ISO Certification in USA

Someone has asked you for an ISO certificate. Maybe a customer, maybe a prime contractor, maybe a procurement portal that will not let you upload a bid without one. You now need to know what the thing actually is, which number applies to you, and what the next twelve weeks look like.

This page is the map to ISO certification in USA. It covers what every scheme has in common, who checks the checker, and where to go for each standard. The detail for each scheme lives on its own page, linked throughout, starting with the certification services IAS offers.

Not sure which ISO certification you need? Tell us what the customer asked for and what you make or do. We will point you at the right scheme before you spend anything. Talk to IAS.

✓ IAS is accredited by UQAS | ✓ System and product schemes | ✓ Audits across all 50 states | ✓ Plain answers before you commit

What ISO certification actually is

ISO standards are published documents. Each one says what a management system for a given subject should contain. It does not say how your company must run. It says what has to exist, be decided, be recorded and be reviewed.

Certification is separate from the standard itself. It is an independent body auditing your organization against that standard and issuing a certificate if the evidence holds up. IAS is that independent body. We do system certification against management system standards, and product certification against product requirements, with the steps set out on the product certification procedure page.

Two things follow. First, the certificate covers a scope — named sites, named activities. It is not a blanket statement about your company. Second, it covers a period. It expires, and it can be withdrawn.

Who accredits IAS

This matters more than most buyers realize. Anyone can print a certificate. The question a customer should ask is who assessed the ISO certification body that issued it.

IAS is accredited by UQAS. UQAS is the accreditation body that assesses IAS against the requirements for bodies operating certification of management systems. Who IAS is and where we audit is set out separately. That assessment looks at our impartiality arrangements, our auditor competence records, how we decide certification, how we handle appeals, and whether our audit practice matches what we say it is. It is repeated on a schedule, not done once.

The accreditation chain behind ISO certification by IAS: the published ISO standard sets the requirements, UQAS accredits IAS as a certification body,
The accreditation chain behind ISO certification by IAS: the published ISO standard sets the requirements, UQAS accredits IAS as a certification body, IAS audits the client organization, and the certificate names a defined scope and expiry date.

Be clear about the direction of that chain. Accreditation is an assessment of IAS. It is not an endorsement of any organization we certify, and it does not transfer to you when you receive a certificate. Your certificate says your system met the standard within its scope on the dates audited. Nothing more.

What every ISO management system standard has in common

The numbers differ. The skeleton rarely does. Most current management system standards share the same high-level structure, which is why a company holding one certificate usually finds the second much easier.

Every one of them will expect you to define the boundary of the system, identify who has a stake in it, set objectives, assign responsibility, control documents, plan and run internal audits, deal with problems when they occur, and hold a management review. The subject changes — quality, environment, safety, information, energy. The machinery around it stays familiar.

That shared skeleton is why combined audits work. If you hold two or three standards, one audit team can cover them in one visit, testing the shared elements once and the subject-specific elements separately.

Which standard applies to you

Start from the request, not the catalog. If a customer named a number, use that number. If nobody named one, work from what you are being asked to prove.

If you are being asked to proveThe usual schemeGo to
Your product or service is consistently delivered to specISO 9001 quality managementISO 9001
You control your environmental impactISO 14001 environmental managementISO 14001
You manage worker health and safety riskISO 45001 occupational health and safetyISO 45001
Customer data in your systems is protectedISO 27001 information securityISO 27001
Food you handle is safe along the chainISO 22000 food safetyISO 22000
Medical devices are designed and made under controlISO 13485 medical device qualityISO 13485
Your test or calibration results are technically validISO 17025 laboratory competenceISO 17025
Your medical laboratory is competentISO 15189 medical laboratoriesISO 15189
You can keep operating through disruptionISO 22301 business continuityISO 22301
You manage and reduce energy useISO 50001 energy managementISO 50001
Your IT services are managed and measuredISO 20000 service managementISO 20000

Most companies that go beyond one standard start with ISO 9001 and add the one their sector cares about. Not every requirement lands on an ISO number, either — if a customer in pharmaceuticals, food or cosmetics asked for good manufacturing practice rather than a management system standard, cGMP certification is the separate scheme for that.

