How to Get ISO 9001 Certified: A Step-by-Step Guide for Businesses

To get ISO 9001 certified, your organization builds a quality management system (QMS) that meets the ISO 9001:2015 requirements, proves it works through internal audits and a management review, and then passes a two-stage certification audit conducted by an accredited certification body. That is the short answer. The rest of this guide turns it into a practical roadmap you can actually follow, from your first planning meeting to holding the certificate.

ISO 9001 is the world’s most widely used quality management standard, and certification is awarded to organizations, not to individuals. The goal of this page is simple: give a business owner or quality manager a clear, ordered plan for becoming certified. For the fine detail of audit stages, see our ISO 9001 Certification Process guide, and for the exact clauses your system must satisfy, see ISO 9001 Requirements. Here we stay focused on the how-to.

Step 1: Understand the ISO 9001 Standard and Set Your Scope

Before you change anything, know what you are aiming at. ISO 9001:2015 is built around a process approach, risk-based thinking, and the Plan-Do-Check-Act cycle. Read the standard (or have your project lead do so) and decide the scope of certification: which sites, products, services, and processes will be covered. A tightly defined scope keeps the project manageable; an inflated one adds cost and complexity.

At this stage, also assign ownership. Appoint a project lead or QMS coordinator and secure visible commitment from top management, because leadership involvement is a requirement of the standard, not an optional extra.

Step 2: Run a Gap Analysis

A gap analysis compares what you already do against what ISO 9001 requires. Most organizations are surprised to find they already meet many requirements informally; the gap analysis simply exposes what is missing, undocumented, or inconsistent.

Work clause by clause and record, for each requirement, whether you fully meet it, partly meet it, or do not meet it at all. The output is a prioritized action list that becomes your implementation plan. Skipping this step is the single most common reason projects run over time and budget, so treat it as essential rather than optional.

Step 3: Build and Document Your QMS

Now you close the gaps. Design the processes, controls, and records the standard expects, and document them at a level that fits your organization. ISO 9001:2015 is deliberately flexible about documentation, so avoid the trap of writing a huge manual nobody reads. Focus on what genuinely controls quality:

  • A quality policy and measurable quality objectives
  • Documented information for the processes you defined in scope
  • Records that demonstrate results (for example, inspection records, corrective actions, supplier evaluations)
  • Clear responsibilities so everyone knows who owns each process

Keep the documentation practical and usable by the people doing the work. Good documentation reflects how you actually operate; it should not be a fictional version of your business written only to please an auditor.

Step 4: Implement the QMS and Train Your People

A documented system delivers nothing until people use it. Roll the new or revised processes out across the business, communicate why they matter, and train staff on the parts that affect their roles. Give the system enough time to generate real records; auditors will want to see evidence that your QMS has been operating, not just that it exists on paper.

This is also the right moment to build internal audit capability. Having trained auditors in-house makes your system stronger and your certification audit smoother. Most organizations start by putting the people who will run those audits through ISO 9001 internal auditor training. IAS offers ISO 9001 Lead Auditor Training for teams that want that competence internally.

Step 5: Conduct an Internal Audit and Management Review

Before an external auditor ever visits, you must audit yourself. An internal audit checks your QMS against the standard and against your own procedures, surfacing nonconformities while you still have time to fix them. Log every finding, complete the corrective actions, and verify they worked.

Follow this with a management review, where top management evaluates the system’s performance, resources, objectives, and opportunities for improvement. Both the internal audit and the management review are requirements of ISO 9001, and a certification body will expect to see evidence that both took place before your certification audit.

Step 6: Choose an Accredited Certification Body

You do not certify yourself, and you should select a certification body whose accreditation scope covers the certification you need. Integrated Assessment Services (IAS) maintains UQAS accreditation for applicable management-system certification schemes. Where a JAS-ANZ-accredited route is required, IAS supports certification through its group company Empowering Assurance Systems (EAS), which holds JAS-ANZ accreditation. Always verify the applicable accreditation scope and the organization named on the certificate.

When comparing bodies, look at their accreditation status, sector experience, auditor availability, and clarity of process rather than price alone. IAS provides accredited ISO 9001 certification and works alongside our partner EAS, giving organizations access to internationally recognized certification.

Step 7: Pass the Certification Audit

The certification audit is conducted in two stages: a Stage 1 readiness review of your documentation and system design, followed by a Stage 2 audit of how the QMS operates in practice. If nonconformities are raised, you address them, and once the auditor is satisfied, the certification decision is made and your certificate is issued.

