It is the first question most companies ask, and the honest answer is that most of the timeline is you, not us. The audits themselves take days. Getting your management system running, with enough records to audit, is what decides whether certification takes a couple of months or most of a year.
As a guide, a small organisation starting from scratch is usually looking at about two to three months from the decision to get certified to holding the certificate. If your system is already up and running, it is quicker, and mostly a question of scheduling the audits.
The steps, in order
1. Build and run your management system. You write down what you do, do what you wrote, and keep records. This is normally the longest phase and it is entirely in your hands. A small company with management commitment and a simple scope moves quickly.
2. Run an internal audit and a management review. Both are required by the standard and both must be done before your Stage 2 audit. They cannot be skipped, and they need real evidence.
3. Request a quote and sign the agreement. We need your employee count, sites, shifts and scope to plan the audit. Usually a few days.
4. Stage 1 audit. We review your documented system, your scope and your readiness, and identify anything that would cause problems at Stage 2.
5. The gap between Stage 1 and Stage 2. Normally at least two weeks, so you have time to act on what Stage 1 found. If Stage 1 shows you are not ready, the gap will be longer.
6. Stage 2 audit. The main audit, checking how your system works in practice. The number of audit days depends on your size, sites and complexity. Audits are normally carried out on site, although remote auditing is an option where the risk is low and the activity allows it.
7. Closing nonconformities. If anything is raised at Stage 2, you have 30 days to submit a corrective action plan for a major nonconformity and 60 days for a minor one. Majors must also be corrected and verified before certification can be granted. How long this step takes is driven by how quickly you respond.
8. Certification decision and certificate. An independent reviewer who was not on the audit team checks the results, and then your certificate is issued, valid for three years.
Where the time actually goes
- Building the system — you control this, and it is usually the bulk of the timeline
- Internal audit and management review — you, and both are mandatory before Stage 2
- Quote and agreement — shared, usually days
- Stage 1 audit — scheduled with you
- Stage 1 to Stage 2 gap — at least two weeks
- Stage 2 audit — scheduled with you
- Closing nonconformities — you
- Certification decision — us, once everything is closed
What slows certification down
- No internal audit or management review yet. This is the most common reason Stage 2 gets delayed.
- A scope that is too broad, covering activities you do not need certified.
- Major nonconformities at Stage 2, which need a corrective action plan within 30 days and have to be corrected and verified before certification.
- Availability. Audits need the right people present, so holidays, shutdowns and busy season all matter.
- Late paperwork, such as signing the agreement or confirming employee numbers.
What speeds it up
- Having records that show the system running, not just documents describing it
- Completing your internal audit and management review before booking Stage 2
- Keeping the scope focused on what you actually need certified
- Naming one person as the contact for scheduling and questions
- Combining standards, such as ISO 9001 with ISO 14001 or ISO 45001, into one audit rather than separate ones
Already certified elsewhere? It is faster
Transferring an accredited certificate to a new certification body does not restart the process. You keep the remainder of your three-year cycle and skip the initial Stage 1 and Stage 2 audits. See how to switch ISO registrars.
Common questions
Can we be certified in 30 days?
Only if your system is already running and you have the records to prove it, including a completed internal audit and management review. Certification audits check evidence, and evidence takes time to build up.
Does ISO 27001 take longer than ISO 9001?
The process is the same. Information security systems often take longer to implement because of the risk assessment and the controls in the Statement of Applicability, but the audit stages do not change.
Do Stage 1 and Stage 2 have to be separate?
Yes, for initial certification. They are separate stages, with time in between so you can act on what Stage 1 finds.
When does the three-year clock start?
At the certification decision. Your first surveillance audit is due within a year of that date.
Does the timeline affect the cost?
Not directly. Audit days are set by your size, scope and complexity rather than how long you take to get ready. See what drives the cost of ISO 9001 certification in Canada.
Ready to plan your timeline?
Tell us your employee count, sites, scope and where you are with your system, and we will tell you what a realistic schedule looks like. Request a quote — no charge, no obligation.
As an accredited certification body we audit and certify management systems. We cannot design or implement your system for you, because that would compromise our impartiality.