Last updated: February 23, 2026
You've been told you need ISO certification to win that contract. Or perhaps your operations director just landed it on your desk with a vague "sort this out" instruction. Either way, you're now responsible for navigating a process that probably feels more complicated than it needs to be.
Here's the truth: getting ISO certified isn't mysterious, but it does require proper preparation. You can't shortcut the process, but you can avoid wasting time on things that don't matter. Let's walk through exactly how to get ISO certified, what actually happens at each stage, and how long it really takes.
Key Takeaways
- ISO certification typically takes 4–9 months from start to finish, depending on your organisation's size and current systems
- You'll need to build a management system that meets the specific ISO standard's requirements before any auditor gets involved
- Certification involves two separate audits (Stage 1 and Stage 2) conducted by an accredited certification body
- You can implement ISO yourself or work with consultants—both routes work, but consultants significantly reduce the time and guesswork
- Costs vary widely based on organisation size, standard chosen, and whether you use external help (expect £3,000–£15,000+ for most SMEs)
- Certification isn't the finish line—you'll need surveillance audits every 12 months and full recertification every three years
- Different ISO standards suit different needs—ISO 9001 for quality, ISO 27001 for information security, ISO 14001 for environmental management
- Preparation matters more than the audit itself—auditors rarely fail properly prepared organisations
Quick Answer
Getting ISO certified requires building a management system that meets your chosen standard's requirements, then passing a two-stage audit from an accredited certification body. Most UK organisations complete the process in 4–9 months. You'll conduct a gap analysis, design and implement your system, run internal audits, then undergo external certification audits. Once certified, you'll maintain the standard through annual surveillance audits and recertify every three years. You can manage this internally or work with ISO consultancy services to accelerate the timeline and ensure first-time success.
What Does ISO Certification Actually Mean?
ISO certification proves your organisation operates a management system that meets internationally recognised standards. It's third-party verification—an independent auditor confirms you're doing what you say you're doing, and that what you're doing satisfies the standard's requirements.
Let's be clear about what certification isn't. It's not a one-time achievement you can forget about. It's not a guarantee that nothing ever goes wrong. And it's definitely not just paperwork (though there is paperwork involved).
Certification means:
- An accredited certification body has audited your management system
- You've demonstrated compliance with all mandatory requirements of the standard
- You've committed to ongoing improvement and regular audits
- You can legitimately use the ISO certification mark in tenders and marketing
The certificate itself lasts three years, but you'll face surveillance audits annually to keep it valid. Miss an audit or fail to address non-conformances, and you'll lose certification. Simple as that.
Which ISO Standard Do You Actually Need?
Before diving into how to get ISO certified, you need to know which standard matters for your situation. Choosing the wrong one wastes months and thousands of pounds.
ISO 9001 (Quality Management) suits organisations that need to prove consistent quality in products or services. It's the most common standard and often required for public sector contracts. If you're in manufacturing or construction, this is probably what you need.
ISO 27001 (Information Security) applies when you handle sensitive data—customer information, financial records, intellectual property. Technology companies and businesses processing personal data increasingly need this to win contracts and demonstrate GDPR compliance.
ISO 14001 (Environmental Management) proves you're managing environmental impacts systematically. Useful for organisations with significant environmental footprints or those tendering for contracts with sustainability requirements.
ISO 45001 (Health and Safety) demonstrates systematic management of workplace health and safety risks. Construction firms and high-risk industries often pursue this alongside ISO 9001.
ISO 13485 (Medical Devices) is mandatory for medical device manufacturers and essential for healthcare organisations involved in device production or distribution.
You can pursue multiple standards simultaneously through an integrated management system, which reduces duplication and audit time. But start with the standard that addresses your most pressing business need.
How to Get ISO Certified: The Complete Process Breakdown
The certification journey follows a fixed sequence. You can't skip stages, but you can move through them efficiently with proper planning.
Step 1: Conduct a Gap Analysis (2–4 Weeks)
Gap analysis identifies what you're already doing versus what the standard requires. This step determines how much work lies ahead and prevents nasty surprises later.