We keep the mechanics brief here on purpose. For a full walkthrough of what happens in each stage and how findings are handled, read our dedicated ISO 9001 Certification Process guide.

Step 8: Maintain and Improve Your Certification

Certification is not a one-time event. ISO 9001 certificates are typically valid for three years, subject to annual surveillance audits that confirm your QMS is still working. At the end of the cycle, a recertification audit renews it for another term.

The organizations that get the most value treat the standard as a continual-improvement tool, using audit findings, customer feedback, and objectives to keep raising performance. To understand the payoff, our ISO 9001 Benefits article sets out what certified businesses typically gain.

How Long Does It Take to Get ISO 9001 Certified?

There is no single answer, because timing depends on your size, complexity, and how mature your existing processes already are. A small organization with reasonably good practices already in place can move relatively quickly, while a larger business building a QMS from scratch will need longer to implement processes and generate enough records for a meaningful audit.

The two factors most within your control are the speed of your documentation and implementation, and how promptly you respond to audit findings. Organizations that resource the project properly and keep momentum move through it far faster than those that treat it as a side task.

What Does ISO 9001 Certification Cost?

Cost varies with the size of your organization, the number of sites, the complexity of your operations, and the certification body you select. Rather than quote figures that would not apply to your situation, we explain the drivers in detail in our ISO Certification Cost guide, so you can budget realistically. For a quote tailored to your scope, it is always best to speak with a certification body directly.

Common Pitfalls to Avoid

  • Skipping the gap analysis and discovering problems only during the audit, when they are more expensive to fix.
  • Over-documenting. A bloated manual that nobody follows is worse than a lean system that people actually use.
  • Weak leadership involvement. ISO 9001 requires genuine top-management commitment, and auditors can tell when it is missing.
  • Auditing too early. Book the certification audit before your QMS has produced real records and you will struggle to demonstrate it works.
  • Choosing a non-accredited certificate to save money, then finding customers or tenders do not recognize it.

A Quick Note on ISO 9001:2026

A revised version of the standard, ISO 9001:2026, is scheduled to publish on 16 September 2026, with an expected three-year transition period. That means certificates issued to the current ISO 9001:2015 remain valid until roughly 2029, so you should certify to ISO 9001:2015 now rather than wait. When the new version arrives, transitioning is straightforward. Our ISO 9001:2026 Revision Guide covers what is changing and how to prepare.

How IAS Helps You Get Certified

IAS is a US-based certification and training body offering accredited ISO 9001 certification to organizations of every size. We keep the process clear, guide you through each step of the certification process, and support your team with recognized lead auditor training when you want internal audit capability. When you are ready to begin, contact us and we will help you plan a route to certification that fits your business.

Frequently Asked Questions

Do I need a consultant to get ISO 9001 certified?
No, a consultant is not required. Many organizations build their QMS with their own team, especially with trained internal auditors. A consultant can speed things up if you lack the time or in-house knowledge, but a certification body must remain independent and cannot both consult on and certify the same system.
Can a small business get ISO 9001 certified?
Yes. ISO 9001 is designed to scale, and small businesses are certified every day. Because the standard is flexible about documentation, a smaller organization can build a lean QMS that fits how it actually operates, often reaching certification faster than a large, complex company.
Is ISO 9001 certification awarded to a person or a company?
It is awarded to an organization, not an individual. Your company’s quality management system is what gets certified. Individuals earn related credentials separately through courses such as ISO 9001 Lead Auditor Training, which builds auditing competence but is not the same as company certification.
Why does accredited certification matter?
An accredited certificate is issued by a certification body operating within a defined accreditation scope. For IAS certification services, the applicable UQAS accreditation scope should be checked against the standard and certification scheme required. For certification delivered through EAS, the applicable JAS-ANZ accreditation scope should likewise be confirmed. This makes the accreditation claim precise rather than relying on a generic statement about accreditation.
What do I need to have ready before the certification audit?
At a minimum, an implemented QMS that has been running long enough to produce records, a completed internal audit with corrective actions closed, and a documented management review. Auditors need evidence that your system operates in practice, not just that the paperwork exists.
Should I certify to ISO 9001:2015 now or wait for ISO 9001:2026?
Certify to ISO 9001:2015 now. Certificates issued against the current version stay valid through the transition period, expected to run to around 2029, so there is no benefit in delaying. You can transition smoothly once the new version publishes; see our revision guide for details.