How to Get ISO 9001 Certified
Last updated 23 August 2026.
To get ISO 9001 certified you decide what your system will cover, learn what the standard actually asks for, put a documented quality management system in place, run it in the business for around three months so it produces real records, check it yourself with an internal audit and a management review, then have it independently assessed. If the assessment finds your system genuinely meets the standard, you are issued a certificate.
That is the whole journey. Most small businesses can get ISO certified in six to nine months without hiring anyone, writing everything themselves. The rest of this page is what actually happens at each stage, and what nobody tells you before you start.
First, the part nobody says out loud
Most people do not go looking for ISO 9001 because they want it. They go looking because something forced the question.
A supplier questionnaire arrives. A tender lands with a box you cannot tick. A good customer gets acquired, and suddenly you are dealing with a procurement department instead of a person. And underneath the practical problem sits a quieter one, which is the feeling that someone from outside is about to look at how you run your business and find it wanting.
That fear is almost never justified, and it is worth saying why.
ISO 9001 is not an exam on how clever your business is. It does not ask you to be bigger, or more corporate, or to run things the way a multinational runs them. It asks a much simpler question: do you do what you say you do, and can you show it? That is it. A well-run five-person firm passes that test far more easily than a chaotic hundred-person one, and auditors know it.
The businesses that struggle are not the small ones. They are the ones that built a system for the certificate instead of for the business, filed it away, and then had to pretend at audit. Which brings us to the single most useful thing on this page.
The rule that decides whether this is worth doing
Live it, do not file it.
A quality management system that sits in a folder is not a quality management system. It is a folder. It will not make you money, it will not reduce your workload, and at audit it will not hold up, because a system nobody uses leaves no evidence behind.
A system you actually operate does the opposite. Fewer things fall through the cracks. Fewer arguments about who was meant to do what. Less of the business living inside one person’s head. The certificate becomes a by-product of running the place properly, rather than a thing you bought.
I spent years running companies at director level before I ever built a management system. I sweated the cashflow and carried the P&L, and I was sceptical of anything that looked like paperwork for its own sake. That scepticism is exactly why the systems I write now are built to be used rather than admired. If a document does not earn its place in your week, it should not be in your system.
The eight stages of getting certified
Here is the real process of ISO 9001 certification, the whole sequence, in the order it happens.
Stage 1. Decide what your certificate will cover
Before anything else, you define your scope: which activities, which sites, which products or services the system applies to.
Keep it honest and keep it tight. A scope that covers what you actually do is far stronger than one that claims everything. If you fabricate, install and service, say so. If you only design and outsource the making, say that instead. The scope appears on your certificate, and it is the first thing a serious customer reads.
This takes an afternoon, not a month.
Stage 2. Find out what the standard actually asks for
ISO 9001 is organised into clauses covering your context, leadership, planning, support, operation, performance evaluation and improvement. Behind the formal language, it is asking you to plan your work, do it in a controlled way, check whether it worked, and fix what did not.
You do not need to memorise it. You do need someone involved who understands what each requirement is really asking for, because a requirement misread becomes a document nobody needs.
If you want the clause-by-clause version in plain English, read what the standard actually asks for.
Stage 3. Measure the gap before you build
Before you write a single document, find out how far your business already is from what the standard asks for. This is called a gap analysis, and it is the step that saves the most time, because it stops you building things you do not need and shows you the handful of things you genuinely lack.
Most small businesses are further along than they fear. You almost certainly already check your work, deal with complaints, choose suppliers with care and keep records. A gap analysis simply lines up what you already do against each requirement of the standard, so the job in front of you becomes a short, honest list rather than a vague dread.
You can do this yourself with our ISO 9001 gap analysis and self-assessment tool. You work through it, answer the questions honestly, and it shows you exactly where the gaps are and what to do about them. It is the cheapest, fastest way to turn “we need to get certified” into a clear plan, and it is the natural first step for anyone starting from scratch.
