Enquire Us

What is ISO 9001 certification?

ISO 9001 is the international standard for a quality management system, published by ISO. This page explains what the standard requires, what a certificate actually means, who issues it and how accredited certification differs from a self declaration.

What ISO 9001 is

ISO 9001 is the international standard that sets out the requirements for a quality management system, published by the International Organization for Standardization. It is the only standard in the ISO 9000 family that an organisation can be certified against. ISO 9000 provides the fundamentals and vocabulary, and ISO 9004 gives guidance on managing for sustained success, but neither is certifiable.

The standard is deliberately generic. It applies to any organisation regardless of size, sector or whether it makes a physical product or delivers a service. It does not specify how good your product must be. It specifies how you must govern the processes that produce it: understand your context and customers, plan against risk, control your operations, measure what happens, and act on what you find.

Which edition applies

The current edition is ISO 9001:2015, the fifth edition. It was amended by ISO 9001:2015/Amd 1:2024, Climate action changes, which requires an organisation to consider whether climate change is a relevant issue when determining its context and the needs and expectations of interested parties. The amendment did not change anything else in the standard.

ISO currently lists ISO 9001:2015 as a standard to be revised and has indicated that a revised edition is expected. Until that revision is published, ISO 9001:2015 with Amendment 1:2024 is the version you implement and are audited against. Check the ISO catalogue entry for ISO 9001 before planning any transition, and expect a transition period to be announced once a new edition appears.

How the standard is structured

Clauses 1 to 3 cover scope, normative references and terms and definitions. The auditable requirements sit in clauses 4 to 10, which follow the harmonised structure common to ISO management system standards.

  • Clause 4, Context of the organisation. External and internal issues, interested parties, the scope of the quality management system, and the QMS and its processes.
  • Clause 5, Leadership. Leadership and commitment, customer focus, the quality policy, and organisational roles, responsibilities and authorities.
  • Clause 6, Planning. Actions to address risks and opportunities, quality objectives and planning to achieve them, and planning of changes.
  • Clause 7, Support. Resources including people, infrastructure, environment, monitoring and measuring resources and organisational knowledge, plus competence, awareness, communication and documented information.
  • Clause 8, Operation. Operational planning and control, requirements for products and services, design and development, control of externally provided processes, production and service provision, release, and control of nonconforming outputs.
  • Clause 9, Performance evaluation. Monitoring, measurement, analysis and evaluation including customer satisfaction, internal audit, and management review.
  • Clause 10, Improvement. Improvement, nonconformity and corrective action, and continual improvement.

The seven quality management principles

ISO 9001 is built on the quality management principles set out in ISO 9000. They are not audit requirements in themselves, but they explain why the requirements are written the way they are.

  • Customer focus
  • Leadership
  • Engagement of people
  • Process approach
  • Improvement
  • Evidence based decision making
  • Relationship management

What certification actually is

Certification is a third party conformity assessment. An independent certification body audits your quality management system against ISO 9001 and, where it conforms, issues a certificate stating the scope of certification and the sites it covers. Two points are commonly misunderstood.

  • ISO does not certify anyone. ISO writes standards. It states plainly that it does not perform certification, does not issue certificates and does not allow its logo to be used in connection with certification.
  • Accreditation and certification are different things. A certification body may itself be accredited by a national accreditation body, which assesses it against ISO/IEC 17021-1. Accreditation is independent confirmation that the certification body is competent. ISO notes accreditation is not compulsory, but most buyers now ask for an accredited certificate, and accredited certificates can be checked in IAF CertSearch.

A certificate is not a warranty of product quality and it is not issued to a person. It is issued to an organisation for a defined scope, and it can be suspended or withdrawn.

How the certification audit runs

  1. Application and scope agreement. The certification body establishes what is being certified, at which sites, and determines the audit time on the basis of the effective number of personnel and the complexity of your processes, following the IAF mandatory document on audit duration.
  2. Stage 1 audit. A documentation and readiness review. The auditor checks the scope, the documented information, the internal audit results and the management review records, and identifies anything that would prevent a successful Stage 2.
  3. Stage 2 audit. An audit of implementation and effectiveness, carried out on site or remotely as permitted, sampling evidence across the processes in scope.
  4. Nonconformity closure. Major nonconformities must be resolved and verified before a certificate is issued. Minor nonconformities are normally addressed through an accepted corrective action plan.
  5. Certification decision. Made by someone at the certification body who was not part of the audit team, and the certificate is then issued.
  6. Surveillance and recertification. Surveillance audits during the three year cycle, normally annually, and a recertification audit before expiry.

Who typically needs it

ISO 9001 is most often driven by customers rather than regulators. Manufacturers and component suppliers use it as a condition of entry to industrial supply chains. Engineering, construction and facilities firms need it to prequalify for tenders. IT and business services providers use it alongside information security certification when bidding for enterprise and public sector work. Exporters use it because an internationally recognised certificate removes a discussion about credibility with a buyer who cannot visit the site.

It is also used internally, by organisations that have grown quickly and want a single agreed way of working rather than several competing ones.

How Univate supports ISO 9001 certification

Univate works on the implementation side: setting a scope that reflects what you actually do, mapping processes and their interactions, building the documented information the standard requires without generating paperwork nobody reads, establishing objectives and measurement that mean something to the business, running the internal audit programme and management review, and preparing your teams for Stage 1 and Stage 2 with the certification body you appoint.

We do not issue certificates. The accreditation rules certification bodies work under keep consultancy and certification separate, and that separation is what makes the certificate worth holding.

ISO 9001 certification questions we are asked most often

What is ISO 9001 certification?

ISO 9001 certification is a third party attestation that an organisation quality management system meets the requirements of ISO 9001. An independent certification body audits the system, and if it conforms, issues a certificate that states the certified scope and the sites covered. ISO itself does not certify organisations and does not issue certificates.

Which edition of ISO 9001 should we certify against?

ISO 9001:2015, the fifth edition, together with ISO 9001:2015/Amd 1:2024 on climate action changes. ISO lists the standard as one to be revised and a new edition is expected, at which point a transition period will be announced. Until then the 2015 edition with the 2024 amendment is what certification bodies audit against.

Is ISO 9001 certification mandatory?

Not as a matter of law in most markets. It becomes effectively mandatory through contracts. Customers, tender processes, group parents and some regulated supply chains require an accredited certificate as a condition of doing business, which is the usual reason organisations pursue it.

What does accredited certification mean and why does it matter?

An accredited certification body has been assessed by a national accreditation body against ISO/IEC 17021-1, which sets requirements for bodies auditing management systems. Accreditation gives independent confirmation of competence. Certificates from accredited bodies can be verified in IAF CertSearch, the International Accreditation Forum database. ISO notes that accreditation is not compulsory and that a body without it is not necessarily disreputable, but buyers and tender panels increasingly ask for accredited certificates specifically.

How long is an ISO 9001 certificate valid?

Three years. Within that cycle the certification body carries out surveillance audits, normally annually, and a recertification audit before the certificate expires. A certificate can be suspended or withdrawn if major nonconformities are not closed or if surveillance is not permitted to take place.

Can we exclude parts of ISO 9001 that do not apply to us?

You can determine that a requirement is not applicable, but only where it cannot affect your ability to provide conforming products and services or to enhance customer satisfaction. Design and development is the requirement most often determined to be not applicable, for example where an organisation manufactures strictly to customer drawings. Any such determination has to be stated and justified in the documented scope of the quality management system, and the auditor will test that justification.

Need help achieving this certification? Univate Global delivers end-to-end implementation in 9 markets. Book a free consultation today.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.