SRAC Logo
hero-certification-guide

ISO certification guide - What you need to know before you start

Info > Certification guide

Do you want to know costs or other details?

Request an offer and you will receive a response as soon as possible.

If you are thinking about getting ISO certification for your company, it is only natural to have questions. This guide explains, simply and without needless technical jargon, the main things you need to know before starting the certification process.

What exactly is ISO certification? What does the company have to do? Who issues the certificate? What is the difference between certification and accreditation? How do I choose a certification body? How long does the process take and what happens during the audit?

What is ISO certification?

Certification is the process by which an independent certification body assesses an organization's management system to check whether it meets the requirements of a given standard.

Depending on the organization's objective, the standards used may include, for example:

  • ISO 9001 – quality management system;
  • ISO 14001 – environmental management system;
  • ISO 45001 – occupational health and safety management system;
  • ISO/IEC 27001 – information security management system;
  • ISO 22000 – food safety management system.

At the end of the process, if the requirements are met, the certification body issues a certificate for the scope of activity and the sites established during the certification process.

Who issues the ISO certificate?

An important point is that ISO does not issue certificates. ISO is the international organization that develops and publishes international standards. Management system certification is carried out by independent certification bodies.

What is an ISO standard?

An ISO standard is a document that sets out requirements, principles or good practices for a given field.

For management system standards, the standard sets out what the organization has to do, but it generally does not impose a single way of working.

For example, ISO 9001 sets requirements for a quality management system, but each organization builds its system according to its activity, size, processes and risks.

Is ISO certification just about documents?

No. A management system has to be implemented and working, not just documented.

During the audit, the auditors check both the relevant documented information and the way the organization applies the system in its day-to-day activity.

Certification or accreditation? What is the difference?

The terms “certification” and “accreditation” are often confused, although they play different roles.

What does certification mean?

Certification concerns the conformity of management systems with the reference standards. It is carried out on the organization by a certification body and, as a result, the certificate may be issued.

What does accreditation mean?

Accreditation is an independent confirmation of the competence of the certification body, given by an accreditation body.

In Romania, RENAR – the Romanian Accreditation Association is the national accreditation body. Bodies that audit and certify management systems must meet the relevant requirements of the ISO/IEC 17021-1:2015 series.

In short:

  • certification applies to the organization;
  • accreditation applies to the certification body.

Why does accreditation matter?

If you need a certificate that is recognised in certain business relationships, public procurement or international contexts, it is important to check that the certification body is accredited for the relevant standard and scope.

It is not enough to check whether a body's website says “accredited”. You need to check what exactly the accreditation covers.

How do you choose a certification body?

Choosing the certification body is one of the most important decisions in the process. The choice should not be based on price alone.

Check the accreditation and its scope

First of all, check whether the certification body is accredited and who granted the accreditation. Ideally, the accreditation should be granted by an IAF MLA signatory, for international recognition. If the certifier is NOT accredited by an IAF member body, the certificate may not be accepted (e.g. in public tenders or international contracts). RENAR accreditation provides international recognition and reduces legal and commercial risks.

Also check which standards and which fields of activity the body is accredited for, and whether the accreditation is valid. Not all bodies certify all industries or fields of activity (EA codes).

Information on the accreditation of certification bodies in Romania can be checked on the RENAR website.

Market reputation

Accredited local bodies can offer more flexibility and lower logistics costs compared to international bodies, which may have higher costs and more rigid communication. When assessing reputation, the relevant factors are years on the market, the number and type of clients, international coverage and the number of accreditations.

Transparent costs over 3 years

Certification works on a 3-year cycle. The quote should include:

  • the cost of the initial audit (Year 1);
  • the cost of the surveillance audits (Years 2 and 3);
  • the auditors' logistics expenses (travel, accommodation).

Impartiality of the certification body

The conformity assessment body (CAB) must remain independent from the audited organization. An important principle of third-party certification is the separation between consultancy and independent certification.

What are the steps of ISO certification?

Although the process may differ depending on the standard, the scope and the organization, management system certification generally follows these steps:

Step 1: Choosing the standard

The first step is to decide what you want to certify. For example:

  • ISO 9001 – if the objective is quality management;
  • ISO 14001 – if the objective is environmental management;
  • ISO 45001 – if the objective is occupational health and safety management;
  • ISO/IEC 27001 – if the objective is information security;
  • ISO 22000 – if the objective is food safety.

