How to Get ISO Certification: A Practical Roadmap for Your Business

To get ISO certification, an organization implements a management system that meets the chosen ISO standard, then passes an audit conducted by an accredited certification body that issues the certificate. ISO certification is awarded to organizations—not individuals—so your goal is to prepare your business, close any gaps against the standard’s requirements, and demonstrate conformity to an independent auditor. This guide walks you through the practical decisions and actions involved, from picking the right standard to choosing a credible certification body and avoiding the pitfalls that slow companies down.

If you want the fine-grained mechanics of the audit itself—Stage 1, Stage 2, and surveillance—see our companion guide on the ISO certification process. This page focuses on the decisions and preparation that get you ready for that audit.

Step 1: Choose the Right ISO Standard

The first practical decision is which ISO standard fits your business. There is no single “ISO certificate.” Each standard addresses a different management discipline, and the right choice depends on your industry, your customers’ expectations, and the risks you most need to control. The most widely adopted standards include:

  • ISO 9001 — Quality management, relevant to almost any organization that wants consistent, customer-focused processes.
  • ISO 14001 — Environmental management, for reducing environmental impact and meeting compliance obligations.
  • ISO 27001 — Information security management, increasingly required by clients handling sensitive or regulated data.
  • ISO 45001 — Occupational health and safety management, for workplaces that want to reduce injury and illness risk.
  • ISO 22000 — Food safety management, for organizations in the food supply chain.
  • ISO 13485 — Medical devices quality management, for manufacturers and suppliers in the medical sector.

Ask three questions: Do our customers or contracts require a specific certification? Which risks—quality, security, safety, environmental—matter most to our operations? And do we plan to integrate more than one standard over time? Many businesses begin with ISO 9001 because its quality framework underpins the others and is the most commonly requested in tenders. If you are unsure, our team can help you map your objectives to the right standard through the ISO certification hub.

Step 2: Prepare Your Organization

Once you have chosen a standard, the bulk of the work is internal preparation. This is where certification is truly won or lost—an auditor can only confirm what you have actually built.

Run a gap analysis

Start by comparing your current practices against the requirements of your chosen standard. A gap analysis identifies where you already conform, where documentation is missing, and where processes need to change. It gives you a realistic scope of work before you commit resources, and a clear breakdown of what your chosen standard expects so nothing is overlooked.

Build and document your management system

Using the gap analysis, develop the policies, procedures, and records the standard calls for. Modern ISO standards are less about heavy paperwork and more about demonstrating that your processes are defined, followed, and improved. Assign clear ownership, define your scope, and make sure top management is visibly committed—leadership involvement is a requirement in every current management-system standard.

Implement and train your team

Documentation only counts if people follow it. Roll out the system across the relevant departments, train employees on their responsibilities, and let the system run long enough to generate real records. Investing in formal ISO training for internal auditors and process owners pays off here, because your own people become able to maintain and improve the system.

Conduct an internal audit and management review

Before you invite an external auditor, audit yourself. An internal audit checks that your system works in practice and surfaces nonconformities while you still have time to fix them. Follow it with a management review, where leadership evaluates performance and confirms the system is ready. A well-run internal audit is the best rehearsal for the external one.

Step 3: Choose an Accredited Certification Body

This is one of the most important—and most overlooked—decisions. Certification should be issued by a competent certification body operating within an applicable accreditation scope. Integrated Assessment Services (IAS) maintains UQAS accreditation for applicable certification schemes. Where a JAS-ANZ-accredited certification route is required, IAS can support that route through its group company Empowering Assurance Systems (EAS), which holds JAS-ANZ accreditation. This distinction helps customers understand exactly which organization provides the accredited certification service.

When evaluating certification bodies, check that they are genuinely accredited for your specific standard, that they have experience in your sector, and that their auditors are qualified. Confirm the scope on their accreditation record rather than taking a logo at face value. Our guide to ISO certification bodies explains how to verify accreditation and what to compare between providers.