Stage 4. Build your documented system
This is the stage people dread and the stage most people overdo.
ISO 9001 does not demand a mountain of paperwork. There is no required quality manual and no fixed list of procedures you are forced to write. What it requires is that the things which matter are controlled, and that you can show it. For most small businesses that means a manageable set of documents and forms covering how you take on work, how you buy, how you check quality, how you handle things going wrong, and how you review performance.
You have three honest options. Write it all yourself from scratch, which is free and slow and usually ends up either bloated or thin. Pay a consultant several thousand to write it for you. Or start from expert-written documentation and adapt it to how your business genuinely works, which is what most small firms should do.
If you take the third route, the documents you’ll need are available from us, either as a complete quality management system pack or as individual templates, so you can fill the specific gaps you have rather than buying a set you do not need.
One warning. Whatever you start from, adapt it. A system that describes a business you do not recognise is worse than no system at all, because your people will not follow it and the auditor will see that in ten minutes.
Stage 5. Run it. This is the stage that matters most.
Once the system is written, you operate it in the business for around three months before assessment.
This is not a waiting period invented to slow you down. Certification is assessed on evidence, and evidence is something a system produces only by being used. On day one, none of it exists. By month three you have real records: work that went through your process, checks that were carried out, a complaint or a non-conformance that got dealt with properly, suppliers assessed, a review that actually happened.
There is a second reason, and it is the one that pays you back. Three months is roughly how long it takes for the system to stop feeling like an imposition and start feeling like how the place runs. If you certify before that happens, you have bought a certificate. If you certify after, you have built something.
Stage 6. Audit yourself before anyone else does
Two things happen before your assessment, and both are required by the standard.
An internal audit, where you check your own system against the standard and against what you said you would do. You are looking for gaps deliberately. Finding problems here is a success, not a failure, and an internal audit that finds nothing tells an assessor you did not really look.
A management review, where whoever runs the business sits down with the evidence and asks whether the system is working, what it is telling you, and what needs to change. Under the 2026 edition of the standard, leadership involvement carries more weight than before, so this is not a box to tick on someone else’s behalf.
Do these properly and your assessment holds very few surprises, because you have already found what an assessor would find.
Stage 7. Choose how you want to be certified
There are two routes, and the right one depends entirely on who is asking to see your certificate.
The traditional route is an accredited certification body. It costs significantly more, usually involves visits, and is what you need if you are bidding for public sector work, government contracts, or dealing with a large client whose procurement rules specifically require an accredited certificate. If your buyer states that requirement, take that route.
The other route is an independent certification body that is not accredited. Accreditation is voluntary in the UK, the United States and every other market. ISO writes the standards; it does not certify anyone and does not regulate who may issue certificates. What makes an unaccredited certificate worth having is entirely down to whether the assessment behind it was genuine, and who put their name to it.
That is the route we offer. A real assessment against the same standard, carried out remotely, by a qualified lead auditor, with the possibility of a certificate being withheld if the system does not meet the requirements. And the judgement behind your certificate comes from someone who has sat where you are sitting. I ran companies at director level for years before I ever built a management system, so I assess your system as a business owner who has carried a payroll and won contracts, not as an auditor who has only ever worked from a checklist. Every certificate is issued on that judgement and carries my name. We are not accredited and we never suggest otherwise. And we will not tell you your system is guaranteed to pass an accredited audit, because that verdict belongs to another auditor. What we will tell you is that your system has been built and audited to genuinely meet ISO 9001, which leaves you in a strong position if you later decide to pursue accredited certification.
You can certify your system remotely without a consultant, on a fixed fee, with no visits and no travel costs.
Stage 8. The assessment itself
The assessment examines two things: your documented system, and the evidence that you are actually running it.
You submit your system and your records. An assessor works through the standard clause by clause, testing whether what you have in place genuinely satisfies each requirement. Then there is an interview, where you walk through how the system works in practice and the assessor follows the evidence where it leads. Documents can be written by anyone. A conversation about how the work really flows cannot be faked, which is why that part exists.
