used to review or
make a certification decision for a product for which they have provided consultancy (see 3.23.2). ).
NOTE 1 The period can be specified in the certification scheme or, if specified by the certification body, it reflects a
period that is long enough to ensure that the review or decision does not compromise impartiality. A specified period of
two years is often used.
NOTE 2 For the evaluation personnel, impartiality requirements are stipulated in Clause 6Clause 6 and additional
requirements are given in the other relevant International Standards cited in 6.2.16.2.1 and 6.2.2.16.2.2.1.
4.2.11 4.2.11 The certification body shall take action to respond to any risks to its impartiality, arising from
the actions of other persons, bodies or organizations, of which it becomes aware.
4.2.12 4.2.12 All certification body personnel (either internal or external) or committees who could
influence the certification activities shall act impartially.
4.3 Liability and financing
4.3.1 4.3.1 The certification body shall have adequate arrangements (e.g. insurance or reserves) to cover
liabilities arising from its operations.
4.3.2 4.3.2 The certification body shall have the financial stability and resources required for its
operations.
4.4 Non-discriminatory conditions
4.4.1 4.4.1 The policies and procedures under which the certification body operates, and the
administration of them, shall be non-discriminatory. Procedures shall not be used to impede or inhibit
access by applicants, other than as provided for in this International Standarddocument.
© ISO/IEC 2026 – All rights reserved
4.4.2 4.4.2 The certification body shall make its services accessible to all applicants whose activities fall
within the scope of its operations.
4.4.3 4.4.3 Access to the certification process shall not be conditional upon the size of the client or
membership of any association or group, nor shall certification be conditional upon the number of
certifications already issued. There shall not be undue financial or other conditions.
NOTE A certification body can decline to accept an application or maintain a contract for certification from a client
when fundamental or demonstrated reasons exist, such as the client participating in illegal activities, having a history of
repeated non-compliances with certification/product requirements, or similar client-related issues.
4.4.4 4.4.4 The certification body shall confine its requirements, evaluation, review, decision and
surveillance (if any) to those matters specifically related to the scope of certification.
4.5 Confidentiality
4.5.1 4.5.1 The certification body shall be responsible, through legally enforceable commitments, for the
management of all information obtained or created during the performance of certification activities.
Except for information that the client makes publicly available, or when agreed between the
certification body and the client (e.g. for the purpose of responding to complaints), all other
information is considered proprietary information and shall be regarded as confidential. The
certification body shall inform the client, in advance, of the information it intends to place in the public
domain.
4.5.2 4.5.2 When the certification body is required by law or authorized by contractual arrangements to
release confidential information, the client or person concerned shall, unless prohibited by law, be
notified of the information provided.
4.5.3 4.5.3 Information about the client obtained from sources other than the client (e.g. from the
complainant or from regulators) shall be treated as confidential.
4.6 Publicly available information
The certification body shall maintain (through publications, electronic media or other means), and make
available upon request, the following:
a) information about (or reference to) the certification scheme(s), including evaluation procedures, rules
and procedures for granting, for maintaining, for extending or reducing the scope of, for suspending, for
withdrawing or for refusing certification;
b) a description of the means by which the certification body obtains financial support and general
information on the fees charged to applicants and to clients;
c) a description of the rights and duties of applicants and clients, including requirements, restrictions or
limitations on the use of the certification body's name and certification mark and on the ways of referring
to the certification granted;
d) information about procedures for handling complaints and appeals.
5 Structural requirements
5.1 Organizational structure and top management
5.1.1 5.1.1 Certification activities shall be structured and managed so as to safeguard impartiality.
5.1.2 5.1.2 The certification body shall document its organizational structure, showing duties,
responsibilities and authorities of management and other certification personnel and any committees.
© ISO/IEC 2026 – All rights reserved
When the certification body is a defined part of a legal entity, the structure shall include the line of
authority and the relationship to other parts within the same legal entity.
5.1.3 5.1.3 The management of the certification body shall identify the board, group of persons, or person
having overall authority and responsibility for each of the following:
a) development of policies relating to the operation of the certification body;
b) supervision of the implementation of the policies and procedures;
c) supervision of the finances of the certification body;
d) development of certification activities;
e) development of certification requirements;
f) evaluation (see 7.47.4););
g) review (see 7.57.5););
h) decisions on certification (see 7.67.6););
i) delegation of authority to committees or personnel, as required, to undertake defined activities on its
behalf;
j) contractual arrangements;
k) provision of adequate resources for certification activities;
l) responsiveness to complaints and appeals;
m) personnel competence requirements;
n) management system of the certification body (see Clause 8Clause 8).).
5.1.4 5.1.4 The certification body shall have formal rules for the appointment, terms of reference and
operation of any committees that are involved in the certification process (see Clause 7Clause 7).).
Such committees shall be free from any commercial, financial and other pressures that might influence
decisions. The certification body shall retain authority to appoint and withdraw members of such
committees.