Sometimes an organization only needs one management system certified, while other times it may opt for several standards (an integrated management system).

Step 2: Defining the certification scope

You need to clearly define which activities, processes and sites will be included in the certification. This is the certification scope.

It matters because the certificate covers the scope that was defined and assessed, not automatically every activity the company carries out.

Step 3: Requesting a quote

The organization sends the certification body the information it needs:

  • the field of activity;
  • the number of employees;
  • the number of shifts;
  • the sites;
  • the standard for which certification is requested.

Based on the agreed quote, the audit program and duration and the contractual details are established.

Step 4: Preparing and implementing the system

Before calling in the certification body, you need to put your documents, procedures and way of working in order, according to the chosen standard.

Step 5: Certification audit – Stage 1 (documentation review)

The auditor checks whether your documents (manuals, procedures, policies) meet the requirements of the standard. Any major gaps are identified before the on-site visit.

Step 6: Certification audit – Stage 2 (on-site audit)

The audit that assesses the implementation and effectiveness of the management system, to see whether what is written in the procedures is actually applied. The auditors talk to employees and review concrete evidence.

Step 7: Dealing with nonconformities

Nonconformities may be identified during the audit. A nonconformity does not automatically mean that the organization cannot be certified. When nonconformities are identified, the organization has to analyze them and define and implement corrective actions.

Step 8: Issuing the certificate

If there are no major nonconformities (or the minor ones have been corrected), the official certificate is issued. It is valid for 3 years, provided that the annual surveillance audits are carried out.

Step 9: Annual surveillance audits (Year 2 and Year 3)

Certification does not end when you receive the certificate. The management system has to be maintained and assessed periodically. During the certification cycle, surveillance audits are carried out according to the established program. They check whether the system continues to meet the applicable requirements and whether it is maintained and improved.

Step 10: Recertification

To extend the validity of the certificate for a new 3-year cycle, a recertification audit takes place.

Do I need a consultant?

You can implement the requirements in-house if you have the resources and the time, but most small and medium-sized companies use an external consultant to prepare the documentation faster and more efficiently.

Note: the consultant cannot also be the auditor from the certification body.

The consultant helps the organization build and implement its management system.

The certification body independently checks whether the system meets the applicable requirements.

How long does ISO certification take?

The duration differs from one organization to another, depending on its complexity and size. A small organization with a single site and relatively simple processes may follow a different path from an organization with several sites and complex processes.

Obtaining ISO certification (whether ISO 9001, ISO 14001 or ISO 45001) takes a few months. It involves implementing the procedures internally, training the staff, checking the system through internal audits and, finally, the external audit carried out by an accredited body in order to issue the certificate. For companies that want maximum efficiency, an integrated management system (IMS) allows several standards to be implemented at the same time, significantly reducing the paperwork, the time and the overall cost of the process.

How much does ISO certification cost?

The cost of certification depends on the size of the organization, the number of employees, the complexity of the processes and the number of sites.

Implementing several standards together, also known as an integrated management system (most often ISO 9001 + ISO 14001 / + ISO 45001), saves documentation effort and money compared to obtaining them one at a time.

The most common mistakes in a first ISO certification

“I just want the certificate.”

Certification is valuable when the management system is implemented and working within the organization.

“I'll choose the cheapest body.”

Price is important, but it should not be the only criterion.

“If I have the documents, I'm certified.”

No. The audit also looks at how the system is implemented and how it works.

“ISO issues the certificate.”

No. ISO develops the standards, while certification is carried out by certification bodies.

“If the body says it is accredited, it is accredited for everything.”

No. You need to check the scope of the accreditation.

Want to find out what certification involves for your company?

Every organization is different. The right standard, the certification scope, the audit duration and the costs depend on the characteristics of the company.

Request a quote for ISO certification

Send us information about your organization and the standard you want to be certified against. SRAC's specialists can tell you the steps involved and send you a quote tailored to your organization.

REQUEST A QUOTE

Not sure which ISO standard is right for you?

Find out which standard fits your organization's activity and objectives.

SEE THE ISO STANDARDS

ISO Certification Guide: Steps, Timeline and Costs | SRAC