You then receive a written report setting out what met the standard and what did not. If there are findings, you correct them and submit the evidence. Once the system meets the requirements, your certificate is issued.
It is worth being clear that a certificate can be refused. That is not a threat, it is the reason the certificate is worth anything. A certificate issued to everyone who pays is worth nothing to the customer you are trying to impress.
What happens after you are certified
Certification is not a one-off event. Your certificate is valid for three years, with a lighter surveillance check each year to confirm the system is still being used, and a fuller reassessment at the end of the three-year cycle.
That pattern exists for a reason. A certificate that never got checked again would tell a customer only that you once had a good system, on one day, some years ago. The annual check is what keeps it meaning something, and it is also the thing that stops a system quietly rotting in a folder.
There is a quieter benefit to those annual checks too. Because I assess as someone who has run businesses, not only as an auditor, the surveillance visit is also a chance to look at how the system is working for you and suggest small changes that make it lighter or more useful. A form that could be simpler. A step that has become a habit worth dropping. Over three years, those small tweaks add up to a system that helps the business run rather than one that sits on top of it. Details of how the cycle works are on the certification page.
How long does it take?
Six to nine months is realistic for a small business starting from nothing, and most of that is not us. It is the time it takes to build your system and then operate it long enough to produce real records, which is the part no honest certifier can skip.
Roughly, that breaks down as one to three months to build the documented system and get it adopted, then around three months of operating it so it generates evidence, then the assessment.
Where we are genuinely fast is that last part. Because the assessment is remote, there are no expensive visits to schedule and no waiting weeks for a date. Once your evidence is ready, we can assess and, if your system meets the standard, certify in a fraction of the time an accredited body takes to send someone out and report back.
If you already have processes written down and simply need to bring them into line with the standard, the whole thing can be considerably quicker. But anyone promising certification in two weeks from a standing start is selling you a certificate, not a system, because there is no evidence trail in two weeks for anyone to assess.
What does it cost?
There are three costs, and only one of them is unavoidable.
- Documentation. Free if you write it yourself, a few hundred if you start from expert templates, several thousand if you hire someone to write it for you.
- Your own time. Real, and usually the largest cost, though most of it is time spent improving the business rather than time lost.
- The assessment and certificate. This is the unavoidable one, and it varies enormously depending on which route you take.
The honest numbers, route by route, are set out in our breakdown of what ISO 9001 certification really costs.
The four mistakes that cost people the most
- Writing documents that describe an imaginary business. If it does not match how the work really happens, your people will ignore it and the assessor will spot it immediately. Describe reality, then improve reality.
- Building the system and then not using it. This is the big one. It turns a genuinely useful exercise into an expensive filing task and leaves you with nothing to be assessed on.
- Making it one person’s job. If the system belongs solely to whoever was told to sort out the ISO thing, it dies the moment they are busy. It needs to be how the business runs, not a side project.
- Certifying before you are ready, to hit a deadline. You end up defending a system you have not really operated. The stress of that is far worse than the delay you were trying to avoid.
What to do this week
- Write down, in one paragraph, what your certificate should cover. That is your scope.
- Find out whether the customer or tender driving this actually requires an accredited certificate, or simply requires ISO 9001 certification. The answer changes which route you take and what you spend.
- List the processes you already have written down somewhere, even informally. Most businesses have more than they think, and it is a shorter list of gaps than you expect.
- Decide whether you are writing the documentation, buying it, or paying someone to do it. That single decision sets your timeline and most of your cost.
None of that requires spending anything, and it is the honest groundwork for how to gain ISO 9001 certification: within a week you will know whether this is a three-month job or a nine-month one.
When you are ready to turn that into a real plan, the fastest first step is our ISO 9001 gap analysis and self-assessment tool. It walks you through every requirement of the standard, shows you exactly where your gaps are, and gives you a clear list of what to fix before you build. It is a small investment that saves you from the most expensive mistake on this page, which is building documents you never needed.
