ISO 9001 Certification Process: A Step-by-Step Guide

The ISO 9001 certification process is the structured sequence an organization follows to build a quality management system (QMS), have it independently audited in two stages, and earn certification against the ISO 9001:2015 standard. In practice it moves from defining your scope, through a gap analysis and implementation of the QMS, to a two-part external audit and a favorable certification decision — after which annual surveillance keeps the certificate valid for a three-year cycle. This guide walks through every step so you know exactly what to prepare, who does what, and how long it typically takes.

ISO 9001 is the world’s most widely used quality management standard, and certification is awarded to organizations, not individuals. It signals to customers, regulators, and partners that your business consistently meets requirements and works to improve. Below is the full path from decision to certificate, which follows the same overall ISO certification process used for other management system standards.

The ISO 9001 Certification Process Steps

The certification journey has two broad phases: preparation (everything you do internally to get ready) and certification (the independent audit and decision carried out by a certification body). Here is the process as a numbered sequence.

  1. Define the scope and confirm the standard. Decide which sites, products, services, and processes the QMS will cover, and confirm ISO 9001:2015 is the correct standard for your quality objectives.
  2. Conduct a gap analysis. Compare your current operations against the requirements of ISO 9001 to identify what already conforms and what is missing.
  3. Build and document the QMS. Create the policies, procedures, and records the standard expects — quality policy, objectives, process maps, and controls.
  4. Train your team. Make sure employees understand the QMS, their roles in it, and how to maintain records, using structured ISO training where it helps.
  5. Implement the system. Run the QMS in day-to-day operations so that real evidence of conformity accumulates.
  6. Perform an internal audit and management review. Check the QMS yourself, correct any nonconformities, and have leadership review performance.
  7. Undergo the Stage 1 audit (documentation review). The certification body confirms your documentation and readiness for the main audit.
  8. Undergo the Stage 2 audit (on-site implementation). Auditors verify that the QMS is genuinely operating and effective.
  9. Receive the certification decision. After any nonconformities are closed, the certification body issues the ISO 9001 certificate.
  10. Complete annual surveillance audits. In years one and two, surveillance audits confirm the QMS is being maintained.
  11. Recertify after three years. A full recertification audit renews the certificate for another three-year cycle.

The sections below explain each phase in more detail.

Pre-Audit Stage: Preparing Your QMS

The pre-audit stage is where most of the work happens. A well-prepared organization moves through the external audits smoothly, so it pays to be thorough here. For the full list of clauses you need to satisfy, see the ISO 9001 requirements blog.

Gap Analysis

A gap analysis is a review of your existing processes against every applicable requirement of ISO 9001:2015. It highlights where you already conform and where action is needed — for example, missing documented information, unclear responsibilities, or processes without measurable objectives. The output is essentially a to-do list that shapes the rest of your project.

Documentation

ISO 9001 requires certain “documented information.” At minimum this includes your quality policy, quality objectives, the scope of the QMS, and records that demonstrate your processes are working. Documentation should reflect how your organization actually operates rather than being copied from a template, because auditors will look for evidence that it matches practice. Maintaining documented information is one of the ISO certification requirements shared across all management system standards.

Training

Employees need to understand the QMS and their part in it. Training builds awareness of the quality policy, competence for specific roles, and confidence in maintaining records. Some organizations also develop in-house audit capability through ISO 9001 internal auditor training, which prepares staff to run the internal audits the standard requires. Employees who go on to lead audit teams can build on that with ISO 9001 lead auditor training.

Provide Resources

Clause 7 of ISO 9001 addresses resources — people, infrastructure, work environment, monitoring equipment, and organizational knowledge. Leadership must make sure the QMS has what it needs to function. Assigning clear ownership and allocating time and budget early prevents delays later in the process, and organizations without in-house expertise sometimes bring in ISO certification consultants to supplement internal resources.

Implementation

With documentation in place and people trained, you run the QMS in live operations. This is a critical period: the external auditors will want to see records generated over time, so the system should be operating for long enough to produce genuine evidence of conformity and improvement before you book the certification audit.

Internal Audit

An internal audit is your own check of the QMS against ISO 9001 and against your documented procedures. It uncovers nonconformities so you can correct them before the certification body arrives. Internal audit findings, together with a management review by leadership, demonstrate that the QMS is being actively monitored — a requirement of the standard in its own right.

Auditing

Once internal audits are closed out and management review is complete, your organization is ready for the external certification audit. Choosing among accredited ISO certification bodies at this point matters, because accreditation is what gives your certificate international recognition — a topic covered in the ISO 9001 accreditation blog.