5.2 Mechanism for safeguarding impartiality
5.2.1 5.2.1 The certification body shall have a mechanism for safeguarding its impartiality. The
mechanism shall provide input on the following:
a) the policies and principles relating to the impartiality of its certification activities;
b) any tendency on the part of a certification body to allow commercial or other considerations to prevent
the consistent impartial provision of certification activities;
c) matters affecting impartiality and confidence in certification, including openness.
NOTE 1 Other tasks or duties (e.g. taking part in the decision-making process) can be assigned to the mechanism,
provided these additional tasks or duties do not compromise its essential role of ensuring impartiality.
© ISO/IEC 2026 – All rights reserved
NOTE 2 A possible mechanism can be a committee established by one or more certification bodies, a committee
implemented by a scheme owner, a governmental authority or an equivalent party.
NOTE 3 A single mechanism for several certification schemes can satisfy this requirement.
5.2.2 5.2.2 The mechanism shall be formally documented to ensure the following:
a) a balanced representation of significantly interested parties, such that no single interest predominates
(internal or external personnel of the certification body are considered to be a single interest, and shall
not predominate);
b) access to all the information necessary to enable it to fulfil all its functions.
5.2.3 5.2.3 If the top management of the certification body does not follow the input of this mechanism,
the mechanism shall have the right to take independent action (e.g. informing authorities,
accreditation bodies, stakeholders). In taking appropriate action, the confidentiality requirements of
4.54.5 relating to the client and certification body shall be respected.
Input that is in conflict with the operating procedures of the certification body or other mandatory
requirements should not be followed. Management should document the reasoning behind the decision to not
follow the input and maintain the document for review by appropriate personnel.
5.2.4 5.2.4 Although every interest cannot be represented in the mechanism, a certification body shall
identify and invite significantly interested parties.
NOTE 1 Such interested parties can include clients of the certification body, customers of clients, manufacturers,
suppliers, users, conformity assessment experts, representatives of industry trade associations, representatives of
governmental regulatory bodies or other governmental services, and representatives of non-governmental
organizations, including consumer organizations. It can be sufficient to have one representative of each interested party
in the mechanism.
NOTE 2 These interests can be limited, depending on the nature of the certification scheme.
6 Re
...


PROJET FINAL
Norme
internationale
ISO/CASCO
Évaluation de la conformité —
Secrétariat: ISO
Exigences pour les organismes
Début de vote:
certifiant les produits, les processus
2026-08-04
et les services
Vote clos le:
2026-10-27
Conformity assessment — Requirements for bodies certifying
products, processes and services
LES DESTINATAIRES DU PRÉSENT PROJET SONT
INVITÉS À PRÉSENTER, AVEC LEURS OBSERVATIONS,
NOTIFICATION DES DROITS DE PROPRIÉTÉ DONT ILS
AURAIENT ÉVENTUELLEMENT CONNAISSANCE ET À
FOURNIR UNE DOCUMENTATION EXPLICATIVE.
OUTRE LE FAIT D’ÊTRE EXAMINÉS POUR
ÉTABLIR S’ILS SONT ACCEPTABLES À DES FINS
INDUSTRIELLES, TECHNOLOGIQUES ET COM-MERCIALES,
AINSI QUE DU POINT DE VUE DES UTILISATEURS, LES
PROJETS DE NORMES
TRAITEMENT PARALLÈLE ISO/CEN
INTERNATIONALES DOIVENT PARFOIS ÊTRE CONSIDÉRÉS
DU POINT DE VUE DE LEUR POSSI BILITÉ DE DEVENIR DES
NORMES POUVANT
SERVIR DE RÉFÉRENCE DANS LA RÉGLEMENTATION
NATIONALE.
Numéro de référence
PROJET FINAL
Norme
internationale
ISO/CASCO
Évaluation de la conformité —
Secrétariat: ISO
Exigences pour les organismes
Début de vote:
certifiant les produits, les processus
2026-08-04
et les services
Vote clos le:
2026-10-27
Conformity assessment — Requirements for bodies certifying
products, processes and services
LES DESTINATAIRES DU PRÉSENT PROJET SONT
INVITÉS À PRÉSENTER, AVEC LEURS OBSERVATIONS,
NOTIFICATION DES DROITS DE PROPRIÉTÉ DONT ILS
AURAIENT ÉVENTUELLEMENT CONNAISSANCE ET À
FOURNIR UNE DOCUMENTATION EXPLICATIVE.
DOCUMENT PROTÉGÉ PAR COPYRIGHT
OUTRE LE FAIT D’ÊTRE EXAMINÉS POUR
ÉTABLIR S’ILS SONT ACCEPTABLES À DES FINS
© ISO/IEC 2026
INDUSTRIELLES, TECHNOLOGIQUES ET COM-MERCIALES,
AINSI QUE DU POINT DE VUE DES UTILISATEURS, LES
Tous droits réservés. Sauf prescription différente ou nécessité dans le contexte de sa mise en œuvre, aucune partie de cette
PROJETS DE NORMES
publication ne peut être reproduite ni utilisée sous quelque forme que ce soit et par aucun procédé, électronique ou mécanique, TRAITEMENT PARALLÈLE ISO/CEN
INTERNATIONALES DOIVENT PARFOIS ÊTRE CONSIDÉRÉS
y compris la photocopie, ou la diffusion sur l’internet ou sur un intranet, sans autorisation écrite préalable. Une autorisation peut DU POINT DE VUE DE LEUR POSSI BILITÉ DE DEVENIR DES
NORMES POUVANT
être demandée à l’ISO à l’adresse ci-après ou au comité membre de l’ISO dans le pays du demandeur.
