When a client asks whether your company is ISO 9001 certified, they are not asking whether you have a piece of paper on the office wall. They are asking whether you work to a method, whether you can prove it and whether someone independent has verified it. ISO certifications are exactly that: a tool that turns the way you manage quality, safety, environment or data into something measurable, verifiable and recognised worldwide. Yet for many business owners the ISO world remains a maze of acronyms, bodies and unclear procedures. In this guide we explain what ISO really is as an organisation, how standards are created, which families of standards matter most, how the certification journey works and what the substantial difference is between a technical standard and a certificate. The goal is to give you an operational map so you can see where you stand and which step makes sense now.
What ISO means and who publishes the standards
ISO is not an Italian or English acronym: it comes from the Greek isos, meaning equal. It is the name chosen by the International Organization for Standardization, which since 1947 has published technical standards applicable in every economic sector. The linguistic choice is no accident: an ISO standard exists to make products, processes and services comparable beyond language, country or local regulation.
ISO is based in Geneva and brings together more than 170 national standards bodies. In Italy the official member is UNI, the Italian standards body, which takes part in international technical committees and translates standards so they apply nationally, often together with CEI for electrotechnical matters. This is why in Italy many standards are called UNI EN ISO: the prefixes show the same text has been adopted internationally (ISO), at European level (EN) and nationally (UNI).
One fundamental point: ISO does not certify anyone. The organisation publishes the standards, but conformity assessment is entrusted to independent, accredited third-party bodies. This clearly separates those who write the rules, those who apply them and those who check them, guaranteeing the system’s independence.
The role of UNI and the national bodies
National standards bodies are not mere translators. They actively contribute to developing standards through technical committees made up of experts, companies, universities, trade associations and consumer representatives. When a new ISO standard goes to consultation, each country can propose changes, cast its vote and influence the final text. UNI alone runs more than 1,500 technical committees and publishes hundreds of new or updated standards every year.
For an Italian company this means the UNI EN ISO standards bought through UNI have full legal standing and can be cited in contracts, public tender specifications and technical documentation. Versions published directly by ISO in English are working copies and should always be paired with the official national text when certification or formal compliance is involved.
How an ISO standard is created
An ISO standard does not appear overnight. The development cycle takes on average three to five years and follows precise phases: a New Work Item Proposal, working draft, committee draft, draft international standard, final draft and finally publication. Each step requires votes among member countries and public consultation.
Once published, a standard is reviewed at least every five years. If the technological or regulatory context has changed, a revision opens. That is why we see ISO 9001:2015, ISO 27001:2022 or ISO 14001:2015: the number after the colon shows the year of the latest official edition. When a new version appears, already certified companies have a transition period (usually three years) to adapt.
What ISO certifications are and what they are really for
An ISO certification is a formal statement, issued by an independent body, confirming that a company complies with a specific international standard. It does not certify the product itself, but the management system through which the company controls a given aspect: quality, environment, information security, worker health, anti-bribery and so on.
The difference from a simple internal manual or company policy is enormous. An ISO certified management system must prove three things: that documented procedures exist, that they are applied in daily practice, and that they produce measurable improvement over time. An external auditor comes to verify all of this through periodic visits, staff interviews and data analysis.
What does obtaining an ISO certification actually achieve? The reasons are many and go beyond image:
Access to public calls and tenders: many contracting authorities require ISO 9001 certification either as a mandatory requirement or as a scoring criterion.
Relationships with large B2B clients: multinationals and complex supply chains demand certified suppliers to guarantee continuity and quality.
Reduced operational risk: a well-structured management system prevents errors, nonconformities and penalties.
Internal organisational improvement: the discipline the standard imposes often uncovers inefficiencies never addressed before.
Insurance and financial advantage: banks and insurers view certified companies favourably.
International recognition: an ISO certificate issued in Italy is recognised in every country participating in the IAF system, which is practically everywhere.