The point of all this
The certificate is the token. It gets you through the procurement gate, satisfies the questionnaire, and tells a stranger that a business they have never met is run properly.
The real prize is the thing underneath it. A business that does not depend on you remembering everything. Work that goes out right the first time more often. Problems that get fixed rather than repeated. And a quiet confidence, when an outside professional does come to look at how you run things, that you have nothing to hide and plenty to show.
That is what changes, and it is the real reason to get ISO 9001 certified. The certificate is just the proof.
Frequently asked questions
How long does it take to get ISO 9001 certified?
Six to nine months is realistic for a small business starting from nothing. That covers one to three months to build your documented system and get people using it, around three months of operating it so it generates real records, then a few weeks for your internal audit, management review and the assessment itself. If your processes are already written down and simply need aligning with the standard, it can be considerably quicker. Anyone promising certification in two weeks is selling a certificate rather than a system, because no evidence trail exists in two weeks for an assessor to examine.
How much does it cost to get ISO 9001 certified?
Getting ISO 9001 certified can cost anywhere from around $1,500 to $15,000 or more, depending entirely on the route you take. A genuine remote assessment by an unaccredited certification body sits at the lower end, around $1,500, with a smaller annual fee after that to keep the certificate current. The traditional accredited route usually runs from $3,000 to $5,000 for the certification work alone, and most firms taking that route also hire a consultant to prepare, which commonly pushes the total into the $6,000 to $15,000 range and sometimes beyond. On top of the assessment you have your documentation, which is free if you write it yourself, a few hundred if you start from expert templates, or several thousand if you pay someone to write it for you. For a full breakdown route by route, see the cost guide.
How hard is it to get ISO 9001 certified?
It is more work than it is difficulty. ISO 9001 does not require technical expertise or a large team; it requires you to decide how your business should run, write that down, actually do it, and keep the evidence. The hard part for most small firms is not understanding the standard, it is the discipline of using the system every week rather than building it and filing it away. Businesses that treat it as how they operate find it straightforward. Businesses that treat it as a document exercise find it painful, because at assessment there is nothing real to show.
Can you get ISO 9001 certified online or remotely?
Yes. Remote assessment is now well established and is how we certify. Your documented system and the records it has produced are submitted electronically, assessed clause by clause against the standard, and followed up with a remote interview about how the system works in practice. Nothing about the rigour changes; what disappears is the travel, the expenses and the scheduling. For a small business without multiple sites or complex physical processes, there is rarely any need for someone to stand in your building to see whether your system works.
Who can issue ISO 9001 certification?
Any competent certification body can issue ISO 9001 certification, whether accredited or not, because accreditation is voluntary everywhere. ISO writes the standards but does not certify organisations and does not regulate who may issue certificates. That leaves two legitimate routes. Accredited bodies operate under oversight from a national accreditation body such as UKAS or ANAB, cost more, and are what you need where a tender or a large client specifically requires accredited certification. Unaccredited certifiers, including ISO Guidance, assess against exactly the same standard and cost less, and the value of the certificate rests on whether the assessment was genuine and who put their name to it. Both are entirely legal. The one thing no certifier should ever do is imply accreditation it does not hold, and we do not.
Does ISO 9001 certification expire?
Yes. An ISO 9001 certificate runs for three years, with a lighter surveillance check each year to confirm the system is still being used, and a fuller reassessment at the end of the cycle. It can also be withdrawn before then if the system stops being operated. That pattern exists deliberately: a certificate that was never checked again would tell a customer only that you had a good system on one day, some years ago. The annual check is what keeps it meaning something.
For the honest figures route by route, see the full cost breakdown.
About the author
Written by Mike Armstrong, founder of ISO Guidance. Mike ran companies at director level before building management systems, so the systems ISO Guidance writes are built to work in the real world, not just on paper. ISO Guidance helps small and medium sized businesses get ISO certified without a consultant.