ISO Certification in USA
Someone has asked you for an ISO certificate. Maybe a customer, maybe a prime contractor, maybe a procurement portal that will not let you upload a bid without one. You now need to know what the thing actually is, which number applies to you, and what the next twelve weeks look like.
This page is the map to ISO certification in USA. It covers what every scheme has in common, who checks the checker, and where to go for each standard. The detail for each scheme lives on its own page, linked throughout, starting with the certification services IAS offers.
Not sure which ISO certification you need? Tell us what the customer asked for and what you make or do. We will point you at the right scheme before you spend anything. Talk to IAS.
✓ IAS is accredited by UQAS | ✓ System and product schemes | ✓ Audits across all 50 states | ✓ Plain answers before you commit
What ISO certification actually is
ISO standards are published documents. Each one says what a management system for a given subject should contain. It does not say how your company must run. It says what has to exist, be decided, be recorded and be reviewed.
Certification is separate from the standard itself. It is an independent body auditing your organization against that standard and issuing a certificate if the evidence holds up. IAS is that independent body. We do system certification against management system standards, and product certification against product requirements, with the steps set out on the product certification procedure page.
Two things follow. First, the certificate covers a scope — named sites, named activities. It is not a blanket statement about your company. Second, it covers a period. It expires, and it can be withdrawn.
Who accredits IAS
This matters more than most buyers realize. Anyone can print a certificate. The question a customer should ask is who assessed the ISO certification body that issued it.
IAS is accredited by UQAS. UQAS is the accreditation body that assesses IAS against the requirements for bodies operating certification of management systems. Who IAS is and where we audit is set out separately. That assessment looks at our impartiality arrangements, our auditor competence records, how we decide certification, how we handle appeals, and whether our audit practice matches what we say it is. It is repeated on a schedule, not done once.

Be clear about the direction of that chain. Accreditation is an assessment of IAS. It is not an endorsement of any organization we certify, and it does not transfer to you when you receive a certificate. Your certificate says your system met the standard within its scope on the dates audited. Nothing more.
What every ISO management system standard has in common
The numbers differ. The skeleton rarely does. Most current management system standards share the same high-level structure, which is why a company holding one certificate usually finds the second much easier.
Every one of them will expect you to define the boundary of the system, identify who has a stake in it, set objectives, assign responsibility, control documents, plan and run internal audits, deal with problems when they occur, and hold a management review. The subject changes — quality, environment, safety, information, energy. The machinery around it stays familiar.
That shared skeleton is why combined audits work. If you hold two or three standards, one audit team can cover them in one visit, testing the shared elements once and the subject-specific elements separately.
Which standard applies to you
Start from the request, not the catalog. If a customer named a number, use that number. If nobody named one, work from what you are being asked to prove.
| If you are being asked to prove | The usual scheme | Go to |
|---|---|---|
| Your product or service is consistently delivered to spec | ISO 9001 quality management | ISO 9001 |
| You control your environmental impact | ISO 14001 environmental management | ISO 14001 |
| You manage worker health and safety risk | ISO 45001 occupational health and safety | ISO 45001 |
| Customer data in your systems is protected | ISO 27001 information security | ISO 27001 |
| Food you handle is safe along the chain | ISO 22000 food safety | ISO 22000 |
| Medical devices are designed and made under control | ISO 13485 medical device quality | ISO 13485 |
| Your test or calibration results are technically valid | ISO 17025 laboratory competence | ISO 17025 |
| Your medical laboratory is competent | ISO 15189 medical laboratories | ISO 15189 |
| You can keep operating through disruption | ISO 22301 business continuity | ISO 22301 |
| You manage and reduce energy use | ISO 50001 energy management | ISO 50001 |
| Your IT services are managed and measured | ISO 20000 service management | ISO 20000 |
Most companies that go beyond one standard start with ISO 9001 and add the one their sector cares about. Not every requirement lands on an ISO number, either — if a customer in pharmaceuticals, food or cosmetics asked for good manufacturing practice rather than a management system standard, cGMP certification is the separate scheme for that.
The ISO certification process, start to finish
The sequence is the same whichever number you pick. The content of the audit changes; the steps do not.

You describe your scope and headcount. IAS confirms what the audit needs to cover. This is also what sets the ISO certification cost: the size of the scope, the headcount and the number of sites decide the audit time, which is why a quote follows the scope rather than arriving before it. Stage 1 is a readiness check — mostly documents, internal audit records and management review. Stage 2 is the real audit, on site or partly remote, testing whether the system works in practice. Findings are written up and you correct them. A reviewer who was not on the audit team makes the certification decision. Then the certificate is issued.
The full step-by-step is on the certification process page, and what auditors actually do on the day is covered in the ISO audit procedure page.
The ISO certification cycle after you pass
The work is not finished when the certificate arrives. It runs on a three-year cycle with surveillance audits in between, then a recertification audit before it expires.

