ISO 9001

ISO 9001 certification,
explained plainly

ISO 9001 is the international standard for a quality management system, and the most widely held management-system certificate in the world. Here is what certification actually involves: the clauses, risk-based thinking, the documented information an auditor expects, the certification stages and the surveillance audits that keep the certificate valid, plus how teams that also run ISO 27001 keep both systems in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The standard

What ISO 9001 actually requires

ISO 9001 certifies a quality management system (QMS), not a product. The 2015 edition sets out its requirements in seven clauses, from the context of the organization to continual improvement, and asks you to run the system, measure it and prove it keeps working over time.

The clauses (4 to 10)

Context, leadership, planning, support, operation, performance evaluation and improvement. The same harmonized structure ISO 27001 and ISO 42001 use, which is why the three combine so well.

No control catalogue

Unlike ISO 27001, there is no Annex A. The requirements are the clauses themselves, and you decide how your processes meet each one.

The certification cycle

A Stage 1 and Stage 2 audit to certify, then a surveillance audit in years one and two and a full recertification in year three.

A system, not a certificate

Certification confirms a working system: processes defined, risks and opportunities considered, results measured, nonconformities corrected and the whole thing reviewed by management.

The full picture

ISO 9001, from first audit to recertification

A plain-language walkthrough of what the standard asks for, and what actually keeps a certificate valid between audits.

01

What is ISO 9001?

ISO 9001 is the international standard for quality management. It does not certify that a product is good or that a service is fast. It certifies that your organization runs a working quality management system (QMS): a defined way of understanding what customers and regulators require, designing processes that deliver it, measuring whether they did, and fixing what fell short, over and over.

That distinction matters more than it sounds. An auditor is not judging your product. They are asking whether you can show them the system you use to get it right consistently, and the evidence that the system runs. ISO 9001 is also, by a wide margin, the most widely held management-system certificate in the world, which is why it turns up in tenders and supplier questionnaires across every industry, not just manufacturing.

The current edition is ISO 9001:2015. It was confirmed unchanged in 2021, and Amendment 1:2024 added a requirement to consider whether climate change is a relevant issue for the organization and its interested parties, the same amendment ISO applied to ISO 27001 and its other management-system standards.

ISO 9001 vs ISO 27001

ISO 9001 and ISO 27001 share the same harmonized clause structure, but they manage different things. ISO 9001 is about the quality of what you deliver to customers; ISO 27001 is about the security of the information you handle. Each is certified on its own, but because clauses 4 to 10 line up almost word for word, many organizations run the two as one integrated management system, with one context analysis, one audit programme, one management review and one set of corrective actions.

02

The seven quality management principles

ISO 9001 rests on seven principles that ISO publishes alongside the standard: customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making and relationship management. None of them is audited directly. They are the reasoning behind the requirements, and reading them first makes the clauses considerably less mysterious.

Two of them shape the whole standard. The process approach asks you to see your organization as a set of interlinked processes with inputs, outputs, owners and measures, rather than a set of departments. Evidence-based decision making asks you to run those processes on data: customer feedback, defect rates, delivery performance, audit findings. The Plan-Do-Check-Act cycle that runs through every clause is simply those two principles applied in a loop.

03

The clauses, 4 to 10

The requirements of ISO 9001 are organized in seven clauses that follow the harmonized structure ISO uses for all of its management-system standards. Clause 4 is context: who your interested parties are, what they require, and what your QMS covers. Clause 5 is leadership: top management owns the quality policy, the objectives and the customer focus, and cannot delegate that ownership. Clause 6 is planning, where risks and opportunities are addressed and quality objectives are set.

Clause 7 is support: the people, infrastructure, competence, awareness, communication and documented information the system needs. Clause 8 is operation, and it is the longest clause, covering how you determine customer requirements, design and develop products and services, control what you buy in from suppliers, run production or service delivery, release outputs and deal with nonconforming ones. Clause 9 is performance evaluation: monitoring, customer satisfaction, internal audit and management review. Clause 10 is improvement: nonconformity, corrective action and continual improvement.