SERVIR DE RÉFÉRENCE DANS LA RÉGLEMENTATION
NATIONALE.
ISO copyright office
Case postale 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Genève
Tél.: +41 22 749 01 11
E-mail: copyright@iso.org
Web: www.iso.org
Publié en Suisse
Numéro de référence
© ISO/IEC 2026 – Tous droits réservés
ii
Sommaire Page
Avant-propos .v
Introduction .vi
1 Domaine d'application . 1
2 Références normatives . 1
3 Termes et définitions . 1
4 Exigences générales . . 4
4.1 Domaine juridique et contractuel .4
4.1.1 Responsabilité juridique .4
4.1.2 Contrat de certification .4
4.1.3 Utilisation de licences, de certificats et de marques de conformité .5
4.2 Gestion de l'impartialité .6
4.3 Responsabilité et financement .7
4.4 Conditions non discriminatoires .7
4.5 Confidentialité .8
4.6 Informations accessibles au public .8
5 Exigences structurelles . 8
5.1 Organisation et direction .8
5.2 Dispositif de préservation de l'impartialité .9
6 Exigences relatives aux ressources . 10
6.1 Personnel de l'organisme de certification .10
6.1.1 Généralités .10
6.1.2 Gestion des compétences du personnel engagé dans le processus de certification .11
6.1.3 Contrat conclu avec le personnel .11
6.2 Ressources pour l'évaluation . 12
6.2.1 Ressources internes . 12
6.2.2 Ressources externes (externalisation) . 12
7 Exigences relatives aux processus .13
7.1 Généralités . 13
7.2 Demande .14
7.3 Revue de la demande .14
7.4 Évaluation . 15
7.5 Revue .16
7.6 Décision de certification .16
7.7 Documents de certification .17
7.8 Annuaire des produits certifiés .17
7.9 Surveillance .18
7.10 Changements ayant des conséquences sur la certification.18
7.11 Résiliation, réduction, suspension ou retrait de la certification . .19
7.12 Enregistrements . 20
7.13 Plaintes et appels . 20
8 Exigences du système de management .21
8.1 Options.21
8.1.1 Généralités .21
8.1.2 Option A .21
8.1.3 Option B .21
8.2 Documentation générale du système de management (Option A) .21
8.3 Maîtrise des documents (Option A) . 22
8.4 Maîtrise des enregistrements (Option A) . 22
8.5 Revue de direction (Option A) . 23
8.5.1 Généralités . 23
8.5.2 Éléments d'entrée de la revue de direction . 23
8.5.3 Éléments de sortie de la revue de direction. 23

© ISO/IEC 2026 – Tous droits réservés
iii
8.6 Audits internes (Option A) . 23
8.7 Actions correctives (Option A) .24
8.8 Actions à mettre en œuvre face aux risques et opportunités (Option A) .24
Annexe A (informative) Principes s'appliquant aux organismes de certification de produitset à
leurs activités de certification .25
Annexe B (informative) Application du présent documentaux processus et aux services .27
Annexe ZA (informative) Relation entre la présente Norme européenne et les exigences du
Règlement (CE) n° 765/2008 du Parlement européen et du Conseil du 9 juillet 2008
fixant les prescriptions relatives à l'accréditation et abrogeant le règlement (CEE)
n° 339/93 du Conseil .28
Bibliographie .30

© ISO/IEC 2026 – Tous droits réservés
iv
Avant-propos
L'ISO (Organisation internationale de normalisation) et l'IEC (Commission électrotechnique internationale)
forment ensemble le système consacré à la normalisation internationale. Les organismes nationaux membres
de l'ISO ou de l'IEC participent au développement de Normes internationales par l'intermédiaire des comités
techniques créés par l'organisation concernée afin de s'occuper des différents domaines particuliers de
l'activité technique. Les comités techniques de I'ISO et de l'IEC collaborent dans des domaines d'intérêt
commun. D'autres organisations internationales, gouvernementales ou non gouvernementales, en liaison
avec I'ISO et l'IEC participent également aux travaux.
Les procédures utilisées pour élaborer le présent document et celles destinées à sa mise à jour sont décrites
dans les Directives ISO/IEC, Partie 1. Il convient, en particulier, de prendre note des différents critères
d'approbation requis pour les différents types de documents. Le présent document a été rédigé conformément
aux règles de rédaction données dans les Directives ISO/IEC, Partie 2 (voir www.iso.org/directives ou
www.iec.ch/members_experts/refdocs).