Stage 1 and Stage 2: The External Audit

The heart of the ISO 9001 certification process is a two-stage external audit conducted by an independent certification body such as IAS. The general approach follows the standard ISO audit procedure used across ISO management system standards.

Stage 1 Audit — Documentation Review

In Stage 1, the auditor reviews your QMS documentation, confirms the scope, and evaluates whether you are ready for the main audit. The auditor may identify areas of concern that you resolve before Stage 2. Think of Stage 1 as a readiness check that prevents surprises during the on-site assessment.

Stage 2 Audit — On-Site Implementation

Stage 2 is the main event. Auditors visit your site (or assess remotely where permitted) to verify that the QMS is fully implemented and effective. They interview staff, examine records, and observe processes to confirm conformity with ISO 9001. Any nonconformities are documented, and you are given the opportunity to correct them.

Certification Decision by the Certification Body

After Stage 2, the certification body reviews the audit evidence independently of the auditors who performed the assessment. If all major nonconformities have been resolved and the QMS conforms to ISO 9001, the body issues the certificate. This certificate is valid for three years, subject to ongoing surveillance. If nonconformities remain open, you address them and provide evidence before the decision is finalized.

Surveillance Audit

Certification is not a one-time event. During the three-year validity period, the certification body conducts annual surveillance audits — typically in years one and two — to confirm that your organization continues to maintain and improve the QMS. Surveillance audits are usually narrower in scope than the full certification audit but still sample key processes and follow up on previous findings. Maintaining good records between audits makes each surveillance visit straightforward.

Recertification Audit

At the end of the three-year cycle, a recertification audit renews your certificate for another three years. It is broader than a surveillance audit and reassesses the entire QMS, much like the original Stage 2 assessment. Planning your recertification well ahead of the expiry date avoids any gap in your certified status.

Duration of the ISO 9001 Certification Process

There is no fixed timeline, because it depends on the size and complexity of your organization and how mature your existing processes are. Many organizations complete the journey in roughly three to six months when they dedicate resources to it, though a small business with simple processes may move faster and a large multi-site operation may need longer. The biggest variables are how much documentation must be created and how long the QMS runs before the certification audit.

Cost of the ISO 9001 Certification Process

Costs vary with organization size, number of sites, the complexity of your processes, and whether you use consulting support. Typical cost drivers include internal preparation time, any training or consultancy you engage, and the certification body’s audit fees for Stage 1, Stage 2, surveillance, and recertification. For a fuller breakdown of what influences the total, see the ISO certification cost blog. IAS provides ISO 9001 certification for organizations across the USA and can outline the specific requirements for your business — contact us for details.

Note: ISO 9001:2026 is scheduled to publish on 16 September 2026 with a three-year transition period; see our ISO 9001:2026 revision guide for what will change, though the certification process itself remains broadly the same.

Frequently Asked Questions

What are the main stages of the ISO 9001 certification process?
The process runs from defining your scope and conducting a gap analysis, to building and implementing the QMS, running an internal audit and management review, and then passing a two-stage external audit (Stage 1 documentation review and Stage 2 on-site assessment). A favorable certification decision follows, with annual surveillance audits and recertification every three years.
How long does it take to get ISO 9001 certified?
Most organizations take about three to six months, depending on their size, the complexity of their processes, and how much documentation needs to be developed. Organizations with mature quality processes already in place can move more quickly.
Is ISO 9001 certified to a person or an organization?
ISO 9001 certification is awarded to organizations, not individuals. Individuals can, however, earn recognized qualifications through ISO 9001 lead auditor training if they want to audit quality management systems.
What is the difference between Stage 1 and Stage 2 audits?
Stage 1 is a documentation review that checks whether your QMS is designed correctly and whether you are ready for the main audit. Stage 2 is an on-site assessment that verifies the QMS is actually implemented and effective through interviews, records, and process observation.
Why should certification be done by an accredited certification body?
An accredited certification body works under the oversight of a recognized accreditation authority, which gives your certificate credibility and international recognition. IAS is a certification body offering ISO 9001 certification and a wide range of other ISO certification services. Independent bodies such as EAS operate under similar accreditation principles.
What happens after I receive my ISO 9001 certificate?
Your certificate is valid for three years. During that period the certification body conducts annual surveillance audits to confirm you are maintaining the QMS, and a recertification audit at the end of the cycle renews the certificate for a further three years.