What happens during gap analysis:
- Review the standard's requirements clause by clause
- Document current processes, procedures, and controls
- Identify gaps between current state and standard requirements
- Estimate resources, timeline, and costs for implementation
- Create a project plan with clear milestones
You can conduct gap analysis internally if you understand the standard, but most organisations work with consultants at this stage. A professional gap analysis costs £1,500–£3,500 but saves months of trial and error.
Step 2: Design Your Management System (4–8 Weeks)
This is where you build the actual system—policies, procedures, work instructions, and records that demonstrate compliance.
Core components you'll create:
- Top-level policy (quality, information security, environmental—whatever fits your standard)
- Scope statement defining what's covered by certification
- Risk and opportunity register addressing potential issues
- Objectives and targets with measurable indicators
- Process documentation showing how work actually happens
- Operational controls ensuring consistent delivery
- Records and templates proving you're following procedures
The documentation doesn't need to be elaborate. Simple, practical documents that people actually use beat comprehensive manuals that gather dust. We've seen one-person businesses get certified with 15 pages of documentation and multinational firms with thousands of pages. Volume doesn't equal compliance.
Step 3: Implement and Embed the System (3–6 Months)
Implementation means putting your documented system into practice and proving it works. This takes the longest because you need evidence of consistent operation.
What implementation involves:
- Training staff on new procedures and their responsibilities
- Operating according to documented processes
- Collecting records that demonstrate compliance
- Monitoring performance against objectives
- Addressing issues as they arise
- Building a quality culture (not just compliance)
You'll need at least three months of operational evidence before certification audits. Auditors want proof the system works day-to-day, not just on paper. One month of perfect records followed by an audit won't cut it.
The 2026 revision of ISO 9001 will place even greater emphasis on leadership accountability, ethics, and quality culture, making genuine implementation more important than ever.
Step 4: Conduct Internal Audits (2–3 Weeks)
Before external auditors arrive, you need to audit your own system. This isn't optional—it's a requirement of every ISO standard.
Internal audit objectives:
- Verify the system operates as documented
- Identify non-conformances before external auditors do
- Check that procedures cover all standard requirements
- Confirm staff understand their responsibilities
- Gather evidence for continual improvement
Most organisations struggle with their first internal audit because they lack auditing experience. ISO training for internal auditors costs £500–£1,200 per person but dramatically improves audit quality. Alternatively, many consultancies offer internal auditing services to get you started properly.
Step 5: Management Review (1 Week)
Top management must review the system's performance before certification. This demonstrates leadership commitment—a core requirement of modern ISO standards.
Management review agenda:
- Internal audit findings and corrective actions
- Performance against objectives
- Customer feedback and complaints
- Risk and opportunity updates
- Resource adequacy
- Improvement opportunities
Document the review meeting and any decisions made. Auditors will ask to see evidence that leadership actively engages with the system.
Step 6: Stage 1 Certification Audit (1 Day)
Once you've completed implementation, internal audits, and management review, you're ready for external certification. This happens in two stages, starting with Stage 1—a readiness review.
The certification body examines:
- Scope definition and certification boundaries
- Policy statements and strategic objectives
- Risk assessment and legal compliance
- Documentation completeness
- Internal audit planning and execution
- Management review records
- Readiness for Stage 2 audit
Stage 1 is a document review, usually conducted at your premises. The auditor identifies any gaps that would prevent successful Stage 2 completion. You'll receive a report listing any issues to address before Stage 2.
Common Stage 1 findings:
- Incomplete documentation coverage
- Insufficient operational records
- Missing internal audits for certain areas
- Inadequate risk assessment
- Unclear scope boundaries
Address these before Stage 2. Most certification bodies require at least 28 days between Stage 1 and Stage 2 to allow for corrections.
Step 7: Stage 2 Certification Audit (1–3 Days)
Stage 2 is the full compliance audit. The auditor examines whether your system works in practice and meets every requirement of the standard.
What auditors assess:
- Implementation of documented procedures
- Staff competence and awareness
- Record accuracy and completeness
- Process effectiveness
- Compliance with legal requirements
- Evidence of continual improvement
- Actual practices versus documented processes
The auditor will interview staff, observe operations, and review records. They're checking that your system is real, not theatrical. If you've prepared properly, this shouldn't feel adversarial—it's a professional assessment, not an interrogation.
