ISO 9001 Certification in USA
Been asked for ISO 9001 by a customer or a tender? Tell us what they asked for and we will tell you what the audit involves. Start at ISO 9001 certification in USA or contact us.
Most people do not go looking for ISO 9001 certification. It arrives in an email. A customer updates their supplier terms. A bid portal adds a field. A prime contractor sends a questionnaire with a line that says “ISO 9001 certified — yes or no.”
That is the situation this page is written for. You are not here for a lecture on quality theory. You want to know what the certificate is, who issues it, who checks the issuer, what an auditor will ask you for, and how long the whole thing takes to get moving.
✓ Accredited certification body | ✓ IAS is accredited by UQAS | ✓ Audits across all US states | ✓ One point of contact from application to certificate
What ISO 9001 certification actually is
ISO 9001 is a standard for a quality management system. A quality management system is simply the set of rules your organization follows to make sure the work comes out right, and the records that prove you followed them.
Certification is separate from the standard. It means an independent certification body audited your system against the standard and found it conforming. The certificate names your organization, the standard, and a scope — the activities and sites that were actually audited. Some buyers and bid portals call this QMS certification; they mean the same document.
That scope line matters more than most buyers expect. A certificate covering one plant does not cover a second plant you opened last year. If your customer asks whether your certificate covers the work they are buying, the scope statement is the answer.
ISO 9001:2026 was published on 16 September 2026 and replaces ISO 9001:2015, with a three-year transition period. If you are starting now, ask which edition your certificate will be issued against before you sign anything. Our ISO 9001 revision guide and the note on what the revision means for US companies cover the transition question.
Who IAS is, and who accredits IAS
IAS stands for Integrated Assessment Services, a conformity assessment body. We audit organizations and issue certificates. We are not the body that decides whether we are competent to do that — someone else does.
IAS is accredited by UQAS. UQAS is an accreditation body. Its job is to assess IAS: our auditors’ competence, our impartiality controls, how we make certification decisions, how we handle complaints, and whether we follow our own procedures. That assessment repeats. It is not a badge collected once.

Here is the point that gets lost. Accreditation is an assessment of IAS. It is no comment on the organizations we go on to certify. UQAS has never visited your factory. It has no opinion on your products. What accreditation tells your customer is that the body which signed your certificate was itself examined against recognized rules for certification bodies.
If you want more on how this layer works in practice, see ISO 9001 accreditation and the general piece on ISO certification bodies.
Before you start: are you ready, or are you guessing?
Plenty of organizations apply before they have anything to audit. That wastes everyone’s time. Use this to check honestly.
| Question | You are ready when | You are not ready when |
|---|---|---|
| Scope | You can name the sites and activities in one sentence | You are still arguing about whether the warehouse counts |
| Processes | Someone can describe how an order moves from inquiry to delivery | Every department describes it differently |
| Records | You can produce last quarter’s records without a search party | Evidence lives in one person’s inbox |
| Nonconformity | You have logged real problems and what you did about them | The log is empty because “nothing went wrong” |
| Internal audit | You have audited your own system at least once | You have never audited yourself |
| Management review | Leadership has reviewed performance and recorded decisions | Leadership has heard the word ISO and nothing else |
| Objectives | You have quality objectives with numbers and owners | You have a quality policy poster and no objectives |
An empty nonconformity log is the single most common reason a Stage 1 audit ends badly. Auditors do not read it as evidence of perfection. They read it as evidence that you are not recording things.
The ISO 9001 certification pathway, step by step
The steps below run in order, and each one depends on the one before it. What the whole thing costs depends on scope and size; the note on ISO 9001 certification cost explains what the price actually covers.

Application and scope. You tell us what you do, where, and how many people do it. We agree the scope wording. Get this right early — changing it later means changing the certificate.
Stage 1. A readiness audit. The auditor looks at your documented system, your internal audit and management review, and decides whether a Stage 2 audit can usefully go ahead. Stage 1 findings are a gift. Fix them before Stage 2.
