Resources
Frequently asked questions
Straight answers, including to the questions a certification body would rather you did not ask. If yours is not here, ask us directly — we answer technical questions without requiring an enquiry first.
116 questions answered
For most organisations, ISO 9001. It establishes the management system structure — context, leadership, planning, competence, internal audit, management review — that every other standard reuses, so a later ISO 14001 or ISO 45001 becomes an addition rather than a fresh build. The exceptions are sector-driven: an IT services company whose customers are asking security questions should start with ISO 27001, a food business with ISO 22000 or HACCP, and a medical device manufacturer with ISO 13485.
There is no fixed minimum period, but there is a fixed minimum of evidence. You need at least one complete cycle of internal audits covering the full scope, and at least one management review with the inputs and outputs the standard requires. In practice that means around three months of genuine operation as an absolute floor, and most organisations need longer.
Yes, and it is usually the efficient route. Standards sharing the High Level Structure — ISO 9001, 14001, 45001, 27001, 22301, 50001 and others — can be operated as one integrated management system and audited together. Integrated audits attract permitted audit-day reductions, so two standards audited together cost meaningfully less than two separate certifications.
No. Many organisations certify without one, particularly where someone internal has been through an implementation before. A consultant buys pace and helps avoid known pitfalls. What a consultant cannot supply is internal ownership, and a system built entirely by an external party without internal engagement tends to fail its first surveillance audit.
Yes. Transfer is a defined process under IAF MD 2. We review your current certificate, the accreditation status of the issuing body, your most recent audit reports and the status of any open nonconformities. Where the existing certification is accredited and in good standing, transfer is usually straightforward and does not require a full initial certification audit.
Cost is driven by audit days, which are calculated under IAF MD 5 from your effective headcount and the risk category of your activity — not set commercially. That means we cannot quote meaningfully without your headcount, scope and number of sites, and any body that quotes a flat price without asking for those is not calculating audit days properly. Our quotations show the calculation, cover the full three-year cycle including both surveillance audits, and state travel separately at cost.
For an organisation with a working system, typically eight to twelve weeks from application to certificate: two to three days for the quotation, about a week to contract and plan, Stage 1, a gap of two to four weeks, Stage 2, then nonconformity closure and the certification decision. If the system still has to be built, add three to six months of implementation before any of that starts.
Three reasons, in order of importance. First, whether the certification is accredited — unaccredited certificates cost less because they are worth less. Second, whether the audit days match the IAF MD 5 calculation. Third, whether surveillance audits are included in the quoted figure or charged separately later. Compare the three-year total for accredited certification with correctly calculated audit days, and the range narrows considerably.
They are quoted separately and charged at actual cost, not marked up. Where we have an assessor resident near your site, travel cost is minimal — which is one practical reason our regional coverage matters.
A major nonconformity means a requirement is absent, or a failure raises significant doubt that the system can deliver conforming outputs — a required process that does not exist, or the same failure appearing across multiple samples. A minor nonconformity is an isolated lapse where the process is otherwise applied. Majors must be closed with verified corrective action before certification can be recommended; minors are usually closed on documentary evidence.
Yes, and you should if you believe it is wrong. Every finding is presented at the closing meeting specifically so it can be discussed while the evidence is available. If a factual disagreement cannot be resolved there, you can appeal formally within 30 days, and the appeal is reviewed by people who were not involved in the original decision.
No, and this is a genuine constraint rather than unhelpfulness. Under ISO/IEC 17021-1 an auditor must not provide consultancy to a client they audit — advising on the solution would compromise the independence of the assessment. We will explain precisely what the requirement is and what evidence would satisfy it. Choosing how to meet it is yours.
Partly, where the technique is appropriate and permitted. Document review, records examination and some interviews can be conducted remotely under IAF MD 4. Verification of physical processes, site conditions and shop-floor practice requires attendance. We will tell you at planning which activities can be remote and why the rest cannot.
There is no pass or fail as such — there are findings. Major nonconformities delay the certification decision until closed, sometimes requiring a follow-up visit. Certification is only refused where the system is so far from conformity that closure within a reasonable period is not credible, and in that case we say so clearly at the closing meeting rather than after.
Three years from the certification decision date, conditional on successful surveillance audits at approximately twelve and twenty-four months. It is not a three-year certificate you can put in a drawer; missing a surveillance audit puts it at risk of suspension.
