← Back to blog

6-Step ISO Certification for Businesses: Verify Accreditation, Automate

September 9, 2026
6-Step ISO Certification for Businesses: Verify Accreditation, Automate

Getting ISO certified means implementing a management system that meets your chosen standard's requirements, running internal audits to prove it works, then hiring an accredited certification body to audit and register you. ISO itself never issues certificates. That job belongs to independent, accredited certification bodies, and the whole process usually runs through documented preparation, a Stage 1 and Stage 2 audit, and ongoing surveillance to keep the certificate active.


TL;DR:

  • Choosing an accredited certification body for your specific ISO standard and scope is critical to ensure your certificate's credibility and acceptance.
  • Conducting a thorough gap analysis early prevents delays caused by overlooked deficiencies during the external audit process.
  • Maintaining consistent documentation, employee training records, and evidence of system operation is essential for a smooth certification and surveillance process.
  • Certification costs vary widely based on company size, scope, and complexity, with timelines usually ranging from three to twelve months depending on organization scale.
  • Regular internal audits and management reviews fully prepared for external verification are vital to avoid costly nonconformities during certification audits.

Skypher
Streamline Your Security Reviews
Skypher helps teams automate security questionnaire responses, collaborate in real time, and connect with more than 30 risk platforms.
Explore Skypher

Table of Contents

Quick Checklist to Get ISO Certified

If you want the short version before the details, here's the sequence most organizations follow, from the first planning meeting to the moment a registrar hands over a certificate.

  1. Pick the standard and define scope. Decide which ISO standard fits your business (9001 for quality, 27001 for information security, 14001 for environmental management) and which departments, locations, or products the certificate will cover.
  2. Run a gap analysis. Compare current practices against the standard's clauses and flag what's missing.
  3. Document processes and assign owners. Write the policies, procedures, and records the standard requires, and name someone accountable for each.
  4. Train staff and collect records. Employees need to understand the system, and you need proof they were trained.
  5. Perform an internal audit and fix what it finds. This step catches problems before an external auditor does.
  6. Select an accredited registrar and schedule the audit. This is the external certification body that formally registers you.

Each of these steps has its own set of decisions and paperwork, which is what the rest of this guide walks through.

Step-by-Step: Preparation, Documentation, and the Certification Audit

Choosing the right ISO standard

Start with your customers and your risk profile, not with what sounds impressive. A software vendor fielding constant security questionnaires from enterprise buyers usually needs ISO 27001. A manufacturer chasing government contracts often needs ISO 9001. A company with environmental permitting exposure looks at ISO 14001. Some organizations end up pursuing two standards at once because their customer base demands both quality and security assurances, and building an integrated management system from the start saves duplicate work later.

Running the gap analysis

A gap analysis compares your current operations against every clause of the standard, and it's where most timeline surprises come from. Common gaps include missing risk assessments, undocumented approval workflows, and training records that exist informally (a manager "knows" who's trained) but were never written down. Build a checklist mapped to the standard's clause structure, walk each department through it, and rate each item as compliant, partially compliant, or missing. Skipping this step is the single most common reason certification projects run long, because problems surface during the certification audit instead of months earlier when they're cheap to fix.

Documented information: what's mandatory versus helpful

ISO standards distinguish between documents the standard explicitly requires (a documented scope statement, a policy, a Statement of Applicability for ISO 27001) and documents you create because they help you run the business consistently. Don't over-document. Auditors want evidence that your system works, not a binder for every conceivable scenario. A lean set of controlled documents, each with a clear owner and revision history, holds up better under audit scrutiny than a bloated document library nobody actually follows.

Pro Tip: Auditors trust systems where documentation matches daily behavior. If your procedure says approvals happen in a ticketing system but your team actually approves things over email, fix the process or fix the document, but don't let the two disagree.