Stage 2. The real audit. The auditor goes to where the work happens, talks to the people who do it, and tests whether the system on paper matches the system in practice. Findings are raised as nonconformities, graded by seriousness.
Corrective action. You respond to findings. Not with a promise — with a correction, a cause, and an action that stops it recurring.
Certification decision. Someone independent of the audit team reviews the evidence and decides. The auditor recommends; they do not decide. That separation is one of the things UQAS assesses.
Surveillance. Audits continue through the certificate’s life.
The certification process in USA page sets out our procedure, and the ISO audit procedure in USA page explains how audits are conducted. For a plain walkthrough, see how to get ISO 9001 certified and the ISO 9001 certification process.
What an auditor actually looks at
An ISO 9001 audit samples. The auditor picks a process, follows it from one end to the other, and asks for evidence at each turn. Here is what separates a system that holds up from one that falls over.
| Area | What good looks like | What weak looks like |
|---|---|---|
| Quality policy | Short, specific, and staff can say what it means for their job | Framed on a wall, written by a consultant |
| Objectives | Measurable, owned, reviewed, and sometimes missed | Vague aspirations with no owner |
| Process control | The written method matches what people actually do | A procedure nobody on the floor has read |
| Supplier control | Suppliers evaluated, reevaluated, and records kept | A list of approved suppliers with no evaluation behind it |
| Customer complaints | Logged, investigated, trends reviewed | Handled informally by whoever picked up the phone |
| Nonconforming output | Identified, segregated, decided on, recorded | Reworked quietly and never written down |
| Internal audit | Covers the whole system, finds real issues | One audit, no findings, same week every year |
| Management review | Inputs and outputs recorded, decisions actioned | Minutes that repeat last year’s minutes |
| Competence | Training needs identified, evidence of effectiveness | Certificates in a folder, no link to the job |
Notice what is not on the list: thickness of documentation. A short system you follow beats a long one you ignore. More detail on the clauses sits in ISO 9001 requirements.
Who does what
Certification is not something done to you. It is a division of labor, and confusion about it causes delays.
| Task | Your organization | IAS |
|---|---|---|
| Define scope and activities | Proposes and confirms | Reviews and agrees |
| Build and run the system | Yes | No — we cannot design what we audit |
| Internal audit | Yes | No |
| Management review | Yes | No |
| Stage 1 and Stage 2 audits | Provides access, people, records | Plans and conducts |
| Raising findings | Responds | Raises and grades |
| Root cause and corrective action | Yes | Reviews evidence |
| Certification decision | No | Independent reviewer decides |
| Certificate and logo use | Follows the rules | Sets the rules |
| Surveillance audits | Hosts | Schedules and conducts |
We cannot consult on the system we then audit. That separation protects the value of your certificate. The logo usage guideline explains what you may put on packaging, vehicles, and documents once certified. If you want independent help building the system, look for a consultant with no connection to your certification body.
Life after ISO 9001 certification

The certificate has a validity period, and nothing is left alone during it. Surveillance audits check that the system is still running and still improving. Before expiry, a recertification audit reviews the whole system again.
Organizations that treat surveillance as an annual scramble find it harder each time. Organizations that keep the internal audit program and management review running find surveillance uneventful. That is the whole difference.
Reading your certificate honestly
It means: an independent auditor sampled your quality management system against ISO 9001 at specific sites, for specific activities, on specific dates, and a separate reviewer decided the evidence supported certification. It means your system was found conforming at the time of audit.
It does not mean: that every product you ship is defect-free. That you comply with any law. That every process was examined — auditing is sampling, not a census. That nothing will go wrong. That a supplier further down your chain is certified.
It is not a guarantee. A certificate is a statement about a management system at a point in time, based on evidence sampled by a competent auditor. Treat any claim beyond that with suspicion, including claims made about certificates by anyone selling them.