Possible outcomes:
- Certification recommended (minor observations noted but no formal non-conformances)
- Certification pending (minor non-conformances requiring correction within 90 days)
- Certification deferred (major non-conformances requiring significant remediation and re-audit)
Most properly prepared organisations pass with minor observations. Major failures typically happen when companies rush the process or fake implementation.
Step 8: Certification Decision and Issue (2–4 Weeks)
After Stage 2, the certification body's technical committee reviews the audit report and makes the certification decision. Assuming approval, you'll receive your certificate and can start using the certification mark.
Your certificate specifies:
- The ISO standard and version
- Your organisation's name and address
- The scope of certification
- Certificate number and issue date
- Expiry date (three years from issue)
You're now certified. But the work doesn't stop.
What Happens After You Get ISO Certified?
Certification requires ongoing maintenance. You can't achieve it then ignore it—the certification body monitors your continued compliance through surveillance audits.
Annual surveillance audits occur approximately 12 months after certification, then again at 24 months. These are shorter than the initial Stage 2 audit (typically 0.5–1 day) but cover a sample of your system to confirm ongoing compliance.
Recertification happens every three years. This is effectively a full re-audit similar to the original Stage 2, confirming your system still meets requirements and has improved over time.
Many organisations use ISO maintenance and retainer services to ensure they're always audit-ready without dedicating internal resources to constant monitoring.
How Long Does ISO Certification Actually Take?
Realistically, expect 4–9 months from project start to certificate in hand. Here's how that breaks down:
| Phase | Duration | Notes |
|---|---|---|
| Gap analysis | 2–4 weeks | Faster with consultant support |
| System design | 4–8 weeks | Depends on complexity and existing documentation |
| Implementation | 3–6 months | Requires operational evidence; can't be rushed |
| Internal audits | 2–3 weeks | Includes corrective actions |
| Certification audits | 1–2 months | Scheduling dependent on auditor availability |
Factors that extend timelines:
- Multiple sites requiring coordination
- Complex operations with numerous processes
- Limited internal resources
- Seasonal businesses needing to demonstrate year-round operation
- Integrated management systems covering multiple standards
Factors that accelerate timelines:
- Existing quality systems (even informal ones)
- Dedicated project management
- Consultant support for ISO implementation
- Management commitment and resource allocation
- Simple, focused scope
The fastest we've seen is three months for a small, well-organised business with strong existing processes. The longest was 18 months for a multinational with 12 sites and complex operations. Most UK SMEs land somewhere between five and seven months.
Should You Use an ISO Consultant or Do It Yourself?
You can absolutely achieve certification without consultants. The standards are publicly available, and nothing prevents self-implementation. But here's what you're taking on:
DIY certification requires:
- Time to learn the standard's requirements thoroughly
- Expertise in management system design
- Internal auditing skills
- Project management capability
- Staff buy-in and training delivery
- Confidence navigating certification body requirements
Benefits of DIY:
- Lower direct costs (no consultant fees)
- Deeper internal knowledge development
- Greater ownership of the system
Drawbacks of DIY:
- Significantly longer timelines (often 12+ months)
- Higher risk of audit failure
- Potential for over-documentation
- Opportunity cost of internal resources
- Steeper learning curve
Consultant-supported certification provides:
- Faster timelines (typically 4–6 months)
- Expert guidance on requirements interpretation
- Templates and documentation frameworks
- Internal auditor training
- Mock audits before the real thing
- Higher first-time pass rates
Cost-wise, consultancy for ISO 9001 typically runs £4,000–£12,000 for SMEs, depending on size and complexity. That sounds significant until you calculate the internal time cost of DIY—hundreds of hours from people who could be doing their actual jobs.
Most organisations we work with choose consultant support for initial certification, then manage surveillance audits internally once they understand the system. That's a sensible middle ground.
How Much Does ISO Certification Cost?