Voluntary and mandatory certification
Almost all ISO certifications are voluntary. No Italian or European law requires you to be certified to ISO 9001 or ISO 14001 simply because of the activity you carry out. That said, the voluntary nature is often only formal: if your market demands certification, in practice you have no alternative.
There are also cases where certification becomes an indirect requirement. This is true in some regulated sectors (medical devices, aerospace, defence) where technical rules explicitly reference ISO standards. Likewise, in the NIS2 and cybersecurity space, having an ISO 27001 system is not mandatory but is in practice the most solid way to demonstrate compliance with European obligations.
What an ISO certification is NOT
It is just as important to clarify what an ISO certification is not. It is not a product quality award: you can be ISO 9001 certified and make mediocre goods, provided your process control system is consistent and documented. It is not a one-off attestation: it is valid for three years with annual checks, and lapses without maintenance. Nor is it a self-declaration: writing on your website that you comply with ISO 9001 without holding a certificate from an accredited body is a mistake that can cost you reputation and penalties.
The main families of ISO standards useful to companies
There are more than 25,000 published ISO standards, but only a small share are certified by companies. Certifiable standards are those defining requirements for a management system, as opposed to technical standards describing test methods, terminology or product specifications. You can recognise the former because the title contains the word requirements.
These are the most widespread management system standard families:
ISO 9001 – Quality management system. It is the most widely held certification in the world and the entry point to the ISO world for most companies.
ISO 14001 – Environmental management system. It governs the organisation’s environmental impacts, from waste to emissions and resource consumption.
ISO 45001 – Occupational health and safety management system. It replaced the old OHSAS 18001 standard.
ISO 27001 – Information security management system. Essential for IT companies and digital services and for NIS2 and GDPR compliance.
ISO 37001 – Anti-bribery management system. Highly relevant for companies working with public administration or in higher-risk contexts.
ISO 42001 – Artificial intelligence management system. The newest standard, and one that will become crucial as the EU AI Act applies.
ISO 22301 – Business continuity management system.
ISO 50001 – Energy management system.
The shared framework: the High Level Structure
Since 2012 all new ISO management system standards follow the same framework, called the High Level Structure (HLS) or Harmonized Structure. This means ISO 9001, ISO 14001, ISO 27001 and the others share the same main chapters: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement.
This has an enormous practical advantage: if a company is already certified to one standard, adding a second or third takes far less work than it appears. Procedures for internal audit, management review, document control and staff competence are shared. An integrated quality-environment-safety management system is today the most efficient choice for most SMEs wanting to cover several fronts.
Certifiable standards and supporting standards
Alongside certifiable standards there are so-called supporting standards or guidelines, which help implement the system properly but are not directly audited. For example, ISO 9004 provides guidance on sustainable quality, ISO 31000 on risk management, ISO 19011 on how to conduct audits. These do not produce a certificate but are valuable tools for companies wanting to go beyond the minimum and build a genuinely high-performing system.
How the ISO certification process works step by step
Obtaining an ISO certification is not an instant event but a structured journey which, on average, takes six to twelve months for a company starting from scratch. With a digital, structured approach like Complaion’s, timelines shorten noticeably compared with traditional routes, because the bulk of document gathering and procedure formalisation is guided step by step without wasted effort.
The typical journey unfolds in these phases:
Gap analysis: an initial assessment comparing the company’s current state with the requirements of the target standard.
System design: defining policies, procedures, roles, measurable objectives and performance indicators.
Implementation: putting the system into practice, training staff, starting to collect records and data.
Internal audit: an independent check run by the company (or external consultants) to confirm the system works before the official audit.
Management review: the formal moment when company leadership assesses the effectiveness of the system.
Stage 1 certification audit: the certification body reviews the documentation and the company’s readiness.
Stage 2 certification audit: operational verification on site, with interviews, observation and review of records.
Certificate issue: if the outcome is positive, a certificate valid for three years is issued.