IAS is a global certification and inspection body. For clients who also need related conformity services, our partner organization EAS extends the group’s reach across additional markets.

Step 4: The Audit—In Brief

With an accredited body selected, certification is confirmed through a two-stage external audit followed by ongoing surveillance:

  1. Stage 1 (readiness review) — The auditor reviews your documentation and confirms your system is designed to meet the standard.
  2. Stage 2 (certification audit) — The auditor evaluates your system in operation, gathering evidence that it is implemented and effective.
  3. Certification decision — If any nonconformities are found, you address them; the body then issues your certificate, typically valid for three years.
  4. Surveillance audits — Periodic checks confirm you continue to conform and improve.

We keep this section deliberately short because the mechanics are covered in depth on our certification process page. Read that for exactly what auditors look for at each stage.

How Long Does It Take to Get ISO Certified?

There is no fixed timeline, and any honest answer depends on your size, complexity, and starting point. As a realistic guide:

  • Small organizations with straightforward processes and few sites often reach certification in a matter of a few months.
  • Mid-sized and larger organizations, or those building a system from scratch, commonly need longer to document, implement, and generate enough records before the Stage 2 audit.

The single biggest variable is how mature your processes already are. A company that documents its work well will move faster than one starting with nothing. Rushing rarely helps—your system needs to run long enough to produce genuine evidence of conformity. Costs vary just as widely; for the factors that drive them, see our overview of ISO certification cost.

Common Pitfalls to Avoid

Businesses that stumble on the path to certification usually make the same avoidable mistakes:

  • Choosing an unaccredited certification body to save money, then finding the certificate is not accepted where it matters.
  • Treating documentation as the goal instead of building processes people actually follow.
  • Weak leadership involvement, which every modern standard flags as a nonconformity.
  • Copy-pasted generic manuals that do not reflect how the business really operates.
  • Skipping the internal audit, so the external auditor finds problems you could have fixed first.
  • Underestimating time, then compressing implementation to the point where records are thin.

Avoiding these keeps your certification credible and your audit smooth.

How IAS Helps

IAS supports organizations at every stage of the journey. Through our ISO certification services we assess your management system against the standard and, where requirements are met, issue accredited certification your customers can trust. We also offer ISO training courses—from awareness to lead auditor—so your team can build and sustain the system internally.

Ready to get started or want advice on the right standard for your business? Contact us and our specialists will help you plan a realistic path to certification.

Frequently Asked Questions

Is ISO certification given to a company or an individual?
ISO certification is granted to organizations. A certification body audits your management system and issues the certificate to the business. Individuals do not become “ISO certified”—instead, they earn training certificates by completing accredited ISO courses, such as internal or lead auditor training.
Which ISO standard should my business start with?
It depends on your goals and what your customers require. Many organizations begin with ISO 9001 for quality management because it is the most widely requested and forms a foundation for other standards. If information security, safety, environmental performance, or food safety is your priority, choose the standard that targets that risk directly.
Do I really need an accredited certification body?
For a certificate that is recognized internationally and accepted in tenders, yes. Accreditation confirms the certification body is competent and impartial. An unaccredited certificate may look similar but is often rejected by customers, regulators, and procurement teams, so it rarely delivers the value you are paying for.
Can we prepare for ISO certification without a consultant?
Yes. Many organizations implement their system in-house, especially after training their staff as internal auditors. A gap analysis, clear documentation, employee training, and an internal audit are all achievable internally. External support can speed things up, but it is not a requirement for certification.
What documents do we need before the audit?
At a minimum you need your defined scope, the policies and procedures your standard requires, and records that show the system is actually operating—internal audit results, management review outputs, and evidence of your day-to-day processes. Our ISO certification requirements guide breaks this down by standard.
How do we maintain certification after we pass?
Certification is typically valid for three years, subject to periodic surveillance audits that confirm you continue to conform and improve. Keep your records current, act on nonconformities, run internal audits, and hold regular management reviews so each surveillance visit is straightforward.