Frequently Asked Questions
Everything you need to know about ISO certification
General Questions
What is ISO certification?
ISO certification is a formal confirmation from an accredited third-party body that your organisation complies with the requirements of an ISO management system standard. It proves your commitment to quality, safety, environmental responsibility, or information security — depending on the standard — and is recognised in over 170 countries. Ace is a consultancy: an IAF-accredited certification body issues the certificate.
How long does ISO certification take in India?
With Ace support, many organisations reach certification-body audit in 4–8 weeks. Time still depends on the standard, the scope of the management system, number of employees and sites, how much usable documentation you already have, and the certification body’s audit dates. Contact Ace for a scoped plan. Ace implements; we do not issue the certificate.
How much does ISO certification cost in India?
ISO certification cost in India depends on the standard, the scope of the management system, number of employees and sites, current documentation, and the certification body’s audit programme. Consulting, training, and audit fees are quoted for that organisation — there is no single published price. Contact Ace for a scoped quote.
How long is ISO certification valid?
Most ISO certifications are valid for three years. During this cycle, annual surveillance audits (Year 1 and Year 2) verify continued compliance. After three years, a full recertification audit renews the certificate for another three-year cycle. Certificates that lapse due to missed audits are not renewable — they must be obtained fresh.
Is ISO certification mandatory in India?
ISO certification is voluntary in most industries. However, it is effectively mandatory for government tenders (GeM portal, CPWD, ONGC, Railways), export to the EU and many other countries, pharma and food companies supplying to regulated markets, and IT companies bidding for large enterprise contracts. The IAF logo on your certificate is the government-recognised mark of validity.
What is the difference between ISO certification and ISO registration?
The two terms are used interchangeably in practice. Some countries use 'registration' to describe the formal listing of your organisation on a certification body's database, while 'certification' refers to the actual certificate issued. In India, both mean the same thing — your organisation has been audited and approved against the relevant ISO standard.
Which ISO certification is best for my business?
ISO 9001 is the usual starting point and is required for most Indian government tenders. ISO 14001 is common for manufacturers and exporters; ISO 45001 for construction, oil and gas, and other high-risk work; ISO 27001 for IT and anyone handling sensitive data. Organisations now also add ISO 22301 for business continuity, ISO 31000 as a risk-management framework, ISO 27701 for privacy, ISO 42001 if they use or provide AI, ISO 13485 for medical devices, and SEDEX/SMETA for social compliance on export supply chains. Ace helps you choose and implement. An IAF-accredited certification body issues ISO certificates; SEDEX is a buyer audit, not an ISO certificate. Ace does not issue certificates.
IAF Accreditation & Certificate Validity
What is IAF accredited certification?
The International Accreditation Forum (IAF) oversees accreditation bodies (NABCB in India, UKAS in the UK). An IAF-accredited certification means an accredited certification body issued your certificate under the IAF MLA, so it is recognised in 100+ countries. Ace only works with those bodies.
How can I verify if an ISO certificate is genuine?
Genuine IAF-accredited certificates can be verified on IAF CertSearch (certsearch.iaf.nu) within 5 working days of issue. Enter the certificate number or organisation name. Certificates not listed on IAF CertSearch or issued by non-accredited bodies have no global legal standing and will be rejected by government procurement portals and international buyers.
What is the difference between IAF and non-IAF certification?
IAF-accredited certificates: globally recognised, verifiable online, accepted in government tenders and international trade, issued after rigorous third-party audits. Non-IAF certificates: limited or no recognition, not listed in IAF CertSearch, often rejected by buyers and government bodies, sometimes issued without a proper audit. Always insist on an IAF-accredited certification body.
Does ISO certification expire if I miss a surveillance audit?
Yes. Missing a surveillance audit triggers a suspension of your certificate. If the issue is not resolved within the suspension window (typically 6 months), the certificate is withdrawn. A withdrawn certificate cannot be reinstated — your organisation must restart the full certification process. Ace Professional Services provides calendar reminders and audit preparation support to prevent this.
Specific ISO Standards
What is ISO 9001 and who needs it?
ISO 9001:2015 is the world's most widely adopted Quality Management System (QMS) standard — used by over 1 million organisations in 170+ countries. It applies to any industry and size. In India it is a pre-qualification requirement for most government tenders, PSU contracts, and international supplier approvals.
What is ISO 14001 certification?
ISO 14001:2015 is the Environmental Management System (EMS) standard. It helps organisations reduce their environmental footprint, comply with environmental regulations, and demonstrate sustainability credentials to stakeholders. It is required for export to EU markets, green procurement in government tenders, and is a prerequisite for many EPDs (Environmental Product Declarations).
What is ISO 45001 and is it replacing OHSAS 18001?
ISO 45001:2018 is the Occupational Health and Safety Management System standard — it fully replaced OHSAS 18001 in March 2021. OHSAS 18001 certificates are no longer valid. ISO 45001 has stronger emphasis on worker participation, leadership commitment, and top-down safety culture. Any organisation that held OHSAS 18001 must now be certified to ISO 45001.
What is ISO 27001 and who needs it?
ISO 27001:2022 is the Information Security Management System (ISMS) standard. It is expected for IT companies bidding on government contracts, BFSI suppliers, cloud providers, and organisations handling sensitive customer data. Ace offers a free Readiness Scan at https://app.isocertifications.in — that scan is not certification.
What is HALAL certification and who issues it in India?