Because there is no annex of controls, the clauses are the whole standard. Every requirement is a "shall" inside them, and an auditor works through them one by one, asking how your processes satisfy each and what evidence shows they do.

04

Risk-based thinking, without a risk register

The 2015 edition replaced the old preventive action requirement with risk-based thinking. Clause 6 asks you to determine the risks and opportunities that could affect your ability to deliver conforming products and services and to satisfy customers, to plan actions to address them, and to evaluate whether those actions worked. It is a way of thinking that runs through the whole system, not a separate procedure.

Unlike ISO 27001, ISO 9001 does not mandate a formal risk assessment methodology or a risk register. You may keep one, and organizations that also run ISO 27001 usually do, but the standard only asks that risks and opportunities are considered, that the consideration is proportionate to their potential impact, and that you can show an auditor where it happened. Process reviews, project kick-offs and management review minutes are all acceptable places for it to live.

05

Documented information: what you must write down

ISO 9001 replaced "documents and records" with a single term, documented information, and distinguishes two kinds. Information you maintain describes the system and has to be kept current: the scope of the QMS, the quality policy, the quality objectives and whatever procedures you have decided your processes need. Information you retain is evidence that the system ran: audit results, management review outputs, records of nonconformities and corrective actions, competence records, calibration and monitoring results, and the records that trace a product or service through operation.

The standard is deliberately quiet about format. It does not require a quality manual any more, does not prescribe procedures, and accepts a well-organized wiki as readily as a binder. What it does require is control: documented information has to be identified, versioned, approved, available where it is needed and protected from unintended change. In practice this is where a QMS lives or dies between audits. A procedure that says one thing while the records show another is the finding auditors raise most often.

06

How ISO 9001 certification works, step by step

Certification is carried out by an accredited certification body, in two stages. Stage 1 is a readiness review: the auditor checks that the QMS exists as documented information, that the scope is defined, that internal audits and a management review have been planned or done, and that the organization is ready to be assessed. It usually produces a list of gaps to close before going further.

Stage 2 is the certification audit proper. The auditor samples your processes against every clause, walks the operation, interviews the people who run it and tests whether the system operates as described, not just whether it is written down. Before Stage 2 the standard expects you to have completed at least one full internal audit cycle and one management review yourself.

From a serious start, most small and mid-size organizations reach Stage 2 in six to twelve months, driven mostly by how much process discipline already exists and how much of it is recorded. The certificate is a checkpoint on a system you keep running, not the end of a project.

07

Staying certified: surveillance audits and recertification

An ISO 9001 certificate is valid for three years, and the certification body does not leave you alone in between. A surveillance audit in each of years one and two checks that the QMS still operates, that internal audits and management reviews have happened, that nonconformities are being closed and that the system is improving. A full recertification audit in year three renews the certificate for another cycle.

This is the part organizations underestimate. The work that earned the first certificate, running the internal audit programme, holding management reviews with the inputs the standard lists, closing corrective actions with evidence of effectiveness, keeping documented information current, is the same work that carries you through every surveillance audit after it. Teams that treat certification as a one-off project rebuild the evidence before each visit; teams that build the QMS into how they already operate do not.

Management review: the minutes the auditor reads first

Clause 9 lists exactly what a management review has to consider: the status of actions from the last review, changes in context, customer satisfaction, quality objectives, process performance, nonconformities, audit results, supplier performance, resources, and risks and opportunities. It also lists what has to come out of it: improvement opportunities, changes to the QMS and resource needs. Auditors read the minutes first because a review that covers those inputs proves the whole system was looked at, not just the parts that were going well.

08

What drives the cost of ISO 9001

There is no single price for ISO 9001, because most of the cost is your own effort rather than a line item. The certification body charges for the Stage 1 and Stage 2 audits and for each surveillance audit, scaled to the number of people, sites and processes in scope. That fee is usually the smaller part.