Certification costs vary based on organisation size, standard complexity, and support level. Here's realistic budgeting for UK SMEs:
Certification body fees:
- Stage 1 and Stage 2 audits: £2,000–£6,000
- Annual surveillance audits: £800–£2,500 each
- Recertification (every 3 years): £2,000–£6,000
Consultancy fees (if used):
- Gap analysis: £1,500–£3,500
- Full implementation support: £4,000–£12,000
- Internal auditor training: £500–£1,200 per person
Internal costs:
- Staff time for implementation (100–300 hours)
- Documentation development
- Training delivery
- Process changes and improvements
Total first-year investment for a typical SME pursuing ISO 9001 with consultant support: £8,000–£20,000. Without consultants but including internal time costs: £5,000–£12,000.
Ongoing annual costs (surveillance audits plus maintenance): £1,500–£4,000.
That's not pocket change, but compare it to the contract value you'll unlock. One public sector tender win often justifies years of certification costs.
Common Mistakes When Pursuing ISO Certification
We've seen hundreds of organisations pursue certification. Here are the mistakes that waste time and money:
Treating it as a paperwork exercise. Documentation matters, but the system must work in practice. Auditors spot theatrical compliance immediately.
Choosing the wrong certification body. Cheapest isn't best. Select a UKAS-accredited body with sector experience. Their reputation affects how your certification is perceived.
Over-documenting everything. More pages don't equal better compliance. Simple, usable documents beat comprehensive manuals nobody reads.
Rushing implementation. You need operational evidence. Three months minimum, realistically longer. Trying to certify after six weeks of operation fails.
Ignoring staff engagement. If your team doesn't understand or support the system, it won't work. Training and communication matter more than perfect procedures.
Assuming certification means perfection. ISO standards require continual improvement, not flawless operation. Having a non-conformance isn't failure—not addressing it is.
Letting it drift after certification. Surveillance audits aren't formalities. Maintain the system actively or risk losing certification.
What About ISO 9001:2026?
The next revision of ISO 9001 is coming. The Draft International Standard was released in August 2025, with the Final Draft expected January 2026 and official publication scheduled for September 2026.
Key changes in ISO 9001:2026:
- Greater emphasis on leadership accountability and ethics
- Enhanced integration of sustainability and ESG considerations
- Stronger focus on supply-chain resilience and risk-based thinking
- Recognition of digital transformation and QMS automation
What this means for you:
If you're currently pursuing ISO 9001:2015 certification, continue. You'll have a three-year transition period from September 2026 to September 2029 to migrate to the new version. Both versions will be valid during this window.
If you're not yet certified, you can still pursue ISO 9001:2015 throughout 2026 and early 2027. Certification bodies will undergo training between September 2026 and August 2027, with limited ISO 9001:2026 certificates issued during this period.
The transition won't be dramatic—ISO revisions build on existing frameworks rather than replacing them. But plan for some system updates during the transition window.
Frequently Asked Questions
How long does ISO certification last?
ISO certificates are valid for three years from the issue date. You'll undergo annual surveillance audits at approximately 12 and 24 months to maintain certification, then a full recertification audit at 36 months. Miss a surveillance audit or fail to address non-conformances, and you'll lose certification before the three-year mark.
Can you get ISO certified without a consultant?
Yes, absolutely. The standards are publicly available, and nothing requires consultant involvement. However, self-implementation typically takes 50–100% longer and carries higher audit failure risk. Most organisations use consultants for initial certification, then manage ongoing compliance internally once they understand the system.
What's the difference between ISO accreditation and certification?
You get certified; certification bodies get accredited. ISO certification means your organisation meets the standard's requirements. Accreditation (usually by UKAS in the UK) means the certification body is competent to assess and certify organisations. Always choose a UKAS-accredited certification body—non-accredited certificates aren't recognised for most tenders.
How much does ISO 9001 certification cost for a small business?
For a UK small business (under 25 employees), expect £8,000–£15,000 for first-year costs including certification body fees and consultant support. Without consultants, direct costs drop to £3,000–£6,000, but internal time costs add significantly. Annual maintenance (surveillance audits) costs £1,500–£3,000.
Do you need ISO certification to tender for government contracts?
