Skip to content
Pathak Associates

ISO Certification

ISO certification for quality and standards.

ISO certification is an independent audit confirming that a business runs a management system meeting a published international standard — ISO 9001 for quality, 27001 for information security, 14001 for environment, 22000 for food safety. It is not a government registration and no law requires it; what it is, is the thing an enterprise customer, a tender or a large buyer's vendor policy asks for, which is why almost everyone who pursues it is doing so because a specific customer asked.

Who this is for

  • International standards
  • Enhanced credibility
  • Govt tender access
  • Process improvement

The process

What we actually do

  1. 1

    We establish which standard the requirement actually names

    The customer or tender document names a specific standard, and certification to a different one does not satisfy it. This sounds obvious and is the commonest wasted spend in this area.

  2. 2

    We do a gap analysis against the standard

    What the standard requires against what the business already does. Most established businesses meet a good deal of it informally; the work is documenting it and closing the genuine gaps, not rebuilding operations.

  3. 3

    We build the documentation the standard requires

    The manual, the procedures, the records and the internal audit programme. Documentation that describes how the business actually works survives the audit; documentation copied from a template does not, because the auditor asks the staff.

  4. 4

    We run the internal audit and management review

    Both are prerequisites the standard itself imposes before a certification body will audit. Skipping them is the usual reason a first audit produces a long list of non-conformities.

  5. 5

    We check the certification body is accredited

    A certificate is only worth what the body behind it is worth. Accreditation under the NABCB or an equivalent IAF signatory is what makes it acceptable to a customer — an unaccredited certificate is often refused at exactly the vendor onboarding it was bought for.

Who this is for

  • Businesses bidding for tenders that specify a certification as a qualifying condition
  • Suppliers to large enterprises whose vendor onboarding requires one
  • Software and IT services businesses whose customers require ISO 27001 for data handling
  • Manufacturers and exporters whose buyers expect ISO 9001
  • Food businesses needing ISO 22000 alongside their FSSAI licence

How long it takes

Two to four months for a small business from gap analysis to certification, depending mostly on how much documentation already exists. The certificate runs three years with annual surveillance audits.

If you do nothing

Nothing legally. Commercially, you are excluded from the tenders and vendor panels that name it as a condition, and in some sectors that is most of the addressable market. The honest test is whether a real customer has asked — if none has, certification is a cost with no buyer behind it.

The law, in figures

Dates, thresholds and sections

Every figure below carries the provision it comes from, so it can be checked.
WhatFigureSource
Legal statusVoluntary — no statute requires ISO certificationISO standards are published by the International Organization for Standardization
ISO 9001Quality management systemsISO 9001:2015
ISO 27001Information security management systemsISO/IEC 27001:2022
Certificate validity3 years, with annual surveillance auditsIAF and certification body requirements
Accreditation in IndiaNABCB, under the Quality Council of IndiaNational Accreditation Board for Certification Bodies

What usually goes wrong

  • Buying a certificate from an unaccredited body, which the customer who asked for it then refuses
  • Certifying to a standard other than the one the tender actually named
  • Adopting template documentation that does not describe how the business really operates
  • Skipping the internal audit and management review, which the standard itself requires first
  • Treating it as a one-off purchase and failing the first surveillance audit a year later

What non-compliance costs

  • No statutory penalty — the standard is voluntary
  • Suspension or withdrawal of the certificate at a surveillance audit
  • Disqualification from a tender where the certification was a qualifying condition
  • An unaccredited certificate is frequently rejected at vendor onboarding, wasting the whole spend

These are statutory amounts, not our fees. What we charge depends on your situation and is quoted before any work starts.

Not to be confused with

These come up in the same conversation and are routinely treated as the same thing. They are not.

FSSAI licence

FSSAI is a statutory licence required by law to handle food in India. ISO 22000 is a voluntary certification a buyer may ask for. A food business needs the first and may want the second.

MSME Udyam registration

Udyam is a free government classification with statutory benefits. ISO certification is a paid third-party audit with commercial benefits. They serve entirely different purposes.

Related services

ISO Certification

Every engagement is priced individually. Answer a few questions and we'll send you a quote.

Request a callback