ISO 14001

ISO 14001 certification,
explained plainly

ISO 14001 is the international standard for an environmental management system, and after ISO 9001 the most widely held management-system certificate in the world. Here is what certification actually involves: the clauses, environmental aspects and compliance obligations, the life cycle perspective, what the 2026 revision changed, the certification stages and the surveillance audits that keep the certificate valid, plus how teams that also run ISO 9001 or ISO 27001 keep every system in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The standard

What ISO 14001 actually requires

ISO 14001 certifies an environmental management system (EMS), not a level of environmental performance. The 2026 edition sets out its requirements in seven clauses and asks you to know your environmental aspects and legal obligations, control them, measure the result and keep improving it.

The clauses (4 to 10)

Context, leadership, planning, support, operation, performance evaluation and improvement. The same harmonized structure ISO 9001, ISO 27001 and ISO 45001 use, which is why the four combine into one integrated system.

Aspects and obligations

There is no control catalogue. The substance is your register of environmental aspects and impacts, the significant ones among them, and the compliance obligations you must meet and periodically evaluate.

The 2026 revision

Published in April 2026, it names climate change, pollution, natural resources, biodiversity and ecosystems as context you must consider, strengthens the life cycle perspective and adds planning of changes. Certificates to the 2015 edition transition until April 2029.

The certification cycle

A Stage 1 and Stage 2 audit to certify, then a surveillance audit in years one and two and a full recertification in year three, with compliance evaluation as the part auditors look at most closely.

The full picture

ISO 14001, from first audit to recertification

A plain-language walkthrough of what the standard asks for, what the 2026 edition changed, and what actually keeps a certificate valid between audits.

01

What is ISO 14001?

ISO 14001 is the international standard for environmental management. It does not certify that your emissions are low or that your products are green. It certifies that your organization runs a working environmental management system (EMS): a defined way of knowing how your activities, products and services interact with the environment, which legal and other obligations apply, of controlling the significant interactions, measuring the outcome and improving it, over and over.

That is why customers, investors and public buyers ask for it. A certificate says a third party has verified the system: aspects are identified, obligations are evaluated, emergencies are prepared for, and management reviews it all. The current edition is ISO 14001:2026, published on 15 April 2026. It replaces ISO 14001:2015, which stays valid for certified organizations through a three-year transition period ending in April 2029.

ISO 14001 vs ISO 9001

ISO 14001 and ISO 9001 share the same harmonized clause structure and are certified by the same bodies in the same two-stage, three-year rhythm, but they manage different things. ISO 9001 is about the quality of what you deliver to customers; ISO 14001 is about the environmental impact of how you deliver it. Because clauses 4 to 10 line up almost word for word, most organizations that hold both run them as one integrated management system, with one context analysis, one audit programme, one management review and one set of corrective actions.

02

The clauses, 4 to 10

Clause 4 is context: the internal and external issues that affect the EMS, now including five named environmental conditions, the interested parties whose expectations you adopt as compliance obligations, and the scope, defined with a life cycle perspective. Clause 5 is leadership: top management owns the effectiveness of the EMS personally, sets the environmental policy with its commitments to protection of the environment, to compliance and to improvement, and assigns the roles. Clause 6 is planning, and it is the heart of the standard: identifying environmental aspects and their impacts, determining which are significant, registering compliance obligations, deriving risks and opportunities, planning actions and setting objectives, plus the new requirement to plan changes.

Clause 7 is support: resources, competence, awareness, communication and documented information. Clause 8 is operation: operating criteria for the processes that carry significant aspects, control of externally provided processes, products and services, the life cycle duties in design and procurement, and emergency preparedness and response. Clause 9 is performance evaluation: monitoring and measurement, the evaluation of compliance with your obligations, internal audit and management review. Clause 10 is improvement: nonconformity, corrective action and continual improvement of environmental performance.

03

Environmental aspects: the register everything else depends on

An environmental aspect is any element of your activities, products or services that interacts with the environment: emissions to air, discharges to water, waste, energy and water consumption, raw materials, land use, noise. Each aspect has impacts, and the standard asks you to identify them across the life cycle, for normal, abnormal and emergency conditions, to distinguish what you control from what you can only influence, and to apply documented criteria to decide which are significant.

The significant aspects drive everything downstream: which obligations matter most, which objectives you set, which processes need operating criteria, which emergencies you prepare for and what you monitor. Auditors start here, because a thin or outdated aspects register means the rest of the system is aimed at the wrong things.

04

Compliance obligations and their evaluation

Compliance obligations are the legal requirements that apply to your aspects, from permits and emission limits to waste and chemicals rules, plus the other requirements you have chosen to adopt, such as customer codes of conduct or industry commitments. Clause 6 asks you to identify them, keep access to them and understand how they apply. Clause 9 then asks for something many organizations underestimate: a separate, periodic evaluation of whether each obligation is actually met, with actions on gaps and a current view of your compliance status.

This is distinct from internal audit, and it is where certification auditors and regulators look most closely. A compliance obligations register nobody evaluates is the finding raised most often against otherwise well-run systems.

05

What the 2026 revision changed

The changes are moderate by design: the revision clarified requirements rather than adding many. Context now explicitly includes climate change, pollution, the availability of natural resources, biodiversity and the condition of ecosystems, in both directions. The life cycle perspective reaches into the scope and the aspects process. Risks and opportunities became a standalone sub-clause with its own traceable register, and planning of changes is a genuinely new clause. Operational control widened from outsourced processes to all externally provided processes, products and services.

