How Long Does ISO Certification Take?

“How long will it take?”

My answer is always “it depends on where your business is starting from”.

There is no standard timescale. A business with established processes, good records and strong management involvement may be able to progress quicker than a business without, or a larger company operating across multiple sites, that will need longer.

The important thing is not simply to achieve certification as quickly as possible. Your management system needs to be implemented and understood by the team.  The management system needs to be put into practice and working before you reach the certification audit.

At HSEQ Excellence, we see certification as a journey rather than a race. Our approach follows a clear path from understanding your business and what it does; your current position through implementation, internal audit, management review and ultimately certification.

What are the stages of ISO certification?

1. Discovery and readiness assessment

Before developing anything new, it makes sense to understand what you already have.  Most established businesses are not starting from zero.

You may already have policies, processes, risk assessments, training arrangements, inspections, objectives, supplier controls, customer feedback systems or other arrangements that contribute towards meeting ISO requirements.

A readiness assessment reviews your existing processes, documentation and controls, identifies strengths and gaps and establishes what needs to happen next.

This allows an implementation plan to be developed around your actual starting point rather than assuming everything needs to be created from scratch.

2. Design and plan the management system

Once the gaps are understood, the management system can be designed and planned.

This may be for one standard, such as:

  • ISO 9001 – Quality Management
  • ISO 14001 – Environmental Management
  • ISO 45001 – Occupational Health and Safety Management

Alternatively, several standards can be brought together within an Integrated Management System (IMS).

The aim should be to align the necessary policies, processes and controls with ISO requirements while keeping the system relevant to how your business operates.

The amount of time required at this stage will depend heavily on what is already in place.

3. Implementation

Creating the management system is only part of the journey.  It then needs to be implemented across the business.

People need to understand their responsibilities, new or revised processes need to be communicated, controls need to be followed, and business needs to start generating evidence that the system is operating.

This may involve training, communication and ongoing support to embed new ways of working.

This stage should not be rushed simply to meet an audit date.  Remember, it is not a race to get the certificate.

A beautifully written management system that nobody is using is not going to demonstrate effective implementation.

4. Internal audit

Before certification, the business needs to undertake internal audits of its management system.

This provides an opportunity to check whether arrangements meet the relevant requirements and, importantly, whether they are working effectively in practice.  It can identify gaps, inconsistencies and opportunities for improvement before the external certification auditor arrives.

Any findings should then be appropriately addressed.

5. Management review

Senior management / Leadership Team / Business owners also need to review the performance and effectiveness of the management system.

Management review considers how the system is performing and provides an opportunity for leadership to consider matters such as objectives, audit results, performance, changes, resources, risks and opportunities, and improvement.

It is an important part of demonstrating both leadership commitment and system effectiveness.

6. Stage 1 certification audit

Once the business is ready, the formal certification process begins.

During the Stage 1 audit, your certification body reviews relevant management system information and assesses your readiness to progress to Stage 2.  Think of Stage 1 as an important readiness checkpoint.  If concerns are identified, they may need to be addressed before progressing to Stage 2.

7. Stage 2 certification audit

Stage 2 is the main certification audit.

The auditor assesses whether the management system has been effectively implemented across the business.  This goes beyond reviewing documents. Auditors may interview employees, review records, follow processes and observe activities taking place within the business.

If nonconformities are identified, these will need to be addressed in accordance with the certification body’s requirements before certification can be granted.

8. Certification and beyond

Subject to a satisfactory audit outcome and completion of the certification body’s independent certification decision process, certification can then be issued.

But this isn’t the end of the journey.

In many ways, certification is the beginning of the next stage.

Management system certification operates on a three-year certification cycle. During that period, the business must continue to maintain, use and improve its management system. The certificate is not evidence that everything was compliant on one day; it represents an ongoing commitment to meeting the requirements of the standard and ensuring that the management system remains effective.

Initial certification

For businesses seeking certification for the first time, the certification process includes the Stage 1 and Stage 2 audits (described above)

Year 1: Surveillance

Certification does not mean the auditor disappears for three years.

A surveillance audit takes place during the following year to assess whether the management system continues to conform to the standard and remains effectively implemented.

Surveillance audits are generally smaller than the initial certification or recertification audit and do not necessarily examine every requirement of the standard at every visit.

Instead, the certification body uses the surveillance visit across the certification cycle to examine different areas of the management system while also reviewing key requirements and performance indicators.

