How to get ISO certified, step by step
Management system certification is independent confirmation that your system meets the requirements of a recognized standard. We audit your system, make an impartial certification decision, and keep your certificate under surveillance for its three-year cycle.
Certification is not a one-off inspection. It is a cycle that checks your system keeps working over time, so your customers can rely on it every year, not just on audit day.
- Written proposalAudit days calculated from documented rules.
- Competent auditorsMatched to your standard and sector.
- Impartial decisionBy someone who was not on the audit team.
- Verifiable certificateListed online with a QR code.
Your path to certification
Eight clear steps from first contact to a verifiable certificate. You know every step, document and decision point before you start.
Tell us your standard(s), scope, sites and headcount.
We calculate audit days from our documented rules and send a written proposal.
You sign the certification agreement; we appoint a competent audit team.
We review your documented information and confirm readiness for Stage 2.
Interviews, observation and records, on site or remotely where permitted.
You correct any nonconformities and provide evidence within the agreed time.
A competent person who was not on the audit team reviews the file and decides.
We issue your certificate and list it in our public verification system.
The three-year certification cycle
Initial certification
Stage 1 and Stage 2 audits, then an independent certification decision.
Surveillance audit 1
Confirms continued conformity and samples processes. Due within 12 months of the decision.
Surveillance audit 2
Covers the remaining processes so the whole system is checked during the cycle.
Recertification
A full reassessment before expiry, leading to a new three-year certificate.
Certification services
Certification Process
Every step from application to certificate, explained in detail.
Learn more
Initial Certification
First-time certification: what to prepare and what to expect.
Learn more
Recertification
Full reassessment to renew your certificate for three more years.
Learn more
Transfer Certification
Move a valid certificate to USGSR without restarting the cycle.
Learn more
Integrated Management Systems
Certify several standards in one combined audit programme.
Learn more
What determines audit time and cost
We do not shorten audit time to win work. Audit time follows our documented rules, so every client in the same situation is treated the same way.
- The number of people working under the system, including contractors
- The number of sites, and whether processes are repeated across them
- The complexity and risk of your activities
- The standard(s), and whether audits are integrated
- Shift work, temporary sites and outsourced processes
What you need before Stage 1
Your system should be implemented and producing evidence before the certification audit begins.
- A defined scope and boundaries for the management system
- Documented information required by the standard: policy, objectives, processes, records
- At least one completed internal audit and management review
- Records showing the system has operated long enough to be evaluated
Nonconformities and certification decisions
| Finding | Meaning | What happens |
|---|---|---|
| Major nonconformity | A requirement is not met, or there is doubt that the system can achieve its intended results | Corrected and verified before certification; may need a follow-up visit |
| Minor nonconformity | A requirement is partly not met, without affecting the system’s ability to achieve its results | Accepted correction and action plan; verified at the next audit |
| Opportunity for improvement | An observation, not a nonconformity | Optional to act on |
Auditors report findings. They do not tell you how to fix them, because that would be consultancy, and it would compromise the impartiality of your certificate.
Certification types
Certification routes differ by standard. Each standard page states which route applies, and every certificate shows its type in our verification system.
Accredited certification
Certification within our USIAS accreditation scope.
Non-accredited certification
USGSR certification for standards and scopes outside the accreditation scope.
Compliance certification
An audit against published requirements, with a certificate that states exactly what it does and does not cover.
Already certified elsewhere?
Organizations with a valid certificate can usually transfer to USGSR without restarting the cycle. We review your current certificate, recent audit reports and any open nonconformities.
Frequently asked questions
How long does ISO certification take?
Once your system is implemented and producing records, Stage 1 and Stage 2 can usually be completed within a few weeks to a few months, depending on scheduling and any corrective actions.
How long is an ISO certificate valid?
Three years, provided surveillance audits are completed on time and the system continues to conform.
What is the difference between Stage 1 and Stage 2?
Stage 1 checks documentation and readiness. Stage 2 evaluates whether the system is implemented and effective in practice.
How much does certification cost?
Cost follows audit time, which depends on your headcount, sites, activities and standards. Send us those details and we will reply with a fixed written proposal.
Can you help us write our procedures?
No. As a certification body we cannot provide consultancy to organizations we certify. We can explain requirements in general terms and offer training that is open to everyone.
What happens if we fail an audit?
There is no pass or fail score. If nonconformities are found, you correct them and we verify the correction before a certification decision is made.
Can we certify several standards together?
Yes. An integrated audit covers shared elements once, which usually reduces total audit time.