L'ISO et l'IEC attirent l'attention sur le fait que la mise en application du présent document peut entraîner
l'utilisation d'un ou de plusieurs brevets. L'ISO et L'IEC ne prennent pas position quant à la preuve, à la
validité et à l'applicabilité de tout droit de propriété revendiqué à cet égard. À la date de publication du
présent document, l'ISO et l'IEC n'avaient pas reçu notification qu'un ou plusieurs brevets pouvaient être
nécessaires à sa mise en application. Toutefois, il y a lieu d'avertir les responsables de la mise en application
du présent document que des informations plus récentes sont susceptibles de figurer dans la base de données
de brevets, disponible à l'adresse www.iso.org/brevets et https://patents.iec.ch. L'ISO et l'IEC ne sauraient
être tenues pour responsables de ne pas avoir identifié tout ou partie de tels droits de propriété.
Les appellations commerciales éventuellement mentionnées dans le présent document sont données pour
information, par souci de commodité, à l'intention des utilisateurs et ne sauraient constituer un engagement.
Pour une explication de la nature volontaire des normes, la signification des termes et expressions spécifiques
de l'ISO liés à l'évaluation de la conformité, ou pour toute information au sujet de l'adhésion de l'ISO aux
principes de l'Organisation mondiale du commerce (OMC) concernant les obstacles techniques au commerce
(OTC), voir www.iso.org/iso/fr/avant-propos.html. Pour l'IEC, voir www.iec.ch/understanding-standards.
Le présent document a été élaboré par le comité ISO pour l'évaluation de la conformité (CASCO), en
collaboration avec le comité technique CEN/CLC/JTC 1, Critères applicables aux organismes d'évaluation de la
conformité, du Comité européen de normalisation (CEN), conformément à l'Accord de coopération technique
entre l'ISO et le CEN (Accord de Vienne).
Cette deuxième édition annule et remplace la première édition (ISO/IEC 17065:2012), qui a fait l'objet d'une
révision technique.
Les principales modifications sont les suivantes:
— mise à jour pour refléter la terminologie de l'ISO/IEC 17000;
— au paragraphe 8.8, remplacement de “Actions préventives” par un nouveau paragraphe “Actions à mettre
en œuvre face aux risques et opportunités”;
— mise à jour et correction de références bibliographiques.
Il convient que l'utilisateur adresse tout retour d'information ou toute question concernant le présent
document à l'organisme national de normalisation de son pays. Une liste exhaustive desdits organismes se
trouve aux adresses www.iso.org/fr/members.html et www.iec.ch/national-committees.

© ISO/IEC 2026 – Tous droits réservés
v
Introduction
La finalité de la certification des produits, processus ou services est d'apporter l'assurance à toutes les
parties intéressées qu'un produit, un processus ou un service remplit les exigences spécifiées. La valeur
d'une certification réside dans le degré de confiance établi par la démonstration impartiale et compétente,
au moyen d'une attestation par tierce partie, que les exigences spécifiées sont respectées. Les parties qui ont
un intérêt dans la certification sont les suivantes (liste non exhaustive):
a) les clients des organismes de certification;
b) les clients des organismes dont les produits, les processus ou les services sont certifiés;
c) les autorités gouvernementales;
d) les organismes non gouvernementaux;
e) les consommateurs et le grand public.
Les parties intéressées peuvent attendre ou exiger que l'organisme de certification réponde à toutes
les exigences du présent document et qu'il réalise la certification conformément à un programme de
certification.
La certification des produits, processus ou services est un moyen de garantir qu'ils répondent aux exigences
spécifiées dans les normes et autres documents normatifs. Certains programmes de certification de
produits, processus ou services peuvent comporter des essais initiaux ou une inspection et une évaluation
des systèmes de management de la qualité des fournisseurs, suivis d'une surveillance prenant en compte
le système de management de la qualité et des essais ou inspections sur des échantillons prélevés à l'usine
ou sur le marché. D'autres systèmes reposent sur des essais initiaux et des essais de surveillance, alors que
d'autres encore ne comprennent que des essais de type.
Le présent document spécifie des exigences, dont le respect a pour but de garantir que les organismes
de certification exploitent des programmes de certification avec compétence, cohérence et impartialité,
facilitant ainsi la reconnaissance de ces organismes et l'acceptation des produits, processus et services
certifiés à un niveau national et international, contribuant de ce fait au développement du commerce
international. Le présent document peut être utilisé comme document de référence pour une accréditation,
une évaluation par des pairs ou une désignation par les autorités gouvernementales, les propriétaires de
programme ou autres.
Les exigences contenues dans le présent document sont surtout rédigées dans le but de servir de critères
généraux pour les organismes de certification exploitant des programmes de certification de produits,
processus ou services; il se peut qu'elles doivent être développées quand des secteurs spécifiques industriels
ou d'autres secteurs les utilisent ou quand il est nécessaire de prendre en compte des exigences comme la
santé et la sécurité. L'Annexe A contient des principes relatifs aux organismes de certification et aux activités
de certifications qu'ils fournissent.
Le présent document ne fixe pas d'exigences portant sur les programmes de certification et la façon dont
ils sont élaborés, et n'a pas davantage pour objet de restreindre les rôles ou les choix des propriétaires
de programmes; il convient cependant que les règles et procédures des programmes, y compris celles qui
identifient les exigences de certification, ne contredisent ni n'excluent aucune des exigences du présent
document.
