Blog / October 10, 2026
How to get ISO certified: six steps and a realistic timeline

To get ISO certified, you choose the standard your customers need, build a management system that meets it, run it for a few months with an internal audit and a management review, and then pass a two-stage audit by an independent certification body. ISO itself does not issue certificates. Most companies start with ISO 9001 certification for quality management.
Step 1: choose the standard and the scope
Start from what your customers and markets ask for. ISO 9001 covers quality, ISO 14001 environment, ISO 45001 health and safety, ISO/IEC 27001 information security, ISO 22000 food safety and ISO 13485 medical devices. Check tender documents and supplier questionnaires, because they often name the standard and sometimes the version.
Then define the scope: which sites, activities and products the certificate will cover. A clear, honest scope makes the system easier to build and the certificate more useful to buyers.
Step 2: build the management system
Read the standard and compare it with how you already work. Most companies already do much of what it asks; the work is to make processes consistent, write down what needs writing and keep records that prove it happens.
Typical building blocks are a policy and objectives, defined processes and responsibilities, the documented information the standard requires, a way to handle problems and corrective actions, and a plan for internal audits and management reviews.
Step 3: run it and train people
A system has to work before it can be certified. Run it for long enough to produce records, usually a few months, and make sure people know their part. Training is available through MEGADEMI at megademi.com.
Step 4: internal audit and management review
Before the certification audit, audit your own system against the standard and hold a management review where leaders look at results, audit findings and improvements. Certification bodies expect to see both completed.
Step 5: Stage 1 and Stage 2 certification audits
Choose a certification body and ask for a written quote. The certification audit has two stages. Stage 1 reviews your documentation and readiness, often online, and lists anything to fix. Stage 2 checks that the system works in practice, online or on site depending on the standard and your activities.
Findings are graded as major or minor. Major findings must be corrected before a certificate can be issued; minor findings need a corrective action plan. The certification body then makes its decision on the evidence.
Step 6: keep the certificate
ISO certificates are valid for three years, with a surveillance audit in each of the first two years and a recertification audit before expiry. Keep the system running between audits: internal audits, management reviews, corrective actions and objectives.
How long does it take?
The audits themselves take days, not months. The time goes into building and running the system. A small company with good existing practices may be ready within a few months; a larger or more complex organization may need longer. Once you are ready, Stage 1 and Stage 2 can usually be scheduled within weeks.
With EUROTECH, ISO certification starts at $800, with online or on-site audits and certificates listed on our verification portal.
Next step: see ISO 9001 certification for what is included and the starting price, or ask for a quote.
