ISO Certification
ISO certification for quality and standards.
Who this is for
- International standards
- Enhanced credibility
- Govt tender access
- Process improvement
The process
What we actually do
- 1
We establish which standard the requirement actually names
The customer or tender document names a specific standard, and certification to a different one does not satisfy it. This sounds obvious and is the commonest wasted spend in this area.
- 2
We do a gap analysis against the standard
What the standard requires against what the business already does. Most established businesses meet a good deal of it informally; the work is documenting it and closing the genuine gaps, not rebuilding operations.
- 3
We build the documentation the standard requires
The manual, the procedures, the records and the internal audit programme. Documentation that describes how the business actually works survives the audit; documentation copied from a template does not, because the auditor asks the staff.
- 4
We run the internal audit and management review
Both are prerequisites the standard itself imposes before a certification body will audit. Skipping them is the usual reason a first audit produces a long list of non-conformities.
- 5
We check the certification body is accredited
A certificate is only worth what the body behind it is worth. Accreditation under the NABCB or an equivalent IAF signatory is what makes it acceptable to a customer — an unaccredited certificate is often refused at exactly the vendor onboarding it was bought for.
Who this is for
- Businesses bidding for tenders that specify a certification as a qualifying condition
- Suppliers to large enterprises whose vendor onboarding requires one
- Software and IT services businesses whose customers require ISO 27001 for data handling
- Manufacturers and exporters whose buyers expect ISO 9001
- Food businesses needing ISO 22000 alongside their FSSAI licence
How long it takes
Two to four months for a small business from gap analysis to certification, depending mostly on how much documentation already exists. The certificate runs three years with annual surveillance audits.
If you do nothing
Nothing legally. Commercially, you are excluded from the tenders and vendor panels that name it as a condition, and in some sectors that is most of the addressable market. The honest test is whether a real customer has asked — if none has, certification is a cost with no buyer behind it.
The law, in figures
Dates, thresholds and sections
| What | Figure | Source |
|---|---|---|
| Legal status | Voluntary — no statute requires ISO certification | ISO standards are published by the International Organization for Standardization |
| ISO 9001 | Quality management systems | ISO 9001:2015 |
| ISO 27001 | Information security management systems | ISO/IEC 27001:2022 |
| Certificate validity | 3 years, with annual surveillance audits | IAF and certification body requirements |
| Accreditation in India | NABCB, under the Quality Council of India | National Accreditation Board for Certification Bodies |
What usually goes wrong
- Buying a certificate from an unaccredited body, which the customer who asked for it then refuses
- Certifying to a standard other than the one the tender actually named
- Adopting template documentation that does not describe how the business really operates
- Skipping the internal audit and management review, which the standard itself requires first
- Treating it as a one-off purchase and failing the first surveillance audit a year later
What non-compliance costs
- No statutory penalty — the standard is voluntary
- Suspension or withdrawal of the certificate at a surveillance audit
- Disqualification from a tender where the certification was a qualifying condition
- An unaccredited certificate is frequently rejected at vendor onboarding, wasting the whole spend
These are statutory amounts, not our fees. What we charge depends on your situation and is quoted before any work starts.
Not to be confused with
These come up in the same conversation and are routinely treated as the same thing. They are not.
FSSAI licence
FSSAI is a statutory licence required by law to handle food in India. ISO 22000 is a voluntary certification a buyer may ask for. A food business needs the first and may want the second.
MSME Udyam registration
Udyam is a free government classification with statutory benefits. ISO certification is a paid third-party audit with commercial benefits. They serve entirely different purposes.
Related services
ITR Filing for Business Owners
Comprehensive ITR filing for proprietors, partnerships, companies, and professionals.
See itPrivate Limited Company Registration
Complete Pvt Ltd registration with Certificate of Incorporation and bank account opening.
See itOne Person Company (OPC) Registration
Solo entrepreneur company registration with limited liability protection.
See itLimited Liability Partnership (LLP) Registration
LLP registration combining flexibility of partnership with liability protection.
See itPartnership Firm Registration
Partnership firm registration with deed drafting and compliance support.
See itPublic Limited Company Registration
Public company registration for businesses seeking public capital and stock exchange listing.
See it