Smaller edits follow the harmonized structure: audit objectives join criteria and scope, management review is split into general, inputs and results, and the former general and continual improvement clauses merge into one. Annex A, the informative guidance, was substantially rewritten. For an organization certified to the 2015 edition, transition is mostly a matter of updating the context analysis, the aspects register and the change process, and most certification bodies fold the transition into a scheduled surveillance or recertification audit.

06

How ISO 14001 certification works, step by step

Certification is carried out by an accredited certification body in two stages. Stage 1 is a readiness review: the auditor checks that the EMS exists as documented information, that the scope, policy, aspects register and compliance obligations are in place, and that internal audit, compliance evaluation and management review have been planned or done. Stage 2 is the certification audit proper: the auditor walks the sites, follows significant aspects into the processes that control them, checks permits and monitoring records, tests emergency preparedness and interviews the people who run it all.

From a serious start, most small and mid-size organizations reach Stage 2 in six to twelve months, driven mostly by how well aspects and obligations are already understood and how much monitoring already exists. The certificate is then valid for three years, with a surveillance audit in each of years one and two and a full recertification in year three.

Emergency preparedness: the drill the auditor asks about

Clause 8 requires you to prepare for the potential emergencies identified among your aspects, such as spills, fires and floods, to respond when they happen, to test the plans periodically and to revise them after tests and real events. Auditors reliably ask for the last drill record and what changed because of it. A plan that has never been tested is a plan on paper.

07

What drives the cost of ISO 14001

The certification body charges for the Stage 1 and Stage 2 audits and for each surveillance audit, scaled to the number of sites, people and significant aspects in scope. That fee is usually the smaller part. The larger cost is building and running the EMS: identifying aspects, registering obligations, writing operating criteria, monitoring with calibrated equipment, evaluating compliance, preparing for emergencies, auditing and reviewing, and keeping all of it current through every audit.

Two levers move that cost more than the certification fee. Scope, because certifying the sites and activities your customers actually ask about is cheaper than certifying everything at once. And integration, because if you also run ISO 9001, ISO 45001 or ISO 27001, one context analysis, one audit programme, one management review and one corrective-action process can serve every certificate, and certification bodies commonly audit them together.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after: the aspects register nobody updated when the new line went in, the permit condition nobody evaluated since the last visit, the emergency plan whose last drill predates the current site layout. That is the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
3-year cycle
audit-readyCertSurveillance 1Surveillance 2
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your ISO 14001 management system, in one workspace

The management-system side of the standard, from clause coverage and compliance obligations to audits, findings and reviews, kept current between surveillance audits. Pick one to see it.

Every clause, in one view

See clauses 4 to 10 as a control set, what applies to your scope and where you stand, each requirement mapped to the documented information, processes and evidence that satisfy it, so the picture stays live instead of being rebuilt before each audit.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

ISO 14001 shares its clause structure with ISO 9001, ISO 45001 and ISO 27001. Map the management-system clauses once in devguard and the same context analysis, audit results and management review satisfy them everywhere they appear, so the next certificate is a fraction of the work of the first.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already certified? Move your ISO 14001 system across

If you already hold ISO 14001, you do not want to rebuild your EMS from a blank page. In a scoped conversation we agree exactly what moves (your aspects register, compliance obligations, policy and objectives, monitoring records, audit history and management review records) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
ISO 14001 FAQ

ISO 14001, answered plainly.

How long does ISO 14001 certification take?

For most small and mid-size organizations, roughly six to twelve months from a serious start to the Stage 2 audit, depending on how well your aspects and obligations are already understood and how much monitoring already exists. Maintaining it afterwards is the longer game: a surveillance audit each year and a full recertification every three years.

Do I have to transition from ISO 14001:2015 to ISO 14001:2026?

Yes, if you want to keep the certificate. ISO 14001:2026 was published on 15 April 2026 with a three-year transition period, so certificates issued to the 2015 edition must be transitioned by April 2029. Certification bodies started transition audits in mid-2026 and typically combine the transition with a scheduled surveillance or recertification audit. The changes are moderate, so for a well-run system the transition is mostly updating the context analysis, the aspects register and the change process.

Does ISO 14001 have controls like Annex A in ISO 27001?

No. ISO 14001 has no control catalogue. Its requirements are the clauses themselves, and the substance comes from your own aspects register and compliance obligations: you decide, by documented criteria, which aspects are significant and what controls they need. Annex A of the standard is guidance, not a list of controls to implement.

Does ISO 14001 require me to meet a certain environmental performance?

No. It requires a system that manages your aspects, meets your compliance obligations and improves environmental performance over time, and it requires you to evaluate compliance periodically. It does not set emission limits or targets; those come from your permits, your laws and the objectives you set yourself.

Can I combine ISO 14001 with ISO 9001 and ISO 45001?

Yes, and this is the most common way to run it. All three follow the same harmonized clause structure, so one context analysis, one internal audit programme, one management review and one corrective-action process can serve all of them. Certification bodies commonly audit the three together as an integrated management system, which cuts audit days as well as maintenance effort.

Is devguard an environmental management tool?

devguard is a compliance workspace, and it carries the management-system side of ISO 14001: clause coverage, versioned documented information, the aspects and obligations registers and their evaluations as evidence, internal audits, nonconformities and corrective actions, management reviews and the roadmap from adoption to certification. It does not replace emissions monitoring, waste tracking or permit management systems. Where you already run ISO 9001 or ISO 27001 in devguard, ISO 14001 slots into the same system.

See how your ISO 14001 system would look in devguard.

The fastest way to know if this fits is a short conversation about how you run ISO 14001 today: where the aspects register and the obligations live, where the audit-cycle effort goes, and whether it should share a workspace with your other management systems. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free