HALAL certification confirms that a product or process meets Islamic dietary and hygiene requirements, making it acceptable for Muslim consumers. In India, it is issued by approved HALAL certification bodies (not the government, and not Ace). It is required for food, cosmetics, pharmaceuticals, and hospitality businesses exporting to the Middle East, Malaysia, Indonesia, and other Muslim-majority markets.
What is SEDEX and how is it different from ISO certification?
SEDEX (Supplier Ethical Data Exchange) is a membership-based platform where businesses share audit data on labour practices, health & safety, environment, and business ethics. Unlike ISO certifications, SEDEX is not a certificate — it is a data-sharing framework used by major global retailers to audit their supply chains. An SMETA audit is the actual audit against SEDEX criteria.
Pricing & Costs
What factors affect ISO certification cost in India?
Key cost factors: (1) Organisation size — number of employees, sites, and processes; (2) Standard complexity — ISO 27001 costs more than ISO 9001 due to technical depth; (3) Current compliance level — a higher baseline means less gap to close; (4) Number of sites — multi-site certifications require additional audits; (5) Urgency — expedited programmes cost more. Ace Professional Services provides fixed-price consulting packages. Certification body fees are separate.
Are there ongoing costs after getting ISO certified?
Yes. The certification body charges for annual surveillance audits, and you may need periodic internal audits, management review, and training for new staff. Those fees depend on the standard, sites, and headcount. Ace can support maintenance; we do not replace the certification body.
Can a small business afford ISO certification?
Micro and small enterprises with fewer than 25 employees can typically complete ISO 9001 with consulting plus certification-body fees in a range that many recover through tenders that require the certificate. Ace offers structured payment plans for MSMEs. We do not guarantee contract wins or a pass at audit.
Implementation & Process
Do we need a consultant, or can we implement ISO standards ourselves?
Self-implementation is possible but most organisations benefit from expert guidance. Consultants reduce implementation time and help avoid documentation that will fail Stage 1. For ISO 27001 or ISO 13485, self-implementation without deep technical expertise significantly increases the risk of failing the certification audit. Ace implements and prepares you for audit; the certification body decides.
What does the ISO certification process look like step by step?
Typical process: (1) Gap analysis; (2) Documentation; (3) Implementation and training; (4) Internal audit; (5) Management review; (6) Certification audit Stage 1; (7) Certification audit Stage 2; (8) Certificate issued by the certification body. Ace supports the implementation steps.
How do I start the ISO certification process?
Start with a conversation about scope and a gap analysis against the chosen standard. Ace then agrees a fixed-price implementation plan: documentation, training, internal audit, and support through Stage 1 and Stage 2. Many organisations reach the certification-body audit in 4–8 weeks; timing still depends on standard, scope, sites, current documentation, and audit dates. For ISO 27001 you can begin with the free Readiness Scan at https://app.isocertifications.in.
How much documentation is required for ISO certification?
Modern ISO standards reduced mandatory documentation compared with older editions. What you need depends on the standard and on your organisation. Ace proposes a minimum coherent set for your scope. We do not mint a document per control, and a client “yes” is not proof that a document is sufficient.
Will ISO certification require us to change our existing processes?
ISO standards rarely require wholesale process change. Ace maps your existing processes to the standard and adds controls where genuine gaps exist. Many organisations already meet a large share of requirements in practice — the gap is often documentation, monitoring, and management review rather than day-to-day operations.
How do we maintain certification after the audit?
Ongoing certification requires annual internal audits, surveillance audits by the certification body, management reviews, closing nonconformities, and continual improvement. Missing surveillance can suspend or withdraw the certificate. Ace can support maintenance; the certification body still owns the certificate.
India-Specific Questions
Is ISO certification required for government tenders in India?
Yes. GeM, CPWD, ONGC, Railways, Defence PSUs, and most state procurement typically require valid ISO 9001 from a certification body accredited by an IAF MLA member. Non-accredited certificates are rejected. ISO 14001 or ISO 45001 may also be required for environmental or safety-sensitive contracts. NABCB (under QCI) is India’s IAF member. NABCB’s own tender guidance (BCB 601) says any IAF MLA-accredited body is sufficient and that insisting only on NABCB is not necessary — but some Indian buyers still write “NABCB-accredited CB” in the bid. Ace prepares you for the audit and works with IAF-accredited bodies, including NABCB-accredited CBs, so you can meet either wording. Ace does not issue the certificate.
Which ISO certifications are most in demand in India?
By demand: (1) ISO 9001 — quality, required across many sectors; (2) ISO 14001 — environment, export and green tenders; (3) ISO 45001 — occupational safety; (4) ISO 27001 — information security for IT and BFSI; (5) HALAL — food and cosmetics export to GCC countries; (6) GMP/WHO-GMP — pharmaceuticals; (7) HACCP/ISO 22000 — food processing. Not every Ace offering is an ISO certificate (for example SEDEX/SMETA).
Can ISO certification help Indian exporters?
Often yes. ISO 9001 is a common minimum for European and North American buyers. ISO 14001 appears in EU supply-chain expectations. HALAL opens GCC and other Muslim-majority markets. ISO 27001 is common for IT exports to financial clients. ISO 13485 is common for medical device export. Buyers still require a certificate from an accredited body, not from Ace.
How is NABCB different from other accreditation bodies in India?
NABCB (National Accreditation Board for Certification Bodies) is India's IAF-member accreditation body under the Quality Council of India. A certification body accredited by NABCB (or another IAF-member body) issues certificates recognised under the IAF MLA. Certifications from bodies with no IAF-member accreditation are not internationally valid. Ace is not an accreditation body and not a certification body.