Les déclarations de conformité aux normes applicables ou à d'autres documents normatifs peuvent se
présenter sous la forme de certificats et/ou de marques de conformité. Les programmes de certification
de produits particuliers ou de groupes de produits, processus et services selon des normes spécifiées ou
d'autres documents normatifs peuvent, dans de nombreux cas, nécessiter leur propre documentation
explicative.
Alors que le présent document traite des organismes qui fournissent une certification (attestation par tierce
partie) d'un produit, d'un processus ou d'un service, nombre de ses clauses peuvent s'avérer également
utiles aux organismes qui réalisent des activités d'évaluation de la conformité de produits, de processus ou
de services par première ou seconde partie.

© ISO/IEC 2026 – Tous droits réservés
vi
Dans le présent document, les formes verbales suivantes sont utilisées:
— le verbe “doit” indique une exigence,
— l'expression “il convient de” indique une recommandation,
— l'expression “il est permis de” indique une permission,
— le verbe “pouvoir” indique une possibilité ou une éventualité.
De plus amples détails figurent dans les Directives ISO/IEC, Partie 2.

© ISO/IEC 2026 – Tous droits réservés
vii
PROJET FINAL Norme internationale ISO/IEC FDIS 17065:2026(fr)
Évaluation de la conformité — Exigences pour les organismes
certifiant les produits, les processus et les services
1 Domaine d'application
Le présent document comporte des exigences portant sur les compétences, la cohérence des activités
et l'impartialité des organismes de certification de produits, processus et services. Les organismes de
certification exerçant selon le présent document ne sont pas tenus de proposer tous les types de certification
de produits, processus et services. La certification de produits, processus et services est une activité
d'évaluation de la conformité par tierce partie (voir l'ISO/IEC 17000:2020, 4.5).
Dans le présent document, le terme “produit” peut se comprendre comme “processus” ou “service”, à
l'exception des cas où figurent des clauses distinctes pour des “processus” ou des “services” (voir Annexe B).
2 Références normatives
Les documents de référence suivants sont indispensables à l'application du présent document. Pour les
références datées, seule l'édition citée s'applique. Pour les références non datées, la dernière édition du
document de référence s'applique (y compris les éventuels amendements).
ISO/IEC 17000, Évaluation de la conformité — Vocabulaire et principes généraux
ISO/IEC 17020, Évaluation de la conformité — Exigences pour les organismes effectuant des inspections
ISO/IEC 17021-1, Évaluation de la conformité — Exigences pour les organismes procédant à l'audit et à la
certification des systèmes de management — Partie 1: Exigences
ISO/IEC 17025, Exigences générales concernant la compétence des laboratoires d'étalonnages et d'essais
ISO/IEC 17029, Évaluation de la conformité — Principes généraux et exigences pour les organismes de validation
et de vérification
3 Termes et définitions
Pour les besoins du présent document, les termes et définitions donnés dans l'ISO/IEC 17000 ainsi que les
suivants s'appliquent.
L'ISO et l'IEC tiennent à jour des bases de données terminologiques destinées à être utilisées en normalisation,
consultables aux adresses suivantes:
— ISO Online browsing platform: disponible à l'adresse https:// www .iso .org/ obp
— IEC Electropedia: disponible à l'adresse https:// www .electropedia .org/
3.1
client
organisme ou personne ayant la responsabilité à l'égard d'un organisme de certification de garantir que les
exigences de certification (3.7) incluant les exigences produit (3.8) sont remplies
Note 1 à l'article: Sauf indication contraire, toutes les fois que le mot “client” est utilisé dans le présent document, il
désigne à la fois le “demandeur” et le “client”.

© ISO/IEC 2026 – Tous droits réservés
3.2
conseil
participation à
a) la conception, la fabrication, l'installation, la maintenance ou la distribution d'un produit certifié ou d'un
produit à certifier, ou
b) la conception, la mise en œuvre, l'exploitation ou la maintenance d'un processus certifié ou d'un
processus à certifier, ou
c) la conception, la mise en œuvre, la fourniture ou la maintenance d'un service certifié ou d'un service à
certifier.
Note 1 à l'article: Dans le présent document, le terme “conseil” est utilisé en relation aux activités des organismes de
certification, du personnel des organismes de certification et des organismes en relation ou liés aux organismes de
certification.
3.3
évaluation
combinaison des fonctions de sélection et de détermination de l'activité d'évaluation de la conformité
Note 1 à l'article: Les fonctions de sélection et de détermination sont décrites dans l'ISO/IEC 17000:2020, A.2 et A.3.
3.4
produit
résultat d'un processus
1)
Note 1 à l'article: L'ISO 9000:2005 mentionne quatre catégories génériques de produits:
— les services (par exemple transport) (voir 3.6);
— les logiciels (par exemple programme informatique, application dictionnaire);
— les matériels (par exemple moteur, pièces mécaniques);
— les produits transformés (par exemple lubrifiant).
De nombreux produits sont constitués d'éléments appartenant à différentes catégories génériques de produits. Le
produit est appelé service, logiciel, matériel ou produit transformé en fonction de l'élément dominant.
