ISO Certification Process: A Step-by-Step Guide

The ISO certification process follows a defined sequence: application, an optional gap analysis, documentation, a Stage 1 audit, a Stage 2 audit, the certification decision, and ongoing surveillance audits. For most organizations, the journey from first inquiry to holding a certificate takes a few weeks to several months, depending on the standard, the size of your operation, and how ready your management system already is. This guide walks through each stage so you know exactly what to expect and how to prepare.

ISO certification is awarded to an organization, not to a person. It confirms that a company’s management system meets the requirements of an international standard such as ISO 9001 for quality or ISO 27001 for information security. Individuals do not get “ISO certified”—instead, they earn training certificates by completing accredited courses. Keeping that distinction clear from the start makes the rest of the process much easier to understand.

What Is ISO Certification?

ISO (the International Organization for Standardization) develops globally recognized standards that define best practice for managing quality, safety, environmental impact, information security, and more. When an accredited certification body audits your organization and confirms you conform to a standard, it issues an ISO certificate valid for a three-year cycle.

Common standards organizations pursue include:

  • ISO 9001 — Quality management
  • ISO 14001 — Environmental management
  • ISO 27001:2022 — Information security management
  • ISO 45001 — Occupational health and safety
  • ISO 22000 — Food safety management
  • ISO 13485 — Medical devices quality management

Whichever standard applies to your business, the certification process follows broadly the same route. You can explore the full range of options on the ISO certification hub or review the underlying prerequisites in our guide to ISO certification requirements.

The ISO Certification Process Step by Step

Below is the complete ISO certification process, broken into the stages every accredited body follows. For a formal overview of how IAS structures this journey, see our dedicated certification process page.

Step 1: Application and Contract Review

The process begins when you submit an application to a certification body. You provide basic information about your organization—its size, number of sites, employee count, industry, and the standard you want to be certified against. The certification body uses these details to determine the audit scope, timeline, and effort involved, then confirms the arrangement in a contract or agreement.

Step 2: Gap Analysis (Optional)

A gap analysis is an optional but valuable early step. An auditor or consultant reviews your existing processes against the chosen standard and identifies where your current practices fall short. This gives you a clear roadmap of what to fix before the formal audit, reducing the risk of nonconformities later. Many first-time applicants find this step well worth the investment.

Step 3: Documentation and Implementation

Next, you build and document your management system so it meets the standard’s requirements. This typically includes a policy, defined objectives, documented procedures, and records that demonstrate the system is working in practice. Just as importantly, you implement the system across day-to-day operations and give it enough time to generate evidence—auditors want to see the system actually running, not merely written down.

Step 4: Stage 1 Audit (Documentation Review)

The Stage 1 audit is a readiness review. The auditor examines your documented management system, evaluates your understanding of the standard, and checks whether you are prepared for the full assessment. Any gaps found here are flagged so you can address them before Stage 2. Think of Stage 1 as a checkpoint that prevents surprises during the main audit.

Step 5: Stage 2 Audit (Certification Audit)

The Stage 2 audit is the main event. Auditors visit your site (or conduct a remote assessment where permitted) to verify that your management system is fully implemented and effective. They interview staff, observe processes, and review records against every applicable clause of the standard. Any findings are classified as major or minor nonconformities, which you must address before certification can be granted. To understand what auditors look for, read our detailed breakdown of the ISO audit procedure.

Step 6: Certification Decision

Once you have closed out any nonconformities, an independent reviewer within the certification body evaluates the audit evidence and makes the certification decision. If everything conforms, the body issues your ISO certificate. This certificate is typically valid for three years, subject to ongoing surveillance.

Step 7: Surveillance Audits and Recertification

Certification is not a one-time event. During the three-year cycle, the certification body conducts surveillance audits—usually annually—to confirm your management system continues to meet the standard. At the end of the cycle, a recertification audit renews your certificate for another three years. This ongoing oversight is what keeps an ISO certificate credible and trusted by customers.

How Long Does the ISO Certification Process Take?