The ISO certification process, start to finish

The sequence is the same whichever number you pick. The content of the audit changes; the steps do not.

The certification pathway from first inquiry to certificate: scope and application, quote and contract, Stage 1 readiness review, Stage 2 main audit,
The certification pathway from first inquiry to certificate: scope and application, quote and contract, Stage 1 readiness review, Stage 2 main audit, findings and corrections, certification decision by an independent reviewer, then certificate issue.

You describe your scope and headcount. IAS confirms what the audit needs to cover. This is also what sets the ISO certification cost: the size of the scope, the headcount and the number of sites decide the audit time, which is why a quote follows the scope rather than arriving before it. Stage 1 is a readiness check — mostly documents, internal audit records and management review. Stage 2 is the real audit, on site or partly remote, testing whether the system works in practice. Findings are written up and you correct them. A reviewer who was not on the audit team makes the certification decision. Then the certificate is issued.

The full step-by-step is on the certification process page, and what auditors actually do on the day is covered in the ISO audit procedure page.

The ISO certification cycle after you pass

The work is not finished when the certificate arrives. It runs on a three-year cycle with surveillance audits in between, then a recertification audit before it expires.

The three-year certification cycle shown as a timeline: initial certification audit, two surveillance audits at roughly annual intervals, then a recer
The three-year certification cycle shown as a timeline: initial certification audit, two surveillance audits at roughly annual intervals, then a recertification audit before the certificate expires and the cycle restarts.

Surveillance audits are shorter than the initial audit and sample parts of the system. They always look at internal audits, management review, complaints, and any findings raised last time. Recertification looks at the whole system again, including whether it has actually improved.

Companies that treat surveillance as a surprise every year have the hardest time. Companies that run their own internal audits on a real schedule barely notice it.

What a strong file looks like, and what a weak one looks like

Auditors are not looking for beautiful documents. They are looking for evidence that decisions were made, acted on and checked. Most audits turn on the same handful of records. Here is the difference as it shows up in an audit room.

ElementWhat holds upWhat gets a finding
Internal auditsCovers every clause and every area across the cycle, with dated reports and closed actionsOne rushed audit before the visit, findings with no closure
Management reviewMinutes showing inputs, decisions, owners and resourcingA signed template with no discussion recorded
Corrective actionCause identified, fix applied, effectiveness checked laterThe problem fixed once, cause never examined
ObjectivesMeasurable, tracked, discussed when missedA wall poster with no data behind it
CompetenceRecords showing who is trained for what, kept currentCertificates in a drawer, no link to roles
Document controlOne current version, obsolete copies removed from the floorThree versions in circulation, staff using the old one
Supplier controlCriteria, evaluation records, action when performance dropsAn approved list nobody has reviewed in years

None of this requires software or a big team. It requires someone owning it.

Who does what

Confusion about roles causes more delay than any technical issue. This is the split.

TaskYour organizationConsultant (optional)IAS
Build the management systemYesMay assistNo
Write your proceduresYesMay assistNo
Run internal auditsYesMay assistNo
Conduct the certification auditNoNoYes
Decide whether to certifyNoNoYes
Correct audit findingsYesMay assistNo
Issue and maintain the certificateNoNoYes

IAS cannot design your system and then audit it. That independence is part of what UQAS assesses. If a body offers to do both, that is a reason to ask questions. Where support is needed on the ground, it comes from our associate partners, who are separate from the audit team.

The limits of any certificate

What it means. An audit team sampled your management system against the named standard, within the stated scope, on stated dates. They found the required elements in place and working well enough to certify. An independent reviewer agreed.

What it does not mean. It is not an inspection of every product you ship, every site you run, or every transaction you process. Auditors sample. It is not a statement that you comply with any law. It is not an opinion on your finances, your ethics or your service quality. It is not a guarantee that nothing will go wrong. And, as above, it is not an endorsement of your company by UQAS.