Not always, but increasingly often. Many public sector tenders require ISO 9001 as a minimum qualification criterion. Some specify additional standards like ISO 14001 or ISO 27001 depending on the contract nature. Check tender requirements carefully—pursuing certification for a specific opportunity makes sense; doing it "just in case" might not.
What happens if you fail an ISO audit?
Minor non-conformances can be corrected within 90 days without losing certification. Major non-conformances require significant remediation and often a re-audit of affected areas. If you fail to address findings within the specified timeframe, certification is withdrawn. Properly prepared organisations rarely fail outright—most issues are minor and correctable.
Can you lose ISO certification once you have it?
Yes. You'll lose certification if you miss surveillance audits, fail to address non-conformances, or demonstrate the system has collapsed. Certification bodies can also suspend or withdraw certificates if they discover fraud or misrepresentation. Maintaining certification requires ongoing effort—it's not a one-time achievement.
How often do you need to be audited after certification?
Annually. Surveillance audits occur approximately 12 months after initial certification, then again at 24 months. At 36 months, you undergo full recertification (similar to the original Stage 2 audit). This cycle continues as long as you maintain certification. Some integrated management systems allow combined audits, reducing the total audit days.
Is ISO certification worth the cost?
That depends entirely on your business needs. If certification unlocks tender opportunities worth £50,000+, it's obviously worthwhile. If you're pursuing it because "everyone else has it" without clear ROI, question the investment. Certification adds genuine value for quality improvement, customer confidence, and market access—but only if you need those benefits.
Can you get multiple ISO certifications at once?
Yes, through an integrated management system. ISO 9001, ISO 14001, ISO 45001, and ISO 27001 share common structure (Annex SL), making integration practical. You'll build one management system addressing all standards' requirements, with a single set of audits covering everything. This reduces duplication and audit time compared to pursuing standards separately.
What's the easiest ISO standard to get certified in?
"Easiest" is the wrong question—choose the standard that addresses your business needs. ISO 9001 is the most common and has the most available support, making it accessible. ISO 14001 can be simpler for organisations with limited environmental impacts. ISO 27001 is more complex due to information security requirements. Match the standard to your situation, not perceived difficulty.
Do ISO requirements differ by industry?
The core ISO standards (9001, 14001, 45001, 27001) apply across all industries with the same requirements. However, how you implement them varies significantly by sector. Manufacturing quality management looks different from professional services. Some industries have sector-specific standards (ISO 13485 for medical devices, ISO 22000 for food safety) that add industry requirements to the base framework.
Conclusion: Your Next Steps to ISO Certification
Getting ISO certified isn't complicated, but it does require methodical preparation and genuine commitment. You'll invest 4–9 months and £8,000–£20,000 (for most SMEs), but you'll gain third-party verification that opens doors to contracts and customers that demand certified suppliers.
Here's what to do next:
Identify which ISO standard addresses your business needs—quality, information security, environmental management, or health and safety. Don't pursue certification just because competitors have it; choose the standard that solves a real problem or unlocks specific opportunities.
Conduct a gap analysis to understand your starting point and required investment. You can do this internally or work with consultants for faster, more accurate assessment.
Decide on your implementation approach—DIY for deeper internal knowledge and lower direct costs, or consultant-supported for faster timelines and higher success rates. Most organisations find the middle ground: consultant guidance for initial certification, internal management thereafter.
Build a realistic project plan with clear milestones, resource allocation, and management commitment. Half-hearted efforts waste money and rarely succeed.
Choose a UKAS-accredited certification body with sector experience and reasonable fees. Their reputation affects how your certification is perceived.
Plan for ongoing maintenance, not just initial certification. Budget for annual surveillance audits and allocate resources to keep the system functioning.
ISO certification works when you treat it as a genuine management tool rather than a compliance burden. The organisations that benefit most are those that embed the system into daily operations and use it to drive actual improvement.
Ready to start your certification journey? Contact ISO Adviser for a straightforward conversation about your situation, realistic timelines, and honest costs. No sales pressure, no corporate nonsense—just practical guidance from consultants who've done this hundreds of times.
