
General8 min read
How Long Does ISO Certification Take? Realistic Timelines
Accredited ISO certification usually takes months. A self-assessment certificate from Zertify takes 4 hours after you pass and pay. Here is the difference.
By Zertify Redaktion
ISO certification with an accredited audit usually takes several months, counting from first preparation to the certificate in your hand. A Zertify certificate, which rests on a self-assessment, is issued within 4 hours after a passed assessment and payment.
The two numbers are far apart because the two routes are different things. This article explains what happens in each, what slows a project down, and how to decide which route fits your business.
The short answer
There is no single duration for ISO certification. It depends on the route you take, the standard, the size of your organisation and how much of a management system you already run.
In plain terms:
- Accredited third-party certification: months, not days. Much of that time goes into preparation, not into the audit itself.
- Self-assessment certification with Zertify: you complete an assessment, and once you have passed and paid, the certificate is issued within 4 hours.
Neither route is automatically better. They answer different needs.
Route one: accredited certification
An accredited certification body audits your organisation against a standard such as ISO 9001 or ISO 27001. The certificate carries the mark of an accreditation body. That is what some tenders and regulators ask for.
The path usually has these phases.
1. Scoping and gap analysis
You decide which parts of the business the certificate will cover. Then you compare what you do today with what the standard requires. For many small firms this is the first time anyone has looked at their processes as a whole. It can take days or weeks, depending on how much you have to review.
2. Building the management system
This is the longest phase. Standards that follow the high level structure share the same clause layout:
- Clause 4: Context of the organization
- Clause 5: Leadership
- Clause 6: Planning
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance evaluation
- Clause 10: Improvement
You define policies, roles, objectives, risks and procedures. You also have to start working the way you wrote it down. Records only exist once the work has been done, so an auditor will expect to see a period of real operation, not just documents written the week before.
3. Internal audit and management review
Before the external audit, you check yourself. Clause 9 asks for an internal audit and a management review. Both need to be done and recorded. If something fails here, you fix it first. This is cheaper than failing in front of the certification body.
4. Stage 1 and stage 2 audits
The external audit commonly happens in two steps. Stage 1 reviews your documentation and readiness. Stage 2 checks on site or remotely that you actually follow the system. The certification body will propose dates, and their calendar is part of your timeline. Booking is often a matter of weeks.
5. Findings and decision
If the auditor raises nonconformities, you have to correct them and show evidence. Only then does the certification body decide on the certificate. A clean audit moves quickly. A messy one adds weeks.
6. After the certificate
Accredited certificates are normally valid for a cycle of several years, with surveillance audits in between. So the effort does not end on the day you receive the certificate. Plan for it.
What makes the accredited route slower or faster
The same project can take much longer in one company than in another. These are the main factors.
Existing structure. If you already document processes, assign responsibilities and review results, you are partly there. If everything lives in people's heads, you have to build first.
Size and complexity. A ten-person agency with one location has less to cover than a firm with several sites, subcontractors and regulated activities.
The standard. Some standards need more technical work than others. Information security, for example, requires risk assessment and controls that go well beyond writing a quality manual.
Management attention. Projects stall when the owner has no time. Clause 5 puts leadership at the centre for good reason. If nobody owns the project, it drifts.
Evidence. Auditors want records. If you need to wait for a full cycle of internal audits, supplier reviews or training before you can show evidence, the calendar sets the pace, not your effort.
Auditor availability. Certification bodies have their own schedules. Plan the dates early.
Route two: Zertify certification
Zertify works differently. You complete an online self-assessment against the standard you choose. If you pass and pay, the certificate is issued by SICE (Swiss Institute of Certification and Education) within 4 hours.
How long the assessment takes depends on you. If you know your processes and have the answers to hand, it goes quickly. If you have to look things up, it takes longer. The 4 hours start after a passed assessment and payment, not before.
This is a certificate based on your own statements. It is not an accredited third-party certification. No external auditor visits you or reviews your records. If you want to understand what that means in practice, the page on certification without an audit explains the model in more detail.
For many small businesses, that is enough. A certificate can show customers and partners that you have thought about your processes and committed to a standard. It also gives you a structured way to find gaps. But it does not replace an audit where an audit is demanded.
Which route do you actually need?
Start from the requirement, not from the speed.
An accredited audit is the better choice when:
- a tender explicitly asks for an accredited certificate
- a customer contract names accredited certification as a condition
- a regulator or industry scheme requires it
- your customers will check who issued the certificate and under which accreditation
In those cases, a faster certificate that does not meet the stated condition is of no use. The guide on accredited or not walks through how to read such requirements and what to ask the other party.
A self-assessment certificate can make sense when:
- you want to document and signal your commitment to a standard without a long project
- no one has asked for accreditation
- you are at an early stage and want a first, structured step
- you want a baseline before deciding whether to invest in a full audit
If in doubt, ask the party who requires the certificate. A short email saves months.
A practical checklist before you start
Use this list to plan either route.
How Zertify fits in
Zertify is built for owners who want a clear, quick and honest option. You can see which management system standards are available on the standards overview. Pick the one that fits your business, not the one with the most famous number.
Prices are listed openly on the pricing page, so you can compare before you commit.
When you are ready, you can start the assessment. You answer questions about how your business works. If you pass and pay, the certificate is issued within 4 hours.
Remember what the certificate is: it is issued by SICE on the basis of a self-assessment. It is not accredited. If a customer, tender or regulator needs an accredited audit, you will need a certification body for that.
Planning realistically
When people ask how long ISO certification takes, they often mean how soon they can show a certificate. The honest answer has two parts.
If you need an accredited certificate, plan for months and start with preparation. Do not wait for the audit date to begin the work. Most delays come from missing records and unclear responsibilities, not from the audit.
If you need a documented commitment to a standard and nobody demands accreditation, a self-assessment can get you there in a single working session, with the certificate issued within 4 hours of a passed assessment and payment.
Choose based on what the other party will accept. Then plan the time around that choice.
Frequently asked questions
How long does an accredited ISO certification take?
It usually takes several months. Most of the time goes into building and running the management system, doing an internal audit and management review, and scheduling the stage 1 and stage 2 audits. The exact duration depends on your size, your existing processes and the standard.
How long does a Zertify certificate take?
Zertify issues the certificate within 4 hours after a passed assessment and payment. The time you need to complete the self-assessment depends on how well you know your own processes.
Is a Zertify certificate the same as an accredited ISO certificate?
No. A Zertify certificate is issued by SICE on the basis of a self-assessment. It is not an accredited third-party certification. If a tender, contract or regulator requires accreditation, you need an accredited certification body.
Why does preparation take longer than the audit?
An auditor expects evidence that your system works in practice. That means defined roles, documented processes, records, an internal audit and a management review. Building and running these takes more time than the audit days themselves.
Do I have to renew an ISO certificate?
Accredited certificates are normally valid for a multi-year cycle with surveillance audits in between, so the work continues after issue. Check the validity terms with the issuing body for the route you choose.