Note 2 à l'article: La notion de produit inclut les résultats de processus naturels tels que la croissance des végétaux et
la formation d'autres ressources naturelles.
3.5
processus
ensemble d'activités corrélées ou interactives qui transforment des éléments d'entrée en éléments de sortie
EXEMPLE Techniques de soudage, processus de traitements thermiques, processus de fabrication exigeant
la confirmation de l'aptitude du processus (par exemple utilisation ou fabrication de produits dans des tolérances
spécifiées), processus de production alimentaire et processus de croissance des végétaux.
Note 1 à l'article: Adapté de l'ISO 9000:2005, 3.4.1.
3.6
service
résultat, généralement immatériel, d'au moins une activité réalisée nécessairement à l'interface entre le
fournisseur et le client
Note 1 à l'article: La prestation d'un service peut impliquer
— une activité réalisée sur un produit tangible fourni par un client (par exemple réparation d'une voiture);
1) Annulée.
© ISO/IEC 2026 – Tous droits réservés
— une activité réalisée sur un produit immatériel fourni par un client (par exemple la préparation du compte de
résultats nécessaire à l'établissement de la déclaration des revenus);
— la fourniture d'un produit immatériel (par exemple fourniture d'informations dans le contexte de la transmission
de connaissances);
— la création d'une ambiance pour le client (par exemple dans les hôtels et les restaurants).
Note 2 à l'article: Adapté de l'ISO 9000:2005, 3.4.2.
3.7
exigence de certification
exigence, incluant l'exigence produit (3.8) qui doit être remplie par le client (3.1) comme condition à l'obtention
ou au maintien de la certification
EXEMPLE Exigences de certification qui ne sont pas des exigences produit:
— conclusion du contrat de certification;
— règlement des honoraires;
— fourniture d'informations sur les changements apportés au produit certifié;
— droit d'accès aux produits certifiés pour les activités de surveillance.
Note 1 à l'article: Les exigences de certification incluent les exigences imposées au client par l'organisme de certification
[habituellement par l'intermédiaire du contrat de certification (voir 4.1.2)] pour répondre au présent document, et
peuvent aussi inclure des exigences imposées au client par le programme spécifique de certification. Les exigences
de certification telles que comprises dans le présent document n'incluent pas les exigences imposées à l'organisme de
certification par le programme spécifique de certification.
3.8
exigence du produit
exigence spécifiée qui se rapporte directement à un produit, stipulée dans des normes ou dans d'autres
documents normatifs identifiés par le programme de certification
Note 1 à l'article: Les exigences de produits peuvent être stipulées dans des documents normatifs tels que des
réglementations, des normes et des spécifications techniques.
3.9
programme de certification
ensemble de règles et procédures qui décrit l'objet de l'évaluation de la conformité, identifie les exigences
spécifiées et fournit la méthodologie pour réaliser la certification et les activités d'évaluation de la
conformité associées
Note 1 à l'article: Dans le présent document, l'objet de l'évaluation de la conformité est un produit, un processus ou un
service.
Note 2 à l'article: Des recommandations générales sur les programmes d'évaluation de la conformité qui comprennent
la certification de produits, de processus ou de services figurent dans l'ISO/IEC 17067.
[SOURCE: ISO/IEC 17000:2020, 4.9, modifié — “l'évaluation de la conformité” a été remplacé par “la
certification et les activités d'évaluation de la conformité associées”; les notes à l'article d'origine ont été
remplacées par de nouvelles notes.]
3.10
portée de la certification
— informations identifiant le ou les produits, processus ou services pour lesquels la certification est
délivrée,
— le programme de certification applicable, et

© ISO/IEC 2026 – Tous droits réservés
— la ou les normes et autres documents normatifs, comprenant une date de publication, auxquels le ou les
produits, processus ou services sont jugés conformes
3.11
propriétaire du programme
personne ou organisme responsable du développement et de la tenue à jour d'un programme de certification
(3.9) spécifique
Note 1 à l'article: Le propriétaire du programme peut être l'organisme de certification lui-même, une autorité
gouvernementale, une association professionnelle, un groupe d'organismes de certification ou d'autres entités.
3.12
organisme de certification
organisme tierce partie d'évaluation de la conformité mettant en œuvre des programmes de certification
Note 1 à l'article: Un organisme de certification peut être gouvernemental ou non gouvernemental (avec ou sans
pouvoir réglementaire).
3.13
impartialité
objectivité quant au résultat d'une activité d'évaluation de la conformité
Note 1 à l'article: L'objectivité peut être comprise comme l'absence de parti pris ou de conflit d'intérêts.
[SOURCE: ISO/IEC 17000:2020, 5.3]
4 Exigences générales
4.1 Domaine juridique et contractuel
4.1.1 Responsabilité juridique
L'organisme de certification doit être une entité juridique ou une partie définie d'une entité juridique, en
sorte que l'entité juridique puisse être tenue légalement responsable de toutes ses activités de certification.
NOTE Un organisme de certification gouvernemental est considéré comme une entité juridique en vertu de son
statut gouvernemental.
