Skip to content
Clearline Systems

Article

What Certification Certainty Really Means (and What No Toolkit or Consultant Can Promise)

No consultant, toolkit or template publisher can promise you will be certified. Here is what you can be certain about, and how to prepare.

Last reviewed October 1, 2026

If you are preparing for ISO certification for the first time, the uncertainty is the hard part. You do not know what the auditors will ask or whether you will be told "yes" at the end. This article is about what can and cannot be certain, and it aims to be fair to everyone involved, including consultants, toolkit publishers like us, and certification bodies.

The one thing nobody can promise

No one other than the certification body can promise you will be certified. ISO itself makes the point: it "does not perform certification or issue certificates", and certification is performed by external certification bodies, so an organization cannot be certified by ISO (ISO, Certification).

ISO describes certification as written assurance provided by an independent body. One certification body's process description says that before it makes a certification decision it reviews whether the information from the audit team is sufficient and whether corrections and corrective actions for any nonconformities are accepted (TÜV NORD, Description of the certification process). That is an independent judgment about your organization, made after the audit. A consultant cannot make it for you. A toolkit cannot make it for you. We cannot make it for you.

So when anyone, including us, says "we promise you will pass", treat it with caution. We do not say it.

What you can be certain about

Uncertainty about the outcome does not mean uncertainty about everything. A good deal of the process is written down, and you can know it in advance.

1. The steps (our summary). Get the standard, decide your scope, build and run your management system with the documented information the standard asks for, keep records as evidence, and then go through the certification body's audits.

2. The two-stage audit. According to the ISO 9001 Auditing Practices Group's guidance paper (which says it has not been through ISO's or IAF's endorsement process), Stage 1 is primarily for scoping and planning Stage 2, and for evaluating whether the organization is ready. It also looks at whether internal audits and management reviews are being planned and performed (ISO 9001 Auditing Practices Group, Guidance on two stage initial certification audit). One certification body describes Stage 2 as evaluating how the system is implemented, including effectiveness, which it says can be done through interviews, verifying information during the audit, and auditing processes and areas of the organization (TÜV NORD).

3. What happens if something is found. The same certification body says nonconformities are presented at a closing meeting so they are understood, and that the time frame for responding is agreed (TÜV NORD).

4. That it continues after the certificate. The same description says surveillance audits are conducted at least once per calendar year during the three-year validity of the certificate, except in a year with a recertification audit (TÜV NORD). Ask your own certification body for its schedule.

5. Where you stand today. You cannot know the audit result, but you can find out how your current system compares with the requirements, clause by clause. We cover that in how to know where you stand before your audit.

Why "a consultant feels more certain"

Feeling more certain with a consultant is reasonable. A consultant is a person you can ask, who can look at your actual site and people, and who may have worked with other organizations. Some organizations will want that, and we would not talk anyone out of it.

What a consultant can give you is experience, tailoring and someone to talk to. What a consultant cannot give you is the audit result, because that is decided by the certification body. Whichever route you choose, the certainty that is available is about the process, not the outcome. If you want to compare the two routes, read toolkit or consultant: what each gives you.

Do you need certification at all?

ISO's own guidance says there is no obligation to be certified to ISO 9001, and that many organizations benefit from using the standard without seeking certification (ISO 9001:2015, How to use it). If a customer or tender requires a certificate, that is a good reason to go for one. If not, it is worth asking whether you need one.

Certainty about sources

We cite sources for the claims in this article and say when we haven't checked something. Our documents paraphrase the standard in our own words and do not reproduce ISO text. Our kits are built on each standard's published clause structure and on public guidance from certification and accreditation bodies, not on a licensed copy of the standard, and they are pre-launch material. Check requirements against your own licensed copy of the standard.

A fair summary

  • No one except the certification body can promise certification. This applies to consultants, toolkits and us.

  • Much of the process is knowable: the steps, the two stages, how findings are handled, and what happens after the certificate.

  • You can know where you stand today by comparing your system with the requirements, clause by clause.

  • Whichever route you choose, the audit checks whether you follow your own system, so your people and records still matter.

If you want a place to start, our free Gap Analysis Checklist for ISO 9001:2026 has 111 plain-English questions covering clauses 4 to 10, with 25 new or changed 2026 requirements flagged. It is a self-assessment and does not promise a pass or certification. Only a certification body can certify your organization.

Clearline Systems is an independent publisher of documentation templates. Clearline Systems is not affiliated with or endorsed by ISO (the International Organization for Standardization), any national standards body, accreditation body or certification body. We don't reproduce ISO text; you'll need your own copy of the standard.

Sources

  1. ISO, Certification: https://www.iso.org/certification.html

  2. ISO 9001 Auditing Practices Group, Guidance on two stage initial certification audit, Edition 1, 13 January 2016 (published by ISO and IAF's practice group; the paper says it is not endorsed by ISO or IAF): https://committee.iso.org/files/live/sites/tc176/files/PDF%20APG%20New%20Disclaimer%2012-2023/ISO-TC%20176-TF_APG-2stage.pdf

  3. TÜV NORD, Description of the certification process, Rev. 20/01.26 (one certification body's description; others may differ): https://www.tuv-nord.com/fileadmin/Sites/TUEV_NORD_Worldwide/Eesti/PDFs/Description_of_the_certification_process_Rev_20-01.26_.pdf

  4. ISO/TC 176/SC 2, ISO 9001:2015, How to use it: https://committee.iso.org/files/live/sites/tc176sc2/files/documents/iso_9001-2015_-_how_to_use_it.pdf.pdf

All sources checked October 1, 2026.