Surveillance audits and renewal
The certificate is not a final destination. During the three years of validity the body carries out annual surveillance audits, checking that the system is maintained, that previously raised nonconformities have been handled and how the indicators are evolving. At the end of the three years a more thorough renewal audit leads into the next three-year cycle.
If serious nonconformities emerge during an audit and are not resolved within the set timeframe, the certificate can be suspended or withdrawn. This is not a theoretical scenario: accredited bodies are themselves supervised and cannot afford to maintain undeserved certifications. That is why maintenance requires continuous management, not a last-minute effort before deadlines.
Minimum required documents
Each standard has specific documentation requirements, but there is a common core of documents and records that always recur:
The company policy for the system (quality, environment, safety, etc.)
Analysis of context and interested parties
Assessment of risks and opportunities
Measurable objectives and plans to achieve them
Operating procedures for key processes
Records of staff training, competence and awareness
Internal audit reports and corrective actions
Management review minutes
Records of nonconformities and improvement actions
Who certification bodies are and how to choose one
Certification bodies are private companies which, after obtaining official accreditation, are authorised to issue ISO certificates. In Italy the single national accreditation body is Accredia, recognised by the Italian state under European Regulation 765/2008. Accredia periodically verifies that bodies meet the independence, competence and impartiality requirements set out in ISO 17021 and related standards.
When a company seeks an ISO certificate it must approach a certification body, not Accredia directly. The body runs the audits, assesses conformity and issues the certificate. The Accredia mark (or that of an equivalent foreign body recognised through the IAF agreements) appears on the certificate as a guarantee that the body is itself supervised.
Dozens of accredited bodies operate in the Italian market. How do you choose one? These are the soundest criteria:
Verified accreditation: always check on the Accredia website that the body is accredited for the specific standard you need.
Experience in your sector: a body that already knows your industry brings competent auditors and sharper questions.
Local presence: audits require site visits, and local auditors cut travel costs and time.
Market reputation: some bodies carry more weight with international clients or in specific supply chains.
Commercial transparency: a clear offer on audit days and deadlines avoids surprises.
Beware of non-accredited certificates
There is a parallel market of certificates issued by non-accredited operators, often at very low cost and in a matter of days. Formally they carry an ISO logo and look equivalent to a real certificate, but they have no value recognised by Accredia, the IAF or public administration. Using a non-accredited certificate in a public tender or a B2B contract exposes the company to exclusion, challenges and, in some cases, criminal liability for untrue declarations. An ISO certificate only has value if issued by a body accredited by a signatory of the international IAF agreements.
The difference between standard, certification and certificate
Three words often used interchangeably that mean different things. Understanding the difference helps avoid misunderstandings with clients, suppliers and contracting authorities.
The standard is the technical document published by ISO (and adopted by UNI in Italy). It contains the requirements a management system must satisfy. The standard itself can be purchased: anyone can buy it, read it and draw on its content without being certified. Many companies state they comply with ISO 9001 in substance without ever obtaining the certificate: that is a legitimate choice, but it does not let you rely on international recognition of the system.
The certification is the process by which an independent, accredited body verifies that the company actually applies the requirements of the standard. It is a journey, not a document: it includes the initial audit, annual surveillance and three-year renewal. Saying a company is ISO 9001 certified means it has successfully completed that journey and is currently subject to the required checks.
The certificate is the paper or digital document attesting the positive outcome of certification. It contains the company details, the reference standard, the scope of the activities covered, the issue date, the expiry date and the marks of the accredited body and the accreditation body. It is the document you attach to tenders, show to clients and publish on your website.
Scope: what your certificate really covers
A detail often underestimated is the certification scope. An ISO 9001 certificate does not necessarily cover all company activities: it may be limited to one site, one product line or a specific family of services. In contracts and tenders you must always check that the scope stated on the certificate matches the activity being supplied.
A practical example: a company that manufactures and installs systems might be certified only for design and not for installation. In a tender requiring certification of the whole process, a partial scope is not enough. Extending the scope requires a specific audit and must be planned in advance.