Surveillance audits are shorter than the initial audit and sample parts of the system. They always look at internal audits, management review, complaints, and any findings raised last time. Recertification looks at the whole system again, including whether it has actually improved.
Companies that treat surveillance as a surprise every year have the hardest time. Companies that run their own internal audits on a real schedule barely notice it.
What a strong file looks like, and what a weak one looks like
Auditors are not looking for beautiful documents. They are looking for evidence that decisions were made, acted on and checked. Most audits turn on the same handful of records. Here is the difference as it shows up in an audit room.
| Element | What holds up | What gets a finding |
|---|---|---|
| Internal audits | Covers every clause and every area across the cycle, with dated reports and closed actions | One rushed audit before the visit, findings with no closure |
| Management review | Minutes showing inputs, decisions, owners and resourcing | A signed template with no discussion recorded |
| Corrective action | Cause identified, fix applied, effectiveness checked later | The problem fixed once, cause never examined |
| Objectives | Measurable, tracked, discussed when missed | A wall poster with no data behind it |
| Competence | Records showing who is trained for what, kept current | Certificates in a drawer, no link to roles |
| Document control | One current version, obsolete copies removed from the floor | Three versions in circulation, staff using the old one |
| Supplier control | Criteria, evaluation records, action when performance drops | An approved list nobody has reviewed in years |
None of this requires software or a big team. It requires someone owning it.
Who does what
Confusion about roles causes more delay than any technical issue. This is the split.
| Task | Your organization | Consultant (optional) | IAS |
|---|---|---|---|
| Build the management system | Yes | May assist | No |
| Write your procedures | Yes | May assist | No |
| Run internal audits | Yes | May assist | No |
| Conduct the certification audit | No | No | Yes |
| Decide whether to certify | No | No | Yes |
| Correct audit findings | Yes | May assist | No |
| Issue and maintain the certificate | No | No | Yes |
IAS cannot design your system and then audit it. That independence is part of what UQAS assesses. If a body offers to do both, that is a reason to ask questions. Where support is needed on the ground, it comes from our associate partners, who are separate from the audit team.
The limits of any certificate
What it means. An audit team sampled your management system against the named standard, within the stated scope, on stated dates. They found the required elements in place and working well enough to certify. An independent reviewer agreed.
What it does not mean. It is not an inspection of every product you ship, every site you run, or every transaction you process. Auditors sample. It is not a statement that you comply with any law. It is not an opinion on your finances, your ethics or your service quality. It is not a guarantee that nothing will go wrong. And, as above, it is not an endorsement of your company by UQAS.
Use the mark honestly. Certification marks can be used on stationery and marketing, but not on products or in ways that suggest the product itself was certified when only the system was. The logo usage guidelines set out what is allowed.
A note on legal duties
This page makes no claim about the law in the United States or anywhere else. Nothing here should be read as advice on what any statute, regulation or contract requires of you.
Certification against an ISO standard is voluntary. It is not a permit and it does not replace any authorization you may need. If you need to know what your legal obligations are, ask your own attorney or a qualified compliance adviser. Where a standard asks you to identify applicable legal requirements, identifying them correctly is your responsibility.
Training that supports ISO certification
Certification audits go better when someone inside the business understands the standard. Two routes cover most needs.
Internal auditor training teaches people to audit their own system properly — enough to produce audit records that stand up rather than tick a box. Lead auditor training goes further, covering audit planning, team leadership and reporting to a recognized syllabus. Course options across standards are listed under ISO training, with the advanced route on the lead auditor training page. For the two most common starting points, see ISO 9001 internal auditor training and ISO 9001 lead auditor training; dates for all courses are on the training schedule.
If you only do one thing before your Stage 2, make it training your internal auditor. Weak internal audits are the single most common source of findings.
Where it usually goes wrong
Scope written too wide. People claim every site and every activity, then cannot evidence half of it. Certify what you can prove, then extend.
No records from before the audit. A standard expects the system to have been running. A system built last month has nothing to review, no trend, no closed actions.
One person holds everything. If the quality manager is the only one who can answer, the auditor will find that out in ten minutes on the shop floor.
Documents nobody uses. Procedures written by a consultant, never read by staff, describing a process that does not match reality. Auditors compare what is written with what happens.
Findings closed on paper. Writing “training given” is not corrective action. Show the cause, the fix and the check that it worked.
Leaving the deadline too tight. Stage 1, corrections, Stage 2 and the decision each take time. Work back from the date your customer needs the certificate. Longer write-ups of these patterns sit on the IAS blog.
Ready to start your ISO certification, or still weighing it up? Send us your scope and the standard you have been asked for. We will explain the steps and what you need in place first. See the common questions or get in touch.
Frequently asked questions
Which ISO certification should I get first?
Whichever one your customer or tender named. If no one named a standard, ISO 9001 is the usual starting point because it covers how you deliver consistently and shares its structure with the others.
How long does ISO certification take?
It depends on how much of the system already exists. The audit stages themselves are scheduled close together; the time is usually spent building records before Stage 1 and correcting findings after Stage 2.
Can a small company get certified?
Yes. Standards scale with the organization. A small firm needs fewer documents and fewer people, but the same elements must exist and be evidenced.
Is ISO certification required by law in the USA?
Nothing here should be taken as a statement of what the law requires. ISO certification is voluntary in itself. Whether any contract or regulator requires it is a question for your own advisers.
What is the difference between accreditation and certification?
Certification is what IAS does to your organization. Accreditation is what UQAS does to IAS. You are certified; IAS is accredited. The two words are not interchangeable.
Does my certificate make my products approved?
No. A management system certificate covers the system, not the product. Product claims need product certification, which is a different scheme with different evidence.
What happens if the audit finds problems?
Findings are graded. You submit corrections, evidence of cause analysis and evidence the fix works. Certification is decided after those are accepted. Findings at the audit are normal, not a failure.
Do I need a consultant?
No. A consultant can speed things up if you have no internal experience, but the work can be done in-house. IAS cannot consult and audit the same organization.
How long is the certificate valid?
It runs on a three-year cycle, with surveillance audits between the initial audit and recertification. It stays valid only if those surveillance audits happen on schedule.
Can certification be withdrawn?
Yes. If surveillance is refused or missed, or serious findings go uncorrected, the certificate can be suspended and then withdrawn.
Can one audit cover two standards?
Yes. Where standards share structure, a combined audit tests the shared parts once and the subject-specific parts separately. You must hold a system that genuinely covers both.
How do I verify a certificate is genuine?
Ask the issuing body. Any certificate should name the certified organization, the standard, the scope, the issue and expiry dates, and the accreditation of the body that issued it.
