How certification works: the road from decision to certificate, step by step
A first-timer’s walk through the certification process: gap analysis, building the system, Stage 1 and Stage 2 audits, the certificate, and the surveillance cycle that keeps it.
For an organisation approaching it the first time, certification can feel like a black box: you know you need the certificate, you know an auditor is involved, and the space in between is a fog. It is far more predictable than that. Certification to a management-system standard like ISO 9001 follows a well-worn sequence, and knowing its shape in advance is most of what separates a calm first certification from an expensive scramble.
This guide walks the whole road - from the decision to pursue certification through to holding (and keeping) the certificate. It assumes ISO 9001, but the same structure applies to most accredited management-system certifications. If the difference between following, compliant, and certified is not yet solid for you, start here; this piece picks up once you have decided certification is the goal.
Step 0: Decide the scope, and mean it
Before any auditor is involved, you make one decision that shapes everything after it: the scope of certification. Scope is the statement of what is being certified - which activities, which sites, which products or services. "Design and manufacture of machined components at the Aarhus facility" is a scope; so is "provision of managed IT services from the Copenhagen office."
Scope matters because it defines the boundary the auditor will assess and the exact wording that will appear on your certificate. Draw it too wide and you take on work and evidence you did not need; draw it too narrow and the certificate will not cover the contracts you are trying to win. Read the tender or customer requirement that is driving certification, and set a scope that covers that work and no more than you can genuinely support.
Step 1: Gap analysis - find the distance to the standard
The first real activity is an honest gap analysis: a clause-by-clause comparison of what the standard requires against what you actually do today. For ISO 9001 that means walking clauses 4 through 10 and asking, for each requirement, "is this in place, is it evidenced, or is it missing?"
A worked example. A software scale-up runs the gap analysis and finds it already does much of clause 8 (operation) well - it has a controlled development and release process. But clause 9.2 (internal audit) has never happened, clause 9.3 (management review) is informal chat that leaves no record, and clause 7.5 (documented information) is scattered across three tools with no version control. The gap analysis turns "we're probably fine" into a concrete list of things to build. That list is the plan for the next step.
You can run the gap analysis yourself, or bring in a consultant to run it. Either way, its output is the same: a prioritised list of gaps, which becomes your implementation backlog.
Step 2: Build the system and generate evidence
This is the longest phase, and it cannot be rushed: certification audits look for evidence over time, not a system switched on the week before. You close the gaps - write and agree the procedures, set up document control, define how nonconformities and corrective actions are handled - and then you operate the system long enough to produce records.
That last point is the one first-timers underestimate. An auditor assessing management review (9.3) wants to see that reviews have actually happened, with inputs and actions recorded; one assessing internal audit (9.2) wants to see completed audits and what they found. You therefore need to run at least one full cycle of these activities - internal audits, a management review, some real nonconformities handled start to finish - before you are auditable. This phase commonly runs a few months; the length depends on how far the gap analysis showed you had to go.
Two activities deserve singling out, because the certification body will look specifically for them:
- A full internal audit of the management system against the standard, with findings recorded and addressed. (Internal audits get their own detailed treatment in internal and external audits explained.)
- A management review at which leadership examines how the system is performing and makes decisions about it, with the inputs and outputs documented.
Both are requirements in their own right and the evidence that your system is genuinely running, not staged for the occasion.
Should you use a consultant?
Around the gap analysis, most first-timers ask whether to bring in outside help. There is no single right answer, but there is a line not to cross.
A good consultant earns their fee by compressing the learning curve: they have run the gap analysis many times, know what evidence a Stage 2 auditor will ask for, and can stop you building bureaucracy the standard never required. For a small team new to a management-system standard, that can turn a year of trial and error into a few focused months.
The costs are real too. A system a consultant writes for you rather than with you tends to be one your people do not own and quietly abandon once the consultant leaves - which surfaces at the first surveillance audit. There is also a hard boundary: a consultant may help build the system, but must not be the one who audits it. Internal audit (clause 9.2) must be independent of the work being audited, as is the certification body's assessment by definition. Help with the build is legitimate; outsourcing the judgement of whether it works is not.
Step 3: Choose an accredited certification body
You do not certify yourself, and you do not want a certificate from a body that is not accredited. Choose a certification body accredited by a recognised accreditation authority - DANAK in Denmark, UKAS in the UK, DAkkS in Germany, and their counterparts elsewhere, all mutually recognised through the IAF arrangement. An accredited certificate is the one buyers and tender evaluators will accept without further questions.
Beyond that, certification bodies are not interchangeable, and the cheapest quote is rarely the right choice. Compare four things directly:
- The accreditation authority behind it. Accreditation is granted scheme by scheme, not as a blanket badge, so confirm the body is accredited for the standard you want and check the authority's public register rather than trusting a logo on a website.
- Sector and scheme experience. An auditor who has spent years on your kind of work reads your evidence faster and asks sharper questions than one meeting your sector for the first time - for a software business, one fluent in how a development and release process produces records beats a generalist.
- Auditor availability against your timeline. If a tender deadline is driving this, the binding constraint is often not how fast you build the system but when the body can schedule Stage 1 and Stage 2 - ask about lead times before you commit, not after.
- The total three-year cost, not the headline fee. Certification runs on a three-year cycle, so the initial fee is only part of the bill. Ask for the whole picture - Stage 1 and Stage 2, both surveillance visits, any per-day or travel charges - and compare bodies on the three-year total.
