Back to Blog
GRC & ComplianceSNI ISO 27001ISO 27001KANUKASCertification BodyAccreditationGRCISO Certification

SNI ISO/IEC 27001 vs ISO/IEC 27001: What's Different, and Which Certification Body to Choose

The tender says “SNI ISO/IEC 27001”; your certificate says “ISO/IEC 27001”. The content is identical — what differs is the body accrediting the issuer. The chain from standard to certification body to accreditation body (KAN, UKAS, ANAB), how to pick the route that suits whoever reads your certificate, and how cost and evidence demands differ.

Cloudsphere Consulting Team

GRC & ISO 27001

August 25, 2026
11 min read

Quick Answer

SNI ISO/IEC 27001:2022 is the identical adoption of ISO/IEC 27001:2022 as an Indonesian national standard published by BSN — clauses 4–10 and all 93 Annex A controls are exactly the same, with nothing added or removed. What differs is not the standard but the body accrediting the certificate issuer: KAN for the national route, or bodies such as UKAS and ANAB for the international one. One properly built ISMS satisfies both, so the only decision left is which certification body to use — and that is determined by whoever will read your certificate.

The Tender Says “SNI ISO/IEC 27001”. Is That a Different Standard?

The question almost always arrives at the same moment: a team reads a procurement document, finds a requirement for an “SNI ISO/IEC 27001:2022 certificate”, then realises the certificate they hold — or are pursuing — reads “ISO/IEC 27001:2022” with no SNI prefix. The worry follows that they have been chasing the wrong standard all along.

The good news is that the content is identical. What differs is not the standard but who accredited the body issuing your certificate — and that difference still matters, because it decides whether your certificate is accepted by whoever asked for it.

In short

SNI ISO/IEC 27001:2022 is the identical adoption of ISO/IEC 27001:2022 as an Indonesian national standard. Clauses 4–10 and all 93 Annex A controls are exactly the same. One properly built ISMS satisfies both; what needs deciding is which certification body to use.

The Short Answer

  • The content is identical

    SNI ISO/IEC 27001:2022 is an identical adoption of ISO/IEC 27001:2022. No added clauses, no removed controls.

  • Accreditation is what differs

    Certificates are issued by certification bodies. Those bodies are themselves accredited — in Indonesia by KAN, elsewhere by bodies such as UKAS or ANAB.

  • One ISMS, two routes

    The information security management system you build does not need to differ. Only the body auditing and issuing the certificate does.

  • The reader decides the route

    Domestic tenders generally name SNI and KAN-accredited bodies. Foreign parent companies or clients generally recognise UKAS or ANAB.

Who Issues What: The Chain People Confuse

Confusion about SNI almost always traces to one thing: the chain between the standard, the certification body, and the accreditation body is never explained. Yet all three are different parties with different roles.

How to read someone else's certificate

When a prospective vendor sends an ISO 27001 certificate, what needs checking is not only the certification body's logo but the accreditation body mark on it — and the scope annex. A certificate with unclear accreditation, or a scope that does not cover the service you are buying, does not give the assurance you assume.

PartyRoleExample
Standards bodyWrites and publishes the standard textISO/IEC for ISO/IEC 27001; BSN for its national adoption as SNI
Certification bodyAudits your organisation and issues the certificateInformation security management system certification bodies, local or international
Accreditation bodyAssesses and accredits the certification bodies themselvesKAN in Indonesia; UKAS in the UK; ANAB in the United States
Your organisationBuilds and runs the ISMS being auditedCertificate holder

KAN, UKAS, and ANAB: What It Means for You

KAN (Komite Akreditasi Nasional) is Indonesia's accreditation body. Certification bodies it accredits issue certificates referencing SNI ISO/IEC 27001:2022 — and this is what government and state-owned enterprise procurement documents generally ask for.

UKAS and ANAB are foreign accreditation bodies better known in multinational environments. Certificates from bodies they accredit are commonly requested by foreign parent companies, global enterprise clients, or partners running cross-border vendor risk programmes.

Mutual recognition between countries runs through the International Accreditation Forum (IAF) framework and its recognition arrangements. That framework is what makes a certificate from one jurisdiction recognised in principle elsewhere. But “recognised in principle” and “accepted by the party asking” are not always the same thing — and for you, only the second one counts.

The international route demands more

From our field experience: audits on the international accreditation route generally demand more detailed evidence and deeper examination, and cost more. That is no reason to avoid it — but the preparation has to be designed to that standard from the start rather than patched before the audit.

The KAN route fits when

  • Your tender document names “SNI ISO/IEC 27001” explicitly
  • Your main buyers are government agencies, state-owned enterprises, or domestic companies
  • The audit budget needs to be as efficient as possible
  • Audit conducted in Indonesian makes life easier for your internal team

The international route (UKAS/ANAB) fits when

  • Your parent company or principal clients are overseas
  • The certificate will be read by a global procurement team with an accepted-accreditation list
  • You are pursuing cross-border enterprise contracts
  • You are ready for a generally stricter evidence standard and deeper audit

How to Decide in Five Minutes

01

Re-read who is asking for the certificate

Not “we want ISO 27001” but “who will read this certificate”. That answer determines the rest.