Legal position
This page describes a voluntary certification scheme. It makes no claim about the law in the United States or in any other country, and nothing here should be read as legal advice. Whether any statute, contract, regulation, or customer term applies to your organization is a question for your own legal advisers. A certificate is not a substitute for that advice and does not demonstrate compliance with any legal requirement.
Where ISO 9001 certification usually goes wrong
- Scope written too wide. Someone includes activities the audit will not reach. The auditor then has to either visit them or cut the scope.
- Documents written for the auditor. Procedures that describe an imaginary company. Staff interviews expose this in minutes.
- No evidence of internal audit. The plan exists. The audits never happened.
- Corrective actions that are just corrections. “We replaced the part” is a correction. Why did the part fail, and what stops the next one?
- Leadership absent. Management review signed by someone who was not in the room.
- Late access. The auditor arrives and the process owner is on vacation.
- Assuming a consultant’s binder is a system. Documentation is not a management system. Behavior is.
Training that supports the system
You need people inside who can audit your own system. That is a requirement, not a nice-to-have. ISO 9001 internal auditor training in USA covers that role. For people who will lead audits or work in the certification field, ISO 9001 lead auditor training in USA goes further. Remote options are listed under ISO 9001 training online in USA, dates under the ISO training schedule, and groundwork for newcomers under foundation training.
If ISO 9001 is not the only thing being asked for
Customers often ask for more than one certificate at once. Environmental requirements point to ISO 14001 certification in USA. Worker safety questions point to ISO 45001 certification in USA. Information security clauses point to ISO 27001 certification in USA. Medical device work points to ISO 13485 certification in USA. Where scopes overlap, audits can often be combined. Ask before you apply separately. The full list is under system certification in USA and ISO certification in USA.
Frequently asked questions
Our customer asked for ISO 9001 certification. Where do I start?
Read the request carefully first. Some customers ask for certification; some ask only that you operate a compliant system. If it is certification, define your scope, then talk to a certification body. Our certification process in USA page is the practical starting point.
Who accredits IAS?
IAS is accredited by UQAS. UQAS assesses IAS as a certification body — our competence, impartiality, and decision-making. That assessment is of IAS, not of the organizations we certify.
Can we be certified if we have only one location?
Yes. Scope is written to match what you do. A single-site organization gets a single-site scope.
Does certification cover our suppliers?
No. Your certificate covers your organization and your scope. If a customer wants your supply chain certified, that is a separate conversation with each supplier.
How long does ISO 9001 certification take?
That depends on how ready you are, not on us. An organization with a running system, completed internal audits, and a management review on record moves quickly. One starting from nothing takes longer. The honest answer comes after we see your scope.
What happens if we get a nonconformity?
You address it. A nonconformity is a finding, not a failure. You describe the correction, investigate the cause, and put in an action that prevents recurrence. Evidence is reviewed before the certification decision.
Do we need a consultant for ISO 9001 certification?
Not necessarily. Many organizations build the system with internal people, especially after internal auditor training. If you use a consultant, use someone other than your certification body.
Can we put the certificate on our website and packaging?
Yes, within rules. Marks and certificate references must not imply things the certificate does not say — for example, product certification in USA, which is a different scheme entirely. See the logo usage guideline.
What is the difference between Stage 1 and Stage 2?
Stage 1 checks whether you are ready and whether your documented system covers the standard. Stage 2 tests whether the system works in practice, on site, with the people who run it.
Does the certificate prove our products are good?
No. It relates to your management system, at the sites and activities in the scope, on the audit dates. It is not a product guarantee and not a compliance statement.
What does ISO 9001:2026 mean for us?
ISO 9001:2026 replaced ISO 9001:2015 on 16 September 2026, with a three-year transition. If you are certified already, plan your transition. If you are starting now, ask which edition applies to your certificate.
Where can I read more before deciding?
Start with ISO 9001 requirements, then the benefits of ISO 9001, then the IAS blog for the wider picture. Our frequently asked questions page answers the procedural questions.
Send us the request you received. We will tell you what scope it implies and what the audit will involve — no theory, just the next step. Reach us via contact us or read more about IAS.
