How to Get ISO Certified: Complete Global Guide for Businesses

ISO certification is achieved by selecting the right standard, defining scope, completing a gap analysis, implementing an effective management system, conducting internal audits and management review, and passing independent Stage 1 and Stage 2 certification audits. The process should create practical business value, not merely produce documentation.

This comprehensive guide explains how organisations in the United Kingdom, Ireland, the Isle of Man, South Africa and the United States can prepare for ISO certification, avoid common mistakes, estimate costs and timescales, select an accredited certification body, verify certificates and maintain continual improvement after certification.

Executive Summary

  • ISO develops standards but does not certify organisations.
  • Certification is issued by an independent certification body against a defined scope.
  • The right standard depends on business objectives, risks, customer demands and legal obligations.
  • Strong leadership, practical processes, competent employees and reliable evidence are essential.
  • Internal audit and management review must occur before certification.
  • Certification does not automatically prove legal compliance.
  • Integrated systems can combine ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and ISO/IEC 20000-1.
  • Certification must be maintained through surveillance audits, corrective action and continual improvement.

Who Should Read This ISO Certification Guide?

This guide is relevant to company directors, business owners, compliance managers, quality managers, health and safety managers, environmental managers, information security professionals, IT service managers, operations leaders, procurement teams and organisations preparing for tenders or customer assurance reviews.

What Does ISO Certification Mean?

ISO certification is independent confirmation that an organisation’s management system conforms to the requirements of a specific ISO or ISO/IEC standard. The certificate applies only to the stated scope, sites and activities.

ISO publishes standards. Certification bodies conduct audits and issue certificates. Accreditation bodies assess the competence and impartiality of certification bodies.

Which ISO Standard Does Your Organisation Need?

ISO 9001: Quality Management

ISO 9001 supports consistent delivery, customer satisfaction, process control and continual improvement. It is suitable for organisations of all sizes and sectors.

ISO 14001: Environmental Management

ISO 14001 helps organisations identify environmental aspects, manage compliance obligations, reduce environmental risk and improve performance.

ISO 45001: Occupational Health and Safety

ISO 45001 provides a framework for hazard identification, worker participation, risk control and improvement of health and safety performance.

ISO/IEC 27001: Information Security

ISO/IEC 27001 supports a risk-based information security management system covering assets, access, suppliers, incidents, continuity, monitoring and improvement.

ISO/IEC 20000-1: IT Service Management

ISO/IEC 20000-1 supports consistent, controlled IT service management, including incidents, changes, service levels, suppliers, continuity and improvement.

ISO 22301: Business Continuity

ISO 22301 helps organisations prepare for disruption, protect critical activities and improve resilience.

How to Get ISO Certified: Step-by-Step Process

Step 1: Define the Business Case

Identify why certification is needed. Common drivers include tenders, customer requirements, growth, governance, reduced risk, market access and operational improvement.

Step 2: Select the Right Standard

Choose the standard that aligns with the organisation’s objectives and obligations. Avoid selecting standards purely for marketing value.

Step 3: Define the Certification Scope

The scope should clearly describe the legal entities, locations, activities, products and services included. A weak or misleading scope can create commercial and audit problems.

Step 4: Secure Leadership Commitment

Top management must approve objectives, provide resources, assign responsibility and review performance. Certification cannot be delegated entirely to a consultant.

Step 5: Complete an ISO Gap Analysis

A gap analysis compares current arrangements with the requirements of the chosen standard. It should identify strengths, missing controls, weak evidence and priority actions.

Step 6: Develop an Implementation Plan

Create a realistic plan with owners, resources, deadlines, risks, training, internal audit dates and certification milestones.

Step 7: Build and Implement the Management System

Develop proportionate policies, processes, risk registers, objectives, controls and records that reflect how the organisation actually works.

Step 8: Train and Engage Employees

Employees should understand the policy, relevant objectives, their responsibilities and the consequences of nonconformity.

Step 9: Operate the System and Retain Evidence

The organisation must demonstrate that the system is active. Evidence may include risk reviews, inspections, supplier assessments, complaints, incidents, actions and performance reports.

Step 10: Conduct Internal Audits

Internal audits test conformity, implementation and effectiveness. Findings should be evidence-based and lead to appropriate corrective action.

Step 11: Complete Management Review

Senior management should review risks, audits, performance, resources, incidents, objectives, changes and improvement opportunities.

Step 12: Select an Accredited Certification Body

Evaluate accreditation, sector competence, audit approach, availability, reputation and total cost. In the UK, UKAS-accredited certification is widely recognised.

Step 13: Complete the Stage 1 Audit

Stage 1 reviews readiness, scope, documentation and key system arrangements. It identifies whether the organisation is prepared for Stage 2.