Implementation: controls, training, evidence

This is where policy becomes practice. Roll out the controls your gap analysis identified, train every affected employee, and start collecting the records auditors will ask for:

  • Training attendance logs and competency assessments
  • Risk assessments and treatment plans
  • Change logs, incident reports, and access reviews (for information security standards)
  • Supplier and vendor evaluation records
  • Calibration or monitoring data (for quality and environmental standards)

Auditors consistently look for records of training, corrective actions, and management review minutes as proof that a system is operating, not just written down.

Internal audit and management review

Before any external body sees your system, you audit yourself. Sample a representative slice of processes and records rather than checking everything, document findings honestly, and open corrective actions for anything nonconforming. Management review follows the internal audit: leadership formally reviews audit results, objectives, and resource needs, and that review gets minuted. Registrars ask for these minutes during the certification audit, and a thin or missing management review is a common finding.

What to expect in the certification audit

The certification audit itself happens in two stages. Stage 1 is a documentation review, often conducted remotely, where the auditor checks that your management system is designed to meet the standard and that you're ready for Stage 2. Stage 2 is the on-site (or remote, depending on the registrar and standard) audit where the auditor interviews staff, samples records, and verifies the system is actually operating as documented. Both stages feed into the certification decision, and passing Stage 1 doesn't guarantee a smooth Stage 2 if evidence collection has been inconsistent.

How Do You Choose and Verify a Certification Body?

ISO writes the standards. Certification bodies (also called registrars) audit organizations against those standards and issue certificates. Accreditation bodies, in turn, audit and approve the certification bodies themselves, which is the layer that keeps the whole system honest. ISO does not certify anyone directly, and it doesn't authorize use of its logo as a certification mark either.

Verifying accreditation before signing a contract is not optional if you plan to use your certificate with serious customers. The IAF CertSearch database consolidates accreditation and certification records across multiple national accreditation bodies, letting you confirm a registrar's status individually, in bulk, or through an API. National accreditation bodies also maintain their own public directories.

Before committing to a registrar, ask:

  • Are you accredited for the specific standard and scope I need, by a recognized national accreditation body?
  • What does your audit schedule look like, and can you accommodate remote audits where applicable?
  • Can you provide reference clients in my industry or of similar size?
  • What happens if a nonconformity is found during Stage 2?

Compare at least three registrars before deciding. Pricing, audit day allocation, and industry familiarity vary more than most first-time applicants expect, and accreditation is one of the strongest trust signals enterprise buyers look for. A certificate from a non-accredited body is often rejected outright by procurement teams and government contract requirements, which makes this the one step where cutting corners costs you the entire investment.

How Much Does ISO Certification Cost and How Long Does It Take?

Cost and timeline both scale with scope, company size, and standard complexity, not with a fixed price list. A single-location company pursuing ISO 9001 with clean existing processes spends far less than a multi-site organization implementing ISO 27001 across several product lines. Consultant fees, registrar audit-day rates, and travel for on-site audits are the biggest variable costs, and OSHA Workplace Safety's guide notes that small projects can run in the low thousands while larger, complex certifications cost considerably more.

Typical timelines break down roughly like this:

  • Small organizations: 3 to 6 months from kickoff to certificate
  • Mid-size organizations: 6 to 12 months, often due to multiple departments and more complex risk assessments
  • Larger or multi-site organizations: timeline varies significantly based on how many locations and business units fall inside the certification scope

The pitfalls that stretch these timelines are predictable. Over-documenting slows everyone down and creates upkeep burden. Weak or rushed internal audits let problems reach the external auditor instead of getting caught early. Limited management involvement stalls decisions on resourcing and corrective actions. Scope creep, where the certification boundary keeps expanding mid-project, is probably the single most common reason a six-month plan becomes a ten-month plan.

What Do Auditors Actually Check?

Regardless of which standard you're pursuing, auditors return to the same core evidence: a documented scope, measurable objectives, records proving the system is implemented, internal audit results, corrective action tracking, and management review minutes. That baseline holds across ISO 9001, ISO 27001, and ISO 14001 alike, but each standard layers on its own focus areas.

