Ask how long ISO certification takes and the usual answer is somewhere between three months and a year. It can be done in a week. What decides it is not the standard, and it is not us. It is three practical things, and you control two of them.
A week is achievable
Where an organisation is ready and an auditor is free, the audit, the report and the certificate can all happen inside a week.
Part of the reason is that we audit in one visit rather than splitting it into two stages. There is no gap of several weeks between a documentation review and an implementation audit, because the documentation review happens beforehand, at no charge, and does not need a separate trip.
The three things that set the pace
Auditor availability. We need a date when an auditor can get to you, on site or remotely. The further ahead you ask, the more choice there is. This is the only one of the three that sits with us.
Whether you are ready. This is the one that decides most timescales, and it is covered below.
Whether the audit finds anything significant. The way findings are classified is set out in what happens during an ISO audit. A major non-conformance has to be addressed and closed before a certificate can be issued. If one is raised, the certificate waits for however long the fix takes, which is entirely in your hands. Minor findings do not hold up a certificate in the same way.
What being ready actually means
Not a thick manual. The audit looks for a system that exists and is being used, which means there has to be something to look at.
The two things that most often hold an organisation up are an internal audit and a management review, because both are activities rather than documents. A system written last month cannot show you have reviewed its performance or audited it, and no amount of good intention substitutes for the record that it happened. That, rather than anything about the standard, is the real reason certification takes some organisations months.
The way to find out where you stand is to let us look at your documentation before the audit. It costs nothing, and it is far better to hear that something is missing while there is time to deal with it.
The gaps that most often hold a certificate up are listed in common reasons companies fail their ISO audit.
How to make it quick
Take the free documentation review, and take it early enough to act on.
Work through the audit checklist and the audit guidance on our certification help page. They set out what a typical audit plan covers and what to have ready, so nothing is a surprise on the day.
Settle your scope before you book. Deciding late what the certificate should cover is a common cause of delay, and the thinking behind it is worth doing properly.
Make sure the right people are available. An audit stalls when the person who runs a process is out for the day and nobody else can speak to it.
After the certificate
Ongoing certification depends on an annual surveillance audit, scheduled around the anniversary of your initial certification. You can hold a one year certificate and decide each year whether to continue, or agree a multiple year term at a lower renewal rate.
If you want a date, tell us what standards you are going for and roughly where you have got to, and we will tell you honestly whether a week is realistic or whether there is work to do first.