How Long Does ISO Certification Take? A Realistic Timeline
Data checked:
TL;DR
For a small business, achieving ISO management-system certification commonly takes around three to six months. A company with a mature system, dedicated internal owner and available audit dates may complete the process in roughly eight to twelve weeks. A business starting from scratch, operating multiple locations or addressing complex risks may need six to twelve months or longer. These are planning ranges, not formal ISO deadlines: the external audit may occupy only a few auditor-days, but implementation, operating evidence, internal audits, management review, booking availability, corrective actions and the independent certification decision create the full calendar timeline.

Ask three ISO consultants how long certification takes and you will get three confident answers, usually somewhere between "six weeks" and "next year". Both can be true. The certification audit itself might occupy two or three auditor-days, but the project around it, writing processes, running them, gathering records, auditing yourself, reviewing performance and waiting for an audit slot, is what fills the calendar.
This guide walks through every stage, explains why audit days and calendar months are different measurements, and gives you a way to estimate your own likely range.
What actually determines the timeline?
No two projects run at the same speed, and the differences are rarely about company size alone. The factors that move the date most are:
- the current maturity of your management system;
- which ISO standard you are seeking;
- the scope of certification, products, services, departments and sites;
- the effective number of personnel, including part-time, temporary and contracted staff;
- the number and type of locations;
- shifts, seasonal operations and outsourced processes;
- industry risk and technical complexity;
- whether an experienced internal project owner is available;
- how genuinely involved top management is;
- whether internal audits and management review are complete;
- certification-body auditor availability;
- the number and severity of audit findings;
- whether several standards are being integrated;
- whether accredited certification is required by a customer or tender.
Fewer employees do not automatically mean an extremely short audit. A ten-person business handling regulated medical data, hazardous processes or safety-critical components can carry more risk than a fifty-person office, and the certification body's audit-time calculation reflects that.
The twelve stages at a glance
Indicative planning times. Stages overlap in practice, and booking lead times often run in parallel with implementation.
- 1
Objective and scope
A few days to 2 weeks
- 2
Gap assessment and plan
1–3 weeks
- 3
Implement the system
4 weeks to 6 months+
- 4
Operate and gather evidence
Several weeks to months
- 5
Internal audit
1–3 weeks, plus actions
- 6
Management review
A few days to 2 weeks
- 7
Select and book the body
Start weeks or months ahead
- 8
Stage 1 audit
Audit activity, then readiness work
- 9
Resolve Stage 1 concerns
1–6 weeks or longer
- 10
Stage 2 audit
One or more auditor-days
- 11
Correct nonconformities
Days to months
- 12
Certification decision
Days to weeks after closure
The complete ISO certification timeline
Define scope and assess the gap
Indicative planning time: one to five weeks
Before anything else, settle six questions. Which standard is required? Which legal entity will be certified? Which products, services, departments and sites are included? Is accredited certification required by the customer or tender? What deadline is genuinely fixed, as opposed to merely desirable? And who owns the project internally?
A vague or shifting scope is the most reliable way to lose a month. It also makes quotations unreliable, because certification bodies calculate audit time from scope, headcount, locations and risk. Change the scope after you receive a quotation and the quotation changes with it.
Once the scope is fixed, compare what you already do against what the standard requires, and identify the missing controls, responsibilities, records and evidence. The output should be a plan with named owners and dates, not a list of clauses. This gap assessment can be done internally if someone knows the standard well, or by an independent consultant. What it cannot be is a service quietly provided by the certification body that will later certify you: impartiality requirements in ISO/IEC 17021-1 stop a certification body from designing the management system it then audits. If you are unsure who does what, the split is set out in our guide to ISO certification bodies versus ISO consultants.
Implement the system and generate evidence
Indicative planning time: four weeks to six months or longer
This is usually the longest stage, and the one most often underestimated. Depending on the standard, it covers defining processes and responsibilities, assessing risks and opportunities, setting policy and objectives, establishing operational controls, producing the documented information the standard actually requires, training employees, arranging monitoring and measurement, setting up corrective action, and identifying applicable legal and contractual requirements.
Implementation means using the system, not buying it. A folder of purchased templates with your logo on the cover creates no evidence, and auditors sample evidence. If your procedure says supplier performance is reviewed quarterly, an auditor will ask to see the reviews.
Once the processes are running, auditors need objective evidence that the system works in practice: completed records, monitoring results, training evidence, supplier evaluations, risk-treatment actions, incident or complaint handling, corrective actions and performance against objectives. This is where the calendar wins arguments. You cannot compress three months of quality records into a weekend. Some certification bodies also set their own expectations about how long the system should have been running, NQA, for example, states that its ISO 9001 clients must be able to demonstrate at least three months of operation before assessment. Treat that as one body's requirement to check, not a universal rule imposed by ISO.
Internal audit and management review
Indicative planning time: two to five weeks, plus corrective actions
The internal audit tests whether your system conforms to the standard and works effectively. It is not the certification audit, and it is not a formality. Auditors should be competent and sufficiently objective, people should not audit their own work, and findings need owners, actions and evidence of completion. A rushed tick-box exercise here reliably produces problems at the certification body's audit, because auditors look at your internal audit programme and judge how seriously you took it.
Top management then reviews performance, audit results, changes affecting the organisation, resources, objectives, risks and opportunities, and improvement needs. The review should produce decisions with owners, recorded in minutes. A calendar invitation with no output is not a management review, and auditors notice the difference immediately.
Select and book the certification body
Recommended timing: begin several weeks or months before the desired audit
You do not have to wait until implementation is finished to request quotations. Start early, because auditor availability frequently becomes the critical path.
To quote accurately, a certification body needs the standard, the scope, employee numbers, locations, shifts, activities and risk, outsourced processes, any existing certifications and your intended audit dates. The first available date may be several weeks away, particularly for specialised standards, regulated sectors or accredited scopes with a small pool of qualified auditors.
Comparing providers is easier with parallel quotations, you can request independent ISO quotes through StandardsDesk, and worth reading alongside our breakdown of what ISO certification costs a small business.
Stage 1 audit and readiness
Indicative elapsed time: audit activity, plus one to six weeks or longer to resolve concerns
Stage 1 normally examines whether you are ready for Stage 2. Depending on the standard and the certification body, it may cover scope and site information, your understanding of the standard, management-system documentation, key processes and risks, internal audit and management review status, regulatory and contractual context, and overall readiness for the full assessment.
Stage 1 is not a rehearsal, and it is not a consulting session. The auditor can tell you what is missing but cannot tell you how to build it. If significant readiness problems appear, Stage 2 may have to be postponed, which is inconvenient, but far cheaper than failing the main audit. You may then need to strengthen evidence, finish outstanding work or correct readiness issues before Stage 2 proceeds. Certification bodies use different terminology for Stage 1 outputs, and not every observation is handled through the same formal route as a Stage 2 nonconformity, so follow the instructions and definitions in your certification body's own process rather than assuming.
Stage 2 audit through to the certification decision
Indicative timing: one or more auditor-days, plus several days to several weeks for corrective actions and the certification decision
Stage 2 assesses implementation and effectiveness through interviews, observation of processes, sampling of records, site visits, review of objectives and performance, internal-audit and management-review evidence, corrective actions, and applicable legal and operational controls. The certification body calculates how much audit time is required. You cannot simply choose the shortest option, and a provider that lets you is telling you something about the value of its certificate.
Findings are usually classified by severity. A minor nonconformity typically requires an accepted corrective-action plan and supporting evidence, in line with the certification body's process. A major nonconformity normally requires stronger evidence and may require a follow-up or additional audit before certification can proceed. Correcting a nonconformity means dealing with the immediate problem and its cause, not just fixing one missing record while the reason it was missing remains in place.
The auditor does not hand over a certificate at the closing meeting. The audit report and any corrective-action evidence are reviewed, and an authorised person or function independent of the audit team makes the certification decision. The certificate is issued only after that decision is positive. Build this review period into your plan, especially if a tender deadline depends on holding the certificate.
Two different clocks
Calendar time
The complete elapsed project time, from deciding to pursue certification until the certificate is issued.
Audit time
The amount of auditor effort calculated by the certification body, normally expressed in auditor-days of about eight hours each.
A two-day Stage 2 audit does not mean a two-day project. Audit duration and project duration are separate numbers, and only the certification body can calculate the first.
Audit days versus calendar time
IAF MD 5:2023 sets out audit-time principles for quality, environmental and occupational health and safety management systems, based on factors including the effective number of personnel, complexity and risk. A few points matter for planning:
- an audit day is normally eight hours;
- initial certification audit time covers both Stage 1 and Stage 2;
- two auditors working for one day can represent two auditor-days, although the team composition must still support an effective audit;
- multiple sites, shifts, complex processes and higher risk categories may increase audit time;
- remote auditing can reduce travel, but it does not automatically remove required audit effort.
ISO/IEC 27001 certification follows additional scheme-specific requirements, including ISO/IEC 27006-1:2024, so a generic audit-day table for quality management does not transfer to information security. Multi-site sampling has its own document, IAF MD 1:2023, and integrated audits are addressed in IAF MD 11:2023. Ask your certification body which documents apply to your scheme.
Example: a 12-person single-site service company
The company already has established operating processes but no formal ISO 9001 management system. One operations manager takes the project on alongside their normal role, with visible support from the director.
- Week 1: define scope and assign the project owner
- Weeks 2–3: gap assessment and implementation plan
- Weeks 3–7: formalise and start operating the necessary processes
- Week 8: internal audit
- Week 9: correct internal findings
- Week 10: management review
- Week 11 or 12: Stage 1 audit
- Weeks 12–14: address Stage 1 concerns
- Week 15 or 16: Stage 2 audit
- Following weeks: corrective-action review and certification decision
A realistic planning estimate here is approximately four months, provided suitable auditors are available and no major problems are found. This is an illustrative scenario, not a guaranteed schedule and not an ISO requirement.
Contrast that with a multi-site manufacturer starting from scratch. It may need six to twelve months or longer, because controls must be implemented across locations, shifts and operational risks before enough evidence exists for anyone to audit.
How the common standards differ
| Standard | Factors that commonly affect preparation time |
|---|---|
| ISO 9001 | Process consistency, customer requirements, performance measures, supplier controls and corrective actions |
| ISO 14001 | Environmental aspects, compliance obligations, operational controls, emergency planning and performance evidence |
| ISO/IEC 27001 | Risk assessment, Statement of Applicability, security controls, asset information, incidents and control-effectiveness evidence |
| ISO 45001 | Hazard identification, worker participation, legal obligations, operational controls, incidents and emergency preparedness |
| Integrated system | Coordination across standards may take longer to implement but can reduce duplication when the systems genuinely share processes |
None of these standards is inherently faster or easier than the others. A software company with mature engineering practices may find ISO/IEC 27001 straightforward and ISO 14001 unfamiliar; a manufacturer often finds the reverse.
Estimate your ISO certification timeline
Six questions produce an indicative planning band. Everything runs in your browser.
Indicative planning band
Approximately 6–12 months
Why this band
Several things still have to be built and then operated long enough to produce evidence, which is what usually stretches the calendar rather than the audit itself.
Biggest likely delay
Internal audit and management review are outstanding, and certification bodies normally expect both before Stage 2.
Next three actions
- Run a focused gap assessment against the standard and write a dated implementation plan.
- Complete the internal audit and hold a genuine management review with recorded decisions.
- Request certification quotations now so booking lead time runs alongside your remaining work.
Confirm available audit dates and the calculated audit duration with a certification body before you commit to any deadline.
This estimator provides an indicative project-planning range, not a quotation, audit-time calculation or guarantee of certification. Your answers are not collected, transmitted or stored.
Common delays
- No clear scope
- No internal owner
- A management system that exists only as templates
- Insufficient operating evidence
- Internal audit not completed
- Management review not completed
- Late selection of a certification body
- Auditor availability
- Sites or shifts omitted from planning
- Unclear legal or regulatory requirements
- Major nonconformities
- Slow corrective-action responses
- Employees unaware of their responsibilities
- Scope changes shortly before the audit
- A consultant promising an unrealistic deadline
How to shorten the timeline safely
Speed should come from preparation, not from removing necessary work. The projects that finish quickly tend to do the same things:
- define the scope immediately and stop changing it;
- assign one accountable internal project owner;
- run a focused gap assessment rather than a general audit of everything;
- reuse existing processes that already work;
- avoid documentation the standard does not require and nobody will read;
- book the certification body early, in parallel with implementation;
- conduct internal audits before Stage 1, not after;
- hold a management review that produces decisions;
- track corrective actions with owners and deadlines;
- keep evidence organised and easy to retrieve during the audit;
- make sure employees understand the processes they personally perform;
- ask the certification body what information it needs to calculate audit time.
Equally, some shortcuts destroy the value of the certificate. Do not fabricate or backdate records. Do not buy a certificate without a genuine audit. Do not accept guaranteed certification from anyone. And do not choose a provider purely because it quoted the shortest audit, a customer checking your certificate will look at who issued it and under what accreditation.
If you want a structured view of where you currently stand, the ISO readiness check walks through the same areas an auditor examines, and the ISO certification hub explains how the standards relate to one another.
What happens after certification?
Certification is not a finish line. An accredited management-system certification normally runs as a cycle: the initial Stage 1 and Stage 2 audit, periodic surveillance audits, and recertification before the cycle ends.
A three-year cycle with surveillance audits in the intervening years is common, but the exact programme follows the applicable certification scheme and your certification body's arrangements. Plan for the recurring audit effort and cost from the start, rather than discovering it at the first surveillance visit.
Frequently asked questions
What is the fastest realistic timeline, and can it be done in 30 days?
Around eight to twelve weeks is the fastest realistic timeline, and only for an organisation whose management system is already operating, whose internal audit and management review are complete, and which can get audit dates quickly. Genuine certification in 30 days is very unlikely: there would be almost no operating evidence to sample, and many certification bodies expect a period of demonstrated operation before assessment. Offers of certification within days should be treated as a warning sign.
How long does ISO 9001 certification take?
Commonly three to six months for a small business, faster where processes already run consistently and slower where quality records, internal audit and management review have to be created from nothing.
How long does ISO/IEC 27001 certification take?
Typically three to six months, though NQA reports that experienced teams sometimes reach certification in two to three months and that six months or more is not uncommon. Risk assessment, the Statement of Applicability and evidence of control effectiveness drive most of the effort.
How long do the Stage 1 and Stage 2 audits take, and what gap is needed between them?
Stage 1 is often a fraction of the total initial audit time, sometimes half a day to a day or two for a small organisation, while Stage 2 can run from one or more auditor-days for a very small, low-risk single-site organisation to considerably longer for larger, multi-site or higher-risk operations. The certification body calculates both durations from your scope and risk, it is not chosen by the client. The gap between the two is frequently two to six weeks, enough to address readiness concerns without the Stage 1 findings going stale, though some certification bodies allow small, straightforward scopes to run Stage 1 and Stage 2 on consecutive days if they agree; that leaves no time to fix readiness problems, so it carries more risk of an unsuccessful Stage 2.
Does a small company have a shorter audit?
Usually, but not always. Effective personnel numbers are only one input. Risk, regulation, technical complexity, shifts and the number of sites can all increase audit time for a small organisation.
What happens if the auditor finds a major nonconformity?
Certification is normally withheld until the issue is resolved with acceptable evidence, and a follow-up or additional audit may be required. This is the single most common cause of a certificate arriving months later than planned.
Can a consultant guarantee a certification date?
No. A consultant does not make the certification decision and cannot control audit findings or auditor availability. A guaranteed pass or guaranteed date is a reason to look elsewhere.
“ISO does not perform certification.”
Need a realistic certification schedule?
ContinueSources and methodology
Timeline ranges in this article are drawn from the published certification-process requirements in ISO/IEC 17021-1, the IAF mandatory documents identified in UKAS's current publication list (IAF MD 1:2023 for multi-site organisations, IAF MD 5:2023 for QMS, EMS and OH&S audit time, and IAF MD 11:2023 for integrated audits), the scheme-specific requirements of ISO/IEC 27006-1:2024, and the published guidance of accreditation bodies (UKAS, ANAB) and certification bodies (NQA). Where a duration reflects one certification body's own client experience, it is attributed to that body rather than presented as an ISO rule. ISO does not publish a universal certification timetable and does not certify organisations itself. Estimates describe commonly observed planning patterns, not guaranteed schedules. All sources were checked on 19 August 2026.
- ISO. Management system standards - checked 19 August 2026
- ISO. Certification - checked 19 August 2026
- ISO. ISO/IEC 17021-1:2015 — Requirements for bodies providing audit and certification of management systems - checked 19 August 2026
- ISO. ISO/IEC 27006-1:2024 — Requirements for bodies providing audit and certification of information security management systems - checked 19 August 2026
- ANAB. How to seek management system certification - checked 19 August 2026
- ANAB. Management systems accreditation - checked 19 August 2026
- UKAS. Publications and technical bulletins for certification bodies - checked 19 August 2026
- NQA. ISO 9001 certification process - checked 19 August 2026
- NQA. How long does ISO 27001 certification take? - checked 19 August 2026
- International Accreditation Forum. IAF MD 5:2023 — Determination of audit time of quality, environmental, and occupational health & safety management systems - checked 19 August 2026
- International Accreditation Forum. IAF MD 1:2023 — Certification of multiple sites based on sampling - checked 19 August 2026
- International Accreditation Forum. IAF MD 11:2023 — Application of ISO/IEC 17021-1 for audits of integrated management systems - checked 19 August 2026
About the author
General information articles from the StandardsDesk editorial team.
Editorial note: StandardsDesk is an independent educational and referral service. It is not an LEI issuing organisation, a Local Operating Unit, a GLEIF Registration Agent, a certification body, or a legal, tax or investment adviser. Services are delivered by independent third-party providers, which may pay StandardsDesk a referral fee. Read the affiliate disclosure.