A note on integrated management systems
If you expect to certify to more than one standard - say ISO 9001 for quality alongside an environmental or health-and-safety management standard - it is usually worth planning them together rather than as separate projects. Modern ISO management-system standards share a common high-level structure: the same clause 4-to-10 skeleton and the same requirements for documented information, internal audit, and management review. That shared backbone lets one set of document controls, one internal-audit programme and one management review serve them all, and a certification body can assess them in a single combined audit - less duplicated effort, and often less time on site. Decide early, at the scope stage: retrofitting a second standard onto a system built for one is more work than designing for both.
Step 4: The certification audit - Stage 1 and Stage 2
The initial certification audit comes in two stages, deliberately separated.
Stage 1 - readiness review. The auditor checks that your management system exists and is ready to be assessed in depth. They review your documented information, confirm the scope, look at your internal audit and management review records, and identify anything that would make a full assessment pointless. Think of Stage 1 as the auditor confirming there is a system to audit and flagging concerns while you still have time to act on them - not a pass or fail, but a heads-up before the real assessment.
Stage 2 - the assessment. Some weeks later, the auditor returns to assess the system in operation against every applicable requirement, testing whether the system you documented is the system you run. Findings are classified - typically major nonconformities (a requirement is not met, or a whole part of the system has broken down), minor nonconformities (a lapse against a requirement), and opportunities for improvement (not required, but worth noting).
A major nonconformity must be resolved before a certificate can be issued; the auditor will want evidence you have corrected it and addressed its cause. Minor nonconformities usually need a corrective-action plan verified at the next visit. It is entirely normal to leave with some findings - a clean sweep is the exception, not the expectation.
What a Stage 2 day actually looks like. It opens with a short opening meeting: the auditor confirms the scope, sets out the plan for the day, and agrees who to speak to and when. The bulk of the day is sampling - pulling specific records ("show me the last three management-review minutes"; "show me how this complaint was closed"), interviewing people from leadership to those doing the work, and watching work as it actually happens. It ends with daily feedback, a brief debrief so nothing at the close comes as a surprise, and a closing meeting where the auditor presents and classifies the findings and sets out what happens next - so you leave knowing exactly what, if anything, must be resolved before a certificate is issued.
Step 5: The certificate - what you actually get
Once findings are resolved to the auditor's satisfaction, the certification body issues the certificate. It states the standard, your organisation, the scope, the issuing body and its accreditation mark, and the dates. That accreditation mark is the part that gives the certificate its currency with third parties.
Read your own certificate carefully and use it precisely. The scope on it is the scope you may claim - no more. If someone asks whether you are certified, the honest answer references the standard, the body, and the scope exactly as written.
A worked timeline: decision to certificate
Put the running example on a calendar. Our software scale-up decided in month 0 to pursue certification because a prime contractor's tender required it. The durations are not promises - they track the size of the gaps and the time the team can give - but the shape is typical.
- Month 0. Decision made; scope drafted as "design, development and support of the company's SaaS platform," with a plan and an internal owner.
- Month 1. Gap analysis against clauses 4 to 10: operation (clause 8) is largely there; internal audit (9.2), management review (9.3) and document control (7.5) are the gaps.
- Months 2–4. The build phase: procedures agreed, document control set up, the nonconformity and corrective-action process (10.2) defined - then operated, not just written.
- Month 5. Enough time has passed for real records: an internal audit completed, a first management review minuted, a few genuine nonconformities taken start to finish.
- Month 6. Certification body engaged; Stage 1 readiness review held, with a few observations to tidy up before Stage 2.
- Months 7–8. Stage 2 assessment; one minor nonconformity closed out; certificate issued once the auditor is satisfied.
Roughly seven to eight months from decision to certificate for this organisation - one with larger gaps, or less time, will take longer. The determinant is the distance the gap analysis exposed, not the calendar.
Step 6: Surveillance and recertification - keeping it
Certification is a three-year cycle, not a one-off event. The certification body returns for surveillance audits - usually annually - to confirm the system is still operating and that earlier findings were closed. These are lighter than the initial Stage 2 but real: a system that has quietly decayed since certification will surface here, and serious or persistent problems can suspend or withdraw the certificate.
Before the three years elapse, a recertification audit - similar in depth to the initial Stage 2 - renews the cycle for another three years. The organisations that find recertification easy are the ones that kept the system live throughout: current documents, ongoing internal audits, regular management reviews, evidence accumulating as a by-product of work. The ones that find it painful are those that treated the first certificate as the finish line.
What makes the difference: evidence that maintains itself
Read back over the steps and one thing recurs - the auditor wants current, retrievable evidence. Gap analysis finds where it is missing; the build phase generates it; Stage 2 tests it; surveillance confirms it is still being produced. The biggest determinant of how hard certification is, is whether your evidence accumulates as you work or has to be reconstructed before each audit.
This is what a quality management system is for. ComplyTrain's QMS is structured around the standard's own requirements, so documents stay controlled, internal audits and management reviews leave their records, and nonconformities carry their corrective-action trail - so Stage 1, Stage 2, and every surveillance visit become a matter of showing what is already there. The ISO 9001 page sets out the requirements the whole process assesses you against.
Preparing for a first certification? Book a demo and we'll show you how ComplyTrain keeps the evidence an auditor asks for organised by clause, so the road from decision to certificate is a straight one.
