The basics

How ISO certification works

A plain-English walk through the process, and where the money actually goes.

What certification actually means

ISO certification means an independent, accredited auditor has checked that your management system meets an international standard, and issued a certificate that says so. It is not a government license and it is not permanent. You earn it, then you keep it by staying audited.

In the US, most standards are certified by private certification bodies that are themselves accredited by ANAB. That accreditation is what makes a certificate trustworthy to your customers.

The path to a certificate

  1. Learn the standard. Understand what it asks for and compare that to how you already work. The gaps become your project plan.
  2. Build the system. Put the processes, records and controls in place. This is where most of the time and money goes, whether you use a consultant or your own team.
  3. Run it. Operate the system for a few months so you have real records for an auditor to review.
  4. Audit yourself. A required internal audit and management review find problems before the certification body does.
  5. Stage 1 and stage 2. The certification body reviews your documents, then visits to check the system works in practice.
  6. Certificate and upkeep. You receive a certificate valid for three years, with a shorter surveillance audit each year and a full recertification at the end.

Where the cost comes from

There are two very different buckets, and people often forget the first one:

1. Implementation (usually the bigger cost)

The work of building the system: consultant fees if you hire help, plus the time your own staff spend. This almost always costs more than the audit itself.

2. The audit (paid to the certification body)

Certification bodies charge by the auditor day. The number of days depends on your company size and the standard. Then you pay for surveillance audits every year and recertification in year three.

Why we show ranges

The same certificate can cost one company half what it costs another. The drivers are size, how much you already document, how many sites you run, whether you hire a consultant, and which certification body you pick. A single figure would be wrong for almost everyone. A range shows the realistic low and high, so you can plan and then compare real quotes against it.

Two things that are not certification

Some standards, like ISO 26000, are guidance only and cannot be certified — anyone selling "certification" for them is misleading you. Others, like ISO/IEC 27701, can only be added on top of another certificate (ISO 27001). Our guides flag both cases.

See a cost range →