Every GMSCPL certificate carries a unique certificate number and can be verified through the certificate verification page on this site, or by contacting us directly. Anyone may verify a certificate; no authorisation from the certified organisation is required, because a certificate that cannot be independently checked is not doing its job.
It means the certification body itself has been assessed by a national accreditation body against ISO/IEC 17021-1, and that the accreditation body is a signatory to the IAF Multilateral Recognition Arrangement. That MLA signature is the mechanism by which a certificate issued in India is recognised elsewhere. A certificate without accreditation from an MLA signatory is a private document — it may look identical and many customers will not accept it.
No. A management system certificate certifies your system, not your product, and applying the mark to a product or its packaging implies product certification. You may use it on letterheads, websites, brochures, vehicles and business cards, alongside your certificate number and the scope. Our Certification Marks Usage Guidelines set out the rules in full and are available in Downloads.
Not to the same client. ISO/IEC 17021-1 prohibits a certification body from providing management system consultancy to an organisation it certifies, and we apply that rule strictly. We do offer advisory services — gap analysis, documentation and implementation support — but an organisation that receives them from us must be certified by a different body for the cooling-off period the accreditation rules define. We tell clients this in writing before any engagement begins.
A certification decision-maker who did not conduct your audit. The audit team gathers evidence and makes a recommendation; an independent reviewer examines the file and makes the decision. This separation is required by ISO/IEC 17021-1 and is one of the things an accreditation body checks most carefully.
Everything observed during an audit is confidential to the client. Auditors are bound by written confidentiality agreements, information is disclosed only with your authorisation or where law requires it, and where the law requires disclosure we tell you that it is being made unless prohibited from doing so.
By verified technical competence for your scope and sector, and by the absence of any conflict of interest — including whether they have provided consultancy or worked for your organisation within the period the rules define. Availability is a scheduling constraint, never a selection criterion.
For an organisation with a working quality system, eight to twelve weeks from application to certificate is typical. If the system still has to be built, allow three to six months for implementation before the Stage 1 audit. The audit itself is usually one day for Stage 1 and two to four days for Stage 2, depending on headcount, number of sites and process complexity.
Audit duration is not negotiable and not set by us commercially — it is calculated from IAF MD 5, which maps effective headcount and risk category to a minimum number of days. We publish the calculation with your quotation so you can see exactly how the figure was reached.
No. ISO 9001 is voluntary in law. In practice it is frequently made contractually mandatory by customers, by tender conditions, or by principals in an export supply chain — which is why most organisations pursue it.
ISO 9001:2015 removed the mandatory quality manual. What it requires is "documented information" — the specific records and procedures the standard names, plus whatever your organisation needs to operate its processes reliably. Many organisations still keep a manual because it is a convenient index; it is a choice, not a requirement.
Three years, subject to successful surveillance audits at approximately 12 and 24 months. A full recertification audit is conducted before expiry to issue the next three-year cycle.
Yes, and it is usually the efficient choice. Both standards share the High Level Structure, so context, leadership, internal audit, management review and improvement can be run as one integrated system. An integrated audit reduces total audit days compared with two separate certifications.
No. The standard does not set numeric environmental performance limits. It requires you to identify the limits that legally apply to you, comply with them, evaluate that compliance periodically, and improve your environmental performance. The numbers come from your regulator, not from ISO.
An open notice does not automatically prevent certification, but it must be disclosed. We will examine your response, root cause analysis and corrective action. An unaddressed or concealed regulatory breach will result in a major nonconformity.
Where your consent conditions require monitoring, yes — the results are evidence of compliance evaluation. Reports should come from a laboratory recognised for the relevant parameters.
OHSAS 18001 was withdrawn in March 2021 and is no longer a valid certification. Migration requires you to add the elements ISO 45001 introduced — organisational context, interested parties, leadership accountability, worker consultation mechanisms, and OH&S risks and opportunities beyond hazard-level risk. In most cases a transition audit rather than a full initial certification is sufficient.
More on ISO 45001 – Occupational Health & Safety Management System
Yes. Clause 8.1.4 explicitly extends control to procurement, contractors and outsourced processes. Auditors will examine contractor selection criteria, induction, work permits and supervision, because that is where a large share of serious injuries occur.
