
If you are thinking about getting ISO certification for your company, it is only natural to have questions. This guide explains, simply and without needless technical jargon, the main things you need to know before starting the certification process.
What exactly is ISO certification? What does the company have to do? Who issues the certificate? What is the difference between certification and accreditation? How do I choose a certification body? How long does the process take and what happens during the audit?
Certification is the process by which an independent certification body assesses an organization's management system to check whether it meets the requirements of a given standard.
Depending on the organization's objective, the standards used may include, for example:
At the end of the process, if the requirements are met, the certification body issues a certificate for the scope of activity and the sites established during the certification process.
An important point is that ISO does not issue certificates. ISO is the international organization that develops and publishes international standards. Management system certification is carried out by independent certification bodies.
An ISO standard is a document that sets out requirements, principles or good practices for a given field.
For management system standards, the standard sets out what the organization has to do, but it generally does not impose a single way of working.
For example, ISO 9001 sets requirements for a quality management system, but each organization builds its system according to its activity, size, processes and risks.
No. A management system has to be implemented and working, not just documented.
During the audit, the auditors check both the relevant documented information and the way the organization applies the system in its day-to-day activity.
The terms “certification” and “accreditation” are often confused, although they play different roles.
Certification concerns the conformity of management systems with the reference standards. It is carried out on the organization by a certification body and, as a result, the certificate may be issued.
Accreditation is an independent confirmation of the competence of the certification body, given by an accreditation body.
In Romania, RENAR – the Romanian Accreditation Association is the national accreditation body. Bodies that audit and certify management systems must meet the relevant requirements of the ISO/IEC 17021-1:2015 series.
In short:
If you need a certificate that is recognised in certain business relationships, public procurement or international contexts, it is important to check that the certification body is accredited for the relevant standard and scope.
It is not enough to check whether a body's website says “accredited”. You need to check what exactly the accreditation covers.
Choosing the certification body is one of the most important decisions in the process. The choice should not be based on price alone.
First of all, check whether the certification body is accredited and who granted the accreditation. Ideally, the accreditation should be granted by an IAF MLA signatory, for international recognition. If the certifier is NOT accredited by an IAF member body, the certificate may not be accepted (e.g. in public tenders or international contracts). RENAR accreditation provides international recognition and reduces legal and commercial risks.
Also check which standards and which fields of activity the body is accredited for, and whether the accreditation is valid. Not all bodies certify all industries or fields of activity (EA codes).
Information on the accreditation of certification bodies in Romania can be checked on the RENAR website.
Accredited local bodies can offer more flexibility and lower logistics costs compared to international bodies, which may have higher costs and more rigid communication. When assessing reputation, the relevant factors are years on the market, the number and type of clients, international coverage and the number of accreditations.
Certification works on a 3-year cycle. The quote should include:
The conformity assessment body (CAB) must remain independent from the audited organization. An important principle of third-party certification is the separation between consultancy and independent certification.
Although the process may differ depending on the standard, the scope and the organization, management system certification generally follows these steps:
The first step is to decide what you want to certify. For example:
Sometimes an organization only needs one management system certified, while other times it may opt for several standards (an integrated management system).
You need to clearly define which activities, processes and sites will be included in the certification. This is the certification scope.
It matters because the certificate covers the scope that was defined and assessed, not automatically every activity the company carries out.
The organization sends the certification body the information it needs:
Based on the agreed quote, the audit program and duration and the contractual details are established.
Before calling in the certification body, you need to put your documents, procedures and way of working in order, according to the chosen standard.
The auditor checks whether your documents (manuals, procedures, policies) meet the requirements of the standard. Any major gaps are identified before the on-site visit.
The audit that assesses the implementation and effectiveness of the management system, to see whether what is written in the procedures is actually applied. The auditors talk to employees and review concrete evidence.
Nonconformities may be identified during the audit. A nonconformity does not automatically mean that the organization cannot be certified. When nonconformities are identified, the organization has to analyze them and define and implement corrective actions.
If there are no major nonconformities (or the minor ones have been corrected), the official certificate is issued. It is valid for 3 years, provided that the annual surveillance audits are carried out.
Certification does not end when you receive the certificate. The management system has to be maintained and assessed periodically. During the certification cycle, surveillance audits are carried out according to the established program. They check whether the system continues to meet the applicable requirements and whether it is maintained and improved.
To extend the validity of the certificate for a new 3-year cycle, a recertification audit takes place.
You can implement the requirements in-house if you have the resources and the time, but most small and medium-sized companies use an external consultant to prepare the documentation faster and more efficiently.
Note: the consultant cannot also be the auditor from the certification body.
The consultant helps the organization build and implement its management system.
The certification body independently checks whether the system meets the applicable requirements.
The duration differs from one organization to another, depending on its complexity and size. A small organization with a single site and relatively simple processes may follow a different path from an organization with several sites and complex processes.
Obtaining ISO certification (whether ISO 9001, ISO 14001 or ISO 45001) takes a few months. It involves implementing the procedures internally, training the staff, checking the system through internal audits and, finally, the external audit carried out by an accredited body in order to issue the certificate. For companies that want maximum efficiency, an integrated management system (IMS) allows several standards to be implemented at the same time, significantly reducing the paperwork, the time and the overall cost of the process.
The cost of certification depends on the size of the organization, the number of employees, the complexity of the processes and the number of sites.
Implementing several standards together, also known as an integrated management system (most often ISO 9001 + ISO 14001 / + ISO 45001), saves documentation effort and money compared to obtaining them one at a time.
Certification is valuable when the management system is implemented and working within the organization.
Price is important, but it should not be the only criterion.
No. The audit also looks at how the system is implemented and how it works.
No. ISO develops the standards, while certification is carried out by certification bodies.
No. You need to check the scope of the accreditation.
Every organization is different. The right standard, the certification scope, the audit duration and the costs depend on the characteristics of the company.
Send us information about your organization and the standard you want to be certified against. SRAC's specialists can tell you the steps involved and send you a quote tailored to your organization.
Find out which standard fits your organization's activity and objectives.