Step 14: Complete the Stage 2 Audit

Stage 2 evaluates implementation through interviews, records, observation and sampling. Nonconformities must be addressed before certification is finalised.

Step 15: Maintain Certification

Certification requires ongoing internal audits, management review, corrective action, surveillance audits and continual improvement.

How Long Does ISO Certification Take?

Timescales depend on organisation size, complexity, standard, existing controls, leadership involvement and available resources. Small organisations with mature processes may become ready within a few months. Larger, multi-site or highly regulated organisations may require significantly longer.

How Much Does ISO Certification Cost?

Cost depends on scope, employee numbers, sites, sector risk, consultancy requirements, software, training and certification-body fees. Organisations should consider both initial and ongoing costs.

  • standard purchase;
  • gap analysis and consultancy;
  • employee time;
  • training;
  • software and Compliance Management Tools;
  • internal audits;
  • Stage 1 and Stage 2 audits;
  • surveillance audits; and
  • recertification.

ISO Certification for Different Organisation Sizes

Small Businesses

Small businesses should use simple, proportionate systems. The standard does not require excessive documentation.

Medium-Sized Organisations

Medium-sized businesses often need stronger process ownership, document control, supplier management and cross-functional reporting.

Large and Multi-Site Organisations

Large organisations need clear governance, site responsibilities, central controls, local implementation and consistent assurance.

International Groups

International groups should balance global consistency with jurisdiction-specific legal requirements and local operational controls.

Industry-Specific ISO Certification Considerations

Manufacturing and Engineering

Focus areas include process control, calibration, supplier quality, traceability, maintenance and environmental or safety risk.

Construction

Construction organisations often integrate ISO 9001, ISO 14001 and ISO 45001 to manage quality, environmental and health and safety risks.

Technology and Managed Services

ISO/IEC 27001 and ISO/IEC 20000-1 are particularly relevant for information security, cloud services, service delivery and customer assurance.

Financial and Professional Services

Key issues include information security, business continuity, supplier risk, confidentiality and regulatory assurance.

Healthcare and Social Care

Patient or service-user safety, data protection, competence, continuity and controlled processes are central.

Public Sector and Education

Procurement, accountability, information governance, service consistency and stakeholder requirements are common drivers.

International ISO Certification Considerations

United Kingdom

UK organisations frequently seek certification to support tenders, regulated supply chains and customer assurance. Accreditation should be checked carefully.

Ireland

Irish organisations may use ISO certification alongside EU law, the EU GDPR and multinational customer requirements.

Isle of Man

Isle of Man businesses often need certification that satisfies local governance while supporting UK and international markets.

South Africa

South African organisations may use ISO certification for tenders, supply chains, POPIA alignment, occupational safety and operational control.

United States

US organisations often use ISO certification for international customers, manufacturing supply chains, cybersecurity assurance and global market access.

ISO Certification and Legal Compliance

ISO certification does not automatically prove legal compliance. ISO standards provide management-system requirements, while legislation creates legal duties.

Organisations should maintain legal and contractual registers, assign owners, evaluate compliance and retain evidence.

ISO Certification, GDPR and Data Protection

ISO/IEC 27001 can support GDPR data protection through risk assessment, access control, incident response, supplier assurance and monitoring. It does not replace lawful basis, transparency, retention, data subject rights or breach-notification requirements.

ISO Certification and SOC 2

SOC 2 Type 1 evaluates control design at a specified date. SOC 2 Type 2 evaluates design and operating effectiveness over a defined period. ISO/IEC 27001 and SOC 2 may complement one another depending on customer and market needs.

Common ISO Certification Myths

Myth: ISO Is Only for Large Companies

ISO standards can be applied proportionately to organisations of any size.

Myth: Certification Guarantees Legal Compliance

It does not. Legal obligations must be identified and managed separately.

Myth: More Documents Mean Better Compliance

Effective implementation and evidence matter more than excessive documentation.

Myth: The Consultant Owns the System

The organisation’s leadership and process owners remain accountable.

Myth: Certification Is Finished After Stage 2

Certification begins an ongoing cycle of surveillance, review and improvement.

Common ISO Certification Mistakes

  • selecting the wrong scope;
  • copying generic templates;
  • weak leadership involvement;
  • insufficient employee awareness;
  • poor document control;
  • incomplete legal registers;
  • weak internal audits;
  • superficial root-cause analysis;
  • management review treated as a formality;
  • actions closed without evidence;
  • poor supplier control;
  • no measurable objectives;
  • focusing only on passing the audit; and
  • failing to improve after certification.

ISO Certification Readiness Maturity Model

Level 1: Reactive

Processes are informal, responsibilities are unclear and evidence is inconsistent.

Level 2: Basic

Key documents exist, but implementation and monitoring are uneven.

Level 3: Controlled

Processes, ownership, records, internal audits and corrective actions are established.