More on ISO 45001 – Occupational Health & Safety Management System
By speaking to non-managerial workers directly, in confidence. We look for evidence that workers were consulted on hazard identification and incident investigation, that they can raise concerns without fear of reprisal, and that raised concerns were acted upon.
More on ISO 45001 – Occupational Health & Safety Management System
HACCP is a hazard-control methodology, not a management system. ISO 22000 wraps HACCP inside a full management system with leadership, planning, competence, verification and improvement. FSSC 22000 is ISO 22000 plus the sector-specific ISO/TS 22002 prerequisite programme and additional scheme requirements — and unlike ISO 22000 on its own, it is GFSI-recognised.
More on ISO 22000 / FSSC 22000 – Food Safety Management System
Yes. A valid FSSAI licence covering the products and site in your certification scope is a compliance obligation. We verify it during Stage 1; an expired or scope-mismatched licence will block progression.
More on ISO 22000 / FSSC 22000 – Food Safety Management System
Yes. Traceability that has never been tested is an assumption. ISO 22000 requires verification of the traceability system, and we expect a documented mock recall with a stated timeframe, mass-balance reconciliation and a conclusion on effectiveness.
More on ISO 22000 / FSSC 22000 – Food Safety Management System
Yes. ISO 22000 covers the whole food chain including food service. The prerequisite programmes applicable to catering (ISO/TS 22002-2) differ from those for manufacturing, and the audit is scoped accordingly.
More on ISO 22000 / FSSC 22000 – Food Safety Management System
Annex A was restructured from 114 controls across fourteen domains into 93 controls across four themes, with eleven genuinely new controls covering threat intelligence, cloud security, ICT readiness for continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring, web filtering and secure coding. Organisations still certified to the 2013 version were required to transition by 31 October 2025.
No. Controls are selected on the basis of your risk assessment. What is mandatory is the Statement of Applicability recording which controls apply, which do not, and why. Excluding a control is entirely legitimate when the risk assessment supports it; excluding it because it is inconvenient is not.
The standard does not name penetration testing as a mandatory control. In practice, control 8.8 on technical vulnerability management is very difficult to evidence credibly without vulnerability assessment, and most organisations in scope for ISO 27001 conduct periodic testing. What we assess is whether findings were tracked and remediated, not the test report alone.
Yes — scope is yours to define, and a narrow initial scope is often sensible. But the scope statement must be honest about boundaries, interfaces and dependencies, and the certificate will state it precisely. Customers do read the scope line; a certificate that excludes the service they are buying will not satisfy them.
ISO 27001 certifies that a management system conforms to an international standard; SOC 2 is an attestation report by a CPA firm against the AICPA Trust Services Criteria. They overlap substantially in control content. ISO 27001 is more widely recognised outside North America and results in a certificate; SOC 2 results in a report. Many organisations eventually hold both.
The standard requires exercising at planned intervals and after significant change, without prescribing a frequency. Common practice is at least annually for each critical plan, with a mix of tabletop and technical exercises. What we assess is whether the programme is justified against your risk profile and whether findings were acted on.
No. Disaster recovery restores IT systems and is a subset of continuity. ISO 22301 covers the whole organisation — people, premises, suppliers, communications and process workarounds — including situations where IT is fine and something else has failed.
Yes, and the fit is natural. ISO 27001:2022 control 5.30 addresses ICT readiness for business continuity, which ISO 22301 develops in full. Organisations frequently certify both under one integrated audit programme.
The standard does not set a numeric target. It requires demonstrated improvement in energy performance against your own baseline, using your own EnPIs. The target is yours; the demonstration is mandatory.
They are complementary. PAT sets specific energy consumption targets for designated consumers under Indian law; ISO 50001 provides the management system that makes those targets achievable and the measurement infrastructure that makes them defensible. Neither substitutes for the other.
Enough to measure your significant energy uses separately from total site consumption. A single main meter is rarely sufficient — if you cannot isolate the consumption of your major loads, you cannot establish meaningful EnPIs or attribute improvement.
For the device business, yes — ISO 13485 is the recognised quality system standard and customers in the sector ask for it specifically. Organisations with both device and non-device product lines sometimes hold both, scoped to their respective activities.
More on ISO 13485 – Medical Devices Quality Management System
No. ISO 13485 certification is a quality system certification. CE marking under the EU MDR requires conformity assessment by a designated Notified Body against the regulation itself, including technical documentation and clinical evaluation. ISO 13485 is a prerequisite for that route, not a substitute.