The EA code
Certificates almost always show an EA code (European co-operation for Accreditation), a number identifying the economic sector. EA codes matter because auditors must be qualified for the specific sector and bodies must be accredited for that scope. A body accredited for EA code 28 (construction) cannot validly certify a company under EA code 33 (IT) without extending its accreditation.
How long it takes and what drives the cost of an ISO certification
The first question every business owner asks is: how long does it take and how much does it cost? The two variables are linked but should be addressed separately.
On timelines, the traditional route for an SME starting from scratch and seeking a single certification (ISO 9001, for example) takes six to twelve months. If the company already has formalised procedures and an organised culture, it can drop below six months. If it starts from zero, with fragmented documentation and no prior experience, timelines stretch. Three factors make the difference: company size, process complexity and the method used to run the project.
With Complaion certification timelines shorten noticeably compared with traditional routes. The reason is structural: the platform digitalises all document gathering, guides the company through every step with verified checklists and provides dedicated auditors who support SMEs without the dispersion typical of traditional consultancy built on long in-person meetings.
On costs, generic figures are not possible because a quote always depends on the company’s specific situation. The variables are numerous:
Number of sites to be certified
Number of employees (which drives the number of audit days)
Process complexity
Number of standards (a single certification or an integrated system)
Starting point (documentation already in place or built from scratch)
The need for staff training
Choice of certification body
Complaion prepares a tailored quote after an initial analysis of the company. That is the most honest way to get a realistic figure rather than a generic range that risks being misleading.
Investment vs cost
One final important point: ISO certification should be seen as an investment, not a pure cost. The return comes from several directions: access to calls and tenders, better internal efficiency, less waste and fewer nonconformities, better insurance terms, greater commercial credibility. Companies that approach the journey seriously, rather than as paperwork, almost always recover the investment within one or two financial years thanks to the operational benefits it triggers.
The most frequent mistakes on the ISO certification journey
Having a clear map of the journey also means knowing where companies stumble most often. Knowing these mistakes in advance helps you avoid them.
Treating certification as a documentation project: many companies focus only on producing manuals and procedures, then struggle at the audit because nobody actually applies what is written.
Underestimating leadership involvement: the standard requires visible leadership. A project dumped entirely on the quality manager, without real backing from the top, rarely survives a rigorous audit.
Copying other companies’ procedures: procedures received from third parties or downloaded online rarely reflect real processes. The auditor notices immediately.
Ignoring training: staff must know the company policy, their objectives and what to do when a nonconformity occurs. Without training the system stays on paper.
Not planning internal audits: internal audits are a requirement, not an option. They must be scheduled, documented and produce concrete actions.
Choosing the body on price alone: saving on the audit and ending up with a weak certificate or poorly qualified auditors is a false economy.
Underestimating maintenance: after passing the initial audit many companies lower their guard. The risk is arriving unprepared at the following year’s surveillance.
How to build a system that lasts
A robust management system does not end with obtaining the certificate. It must become part of company routine. Systems that last share a few traits: lean procedures that are genuinely used, few but monitored indicators, a monthly or quarterly data review cycle, and a system owner with real authority rather than a purely formal role. Digitalising document and record management makes an enormous difference: paper systems, or files scattered across shared folders, degrade quickly.
ISO certifications and new European obligations: NIS2, GDPR, AI Act
The European regulatory landscape is making ISO certifications even more relevant. Not because they become mandatory in the strict sense, but because they are the most effective way to demonstrate compliance with obligations that are fully binding.
The NIS2 Directive, implemented in Italy by Legislative Decree 138/2024, imposes strict obligations on a wide range of companies regarding cybersecurity, risk management, incident notification and management accountability. A company that already runs an information security management system compliant with ISO 27001 already covers much of what NIS2 requires. Adopting ISO 27001 is not an obligation, but it is the most rational shortcut to compliance.
