How to Get ISO 9001 Certification in the UK

By Brian Crocker · Published 27 September 2026

Getting ISO 9001 certified in the UK is nine steps: define your scope, run a gap analysis, build the missing documentation, run the system for long enough to generate records, do one internal audit, hold a management review, choose a UKAS-accredited certification body, pass a Stage 1 document audit, then pass a Stage 2 implementation audit. For a business under 50 people starting from an organised but undocumented position, three to six months is realistic. Nothing in the process requires a consultant. This guide walks each step, says who does it and what "done" looks like, and flags the two places most first-timers lose time.

Before step 1: is this the right year?

One timing question is worth settling first. ISO 9001:2026 published on 16 September 2026 — UKAS confirms that it "was published on 16 September 2026 and replaces ISO 9001:2015 + Amendment 1:2024 over a defined transition period" — which raises the obvious question: certify now to the outgoing 2015 edition, or go straight to 2026?

Certify now if you need the certificate for a contract, tender or customer requirement. Certificates issued to the outgoing edition remain valid through the transition period — which runs to 30 September 2029 — and transitioning later is a much smaller job than a first certification. In the UK you can still apply against the 2015 edition until 16 March 2028, when UKAS requires certification bodies to "stop accepting new applications against the previous version of the standard". Waiting to avoid a transition means going without a certificate you need, which is the more expensive problem.

Going straight to the 2026 edition only makes sense if the certificate is discretionary and you are not in a hurry. Certification bodies need their own accreditation extended before they can audit to the new edition: UKAS transition decisions commence 1 January 2027 and are all to be completed by 30 September 2027. Until your body has been granted transition, UKAS is explicit that "certification issued against ISO 9001:2026 must not be represented as accredited certification".

Step 1: define your scope

Your scope is the statement of what the quality management system covers — which activities, which products or services, which sites. It appears on the certificate, and it is what your customers will read.

Get this right first because everything downstream sizes off it. A scope that includes a site you rarely use adds audit days. A scope that is too narrow fails the customer requirement you are certifying for in the first place.

Done looks like: one or two sentences naming activities, products/services and locations, agreed by whoever signs the contracts.

Step 2: run a gap analysis

Compare what you already do against what the standard asks for. Most established businesses are 50–70% of the way there without knowing it — you already have processes, you just have not documented or evidenced them.

Work through clause by clause and record three things per requirement: what you do now, what evidence exists, and what is missing. Our ISO 9001 gap analysis checklist walks the structure, and the free ISO 9001 readiness quiz gives a ten-question first read if you want a rough position before committing time.

Done looks like: a dated gap register with an owner and target date per gap.

Step 3: build the missing documentation

This is where the time goes, and where most of the money goes if you outsource it.

The standard requires specific documented information, not a procedure for everything. For a business under 50 people that typically means a quality manual or equivalent, a handful of procedures covering your core processes, and the records the standard requires. Over-documenting is the classic first-timer error: every document you write is a document you have to maintain, review and be audited against.

Useful starting points on the pieces most businesses need:

Done looks like: documented information that describes what you actually do, not an aspirational system.

Step 4: run the system and generate records

This is the step people try to skip, and it is the one that cannot be skipped.

An auditor certifies a system in operation. That means records: completed checks, raised nonconformities, supplier evaluations, training records, customer feedback. A perfect set of procedures with no evidence behind them fails Stage 2.

How long? Enough to produce a meaningful record set across your core processes. Two to three months of live operation is a common minimum for a small business, longer if your process cycle is long.

Done looks like: records exist for every process in scope, generated by the people who do the work.

Step 5: run one internal audit

Internal audit is a requirement in its own right, and it is also your rehearsal. Audit your own system against the standard before an external auditor does.

The auditor must be independent of the work being audited — in a small business that usually means one person audits another's area, or you use an external auditor for the internal audit. Our ISO 9001 internal audit checklist sets out fifteen questions your certification auditor is likely to ask, and the audit schedule template covers how to plan the programme.

Done looks like: an audit report with findings, and corrective actions raised against them — see the non conformance report template.

Step 6: hold a management review

Top management has to review the system, and the review has required inputs and outputs. Auditors check the minutes.

This is a genuine meeting with a genuine agenda, not a document you write afterwards. The ISO 9001 management review guide covers what has to be on the agenda.

Done looks like: dated minutes showing the required inputs discussed and decisions recorded.

Step 7: choose a UKAS-accredited certification body

You cannot certify yourself. You appoint a certification body, and if the certificate needs to satisfy a customer or a framework, it needs to be UKAS-accredited.

UKAS describes accreditation as demonstrating "to the marketplace that certification bodies are technically competent to audit and certify activity in accordance with the requirements of national and international standards and regulations". Check any body against the UKAS directory of accredited organisations before you talk to them, and confirm they are accredited for your sector, not just for ISO 9001 generally.

Get at least three quotes broken out by audit day — choosing an ISO 9001 certification body sets out what to compare, and the certification cost breakdown covers the ranges.

Done looks like: a signed contract with agreed Stage 1 and Stage 2 dates.

Step 8: Stage 1 audit — document review

The auditor reviews your documented system, confirms the scope, and assesses whether you are ready for Stage 2. It is typically one day for a small business, often partly remote.

Stage 1 findings are normal and are meant to be fixable before Stage 2. Treat it as a diagnostic, not a test.

Done looks like: a Stage 1 report with any readiness issues identified and a Stage 2 date confirmed.

Step 9: Stage 2 audit — implementation

The auditor assesses the system in practice: interviewing staff, sampling records, walking processes. Typically two to three days for a business of 10–50 people.

Major nonconformities must be closed before the certificate is issued, which may require a follow-up visit. Minor ones are usually closed by evidence submitted afterwards. The ISO 9001 audit checklist covers what to have ready by clause area, and the free audit readiness checker flags what is still outstanding.

Done looks like: a recommendation for certification, then the certificate.

How long it actually takes

Starting position Realistic elapsed time
Established processes, some documentation, dedicated owner 3–4 months
Established processes, little documentation 4–6 months
Processes informal or undefined 6–9 months
Multi-site or complex scope 9–12 months

The two places time is lost are step 4 (you cannot compress the record-generation period) and certification-body scheduling (audits book weeks ahead, and more during a transition year). Our ISO 9001 certification timeline breaks the phases down further.

Practical takeaway checklist

  1. Decide whether you need the certificate this year — if a contract requires it, certify now
  2. Write the scope statement and get it agreed
  3. Run a documented gap analysis and keep the register
  4. Build only the documentation the standard requires
  5. Run the system live long enough to generate real records
  6. Complete one internal audit with an independent auditor
  7. Hold a management review with minutes
  8. Check certification bodies against the UKAS directory, including sector scope
  9. Get three quotes broken out by audit day
  10. Fix Stage 1 findings before Stage 2 rather than arguing them

If you want a cost figure before committing, the free ISO 9001 cost estimator gives a baseline for your company size and sector, and ISO 9001 for small business covers what a proportionate system looks like at this scale.

This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO 9001 is a voluntary standard, not a legal requirement. Certification requirements vary by scope, sector and certification body — verify with your UKAS-accredited certification body before making compliance decisions.

ClauseWise is coming soon

Generate your ISO 9001 and ISO 27001 documentation without consultant fees.