Guides · Certification

How to get ISO 9001 certified: a step-by-step guide for UK SMEs

The route from nothing to a UKAS-accredited certificate, written by a Lead Auditor — including the mistakes that cost SMEs months.

Step 1 — Understand what you're actually being assessed on

ISO 9001:2015 doesn't certify your products; it certifies your management system — how you plan, run, check and improve the business. The requirements sit in clauses 4–10: context, leadership, planning, support, operation, performance evaluation and improvement. Everything an auditor asks maps back to one of those clauses.

Step 2 — Gap analysis

Compare what you do today against the standard. Most SMEs find they already do 60–70% of what's required — they just can't evidence it. A gap analysis tells you what's missing and, more importantly, what order to fix it in. Our free readiness check gives you a first cut across the six areas in five minutes.

Step 3 — Build the system around your processes, not the standard's headings

The single biggest mistake: writing a manual that parrots the standard's clause structure while the business carries on working a different way. Auditors see through it in minutes. Map your real processes — how an order actually flows from enquiry to delivery — then attach the standard's requirements to them. Document only what adds control: a policy, core procedures, work instructions where a mistake matters, and the records that prove work happened.

Step 4 — Run it and collect evidence (this is the part you can't rush)

A certification body wants to see the system operating, not just existing. Plan for roughly three months of live running before assessment: records accumulating, nonconformities raised and closed, at least one full internal audit cycle and one management review. This is where spreadsheet-based systems buckle — evidence lives in inboxes and gets reconstructed under pressure. If daily work produces the records automatically, this phase is simply… working.

Step 5 — Internal audit and management review

Both are mandatory before certification, and both are covered in depth in our internal audit guide. The short version: audit every process against the clauses that apply to it, classify findings honestly, fix what you find, and hold a management review with the inputs clause 9.3.2 lists — all of them, minuted.

Step 6 — Choose a UKAS-accredited certification body

In the UK, look for UKAS accreditation — it's what makes your certificate meaningful to customers and procurement teams. Get quotes from two or three bodies (fees vary meaningfully; see our costs guide), and ask about auditor availability in your sector.

Step 7 — Stage 1 and Stage 2 assessments

Stage 1 is a documentation and readiness review: the auditor checks the system is designed to meet the standard and that you're ready for full assessment. Expect findings — that's its purpose. Stage 2, typically a few weeks later, is the full audit: the auditor follows your processes, interviews your people and samples your records. Minor nonconformities are normal and don't block certification; you'll agree corrective actions. Major nonconformities mean a re-visit, which is what steps 4 and 5 exist to prevent.

Step 8 — Certificate, then surveillance

Certificates run on a three-year cycle: surveillance audits in years one and two, recertification in year three. The systems that sail through surveillance are the ones the business actually uses daily — which is the entire design philosophy behind CheckpointQA.

How long does all this take?

For a 10–250 person organisation with commitment from the top: 4–9 months end to end, with the evidence-gathering period as the floor. The build phase is where months get lost — and where the right tooling collapses the timeline from months to days.

Written by Gareth Bewley PCQI, BSI-certified ISO 9001:2015 Lead Auditor. Published 4 July 2026.

See where you stand first

The free readiness check scores you across the six areas your auditor will examine — instantly, no sign-up.