ISO 9001 certification shows customers that an independent auditor has checked how your organization plans, delivers and improves its products or services. If a customer or tender has asked for it, this guide explains what to put in place, what happens during the audits and how long it usually takes.
What ISO 9001 certification actually means
ISO 9001 is the international standard for quality management systems. ISO publishes the standard, but it does not certify anyone. Certification is carried out by an independent certification body, which audits your system and, if the evidence shows the requirements are met, issues a certificate valid for three years. The certificate covers a defined scope: the activities and sites it applies to.
Step 1: Put your quality management system in place
- Context and scope: what your organization does, who your interested parties are, and which activities and sites the system covers.
- Leadership: a quality policy, measurable quality objectives and clear responsibilities.
- Risk-based planning: identifying risks and opportunities that could affect quality.
- Controlled operations: confirming customer requirements, controlling suppliers, delivering the work and handling problems.
- Performance evaluation: monitoring, customer satisfaction, internal audits and management review.
- Improvement: corrective action that addresses root causes.
Keep the documentation proportionate. ISO 9001:2015 does not require a quality manual.
Step 2: Run the system and build records
Auditors need evidence, so the system has to operate for a while before Stage 1. Complete at least one full internal audit and one management review, and act on what they found.
Step 3: Apply for certification
Request a quote with four facts: the standard, your scope, your headcount and your number of sites. These determine the audit time. Request an ISO 9001 quote
Step 4: Stage 1 audit
The Stage 1 audit checks your documented information, scope and readiness, and plans Stage 2. Read more about Stage 1
Step 5: Stage 2 audit
Stage 2 is the main certification audit. The auditor interviews top management and staff, observes work and samples records. At the closing meeting you hear the findings.
Step 6: Close nonconformities and get the decision
Major nonconformities must be corrected and verified before certification. For minor ones, you submit an accepted corrective action plan. An independent reviewer then makes the decision, and your certificate is listed in our public verification system.
Step 7: Keep it going
Surveillance audits take place at least annually, and a recertification audit before the certificate expires.
How long does it take?
| Phase | Typical duration |
|---|---|
| Building the system (if starting from scratch) | 3–12 months |
| Operating the system to produce records | A few months |
| Stage 1 to certification decision | A few weeks to a few months |
Common mistakes to avoid
- Writing documents for the auditor instead of for the business.
- Objectives that cannot be measured.
- Skipping the internal audit or holding management review just for show.
- A scope that does not match what you actually sell.
Ready to start? Tell us your scope, sites and headcount, and we will confirm the audit days and send a written proposal. Request an ISO 9001 Quote