Certification process
From application to certificate
Every stage of accredited certification, what happens in it, how long it genuinely takes, and who is accountable for each decision.
- 8–12weeks, application to certificate
- 2–3working days to quote
- 3 yrscertification cycle
The certification process is more standardised than most organisations expect. It is governed by ISO/IEC 17021-1 and by accreditation rules that apply to every accredited certification body, which means the sequence below is broadly the same wherever you certify. What differs between bodies is competence, rigour, and how honestly the timeline is communicated to you at the start.
We publish the whole path — including the parts that take longer than anyone would like — because a client who understands the process is a client who arrives at Stage 2 ready. The single largest cause of a delayed certificate is not the audit. It is corrective action that has to be submitted twice because the root cause analysis was not done properly the first time.
Before you apply
- Your management system is implemented and operating, not only written
- One full internal audit cycle covering the whole scope is complete
- One management review has been held with the required inputs and outputs
- Statutory licences for your activity are valid and current
Missing any of these is not a reason to wait before contacting us — it is a reason to contact us early, so the timeline you plan around is the real one.
The full journey
Seven steps, start to finish
Durations are indicative and assume a system that is genuinely operating. We will tell you at Stage 1 if the dates you are working to are not achievable.
- 01
Application & Quotation
2–3 working days
You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.
- 02
Contract & Audit Planning
1 week
On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.
- 03
Stage 1 — Readiness Review
1 day (typical)
A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.
- 04
Stage 2 — Certification Audit
2–5 days (scope dependent)
On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.
- 05
Corrective Action & Decision
2–4 weeks
You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.
- 06
Certificate Issue
3–5 working days
A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.
- 07
Surveillance & Recertification
Annual
Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.
In detail
Go deeper on any stage
Each page below covers one part of the process in full, including the rules we are bound by and the decisions that are not ours to make.
How to Apply
The five pieces of information we need to scope your audit and issue a fixed quotation.
Learn moreAudit Stages (Stage 1 & Stage 2)
What actually happens in each audit, and how findings are graded when they are raised.
Learn moreSurveillance & Recertification
Keeping the certificate valid across the three-year cycle, and the deadlines that catch people out.
Learn moreFees & Certification Cycle
How audit days are calculated under IAF MD 5, and what your quotation does and does not include.
Learn moreSuspension, Withdrawal & Appeals
When certification is restricted, on what grounds, and your right to appeal any decision we make.
Learn moreGrievance & Complaints Handling
How to raise a complaint about us, our auditors, or a certified client — and what we do with it.
Learn moreBefore you commit
Process — common questions
For most organisations, ISO 9001. It establishes the management system structure — context, leadership, planning, competence, internal audit, management review — that every other standard reuses, so a later ISO 14001 or ISO 45001 becomes an addition rather than a fresh build. The exceptions are sector-driven: an IT services company whose customers are asking security questions should start with ISO 27001, a food business with ISO 22000 or HACCP, and a medical device manufacturer with ISO 13485.
There is no fixed minimum period, but there is a fixed minimum of evidence. You need at least one complete cycle of internal audits covering the full scope, and at least one management review with the inputs and outputs the standard requires. In practice that means around three months of genuine operation as an absolute floor, and most organisations need longer.
Yes, and it is usually the efficient route. Standards sharing the High Level Structure — ISO 9001, 14001, 45001, 27001, 22301, 50001 and others — can be operated as one integrated management system and audited together. Integrated audits attract permitted audit-day reductions, so two standards audited together cost meaningfully less than two separate certifications.
No. Many organisations certify without one, particularly where someone internal has been through an implementation before. A consultant buys pace and helps avoid known pitfalls. What a consultant cannot supply is internal ownership, and a system built entirely by an external party without internal engagement tends to fail its first surveillance audit.
Yes. Transfer is a defined process under IAF MD 2. We review your current certificate, the accreditation status of the issuing body, your most recent audit reports and the status of any open nonconformities. Where the existing certification is accredited and in good standing, transfer is usually straightforward and does not require a full initial certification audit.
Cost is driven by audit days, which are calculated under IAF MD 5 from your effective headcount and the risk category of your activity — not set commercially. That means we cannot quote meaningfully without your headcount, scope and number of sites, and any body that quotes a flat price without asking for those is not calculating audit days properly. Our quotations show the calculation, cover the full three-year cycle including both surveillance audits, and state travel separately at cost.
For an organisation with a working system, typically eight to twelve weeks from application to certificate: two to three days for the quotation, about a week to contract and plan, Stage 1, a gap of two to four weeks, Stage 2, then nonconformity closure and the certification decision. If the system still has to be built, add three to six months of implementation before any of that starts.
Three reasons, in order of importance. First, whether the certification is accredited — unaccredited certificates cost less because they are worth less. Second, whether the audit days match the IAF MD 5 calculation. Third, whether surveillance audits are included in the quoted figure or charged separately later. Compare the three-year total for accredited certification with correctly calculated audit days, and the range narrows considerably.
Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.
Next step
Ready to start?
Tell us your scope, your headcount and your sites. We will come back within two to three working days with a fixed quotation and the audit-day calculation behind it.