Use the mark honestly. Certification marks can be used on stationery and marketing, but not on products or in ways that suggest the product itself was certified when only the system was. The logo usage guidelines set out what is allowed.

A note on legal duties

This page makes no claim about the law in the United States or anywhere else. Nothing here should be read as advice on what any statute, regulation or contract requires of you.

Certification against an ISO standard is voluntary. It is not a permit and it does not replace any authorization you may need. If you need to know what your legal obligations are, ask your own attorney or a qualified compliance adviser. Where a standard asks you to identify applicable legal requirements, identifying them correctly is your responsibility.

Training that supports ISO certification

Certification audits go better when someone inside the business understands the standard. Two routes cover most needs.

Internal auditor training teaches people to audit their own system properly — enough to produce audit records that stand up rather than tick a box. Lead auditor training goes further, covering audit planning, team leadership and reporting to a recognized syllabus. Course options across standards are listed under ISO training, with the advanced route on the lead auditor training page. For the two most common starting points, see ISO 9001 internal auditor training and ISO 9001 lead auditor training; dates for all courses are on the training schedule.

If you only do one thing before your Stage 2, make it training your internal auditor. Weak internal audits are the single most common source of findings.

Where it usually goes wrong

Scope written too wide. People claim every site and every activity, then cannot evidence half of it. Certify what you can prove, then extend.

No records from before the audit. A standard expects the system to have been running. A system built last month has nothing to review, no trend, no closed actions.

One person holds everything. If the quality manager is the only one who can answer, the auditor will find that out in ten minutes on the shop floor.

Documents nobody uses. Procedures written by a consultant, never read by staff, describing a process that does not match reality. Auditors compare what is written with what happens.

Findings closed on paper. Writing “training given” is not corrective action. Show the cause, the fix and the check that it worked.

Leaving the deadline too tight. Stage 1, corrections, Stage 2 and the decision each take time. Work back from the date your customer needs the certificate. Longer write-ups of these patterns sit on the IAS blog.

Ready to start your ISO certification, or still weighing it up? Send us your scope and the standard you have been asked for. We will explain the steps and what you need in place first. See the common questions or get in touch.

Frequently asked questions

Which ISO certification should I get first?

Whichever one your customer or tender named. If no one named a standard, ISO 9001 is the usual starting point because it covers how you deliver consistently and shares its structure with the others.

How long does ISO certification take?

It depends on how much of the system already exists. The audit stages themselves are scheduled close together; the time is usually spent building records before Stage 1 and correcting findings after Stage 2.

Can a small company get certified?

Yes. Standards scale with the organization. A small firm needs fewer documents and fewer people, but the same elements must exist and be evidenced.

Is ISO certification required by law in the USA?

Nothing here should be taken as a statement of what the law requires. ISO certification is voluntary in itself. Whether any contract or regulator requires it is a question for your own advisers.

What is the difference between accreditation and certification?

Certification is what IAS does to your organization. Accreditation is what UQAS does to IAS. You are certified; IAS is accredited. The two words are not interchangeable.

Does my certificate make my products approved?

No. A management system certificate covers the system, not the product. Product claims need product certification, which is a different scheme with different evidence.

What happens if the audit finds problems?

Findings are graded. You submit corrections, evidence of cause analysis and evidence the fix works. Certification is decided after those are accepted. Findings at the audit are normal, not a failure.

Do I need a consultant?

No. A consultant can speed things up if you have no internal experience, but the work can be done in-house. IAS cannot consult and audit the same organization.

How long is the certificate valid?

It runs on a three-year cycle, with surveillance audits between the initial audit and recertification. It stays valid only if those surveillance audits happen on schedule.

Can certification be withdrawn?

Yes. If surveillance is refused or missed, or serious findings go uncorrected, the certificate can be suspended and then withdrawn.

Can one audit cover two standards?

Yes. Where standards share structure, a combined audit tests the shared parts once and the subject-specific parts separately. You must hold a system that genuinely covers both.

How do I verify a certificate is genuine?

Ask the issuing body. Any certificate should name the certified organization, the standard, the scope, the issue and expiry dates, and the accreditation of the body that issued it.