The larger cost is building and running the QMS: mapping processes, defining what documented information they need, running internal audits, holding management reviews, tracking corrective actions to closure and keeping all of it current through every audit. Organizations that keep it in spreadsheets and shared drives pay for it again before every surveillance audit, in the time it takes to reconstruct records that were never kept in one place.

Two levers move total cost more than the certification body’s fee. The first is scope: certifying the sites and processes your customers actually ask about, rather than everything at once. The second is integration: if you also run ISO 27001, an integrated management system lets one audit programme, one management review and one corrective-action process serve both certificates, and many certification bodies will audit the two together.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after: the procedure nobody has updated since the last audit, the nonconformity closed without evidence, the management review minutes reassembled from memory the week before the surveillance visit. That is the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
3-year cycle
audit-readyCertSurveillance 1Surveillance 2
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your ISO 9001 management system, in one workspace

The management-system side of the standard, from clause coverage and documented information to audits, findings and reviews, kept current between surveillance audits. Pick one to see it.

Every clause, in one view

See clauses 4 to 10 as a control set, what applies to your scope and where you stand, each requirement mapped to the documented information, processes and evidence that satisfy it, so the picture stays live instead of being rebuilt before each audit.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across every standard you add.

ISO 9001 shares its clause structure with ISO 27001 and ISO 42001. Map the management-system clauses once in devguard and the same context analysis, audit results and management review satisfy them everywhere they appear, so the second certificate is a fraction of the work of the first.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already certified? Move your ISO 9001 system across

If you already hold ISO 9001, you do not want to rebuild your QMS from a blank page. In a scoped conversation we agree exactly what moves (your process documentation, quality policy and objectives, audit history, nonconformities and management review records) and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
ISO 9001 FAQ

ISO 9001, answered plainly.

How long does ISO 9001 certification take?

For most small and mid-size organizations, roughly six to twelve months from a serious start to the Stage 2 audit, depending on how much process discipline already exists and how much of it is recorded. Maintaining it afterwards is the longer game: a surveillance audit each year and a full recertification every three years.

Does ISO 9001 have controls like Annex A in ISO 27001?

No. ISO 9001 has no control catalogue. Its requirements are the clauses themselves, 4 to 10, and you decide how your processes meet each one. That is why two organizations with the same certificate can run very different quality systems, and why an auditor spends more time in your processes than in a checklist.

Does ISO 9001 require a risk register?

No. The standard asks for risk-based thinking: risks and opportunities are determined, actions to address them are planned and their effectiveness is evaluated. It does not mandate a methodology or a register. Organizations that also run ISO 27001 usually keep one anyway, because it satisfies both standards at once.

Do I still need a quality manual?

Not since the 2015 edition. The standard asks for documented information: maintained information that describes the system (scope, policy, objectives, whatever procedures your processes need) and retained information that proves it ran (audit results, review outputs, nonconformity records). The format is yours to choose, as long as it is controlled.

Can I combine ISO 9001 with ISO 27001?

Yes, and many organizations do. Both follow the same harmonized clause structure, so one context analysis, one internal audit programme, one management review and one corrective-action process can serve both. Certification bodies commonly audit the two together as an integrated management system, which cuts audit days as well as maintenance effort.

Is devguard a quality management tool?

devguard is a compliance workspace, and it carries the management-system side of ISO 9001: clause coverage, versioned documented information, internal audits, nonconformities and corrective actions, management reviews and the evidence behind them. It does not replace production, inspection or supplier-quality tooling. Where you already run ISO 27001 in devguard, ISO 9001 slots into the same system.

See how your ISO 9001 system would look in devguard.

The fastest way to know if this fits is a short conversation about how you run ISO 9001 today: what you maintain, where the audit-cycle effort goes, and whether it should share a workspace with your ISMS. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free