Certification

ISO 9001 Certification Process: Steps, Timeline and What Auditors Check

The six stages of ISO 9001 certification, how long each takes and what auditors look for at Stage 1 and Stage 2.

Quality manager reviewing ISO 9001 certification documents and performance charts
Records and measured objectives are the evidence auditors sample.
Published
Written by
SRA INT
Section
Blogs
Related service
ISO 9001 Certification
In this article10 sections
  1. Step 1: Agree the scope and run a gap analysis
  2. Step 2: Build the quality management system
  3. Step 3: Run the system and build evidence
  4. Step 4: Internal audit and management review
  5. Step 5: Stage 1 audit (readiness)
  6. Step 6: Stage 2 audit (implementation)
  7. After certification
  8. How long does ISO 9001 certification take?
  9. Which edition: ISO 9001:2015 or ISO 9001:2026?
  10. Key takeaways
  11. Frequently asked questions

Quick answer: The ISO 9001 certification process has six stages: gap analysis, building the quality management system, running it long enough to create records, an internal audit and management review, a Stage 1 audit of readiness, and a Stage 2 audit of how the system works in practice. Most small and mid-sized organisations finish in three to nine months.

Most managers we speak to have the same first question: “How long will this take, and what will the auditor actually look at?” Fair enough. ISO 9001 has a reputation for paperwork, but the organisations that get through certification smoothly are rarely the ones with the thickest manuals. They are the ones that understood the process early and built their system around the way they already work.

This guide walks through each step of the ISO 9001 certification process, what typically slows people down, and what auditors look for at each stage.

Step 1: Agree the scope and run a gap analysis

Before writing a single procedure, decide what the certificate will cover. Is it the whole company or one site? Design and manufacturing, or installation only? The scope appears on your certificate, so clients will read it.

Next, compare how you work today against the requirements of the standard. A good gap analysis gives you a short, prioritised list rather than a 40-page report. In our experience most organisations already meet a large part of the standard; the gaps tend to cluster around a few areas:

  • Quality objectives that are not measured or reviewed
  • No formal way of evaluating suppliers
  • Customer complaints handled well but never recorded or analysed
  • Training that happens but leaves no evidence
  • Measuring equipment without a calibration schedule

Step 2: Build the quality management system

This is where you close the gaps. ISO 9001 asks for less mandatory documentation than many people expect. You will need a defined scope, a quality policy, measurable quality objectives and records that prove the system works. Beyond that, document what helps your people do the job consistently.

Keep it practical. A one-page process map that the team actually uses is worth more than a procedure nobody opens. Assign an owner to every process and agree how you will know whether it is performing.

The six stages of the ISO 9001 certification process, from gap analysis to the Stage 2 audit
The six stages of ISO 9001 certification.

Step 3: Run the system and build evidence

Auditors need to see the system working, not just written down. Plan for at least two to three months of operation before your certification audit. During this period you should be producing the records the auditor will sample: completed inspections, supplier evaluations, training records, corrective actions and objective tracking.

Step 4: Internal audit and management review

Before an external auditor arrives, check the system yourself. The internal audit should cover every process in scope and every clause of the standard. Findings are not a bad sign; an audit report with no findings at all usually makes an external auditor suspicious.

Then hold a management review. Top management looks at audit results, customer feedback, process performance and objectives, and decides what to improve. Keep the minutes; they are one of the first records a certification auditor asks for.

Step 5: Stage 1 audit (readiness)

The certification body reviews your documented information, confirms the scope and checks whether you are ready for Stage 2. Stage 1 is often partly remote. Expect questions about your context, interested parties, risks and opportunities, and whether the internal audit and management review have taken place.

Step 6: Stage 2 audit (implementation)

This is the main event. The auditor interviews people across the business, follows real orders or projects from enquiry to delivery and samples records. Any nonconformities must be addressed within the time the certification body sets, usually with a root-cause analysis and evidence of correction. Once they are closed, the certificate is issued.

After certification

An ISO 9001 certificate is normally valid for three years, with surveillance audits in years one and two and a recertification audit before expiry. Treat each visit as a free health check rather than an exam.

How long does ISO 9001 certification take?

Organisation Typical timeline What usually drives it
Up to 25 people, single site 3–4 months Time to produce enough records
25–150 people 4–6 months Number of processes and owners
Multi-site or design-heavy 6–12 months Site coordination and design controls

Audit duration and cost are set mainly by headcount, number of sites and complexity, following accreditation rules, so ask for a quote once your scope is clear.

Which edition: ISO 9001:2015 or ISO 9001:2026?

ISO published ISO 9001:2026 in September 2026, and a transition period is now running. If you are starting today, we recommend building your system to the new edition so you do not have to change it again soon. Our news piece on what changes in ISO 9001:2026 covers the differences, and your certification body will confirm which edition it can certify against during the transition.

Whichever edition you use, choose a certification body that is accredited for ISO 9001. Accreditation is what gives the certificate international recognition; read why in our article on the new Global Accreditation Cooperation.

Key takeaways

  • Fix the scope first; it appears on your certificate.
  • Most gaps cluster around objectives, suppliers, complaints, training and calibration.
  • Run the system for two to three months before the audit to build real evidence.
  • Stage 1 checks readiness; Stage 2 checks that the system works in practice.
  • Build new systems to ISO 9001:2026 to avoid a second change.

Frequently asked questions

Is ISO 9001 certification mandatory?

No. ISO 9001 is voluntary, but many clients, government tenders and major contractors in the GCC and elsewhere require it from their suppliers.

Can a small company get ISO 9001 certified?

Yes. The standard applies to organisations of any size. A small company simply needs fewer documents and a shorter audit.

How often are surveillance audits?

Usually once a year, in the two years between initial certification and recertification.

What happens if the auditor finds a nonconformity?

You correct it, investigate the root cause and send evidence to the certification body. Minor findings rarely delay the certificate for long.

Planning your certification? Explore ISO 9001 certification with SRA, or prepare your team with our ISO training courses. You can read ISO’s own overview of the standard on the ISO 9001 page at iso.org.