More on ISO 13485 – Medical Devices Quality Management System
ISO 13485 requires risk management across the product realisation lifecycle and references ISO 14971 as the method. In practice, an auditor will expect an ISO 14971-structured risk management file; a generic risk register will not satisfy the requirement.
More on ISO 13485 – Medical Devices Quality Management System
Only if your device and process require controlled contamination levels — sterile devices, implantables and certain IVDs typically do. Where a cleanroom is used it must be qualified and monitored, and the monitoring records are audited.
More on ISO 13485 – Medical Devices Quality Management System
No. ITIL is a framework of good practice and its certifications are held by individuals. ISO/IEC 20000-1 is a standard that organisations are certified against. ITIL adoption is excellent preparation but is neither necessary nor sufficient on its own.
Yes, but the standard requires you to demonstrate governance of processes operated by other parties. You must show control of the outsourced services through defined requirements, monitoring and review. You cannot certify a scope whose processes you neither operate nor govern.
Very commonly, yes. The two share a management system structure and interlock at incident management, change management, capacity and continuity. An integrated audit programme reduces total audit days and prevents two systems drifting apart.
ISO 9001 treats the learner as a customer. ISO 21001 recognises that the learner is the primary beneficiary while parents, employers, funders and regulators are separate interested parties with distinct requirements, and it adds education-specific requirements on curriculum design, learning outcome assessment, accessibility and learner data. It is a better structural fit for an educational organisation.
More on ISO 21001 – Educational Organizations Management System
No. NAAC and NBA are national accreditation frameworks for higher education institutions with their own criteria and processes. ISO 21001 is a management system certification and complements them — the evidence base built for ISO 21001 supports NAAC and NBA submissions substantially.
More on ISO 21001 – Educational Organizations Management System
Yes. The standard is delivery-mode neutral. For online providers the audit gives particular attention to platform availability, learner support responsiveness, assessment integrity and data protection.
More on ISO 21001 – Educational Organizations Management System
No, and the standard says so explicitly. Certification confirms that an anti-bribery management system conforming to the requirements has been implemented — it is not a warranty that bribery has never occurred or will never occur. What it demonstrates is that reasonable and proportionate procedures are in place to prevent, detect and respond to it.
ISO 37001 treats facilitation payments as bribes. Where they are illegal in the applicable jurisdiction — as they are in India — the system must prohibit them. Where an organisation faces genuine coercion, the standard expects a documented policy on how such situations are handled, recorded and reported.
The function must have appropriate competence, status, authority and independence, and direct access to the governing body. In smaller organisations it may be an existing senior role, provided there is no conflict of interest with the commercial decisions being controlled.
Either. ISO 41001 explicitly addresses both the demand organisation and the facility management organisation, and an internal corporate real estate function can certify its own management system.
ISO 55001 governs the whole lifecycle value of physical assets — acquisition, operation, renewal and disposal — at a portfolio level. ISO 41001 governs the delivery of facility services within the built environment. They complement each other; large asset-intensive organisations often hold both.
No. ISO 27701 is an extension to an ISO 27001 ISMS and has no independent existence. You can certify both together in a single audit programme, or add ISO 27701 to an existing ISO 27001 certificate at a surveillance or recertification audit.
It does not, and no certification can. GDPR and the DPDP Act are laws; compliance is determined by regulators and courts. ISO 27701 gives you a management system that addresses the operational obligations of those laws and produces the evidence a regulator would ask for. It is strong supporting evidence, not a legal shield.
You may well be both, in different contexts — a processor for client data and a controller for your own employee and marketing data. ISO 27701 allows a scope covering both roles, and the audit examines the applicable control set for each.
No. AEO status is granted by Indian Customs under CBIC following their own application and validation process. ISO 28000 certification does not confer it, but the control evidence overlaps substantially and organisations holding ISO 28000 typically find the AEO application materially easier to complete.
More on ISO 28000 – Security Management System for the Supply Chain
Any organisation with security risk in its supply chain can certify. The 2022 revision explicitly broadened the framing beyond logistics operators to manufacturers, retailers and service providers.
More on ISO 28000 – Security Management System for the Supply Chain
No. IATF 16949 must be implemented alongside ISO 9001:2015 — it defines the automotive supplement, not the base management system. The audit assesses both together and the certificate reflects the combined system.