The GDPR, in force since 2018, does not require ISO certifications but refers to them as tools for demonstrating the controller’s accountability. In particular, ISO 27001 and ISO 27701 (privacy-specific) are widely recognised as evidence of technical and organisational adequacy.
The EU AI Act, the European artificial intelligence regulation approved in 2024, introduces growing obligations for those who develop or use AI systems. The ISO 42001 standard, published in 2023, is the first management system dedicated to artificial intelligence and will quickly become the reference for demonstrating compliance with European obligations.
The advantage of an integrated system
For a company that must answer to NIS2, the GDPR and perhaps also contractual obligations from international clients, building an integrated management system combining ISO 9001, ISO 27001 and, where relevant, ISO 42001 lets you meet every request with a single documentary and organisational infrastructure. The alternative — separate, overlapping projects — is more expensive and creates duplication that slows daily operations.
Frequently asked questions about ISO certifications
Are ISO certifications required by law?
In almost all cases, no. ISO certifications are voluntary tools. In many sectors, however, they become mandatory in practice because they are required by public tenders, large clients’ specifications or international contracts. In some regulated areas (medical devices, aerospace) ISO standards are explicitly referenced by sector legislation and therefore become indirect requirements.
What is the difference between ISO 9001 and ISO 9000?
ISO 9000 defines the terms and basic concepts of quality management, but it is not certifiable. ISO 9001 contains the actual requirements and is the standard companies get certified against. People commonly say “ISO 9000 certification” but that is imprecise: the certificate always states ISO 9001.
How long does an ISO certificate last?
An ISO certificate is valid for three years from the date of issue. During those three years annual surveillance audits verify that the system is maintained. At expiry a renewal audit leads into the next three-year cycle. If surveillance audits are not passed, the certificate can be suspended or withdrawn before its natural expiry.
Can I certify on my own, without consultants?
Technically yes, but it rarely succeeds in companies without existing internal expertise. The standard is complex to interpret correctly, the documentation system requires method and the audits are demanding. Support from experienced consultants or dedicated digital platforms drastically reduces risk and error, and shortens timelines.
If I change the company name, does the certificate stay valid?
It depends on the change. A simple change of company name, with no substantial change to the business, means the body updates the certificate. If the corporate structure changes significantly (mergers, demergers, business unit transfers), the body must assess the situation and may require additional audits.
Can I certify against several ISO standards at once?
Yes, and in many cases it is the most efficient choice. ISO management system standards share the same high level structure, so an integrated quality-environment-safety or quality-information security system can be built as a single project. The audit itself can be combined, reducing total days and costs.
What happens if I fail the certification audit?
If nonconformities emerge during the audit, the body sets a period to resolve them (usually 60-90 days). If the company shows the nonconformities were corrected within that time, the certificate is issued. If they are serious and cannot be fixed quickly, the audit has to be repeated. It is not a definitive failure: many companies reach certification after a round of corrections.
Is an Italian ISO certificate valid abroad?
Yes, provided it was issued by a body accredited by Accredia (or an equivalent body). Accredia participates in the IAF Multilateral Recognition Arrangement, which guarantees mutual recognition of certificates among signatory countries, covering practically every developed economy in the world.
The next step for your company
ISO certifications are not paperwork but a real competitive advantage when approached with method. The international ISO system gives companies a globally recognised way to demonstrate quality, security, reliability and compliance with new European rules. The journey is structured but perfectly manageable, provided you choose the right partner and an approach that builds on the company’s real operations instead of burdening it with needless bureaucracy.
Complaion supports Italian and Spanish SMEs throughout the ISO certification cycle, from choosing the most suitable standard to maintaining it in later years. Thanks to a digital approach, dedicated auditors and a structured method, timelines shorten noticeably compared with traditional routes and your team stays focused on the business. If you want to understand which certification makes sense for your company and receive a tailored quote based on your real situation, request a free consultation from the Complaion team. We will help you build a clear, sustainable path aligned with your commercial objectives.