Year 2: Surveillance 2 and Recertification Planning

A further surveillance audit takes place during the second year of the cycle.

By this point, the certification body is not simply looking at whether the organisation still has the policies, procedures and processes that were originally audited.

It is looking for evidence that the management system is alive, being used and evolving with the business.

Businesses change. People join and leave. Processes develop. New risks and opportunities emerge. Customers change. Legislation changes. Technology develops. New products, services, sites or markets may be introduced.

The management system should respond to those changes rather than remaining frozen in the form it took when certification was first achieved.

The auditor and certification will take into account changes within the business and changes to the management system to plan for year 3 and the recertification visit.

Year 3: Recertification

Before the existing certification cycle comes to an end, a recertification audit is carried out.

Recertification is more comprehensive than a routine surveillance audit. Its purpose is to evaluate the continued conformity and effectiveness of the management system as a whole and its continued relevance and applicability to your business. 

The auditor will be looking at the business performance across the certification cycle, not simply what has happened since the previous surveillance visit.

This provides an opportunity to consider the bigger picture:

  • Is the management system still doing what it was designed to do?
  • Has it developed as the organisation has developed?
  • Is it helping the organisation achieve its intended outcomes?
  • Is there evidence of continual improvement?

Subject to a satisfactory recertification audit and completion of the certification body’s certification decision process, certification is renewed and the organisation begins a new three-year certification cycle.  A new certificate is issued

The process then continues:

Certification should never be viewed as the finish line.

The strongest businesses move away from thinking:

“What do we need to do for the auditor?”

and towards:

“How do we make this part of the way we run our organisation?”

That distinction is important.

A management system maintained purely for certification can quickly become paperwork.

A management system embedded into everyday operations becomes part of how the organisation works, makes decisions, manages risk, measures performance and improves.

So, how many months does ISO certification take?

There is no single answer, and you should be cautious about anyone promising certification within a fixed number of days without first understanding your organisation.

Timescales will be influenced by factors including:

  • the standard or standards being implemented;
  • the size and complexity of the organisation;
  • the number of sites;
  • the nature and risk of the activities undertaken;
  • what processes and controls are already established;
  • the maturity of existing management arrangements;
  • the availability of key people;
  • how quickly identified gaps can be addressed;
  • how effectively the system is implemented;
  • the availability of your chosen certification body; and
  • how quickly any certification audit findings are addressed.

For some business, the journey may take a matter of months; for others, it may take longer.

The better question is not “How quickly can we get the certificate?”

It is:

“How quickly can we build and demonstrate a management system that genuinely works for our business?”

Can ISO certification be fast-tracked?

Sometimes there is a genuine commercial deadline.

Perhaps a customer has requested certification, a tender requires it or the organisation needs certification before joining a particular supply chain.

In those circumstances, it may be possible to develop an accelerated implementation plan.

However, fast-tracking the project shouldn’t mean bypassing the important parts of the process.

The business still needs an implemented management system and sufficient evidence to demonstrate that it is operating effectively.

If you have a certification deadline, the best approach is to start early and work backwards from the required date.

What can delay ISO certification?

Interestingly, documentation isn’t always what causes the biggest delay.

Common causes include:

  • actions not being completed;
  • limited senior management involvement;
  • difficulty getting information from different departments;
  • processes being documented but not implemented;
  • insufficient records or evidence;
  • internal audit findings remaining unresolved;
  • management review not being completed;
  • changes being introduced but not communicated; and
  • waiting until the last minute to appoint a certification body.

ISO implementation works best when it is treated as a business project, with responsibilities, actions and timescales clearly defined.

Don’t rush towards the certificate.  Whilst the certificate is important, it should not become the sole objective.

More time spent getting the foundations right can result in a management system that is far easier to operate after certification.

At HSEQ Excellence, our approach is practical, proportionate and built around your business.

Have a certification in mind?

Whether you need ISO certification for a tender, customer requirement or as part of your wider business strategy, the first step is understanding where you are now.

Our ISO Readiness Assessment reviews your existing arrangements, identifies the gaps and provides a practical roadmap towards certification.

From there, we can help you understand what a realistic certification timescale looks like for your organisation.

Click the here for more information:

Scan the QR code to find out more about our ISO Readiness Assessment and start planning your ISO journey.

Similar Posts