There is no single answer, because timelines depend on several factors:

  • Organization size and complexity — More sites and processes require more audit time.
  • Standard chosen — Some standards demand more extensive documentation and evidence.
  • Current maturity — A company with established processes moves faster than one starting from scratch.
  • Resource commitment — Dedicated internal ownership dramatically shortens the timeline.

Smaller organizations with a well-run system can often complete the process in a couple of months, while larger or more complex operations may need six months or more. Building the system and gathering enough operating evidence is usually the longest phase—not the audits themselves.

Tips for a Successful ISO Certification Process

  • Assign clear ownership. Appoint a competent person or team to lead implementation and act as the point of contact for auditors.
  • Train your people. Employees who understand the standard and their role in it make audits smoother. Consider ISO internal auditor training to build in-house capability.
  • Keep records organized. Auditors rely on evidence. Well-maintained, accessible records shorten audits and reduce findings.
  • Run internal audits first. A mock or internal audit surfaces weaknesses before the certification body does.
  • Don’t rush implementation. Give your system enough time to run so it can generate the evidence auditors expect to see.

Benefits of Achieving ISO Certification

Completing the ISO certification process delivers advantages well beyond the certificate on the wall:

  • Market credibility — Certification signals to customers and partners that your operations meet a recognized international benchmark.
  • Operational efficiency — Standardized processes reduce waste, rework, and confusion.
  • Better risk management — Structured systems help you identify and control risks before they escalate.
  • Stronger customer confidence — Consistent quality and clear accountability improve satisfaction and retention.
  • New opportunities — Many contracts and tenders require suppliers to hold ISO certification.

For a fuller look at the payoff, see our article on ISO certification benefits.

Choosing the Right Certification Body

The certification body you select matters. Accreditation, industry experience, and a transparent process all influence the value of your certificate. IAS is a global certification and training body that works with organizations of all sizes across a wide range of standards, and we partner with Empowering Assurance Systems (EAS) to support clients worldwide. If you are comparing providers, our guide to ISO certification bodies explains what to look for.

Ready to begin? Contact our team to discuss your standard, scope, and timeline, and we will map out the ISO certification process for your organization.

Frequently Asked Questions

What are the main steps in the ISO certification process?
The core steps are application, an optional gap analysis, documentation and implementation, the Stage 1 audit, the Stage 2 audit, the certification decision, and ongoing surveillance audits. Each stage builds on the last, moving your organization from initial inquiry to holding a valid certificate. The certificate is then maintained through periodic surveillance over a three-year cycle.
How long does it take to get ISO certified?
Timelines vary from a couple of months to more than six months, depending on your organization’s size, the standard you choose, and how mature your current management system is. Building and running the management system so it produces enough evidence is usually the longest phase. Committing dedicated internal resources is the single most effective way to shorten the process.
What is the difference between a Stage 1 and Stage 2 audit?
The Stage 1 audit is a readiness review that checks your documented management system and confirms you are prepared for full assessment. The Stage 2 audit is the main certification audit, where auditors verify that your system is fully implemented and effective through interviews, observations, and record reviews. Nonconformities found at Stage 2 must be resolved before certification is granted.
Can an individual get ISO certified?
No—ISO certification is awarded to organizations, not individuals. People earn training certificates by completing accredited courses such as ISO lead auditor training or foundation programs. These qualifications demonstrate personal competence but are separate from an organization’s ISO certificate. Learn more in our guide to ISO certification for individuals.
Is a gap analysis required for ISO certification?
A gap analysis is optional, not mandatory. However, it is highly recommended for first-time applicants because it identifies where your current processes fall short of the standard before the formal audit. Addressing those gaps early reduces the likelihood of nonconformities during the Stage 2 audit and helps the overall process run more smoothly.
How much does the ISO certification process cost?
Cost depends on factors such as your organization’s size, the number of sites, the standard chosen, and the audit effort required. Because these variables differ for every business, certification bodies provide tailored quotes rather than fixed prices. Our guide to ISO certification cost explains the main factors that influence pricing.