Certification / Accreditation

ISO 17025 Testing and calibration laboratories

ISO 17025 is the international standard for testing and calibration laboratories. Unlike most management system standards, it assesses technical competence as well as management processes, covering personnel, equipment, methods and the validity of results themselves.

At its core, it’s about metrological traceability: proving your measurement results trace back, through an unbroken chain of calibrations, to a recognised reference. Laboratories are accredited, not certified, against this standard, and in the UK that accreditation is provided by UKAS.

Who it’s for and what’s involved

Relevant if you are:

A testing or calibration laboratory, of any size

Running mobile or on-site testing services

Already holding ISO 9001 and want to streamline accreditation

Needing UKAS recognition for client or regulatory reasons

Achieving certification involves:

Demonstrating personnel competence and equipment calibration

Establishing metrological traceability for measurement results

Choosing Option A or Option B for management system requirements

Passing a UKAS assessment

How Q! supports certification

Technical competence, not just paperwork

Because this standard combines management system requirements with technical competence, we work closely with laboratory personnel on the technical detail: method validation, measurement uncertainty and traceability, not just documentation. If you already hold ISO 9001, we help you use Option B to streamline the management system requirements rather than duplicating effort.

Wondering whether you need ISO 17025 and UKAS accreditation?

Mini FAQs

It depends less on company size than people expect, and more on whether your risk assessment is done properly. A thin, generic risk assessment will get found out at audit. A thorough one, reflecting how the business actually handles information, tends to make the rest of the standard fall into place.
Annex A was reorganised from 114 controls across 14 categories to 93 controls across four themes. More significant in practice were the new controls: threat intelligence, cloud services security, data masking and ICT readiness for business continuity. Most of the work in transitioning was rebuilding the Statement of Applicability, not relabelling documents.
Often, yes, particularly for businesses handling client data where a security incident would be commercially damaging. Certification forces a level of discipline around information security that many businesses benefit from regardless of whether a customer has formally requested it, and it puts you ahead of the request when it eventually comes.
Yes. ISO 27001 shares its Harmonised Structure with ISO 9001, ISO 14001, ISO 45001 and ISO 50001, making integration into a single management system practical for businesses already certified elsewhere. The wider ISO 27000 series also includes standards for drilling into specific sub-topics, such as ISO 27017 for cloud security and ISO 27701 for privacy information management, useful if a particular area needs deeper treatment than Annex A alone provides.
ISO 42001 covers AI management systems, a closely related but distinct set of risks. The two standards are increasingly relevant together for technology businesses developing or deploying AI.
Plenty of technically capable teams can write policies and select controls themselves. Where a consultant earns their place is in the risk assessment itself, pressure-testing whether it reflects the business, and in preparing for audit so nothing comes as a surprise on the day.

Relevant case studies

We’re proud of the service we provide and the feedback we get from our clients. but don’t just take our word for it.

Client: QFactorial

Our own B Corp journey: practising what we preach

Read more

Whatever business stage you are at…

We’re
here.

Starting up

Foundations, framework, roadmap

Growing up

Strategies for growth and resilience

Shaking up

Managing change to mitigate and maximise

Stepping up

Compliance without tears

Opening up

Assurance and confidence

Speeding up

Performance improvement

Selling up

Exit value, the ultimate return


Want to know if ISO 27001 is right for your business?

Book a free discovery call and we will establish where you are and what the path to certification actually involves.

Our Services:

Our sectors of expertise: