Skip to content
Clearline Systems

Article

How ISO Certification Works: The Steps, From Getting the Standard to Surveillance Audits

A plain-English walk through ISO certification: scope, Stage 1 and Stage 2 audits, nonconformities, the decision, and surveillance. Our summary, not ISO text.

Last reviewed October 1, 2026

If you have never been through ISO certification, the process can feel opaque. This article sets out the path in plain English. It is our summary of how certification bodies and ISO describe it, and yours may differ in detail, so ask your certification body for its own process.

A note on sources. This is our own summary of public sources, not ISO text. Check requirements against your own copy of the standard. Only a certification body can certify your organization.

Who does what

ISO writes the standards. ISO's own page says it "does not perform certification or issue certificates", and that certification is performed by external certification bodies, so a company or organization cannot be certified by ISO (ISO, Certification). Certification bodies in turn may be accredited by accreditation bodies. ANSI's release on ISO 9001:2026 says organizations pursuing certification should look for a certification body accredited by a recognized accreditation body, and that certification to ISO 9001 is voluntary (ANSI, September 16, 2026).

The eight steps

These eight steps are our own simplified summary, not a list from ISO or any certification body.

1. Get the standard. Buy your own copy from ISO or your national standards body. Any checklist, guide or template, ours included, paraphrases requirements in its own words and is not a substitute.

2. Decide your scope. Which site, division or product line will the system cover? Be honest about it, because your certification body will audit the scope you define.

3. Build and run your management system. This includes the documented information the standard asks for. See our article on documented information for how that is described in ISO's guidance.

4. Keep records and run internal audits and management reviews. Records are evidence of what you actually do. The ISO 9001 Auditing Practices Group's guidance paper says Stage 1 may evaluate whether internal audits and management reviews are being planned and performed (ISO 9001 Auditing Practices Group, Guidance on two stage initial certification audit). That paper says it has not been through ISO's, ISO/TC 176's or IAF's endorsement process.

5. Stage 1 audit. TÜV NORD, one certification body, says the initial certification audit is conducted in two stages. It describes the objectives of Stage 1 as including a review of the client's management system documentation, evaluating site-specific conditions and discussing with personnel to determine preparedness for Stage 2, gathering information about scope and processes, and planning Stage 2. It says that if areas of concern are identified in Stage 1, the client must resolve them before Stage 2 (TÜV NORD, Description of the certification process, Rev. 20/01.26). The APG paper describes Stage 1 as primarily for scoping and planning Stage 2 and for evaluating whether the organization is ready.

6. Stage 2 audit. TÜV NORD says the purpose of Stage 2 is to evaluate the implementation, including effectiveness, of the management system, and that this can be done through interviews, verifying relevant information during the audit and auditing relevant processes and areas of the organization. It says there is a closing meeting at which audit conclusions are presented, nonconformities are presented so they are understood, and the timeframe for responding is agreed.

7. Fix any nonconformities, then the certification decision. TÜV NORD says the certification body reviews, before making a certification decision, that the information from the audit team is sufficient and that corrections and corrective actions for nonconformities are accepted. The certificate is issued based on that decision. The decision is the certification body's. We cannot make it for you, and neither can a consultant or a template.

8. Keep going. TÜV NORD says surveillance audits are conducted at least once per calendar year within the three-year validity of the certificate, except in the years when a recertification audit is conducted, and that the recertification audit is completed before the certificate expires. Ask your own certification body for its schedule.

What to ask a certification body

Because details vary, here are questions worth asking before you sign anything:

  • How does it run Stage 1 and Stage 2, and how are they scheduled?

  • How does it handle nonconformities, and what is the time frame for responding?

  • What are its arrangements for surveillance and recertification?

  • If a new edition of the standard is being phased in, what are its transition dates? (See our article on the ISO 9001:2026 transition timeline.)

These are our own suggestions, not a list from ISO or any certification body.

Do you need certification?

ISO/TC 176/SC 2's guidance on ISO 9001:2015 says there is no obligation to be certified to ISO 9001, and that organizations can benefit from using the standard without seeking certification (ISO/TC 176/SC 2, ISO 9001:2015, How to use it). If a customer or tender asks for a certificate, that is a clear reason to go for one. If not, it is worth asking whether you need one.

Doing it yourself or with help

Some organizations do this with a consultant and some do it in-house. Both are legitimate choices. Either way, you still have to do the work, and the certification body decides the outcome. Our article on what each route gives you goes into this, and our article on what certification certainty really means explains what can and cannot be known in advance.

A sensible first step

If you are willing to try the preparation yourself, a sensible first step is seeing where you stand today. Our free Gap Analysis Checklist for ISO 9001:2026 has 111 plain-English questions covering clauses 4 to 10, with 25 new or changed 2026 requirements flagged. It comes in Excel and Word. The download page has a short sign-up form; occasional emails about Clearline Systems kits are a separate, optional tick box. For how to use the results, see how to know where you stand before your audit.

The checklist paraphrases requirements in our own words. It is not ISO text, you will still need your own copy of the standard, and using it does not promise a pass or certification. Only a certification body can certify your organization.

Clearline Systems is an independent publisher of documentation templates. Clearline Systems is not affiliated with or endorsed by ISO (the International Organization for Standardization), IAF, ANSI, TÜV NORD, any national standards body, accreditation body or certification body. We don't reproduce ISO text; you'll need your own copy of the standard.

Sources

  1. ISO, Certification: https://www.iso.org/certification.html

  2. ISO 9001 Auditing Practices Group, Guidance on two stage initial certification audit, Edition 1, January 13, 2016 (the paper says it is not endorsed by ISO, ISO/TC 176 or IAF): https://committee.iso.org/files/live/sites/tc176/files/PDF%20APG%20New%20Disclaimer%2012-2023/ISO-TC%20176-TF_APG-2stage.pdf

  3. TÜV NORD, Description of the certification process, Rev. 20/01.26 (one certification body's description; others may differ): https://www.tuv-nord.com/fileadmin/Sites/TUEV_NORD_Worldwide/Eesti/PDFs/Description_of_the_certification_process_Rev_20-01.26_.pdf

  4. ANSI, "First Full Revision of ISO 9001 in a Decade Now Available from ANSI," September 16, 2026: https://www.prnewswire.com/news-releases/first-full-revision-of-iso-9001-in-a-decade-now-available-from-ansi-302880800.html

  5. ISO/TC 176/SC 2, ISO 9001:2015, How to use it: https://committee.iso.org/files/live/sites/tc176sc2/files/documents/iso_9001-2015_-_how_to_use_it.pdf.pdf

All sources checked October 1, 2026.