  • ISO 9001: Auditors focus on process performance data, customer satisfaction measures, and documented procedures wherever the standard requires them. DNV's certification guidance emphasizes that certification depends on an effective quality management system, not just a documented one.
  • ISO 27001: Expect close scrutiny of your risk assessment methodology, the Statement of Applicability, and evidence that Annex A controls aren't just selected but actually operating, things like access reviews, incident logs, and vendor risk assessments.
  • ISO 14001: Auditors look at how you've identified environmental aspects, tracked compliance obligations, and implemented operational controls to manage them.

Preparing evidence specific to your standard, rather than generic compliance paperwork, is what separates a smooth Stage 2 audit from one full of findings.

What Happens After You Get Certified?

Certification isn't a one-time event. Registrars conduct surveillance audits, typically annually, to confirm your management system keeps operating as it did during the certification audit. These are lighter-touch than the initial audit but still sample key processes and follow up on any prior nonconformities.

Handling nonconformities well matters more than avoiding them entirely. Auditors expect a documented corrective action process: identify the root cause, fix it, and verify the fix worked. A pattern of unresolved or recurring nonconformities is a bigger red flag than a single well-managed one.

Full recertification happens roughly every three years, alongside the surveillance cycle. Organizations that treat the management system as a living part of operations, rather than something revived right before an audit, tend to sail through recertification. Those that let documentation go stale between audits often face a scramble that looks a lot like the original certification project.

Can You Use the ISO Logo, and Where Do You File a Complaint?

ISO develops standards, but it does not issue certificates and does not permit companies to use the ISO logo as proof of certification. Any marketing material claiming "ISO certified" should reference the specific standard number and the certification body that issued it, not an ISO logo.

To verify a company's certification claim, ask for a copy of the certificate, then confirm it independently:

  • Check the certificate's status directly with the certification body that issued it
  • Search IAF CertSearch to confirm the registrar's accreditation and the certificate's validity
  • Cross-check the registrar against its national accreditation body's public directory

If something looks wrong, a false claim, an expired certificate, or a registrar operating outside its accredited scope, the complaint path runs from the certification body first, up to the national accreditation body, and ultimately to the IAF if the issue isn't resolved.

Tools and Automation That Speed Up the Process

Gap analysis, evidence collection, and audit prep are document-heavy work, and the right tooling cuts real time off each phase, as explained in Why brands should use SaaS SEO: sustainable growth to improve operational efficiency. Document libraries with version control keep policies from drifting out of sync with practice. Automated checklists mapped to standard clauses catch missing evidence before an auditor does. For teams facing an increasing volume of customer security questionnaires alongside their certification work, questionnaire automation reduces the redundant effort of answering similar compliance questions repeatedly across sales cycles.

Some platforms approach this from the security questionnaire side specifically: integrating with multiple third-party risk management tools, supporting multilingual response generation, and centralizing evidence so compliance teams aren't hunting through old files every time a new questionnaire or audit request lands. For organizations juggling ISO preparation and a growing stack of customer due-diligence requests, tooling like this narrows the gap between "we have the evidence somewhere" and "here it is, ready to submit."

Tools and Automation That Speed Up the Process — overview diagram

The Real Bottleneck Isn't the Paperwork

Most guidance on ISO certification treats it as a documentation exercise: write enough policies, collect enough records, and the certificate follows, that's backwards. The organizations that struggle aren't the ones with thin paperwork. They're the ones where leadership treats the management system as a project instead of an operating discipline, so the system decays the moment the audit ends.

The Real Bottleneck Isn't the Paperwork — overview diagram

The step everyone underrates is the internal audit. It gets rushed because it doesn't feel like "real" progress, no registrar, no certificate, just an internal check. But a weak internal audit means every gap surfaces later, in front of an external auditor, at the worst possible time. Prioritize it like the external audit, because functionally, it is a rehearsal for one.

If you take one thing from this, verify accreditation before anything else. A certificate from an unaccredited body isn't a shortcut. It's a liability that surfaces the first time a serious customer or contract officer asks for proof, and by then the sunk cost is real money and real time.

— Gaspard

Sources