  • Government or SOE tender → check whether it names SNI or KAN accreditation
  • Enterprise client → ask whether they hold an accepted-accreditation list
  • Foreign parent → follow the group's standard
02

Read the requirement literally

Some documents say “ISO 27001 or equivalent”; others say “SNI ISO/IEC 27001 from a KAN-accredited body”. The second closes the choice; the first opens it.

03

Count backwards from the deadline

Implementation through to certificate issuance typically takes three to four months for a focused small organisation. If the tender deadline is shorter, the question is not which route but whether it is feasible at all.

04

Ask for the scope annex, not just the price

Compare certification bodies on accreditation scope and surveillance schedule, not only first-year audit fees.

Cost & Time: What Changes, What Doesn't

The most misunderstood part: choosing an accreditation route does not change the implementation work. Gap analysis, risk assessment, ISMS development, training, and internal audit are the same either way — because the standard is the same.

What differs is the certification body's audit fee and the evidence it demands. That is why the route should be decided at the start of the programme rather than the end: preparing evidence to a higher standard from the outset is far cheaper than redoing evidence collection a month before the audit.

The route is not what drives cost

The largest cost driver remains certification scope — how many units, sites, and systems — and the organisation's starting condition. Two similarly sized organisations can differ twofold in cost because of scope, not because of accreditation body.

ComponentKAN routeInternational route
ISMS implementation workSameSame
Standard content satisfiedClauses 4–10 + 93 Annex A controlsClauses 4–10 + 93 Annex A controls
Certification body audit feeGenerally lowerGenerally higher
Evidence depth demandedStandardGenerally stricter
Audit languageUsually IndonesianUsually English
Certificate validityThree years with annual surveillanceThree years with annual surveillance

Four Expensive Mistakes

Choosing the body after the ISMS is finished

If the international route is eventually chosen, its stricter evidence standard only surfaces at the end — and evidence collection is redone under deadline pressure.

Assuming a certificate opens every tender

Some procurement documents name a specific accreditation explicitly. A valid certificate from an unnamed route can still fail at the administrative stage.

Ignoring the scope annex

A certificate applies only to the scope written in its annex. Too narrow a scope leaves the certificate failing to answer the question a client actually asked.

Chasing the certificate, not the system

A certificate lasts three years with annual surveillance. An ISMS that stops running after the first audit shows up at the next surveillance, and losing a certificate costs far more than maintaining one.

Conclusion

SNI ISO/IEC 27001:2022 and ISO/IEC 27001:2022 are not competing standards — one is the national adoption of the other, with identical content. So there is no such thing as choosing the wrong standard; there is only choosing the wrong certification body for whoever will read your certificate.

The decision is straightforward when asked in the right order: start from who is asking, read the requirement literally, then pick the accreditation route. What is not straightforward — and what actually decides the outcome — is building an ISMS that genuinely runs, because that part is identical on both routes and has no shortcut.

Cloudsphere builds an ISMS that satisfies ISO/IEC 27001:2022 and SNI ISO/IEC 27001:2022 alike, and supports both the KAN-accredited route and international accreditation such as UKAS. We help you decide which route suits whoever will read your certificate — before audit fees are committed.

Frequently Asked Questions

Is SNI ISO/IEC 27001 the same as ISO/IEC 27001?

The content is exactly the same. SNI ISO/IEC 27001:2022 is the identical adoption of ISO/IEC 27001:2022 as an Indonesian national standard. Clauses 4 through 10 and all 93 Annex A controls do not differ in any respect. Only the accreditation of the issuing body differs, so one properly built information security management system satisfies both at once.

What is KAN's role in ISO 27001 certification?

KAN (Komite Akreditasi Nasional) is Indonesia's accreditation body. KAN does not issue ISO 27001 certificates to organisations; it accredits the certification bodies entitled to issue them. That is why what needs checking on a certificate is not only the certification body's name but the accreditation body standing behind it.

When should a KAN-accredited body be chosen?

When your tender or procurement document names SNI ISO/IEC 27001 or KAN accreditation explicitly, and when your principal buyers are government agencies, state-owned enterprises, or domestic companies. This route is generally more efficient on audit cost, and the audit is conducted in Indonesian.

When is an international route such as UKAS more appropriate?

When your parent company or principal clients are overseas, or when the certificate will be read by a global procurement team holding a list of accreditations they accept. Bear in mind this route generally demands a stricter evidence standard, a deeper audit, and higher fees, so preparation needs designing to that standard from the start of the programme.

Are certificates from KAN-accredited bodies recognised abroad?

Mutual recognition between countries runs through the International Accreditation Forum framework and its recognition arrangements. But recognised within a framework and accepted by the party asking are not always the same: some global procurement teams maintain a specific list of accreditations they accept. The safest approach is to ask them first.

Does switching accreditation route mean redoing the implementation?

The management system does not need rebuilding, because the standard is identical. What repeats is the certification audit by the new body. What to anticipate is a more detailed evidence demand when moving to the international route — which is precisely why the route should be decided at the start of the programme rather than after the ISMS is complete.

About the Author

Cloudsphere Consulting Team

GRC & ISO 27001

Cloudsphere's GRC consulting team, guiding Indonesian organizations to ISO 27001 certification and PDP Law compliance from gap analysis through audit.

Share Article

Related Topics

SNI ISO 27001ISO 27001KANUKASCertification BodyAccreditationGRCISO Certification