Level 4: Managed

Performance is measured, risks are actively managed and leadership uses the system for decision-making.

Level 5: Optimised

The management system is integrated with strategy, data, automation and continual improvement.

Key Performance Indicators for ISO Management Systems

  • objective achievement;
  • customer complaints and satisfaction;
  • nonconformities and repeat findings;
  • corrective-action closure time;
  • supplier performance;
  • training completion and competence;
  • incidents and near misses;
  • environmental performance;
  • security incidents;
  • service availability;
  • audit completion; and
  • overdue reviews and actions.

Digital Transformation and Compliance Management Software

Spreadsheets, shared drives and email can become difficult to control as standards, sites and jurisdictions increase. A Compliance Management Platform can centralise obligations, policies, risks, audits, evidence, actions and reporting.

Effective Compliance Management Tools can help organisations:

  • map controls across several standards;
  • assign owners and deadlines;
  • control documents and approvals;
  • manage risk and legal registers;
  • track internal audits and corrective actions;
  • retain certification evidence;
  • monitor performance; and
  • produce leadership dashboards.

To see how ISO requirements, audits, risks and actions can be managed in one integrated system, book an Objectly demonstration.

Illustrative ISO Certification Case Study

Challenge: A growing multi-site service organisation relied on spreadsheets, inconsistent procedures and informal risk management.

Approach: The organisation defined scope, completed a gap analysis, assigned process owners, created an integrated management system, trained employees and completed internal audits and management review.

Outcome: Audit readiness improved, responsibilities became clearer, evidence was easier to retrieve and recurring issues were addressed through corrective action.

Lesson: Certification succeeds when the management system improves daily operations rather than existing only for the auditor.

How to Verify an ISO Certificate

Request the certificate and review:

  • legal organisation name;
  • certified sites;
  • scope;
  • standard and edition;
  • certificate number;
  • issue and expiry dates;
  • certification body; and
  • accreditation mark.

Confirm validity with the certification body or an official directory where available. Check that the certification body’s accreditation covers the relevant standard and sector.

How Compliance Managers Can Help

Compliance Managers Group brings certified implementation and lead-auditor capability across ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and ISO/IEC 20000-1, supported by degree-level safety management education and more than 25 years of practical experience in business management, IT, IT support, IT security, systems development, legal compliance management, project management and operating businesses.

Support can include:

  • standard selection and scope definition;
  • gap analysis;
  • implementation planning;
  • integrated management-system design;
  • policy, process and register development;
  • legal and contractual compliance mapping;
  • employee training;
  • internal audits;
  • management-review preparation;
  • certification-body readiness;
  • Compliance Management Solutions; and
  • ongoing outsourced support.

Frequently Asked Questions About ISO Certification

Can a small business get ISO certified?

Yes. The system should be proportionate to the organisation’s size, activities and risk.

Does ISO issue certificates?

No. Independent certification bodies issue certificates.

Is ISO certification legally required?

Usually not, but it may be required by contracts, tenders, regulators, customers or sector schemes.

Can one system cover multiple standards?

Yes. Shared structures allow quality, environmental, safety, information security and IT service requirements to be integrated.

What happens if an organisation fails an ISO audit?

Nonconformities must be addressed. Certification depends on the severity of findings and satisfactory corrective action.

How long does a certificate remain valid?

Certificates normally operate within a multi-year certification cycle with surveillance audits and eventual recertification.

Do employees need formal ISO qualifications?

Not usually, but employees must be competent for their assigned responsibilities.

Can certification be transferred between certification bodies?

Often yes, subject to review and acceptance by the receiving certification body.

Can a company certify only one department?

Potentially, provided the scope is clear, meaningful and not misleading.

Does ISO certification increase revenue?

Certification does not guarantee revenue, but it may improve tender eligibility, market access and customer confidence.

What is a nonconformity?

A nonconformity is a failure to meet a requirement of the standard, the management system or an applicable obligation.

What is corrective action?

Corrective action addresses the cause of a nonconformity to prevent recurrence.

What is the difference between certification and accreditation?

Certification bodies certify organisations. Accreditation bodies assess certification bodies.

Is remote ISO certification possible?

Some audit activities may be conducted remotely, depending on risk, accreditation rules, scope and certification-body arrangements.

Can ISO certification support tenders?

Yes. Many buyers request certification or equivalent evidence during procurement.

Conclusion: Build a System That Works Beyond the Audit

ISO certification should strengthen governance, consistency, customer confidence, risk control and continual improvement. The certificate is the visible result; the real value is the management system behind it.

Compliance Managers can help organisations across the United Kingdom, Ireland, the Isle of Man, South Africa and the United States select the right standards, prepare for an ISO audit and implement a practical system that delivers value beyond certification.

Categories

Consulting

Comments are closed

Latest Comments

No comments to show.