Guides

The ISO Certification Process Explained — Application to Certificate

What actually happens between deciding to certify and holding a certificate: every stage, who does what, how long each takes, and where the delays genuinely come from.

  • GMSCPL Technical Team
  • 8 April 2026
  • 8 min read

The certification process is more standardised than most organisations expect, because it is governed by ISO/IEC 17021-1 and by accreditation rules that apply to every accredited certification body. That means the sequence below is broadly the same wherever you certify. What differs between bodies is competence, rigour and how honestly the timeline is communicated.

Stage 0 — Before you apply

Your management system must be implemented and operating. Specifically, you need at least one complete internal audit cycle covering the full scope, and at least one management review. These are not bureaucratic gates: without them there is no evidence that the system works, and a Stage 2 audit would have nothing to sample.

Application and quotation — 2 to 3 working days

You provide scope, sites, headcount and process information. The certification body calculates audit days under IAF MD 5 and issues a quotation. Ask to see the calculation. A body that will not show it is either not doing it or not doing it correctly.

Contract and planning — about 1 week

On acceptance, a lead auditor is appointed based on verified technical competence for your sector, audit dates are agreed and an audit plan is issued in advance. You should receive the plan before the audit, not on the morning of it.

Stage 1 — typically 1 day

A readiness review: scope confirmation, documentation review, evaluation of your understanding of the standard, examination of internal audit and management review evidence, and assessment of anything that would prevent Stage 2 from succeeding. Stage 1 exists to stop you paying for a Stage 2 you are not ready for.

The gap — 2 to 4 weeks

Time to address Stage 1 concerns. This gap is required rather than optional; conducting Stage 2 immediately after Stage 1 defeats the purpose of Stage 1.

Stage 2 — 2 to 5 days

The certification audit proper. The system is assessed as it operates: process sampling across shifts and sites, interviews at every level including non-managerial staff, examination of records over time, and evaluation of internal audit and corrective action effectiveness. Every finding is presented at the closing meeting.

Corrective action — 2 to 4 weeks

This is where timelines are actually lost. Nonconformities require root cause analysis, correction, corrective action and evidence. Organisations that submit "operator counselled" get it rejected and lose another cycle. Doing the root cause analysis properly the first time is the single largest lever you have over the total timeline.

Certification decision — 1 to 2 weeks

An independent decision-maker who did not conduct your audit reviews the complete file and decides. This separation is mandatory. Certificates are then issued and the organisation is listed on the public certified-client directory.

And then the cycle continues

Surveillance audits at approximately twelve and twenty-four months, then a full recertification audit before the three-year expiry. The first surveillance must occur within twelve months of the certification decision date — a deadline that catches out organisations who assume it runs from the certificate date.

Keep reading

Related articles

Next step

From reading to certified

If this raised a question about your own scope, timeline or readiness, ask it. We will tell you what the work involves before you commit to anything.