Back to blog
ISO 9001 Certification 9 min read

ISO 9001 certification process: Stage 1, Stage 2, and what happens after

The ISO 9001 certification process is not a single audit. It is gap analysis, a working QMS, internal audit, management review, then two registrar stages. Here is the sequence auditors in Canada and the US actually follow.

Quick answer

What is the ISO 9001 certification process?

Stage 1 is a readiness and documentation review. Stage 2 is the implementation audit: interviews, records, and process sampling. Certification is issued only after Stage 2 (and any major nonconformities are closed). Surveillance audits then keep the certificate alive for three years.

What happens before Stage 1?

You choose scope, run a gap analysis, document the QMS, train people, run at least one internal audit cycle, and hold management review. Skipping internal audit is one of the fastest ways to collect Stage 1 findings.

ISO does not require a consultant. It does require evidence the system is used. That is why software beats a binder: the trail already exists when the auditor asks. 4ES Hub AI can draft the documented information; your team still operates it. See from zero to certified.

What is a Stage 1 ISO audit?

Stage 1 checks whether the documented system addresses ISO 9001 and whether you appear ready for Stage 2. Auditors look at scope, quality policy, objectives, key procedures, internal audit and management review evidence, and site logistics. Stage 1 does not grant a certificate.

Findings here are a gift if you treat them that way: cheaper to fix before Stage 2. Remote Stage 1 is common for smaller organizations; your certification body decides.

What is a Stage 2 ISO audit?

Stage 2 is the certification audit. The auditor samples processes end to end, interviews staff who actually do the work, and tests whether records match the documented information. Minor nonconformities are common and usually require a corrective action plan. Major nonconformities—core clause not functioning—delay the certificate until they are closed and often re-audited.

After a successful Stage 2, the body completes technical review and issues the certificate, typically within a few weeks. Choose an accredited body; see how to choose ISO 9001 certification companies.

What happens after you are certified?

Surveillance audits (usually annual) sample the system so it has not quietly died. Recertification happens at the end of the three-year cycle. The cheap mistake is celebrating the certificate and returning to shared drives. Keep documents, training, CAPA, and audits in one platform—4ES Hub is built as that system of record from $399/month.

Frequently asked questions

What is the difference between Stage 1 and Stage 2 ISO audits?

Stage 1 reviews documentation and readiness. Stage 2 verifies the QMS is implemented and effective through interviews, observation, and record sampling. Only Stage 2 can lead to a certificate.

Do I need an internal audit before Stage 1?

In practice, yes. Certification bodies expect you to have audited your own system and held management review. Showing up with a manual and no internal audit is a common Stage 1 finding.

What happens if we fail Stage 2?

Major nonconformities must be corrected and usually re-audited. Minors typically need a plan and evidence of implementation. The certificate is withheld until the body accepts closure of majors.

How does 4ES Hub support the certification process?

4ES Hub holds the documented information, training records, internal audits, nonconformities, and management review in one system so Stage 1 and Stage 2 sampling is straightforward. AI can draft starting records; your team operates them.

Run the process in software, not email

Try 4ES Hub free. Arrive at Stage 1 with linked documents, training, internal audits, and management review already in one place.

Try free — start now