Yes. IATF rules require that the organisation supplies, or has been contracted to supply, automotive customer parts. Sites with no automotive customer are not eligible for IATF certification, though they may certify to ISO 9001.
Each OEM publishes its own additional requirements — on PPAP submission levels, warranty handling, labelling, reporting and much else — that suppliers must meet in addition to IATF 16949. Conformance to the CSRs of every customer in your scope is mandatory and is audited.
Yes, deliberately. Audit days, auditor qualification, nonconformity response timeframes and certification decisions all follow IATF-mandated rules. Certain findings — including failure to close a major nonconformity within the required period — carry mandatory certificate suspension with no discretion available to the certification body.
For most product categories there is no CE certificate to issue — CE marking is a self-declaration by the manufacturer, supported by a technical file. Where the applicable legislation mandates third-party assessment, that must be performed by an EU-designated Notified Body. Our role is to prepare you correctly for either route.
CE marking has no expiry date, but the declaration must remain accurate. Any change to the product, to the applicable legislation, or to the harmonised standards may require reassessment and an updated technical file and Declaration of Conformity.
The ISI Mark Scheme applies to products under a Quality Control Order and involves a full factory inspection plus ongoing in-house testing. The Compulsory Registration Scheme covers electronics and IT goods and is based on self-declaration supported by testing at a BIS-recognised laboratory, without a factory inspection. Which applies is determined by the product, not by preference.
CRS registration typically takes six to ten weeks, dominated by laboratory testing turnaround. ISI mark licensing usually takes three to six months because it includes factory inspection and in-house laboratory establishment. FMCS applications generally take longer.
For ISI mark licences, yes — the scheme requires the manufacturer to conduct specified routine and acceptance tests in-house, with calibrated equipment and competent personnel. The required scope is defined by the applicable Indian Standard.
HACCP certifies the hazard control methodology. ISO 22000 certifies a full food safety management system that contains HACCP plus leadership, planning, competence, communication, verification and improvement. If your buyer specifies HACCP, or you want certified hazard control quickly, start with HACCP. If you need GFSI recognition or a management-system-level certificate, go to ISO 22000 or FSSC 22000.
There is no correct number. Too many usually indicates that prerequisite programmes are being misclassified as critical control points; too few usually indicates hazards have been missed. What matters is that each determination is justified by the hazard analysis and defensible against the decision tree.
Yes. A critical limit must be shown to actually control the hazard — through published scientific literature, regulatory limits, validated processing studies or challenge testing. A limit chosen because it matched current practice is not a validated limit.
No. Importing countries recognise specific Halal certification bodies, and recognition lists differ between Malaysia (JAKIM), Indonesia (BPJPH), the UAE (ESMA/MOIAT) and others. Certification must be obtained from a body recognised by your destination market. We help determine which recognition your target market requires.
In many schemes yes, provided segregation is complete and demonstrable — separate lines or validated cleaning between runs, separate storage, separate utensils, and traceability that keeps the streams distinct. Some schemes and some products require fully dedicated facilities. The applicable rule depends on the certifying body and the product category.
No. Pharmaceuticals, nutraceuticals, cosmetics and personal care products are increasingly certified, because ingredients such as gelatin, glycerin, stearates and alcohol carriers raise the same questions there as in food.
It depends on risk. For a repeat item from a proven supplier, a pre-shipment inspection may be sufficient. For a first article, a critical component or a new supplier, in-process inspection at defined hold points catches problems while they are still correctable. We recommend the pattern during scoping.
We record the nonconformity with photographic evidence and issue the report. The commercial decision — accept, rework, reject or accept with concession — belongs to you. Our role is to give you accurate information, not to make the decision.
Usually, subject to inspector availability at the location and the technical discipline involved. Assignments requiring specialist qualification, such as NDT Level II or coating inspection, need more lead time.
A certification audit assesses conformity to a published standard and results in a certificate. A factory audit assesses capability against your requirements and results in a report and score for your commercial decision. The audit criteria are set by you, not by ISO.
Yes, where your contract with the supplier permits it. Unannounced and semi-announced audits are common in social compliance and food safety, precisely because they observe normal operating conditions rather than a prepared presentation.
Yes, through our international auditor network. Lead time and cost vary with location; we confirm both during scoping.
