ISO 9001 Certification Process: Steps, Timeline and What Auditors Check
The six stages of ISO 9001 certification, how long each takes and what auditors look for at Stage 1 and Stage 2.

- Published
- Written by
- SRA INT
- Section
- Blogs
- Related service
- ISO 9001 Certification
In this article10 sections
- Step 1: Agree the scope and run a gap analysis
- Step 2: Build the quality management system
- Step 3: Run the system and build evidence
- Step 4: Internal audit and management review
- Step 5: Stage 1 audit (readiness)
- Step 6: Stage 2 audit (implementation)
- After certification
- How long does ISO 9001 certification take?
- Which edition: ISO 9001:2015 or ISO 9001:2026?
- Key takeaways
- Frequently asked questions
Quick answer: The ISO 9001 certification process has six stages: gap analysis, building the quality management system, running it long enough to create records, an internal audit and management review, a Stage 1 audit of readiness, and a Stage 2 audit of how the system works in practice. Most small and mid-sized organisations finish in three to nine months.
Most managers we speak to have the same first question: “How long will this take, and what will the auditor actually look at?” Fair enough. ISO 9001 has a reputation for paperwork, but the organisations that get through certification smoothly are rarely the ones with the thickest manuals. They are the ones that understood the process early and built their system around the way they already work.
This guide walks through each step of the ISO 9001 certification process, what typically slows people down, and what auditors look for at each stage.
Step 1: Agree the scope and run a gap analysis
Before writing a single procedure, decide what the certificate will cover. Is it the whole company or one site? Design and manufacturing, or installation only? The scope appears on your certificate, so clients will read it.
Next, compare how you work today against the requirements of the standard. A good gap analysis gives you a short, prioritised list rather than a 40-page report. In our experience most organisations already meet a large part of the standard; the gaps tend to cluster around a few areas:
- Quality objectives that are not measured or reviewed
- No formal way of evaluating suppliers
- Customer complaints handled well but never recorded or analysed
- Training that happens but leaves no evidence
- Measuring equipment without a calibration schedule
Step 2: Build the quality management system
This is where you close the gaps. ISO 9001 asks for less mandatory documentation than many people expect. You will need a defined scope, a quality policy, measurable quality objectives and records that prove the system works. Beyond that, document what helps your people do the job consistently.
Keep it practical. A one-page process map that the team actually uses is worth more than a procedure nobody opens. Assign an owner to every process and agree how you will know whether it is performing.

Step 3: Run the system and build evidence
Auditors need to see the system working, not just written down. Plan for at least two to three months of operation before your certification audit. During this period you should be producing the records the auditor will sample: completed inspections, supplier evaluations, training records, corrective actions and objective tracking.
Step 4: Internal audit and management review
Before an external auditor arrives, check the system yourself. The internal audit should cover every process in scope and every clause of the standard. Findings are not a bad sign; an audit report with no findings at all usually makes an external auditor suspicious.
Then hold a management review. Top management looks at audit results, customer feedback, process performance and objectives, and decides what to improve. Keep the minutes; they are one of the first records a certification auditor asks for.
Step 5: Stage 1 audit (readiness)
The certification body reviews your documented information, confirms the scope and checks whether you are ready for Stage 2. Stage 1 is often partly remote. Expect questions about your context, interested parties, risks and opportunities, and whether the internal audit and management review have taken place.
Step 6: Stage 2 audit (implementation)
This is the main event. The auditor interviews people across the business, follows real orders or projects from enquiry to delivery and samples records. Any nonconformities must be addressed within the time the certification body sets, usually with a root-cause analysis and evidence of correction. Once they are closed, the certificate is issued.
After certification
An ISO 9001 certificate is normally valid for three years, with surveillance audits in years one and two and a recertification audit before expiry. Treat each visit as a free health check rather than an exam.
How long does ISO 9001 certification take?
| Organisation | Typical timeline | What usually drives it |
|---|---|---|
| Up to 25 people, single site | 3–4 months | Time to produce enough records |
| 25–150 people | 4–6 months | Number of processes and owners |
| Multi-site or design-heavy | 6–12 months | Site coordination and design controls |
Audit duration and cost are set mainly by headcount, number of sites and complexity, following accreditation rules, so ask for a quote once your scope is clear.
Which edition: ISO 9001:2015 or ISO 9001:2026?
ISO published ISO 9001:2026 in September 2026, and a transition period is now running. If you are starting today, we recommend building your system to the new edition so you do not have to change it again soon. Our news piece on what changes in ISO 9001:2026 covers the differences, and your certification body will confirm which edition it can certify against during the transition.
Whichever edition you use, choose a certification body that is accredited for ISO 9001. Accreditation is what gives the certificate international recognition; read why in our article on the new Global Accreditation Cooperation.
Key takeaways
- Fix the scope first; it appears on your certificate.
- Most gaps cluster around objectives, suppliers, complaints, training and calibration.
- Run the system for two to three months before the audit to build real evidence.
- Stage 1 checks readiness; Stage 2 checks that the system works in practice.
- Build new systems to ISO 9001:2026 to avoid a second change.
Frequently asked questions
Is ISO 9001 certification mandatory?
No. ISO 9001 is voluntary, but many clients, government tenders and major contractors in the GCC and elsewhere require it from their suppliers.
Can a small company get ISO 9001 certified?
Yes. The standard applies to organisations of any size. A small company simply needs fewer documents and a shorter audit.
How often are surveillance audits?
Usually once a year, in the two years between initial certification and recertification.
What happens if the auditor finds a nonconformity?
You correct it, investigate the root cause and send evidence to the certification body. Minor findings rarely delay the certificate for long.
Planning your certification? Explore ISO 9001 certification with SRA, or prepare your team with our ISO training courses. You can read ISO’s own overview of the standard on the ISO 9001 page at iso.org.