4.1.2 Contrat de certification
4.1.2.1 L'organisme de certification doit disposer d'un contrat juridiquement applicable de fourniture
d'activités de certification à ses clients. Les contrats de certification doivent tenir compte des responsabilités
de l'organisme de certification et de celles de ses clients.
4.1.2.2 L'organisme de certification doit s'assurer que le contrat de certification engage le client à se
conformer au moins aux points suivants:
a) répondre en permanence aux exigences de certification (voir 3.7), incluant la mise en œuvre les
changements appropriés qui sont communiqués par l'organisme de certification (voir 7.10);
b) si la certification s'applique à une production en série, s'assurer que le produit certifié continue de
répondre aux exigences du produit (voir 3.8);
c) prendre toutes les dispositions nécessaires pour
1) la conduite de l'évaluation (voir 3.3) et la surveillance (le cas échéant), y compris la fourniture
d'éléments en vue de leur examen tels que: de la documentation et des enregistrements, l'accès au
matériel, aux sites, aux zones, aux personnels et sous-traitants du client concernés;
2) l'instruction des réclamations
,
© ISO/IEC 2026 – Tous droits réservés
3) la participation d'observateurs, le cas échéant;
d) faire des déclarations sur la certification en cohérence avec la portée de la certification (voir 3.10);
e) ne pas utiliser la certification de ses produits d'une façon qui puisse nuire à l'organisme de certification
ni faire de déclaration sur la certification de ses produits que l'organisme de certification puisse
considérer comme trompeuse ou non autorisée;
f) en cas de suspension, de retrait ou à l'échéance de la certification, cesser d'utiliser l'ensemble des
moyens de communication qui y fait référence et remplir toutes les exigences prévues par le programme
de certification (par exemple renvoi des documents de certification) et s'acquitter de toute autre mesure
exigée;
g) si le client fournit des copies de documents de certification à autrui, il doit les reproduire dans leur
intégralité ou tel que spécifié par le programme de certification;
h) en faisant référence à la certification de ses produits dans des supports de communication, tels que
documents, brochures ou publicité, se conformer aux exigences de l'organisme de certification et/ou aux
spécifications du programme de certification;
i) se conformer à toutes les règles et procédures qui peuvent être prescrites dans le programme de
certification du produit relatives à l'utilisation des marques de conformité et aux informations relatives
au produit;
NOTE Voir également l'ISO/IEC 17030.
j) conserver un enregistrement de toutes les réclamations dont il a eu connaissance concernant la
conformité aux exigences de certification et mettre ces enregistrements à la disposition de l'organisme
de certification sur demande, et
1) prendre toute action appropriée en rapport avec ces réclamations et les imperfections constatées
dans les produits qui ont des conséquences sur leur conformité aux exigences de la certification;
2) documenter les actions entreprises.
NOTE La vérification du point j) par l'organisme de certification peut être spécifiée dans le programme de
certification.
k) informer, sans délai, l'organisme de certification des changements qui peuvent avoir des conséquences
sur sa capacité à se conformer aux exigences de la certification.
NOTE Exemples de changements:
— la propriété ou le statut juridique, commercial, et/ou organisationnel;
— l'organisation et la gestion (par exemple le personnel clé tel que les dirigeants, les décisionnaires ou les
techniciens);
— les changements apportés au produit ou à la méthode de production;
— les coordonnées de la personne à contacter et les sites de production;
— les changements importants apportés au système de management de la qualité.
4.1.3 Utilisation de licences, de certificats et de marques de conformité
4.1.3.1 L'organisme de certification doit exercer le contrôle tel que spécifié par le programme de
certification sur la propriété, l'utilisation et l'affichage des licences, des certificats, des marques de
conformité, ainsi que de tout autre dispositif destiné à indiquer la certification d'un produit.
NOTE L'ISO/IEC 17030 fournit les exigences relatives à l'utilisation des marques de tierces parties.

© ISO/IEC 2026 – Tous droits réservés
4.1.3.2 Des références erronées au programme de certification ou une utilisation trompeuse des licences,
des certificats, des marques ou de tout autre dispositif indiquant qu'un produit est certifié, figurant dans la
documentation ou d'autres outils publicitaires doivent être corrigées par une action appropriée.
4.2 Gestion de l'impartialité
4.2.1 Les activités de certification doivent être menées avec impartialité.
4.2.2 L'organisme de certification doit être responsable de l'impartialité de ses activités de certification et
ne doit pas laisser des pressions commerciales, financières ou autres compromettre cette impartialité.
4.2.3 L'organisme de certification doit identifier régulièrement les risques susceptibles de nuire à son
impartialité. Cela doit inclure les risques résultant de ses activités, de ses relations ou des relations de
son personnel (voir 4.2.12). Cependant, ces relations ne présentent pas nécessairement un risque pour
l'impartialité de l'organisme de certification.
NOTE 1 Une relation présentant un risque pour l'impartialité de l'organisme de certification peut résulter de
facteurs tels que la propriété, la gouvernance, la direction, le personnel, le partage de ressources, la situation
financière, des contrats, la commercialisation (y compris la stratégie de marque), le paiement de commissions sur les
ventes ou autres incitations à l'apport de nouveaux clients, etc.