As deep as the risk justifies and access permits. For most categories, Tier 1 and the critical Tier 2 sources account for the majority of the exposure. Where a specific material carries regulatory or reputational risk we trace it to origin.
That refusal is itself a finding, and a significant one. We record it and report it. Contractually, the ability to audit sub-tiers is best secured in the supply agreement before it is needed.
ISO 9001, ISO 14001, ISO 45001, ISO 22000, ISO 27001, ISO 50001 and ISO 13485 are run on a scheduled calendar. Other standards are delivered on request where a minimum group size is met.
Yes. The course is assessed continuously across the five days and concludes with a written examination. Both components must be passed. Delegates who pass continuous assessment but not the examination may normally re-sit the examination within twelve months.
Passing gives you the training qualification — the first of three requirements. Full IRCA auditor certification additionally requires demonstrated work experience and a logged number of audit days at the appropriate grade. The course is the entry point, not the destination.
Yes. In-house delivery is generally economical from around eight delegates, can be scheduled around your operations, and allows examples to be drawn from your own sector.
Two days for a single standard. Integrated courses covering two or three standards typically run three days, because the audit planning and evidence-gathering content is shared while the technical requirements are not.
No. Every management system standard requires objectivity and impartiality in the audit process. Auditors must not audit their own work. In small organisations this is usually solved by cross-functional auditing — production audits quality, quality audits purchasing, and so on.
The course includes assessment exercises and a short end-of-course assessment. It is a competence-building course, not an IRCA-certified examination course; delegates receive a certificate of successful completion.
Typically half a day for a single standard at operator level, and one full day where the audience needs to apply requirements rather than simply recognise them. Top management briefings usually run two to three hours.
Yes. Shop-floor awareness training is substantially less effective in a language the audience does not use at work. We deliver in Hindi, Telugu and English as standard, and other languages on request.
Up to around thirty for an interactive session. Larger groups are better split into multiple sessions — beyond that size participation collapses and the training becomes a presentation.
In-house delivery becomes economical from around eight delegates for most programmes. Below that, public course enrolment is usually the better value.
Yes. Multi-site programmes are run to a common syllabus and assessment so competence is comparable across locations, with site-specific examples inserted where processes differ.
Yes, for content that survives the format — awareness, standard interpretation and documentation workshops work well live-online. Practical audit skills training is materially better in person, and we will say so rather than sell a weaker delivery.
Typically one to three days on site depending on headcount, sites and the number of standards in scope, plus about a week for the report. Multi-site or multi-standard assessments take longer.
Yes — this matters, so we state it plainly. Advisory work creates an impartiality conflict under ISO/IEC 17021-1. If we conduct your gap analysis as a consultancy engagement, your certification must be performed by a different certification body for the applicable cooling-off period. A pre-audit conducted under our certification process is a different thing and does not carry that consequence; we will help you choose the right route before you commit.
They overlap in method and differ in purpose and consequence. A pre-audit is part of the certification process and identifies findings without recommending solutions. A gap analysis is advisory and includes recommendations on how to close what it finds — which is precisely why it triggers the impartiality rule.
Not for ISO 9001:2015, which removed the requirement. ISO 13485 does still require one. Many organisations keep a manual voluntarily because it is a useful index and a convenient document to hand to a customer, but for most standards it is a choice rather than an obligation.
We can, and we will tell you honestly that unmodified templates are the leading cause of documentation nonconformity. If budget dictates a template start, the essential work is the adaptation — and that is the part that must not be skipped.
Enough that the process is performed consistently by a competent person, plus whatever the standard specifically names. If a document exists that nobody reads and no requirement demands, it is a maintenance liability rather than a control.
Three to six months for a single standard in an organisation with defined processes; six to twelve for a complex, multi-site or multi-standard scope, or where the underlying processes need to be established first. Anyone promising six weeks is describing documentation, not implementation.
Many organisations do, successfully — particularly where someone internal has run an implementation before. The standards are publicly available and the requirements are readable. External support buys pace and avoids known pitfalls; it is not a substitute for internal ownership, and no adviser can supply that.
No, and any provider claiming otherwise is describing something other than an independent certification process. Certification is decided by an audit against evidence. What structured implementation does is make the evidence exist.
Next step
Still unanswered?
Send us the question. Technical questions get a technical answer from someone who conducts audits, not a sales response.