The ISO Certification Process Step by Step

ISO certification can appear complicated when a business is beginning the process.

However, certification becomes easier to manage when it is divided into clear stages.

The exact requirements depend on the selected standard, the company’s activities, the certification scope, and the organization’s current systems.

Step 1: Identify the Business Objective

Begin by defining why the company wants certification.

Common objectives include:

  • Improving quality
  • Meeting customer requirements
  • Participating in tenders
  • Improving workplace safety
  • Protecting information
  • Managing environmental impacts
  • Entering new supply chains

A clear objective helps the organization select the appropriate standard.

Step 2: Choose the Correct ISO Standard

The business must select a standard that matches its needs.

Examples include:

  • ISO 9001 for quality management
  • ISO 14001 for environmental management
  • ISO 45001 for occupational health and safety
  • ISO/IEC 27001 for information security
  • ISO 22000 for food safety

Some businesses implement several standards through one integrated management system.

Step 3: Define the Certification Scope

The scope explains what the management system covers.

It may include:

  • Specific products or services
  • Business activities
  • Departments
  • Locations
  • Employees
  • Operational processes

The scope should accurately represent the activities the company wants certified.

Step 4: Conduct a Gap Analysis

A gap analysis compares current company practices with the requirements of the selected standard.

It identifies:

  • Processes that already meet requirements
  • Missing policies
  • Weak controls
  • Missing records
  • Training needs
  • Areas requiring improvement

The results become the basis of an implementation plan.

Step 5: Create an Implementation Plan

The organization should establish clear actions, responsibilities, deadlines, and resources.

The plan may include:

  • Required documents
  • Employee training
  • Process changes
  • Risk assessments
  • Performance indicators
  • Internal-audit dates
  • Management-review dates
  • Corrective actions

Senior management should monitor progress.

Step 6: Develop the Management System

The business creates or updates the necessary policies, procedures, controls, forms, and records.

Documentation should reflect actual business operations.

Avoid creating complicated procedures that employees cannot follow.

Useful documentation is clear, controlled, accessible, and relevant.

Step 7: Train Employees

Employees must understand the management system and their responsibilities.

Training may cover:

  • Company policy
  • Relevant procedures
  • Customer requirements
  • Risk controls
  • Reporting methods
  • Emergency responsibilities
  • Documented information
  • Improvement activities

Training records should be maintained where appropriate.

Step 8: Implement the System

The company must use the management system in real operations.

Employees should follow procedures, complete records, monitor processes, report problems, and apply controls.

A certification audit cannot be passed effectively through documents alone. Auditors will look for evidence that the system is working.

Step 9: Monitor Performance

The organization should measure whether the system is achieving its objectives.

Examples include:

  • Customer complaints
  • Defect rates
  • Delivery performance
  • Safety incidents
  • Environmental consumption
  • Security incidents
  • Supplier performance
  • Training completion

Performance information should support decision-making.

Step 10: Conduct an Internal Audit

An internal audit evaluates whether the management system meets planned arrangements and is effectively implemented.

ISO 19011:2026 provides current international guidance for auditing management systems.

Internal auditors should be sufficiently independent from the work they audit and should report findings objectively.

Step 11: Complete Management Review

Senior management reviews the system’s performance.

The review normally considers:

  • Audit results
  • Objectives
  • Customer feedback
  • Process performance
  • Risks and opportunities
  • Corrective actions
  • Resource needs
  • Improvement opportunities

Management review demonstrates leadership involvement.

Step 12: Correct Identified Problems

Any nonconformities should be corrected before the external audit.

The organization should investigate the cause, implement corrective action, and verify whether the action was effective.

Step 13: Select a Certification Body

ISO does not audit organizations or issue certificates. Certification is performed by independent certification bodies.

The business should evaluate the certification body’s competence, recognition, experience, scope, audit approach, and contractual terms.

Step 14: Complete the Certification Audit

Management-system certification commonly involves an initial review followed by a more detailed assessment of implementation.

Auditors may review:

  • Documents
  • Records
  • Employee awareness
  • Operational processes
  • Internal-audit results
  • Management review
  • Corrective actions

Any findings must be addressed according to the certification body’s requirements.

Frequently Asked Questions

Can a business obtain certification immediately?

The company must first implement the management system and create sufficient evidence that it is operating.

Who issues ISO certificates?

Independent certification bodies issue certificates. ISO itself does not perform certification.

Is certification the end of the process?

No. The organization must maintain, monitor, audit, and continually improve its management system.

Begin Your ISO Certification Process

A structured implementation plan can reduce confusion, delays, and unnecessary work.

Contact ISOCERT PRO to discuss the certification process for your organization.