NOTE 2 L'identification des risques n'implique pas une évaluation du risque selon l'ISO 31000.
4.2.4 Si un risque pour l'impartialité est identifié, l'organisme de certification doit pouvoir apporter la
preuve de la manière dont il élimine le risque ou le limite au minimum. Ces informations doivent être mises
à la disposition du dispositif indiqué en 5.2.
4.2.5 La direction de l'organisme de certification doit s'engager en matière d'impartialité.
4.2.6 L'organisme de certification et toute autre partie de la même entité juridique, ainsi que les entités
dépendant de son contrôle organisationnel (voir 7.6.4) ne doivent pas
a) être le concepteur, le fabricant, l'installateur, le distributeur, le responsable de l'entretien du produit
certifié,
b) être le concepteur, l'utilisateur, l'exploitant, le responsable de la maintenance du processus certifié,
c) être le concepteur, l'utilisateur, le fournisseur, le responsable après-vente du service certifié,
d) proposer ou fournir à leurs clients des activités de conseil (voir 3.2), et
e) proposer ou fournir à leurs clients des conseils en matière de système de management ou d'audit interne
quand le programme de certification exige l'évaluation du système de management du client.
NOTE 1 Ceci n'empêche pas:
— la possibilité d'échanger des informations (par exemple des explications sur les conclusions ou des éclaircissements
concernant des exigences) entre l'organisme de certification et ses clients, et
— l'utilisation, l'installation et la maintenance de produits certifiés qui sont nécessaires au fonctionnement de
l'organisme de certification.
NOTE 2 “Conseils en matière de système de management” est défini dans l'ISO/IEC 17021-1:2015, 3.3.
4.2.7 L'organisme de certification doit s'assurer que les activités des entités juridiques séparées
avec lesquelles l'organisme de certification ou l'entité juridique dont il fait partie ont des relations ne
compromettent pas l'impartialité de ses activités de certification.
NOTE Voir 4.2.3, NOTE 1.
© ISO/IEC 2026 – Tous droits réservés
4.2.8 Lorsque l'entité juridique séparée dont il est question en 4.2.7 offre ou produit le produit certifié
(ou à certifier), ou offre ou fournit des conseils (voir 3.2), la direction de l'organisme de certification et le
personnel chargé du processus de revue et de prise de décision de certification ne doivent pas être impliqués
dans les activités de l'entité juridique séparée. Le personnel de l'entité juridique séparée ne doit pas être
impliqué dans la gestion de l'organisme de certification, la revue ou la décision de certification.
NOTE En ce qui concerne le personnel d'évaluation, l'Article 6 du présent document stipule des exigences relatives
à l'impartialité. D'autres Normes internationales applicables mentionnées en 6.2.1 et 6.2.2.1 stipulent également des
exigences supplémentaires.
4.2.9 Les activités de l'organisme de certification ne doivent pas être commercialisées ou proposées
comme étant liées aux activités d'un organisme de conseil (voir 3.2). De même, un organisme de certification
ne doit pas déclarer ou suggérer que la certification serait plus simple, plus facile, plus rapide ou moins
onéreuse s'il était fait appel à un organisme de conseil spécifié.
4.2.10 Pendant une période spécifiée par l'organisme de certification, le personnel qui a assuré des
prestations de conseil (voir 3.2) pour un produit donné ne doit pas procéder à la revue, ni prendre de décision
de certification pour ce produit.
NOTE 1 La période peut être spécifiée dans le programme de certification ou, si elle est spécifiée par l'organisme
de certification, il convient qu'elle représente une période de temps suffisamment longue pour que l'impartialité de la
revue ou de la décision ne soit pas compromise. Une période spécifiée de deux ans est souvent retenue.
NOTE 2 En ce qui concerne le personnel d'évaluation, l'Article 6 du présent document stipule des exigences relatives
à l'impartialité. D'autres Normes internationales applicables mentionnées en 6.2.1 et 6.2.2.1 mentionnent également
des exigences supplémentaires.
4.2.11 L'organisme de certification doit prendre les mesures nécessaires lorsqu'il prend conscience que son
impartialité est menacée par les actions d'autres personnes, entités ou organismes.
4.2.12 L'ensemble du personnel de l'organisme de certification, qu'il soit interne ou externe, ou les comités,
qui pourraient influencer les activités de certification, doit agir de manière impartiale.
4.3 Responsabilité et financement
4.3.1 L'organisme de certification doit prévoir les dispositions nécessaires (par exemple assurance ou
provisions) pour couvrir les responsabilités résultant de ses opérations.
4.3.2 L'organisme de certification doit avoir une stabilité financière et les ressources nécessaires à ses
opérations.
4.4 Conditions non discriminatoires
4.4.1 Les politiques et les procédures qui régissent le fonctionnement de l'organisme de certification,
ainsi que leur administration, doivent être non discriminatoires. Hormis les clauses prévues dans le présent
document, les procédures ne doivent pas servir à entraver ou interdire l'accès aux demandeurs.
4.4.2 L'organisme de certification doit rendre ses services accessibles à tous les demandeurs dont les
activ
...