How long does ISO certification take? For a typical small or medium organisation with committed leadership and reasonably mature processes, a realistic planning range is three to nine months. A complex, regulated, or multisite organisation may need nine to eighteen months. These are practical estimates, not deadlines set by ISO.
The timetable depends on your chosen standard, scope, current level of control, resources, operating history, certification body availability, and speed of corrective action. Certification is not obtained from ISO itself. An independent certification body audits your management system and makes the certification decision. The timeline below shows where the work usually sits and why rushing evidence creation often causes delays later.
What changes the ISO certification timeline?
Two organisations pursuing the same standard can have very different journeys. An established company may already have process controls, performance data, competent people, and regular management meetings. It may only need to align these practices with the standard. A growing business that relies on informal knowledge must design controls, train people, and generate reliable records.
The main variables are:
- the number of sites, employees, shifts, and processes in scope;
- the complexity and risk of products, services, and technology;
- applicable legal, regulatory, and customer requirements;
- the availability of process owners and top management;
- the quality of existing documents and records;
- integration with other management systems;
- the number and seriousness of gaps; and
- audit dates are available from a competent certification body.
Set the scope before requesting quotations. Scope changes can affect audit duration, competence requirements, price, and scheduling.
Weeks 1 to 3: scope, gap analysis, and plan
Start by selecting the correct standard and defining what the management system covers. Confirm sites, activities, products, services, outsourced processes, and legal obligations. Then compare current practices with each applicable requirement.
A focused gap analysis normally takes several days to two weeks, depending on size and complexity. Its value is not the checklist score. It should identify what is missing, what is ineffective, who owns each action, and which gaps create the greatest risk. Convert the results into a resourced implementation plan with milestones.
At this stage, speak to certification bodies about competence, accreditation, likely audit time, and availability. You can reserve provisional dates but leave enough time for the system to operate and produce evidence.
Weeks 3 to 16: design and implement the system
This implementation phase is usually the longest phase. Develop only the documented information needed to control work and meet the selected standard. Establish objectives, responsibilities, operational controls, monitoring methods, communication, competence, and corrective action processes. Standard specific work may include environmental aspects, safety hazards, information security risks, or an energy review.
Implementation means people use the controls. A procedure approved yesterday does not prove an effective system. Train relevant employees, communicate changes, capture records, monitor indicators, and correct early problems. A typical organisation may need six to sixteen weeks for this work, while major technology, infrastructure, or behavioural changes take longer.
Good ISO implementation support should transfer knowledge to process owners. If only the consultant can explain the system, the organisation is not ready.
Weeks 12 to 22: build evidence and test performance
Allow enough operating history to show trends and completed cycles. Auditors need objective evidence that controls work across the scope. The appropriate period depends on process frequency. A monthly task needs several useful samples; an annual legal review may require planned evidence or an earlier completed cycle.
Run the internal audit programme using competent, objective auditors. Cover all applicable requirements and the full certification scope, with greater attention to higher-risk processes and previous problems. Report findings clearly, correct nonconformities, and verify effectiveness.
Top management must then conduct management review using the required inputs and make decisions about performance, resources, changes, risks, and improvement. Do not hold a ceremonial meeting only to produce minutes. Certification auditors test whether leadership uses the system to direct the business.
Stage 1 audit: readiness and planning
The certification body conducts Stage 1 to understand the organisation, review key documented information, confirm scope, and evaluate readiness for Stage 2. It commonly examines internal audit and management review status, objectives, process understanding, sites, legal requirements, and the maturity of implementation.
Stage 1 may take one or more audit days. The most important scheduling issue is the time needed afterwards. Any area of concern that could become a nonconformity at Stage 2 should be addressed. Allow roughly two to six weeks, depending on the issues and the agreed audit interval.
Stage 2 audit and certification decision
Stage 2 evaluates implementation and effectiveness throughout the scope. Auditors interview people, observe work, sample records, follow process trails, and test conformity with the standard and your own controls. The audit may take a few days for a smaller organisation and longer for complex or multi-site scopes.
If auditors raise nonconformities, submit corrections, root cause analysis, and corrective actions within the certification body’s deadlines. Major findings usually require stronger verification before certification can proceed. The audit team makes a recommendation, but an independent certification decision follows the review of the audit file. Allow another two to six weeks for closure and decision, while recognising that each body has its own process.
How long does ISO certification take in total?
Treat three to nine months as a planning range for a prepared small or medium organisation, not as a promise. Add contingency for scarce specialists, legal approvals, system changes, employee availability, and corrective action. Use management system maintenance after certification because surveillance audits continue throughout the cycle.
Rushing can produce attractive documents without reliable evidence. A better route is to set a clear scope, prioritise high-risk gaps, let controls operate, and test the system honestly. WWISE can help you build a realistic project plan, prepare for both audit stages, and reduce avoidable rework.