+91 9828123489
HomeLicense/CertificationISO Certification

ISO Certification in Assam

ISO Certification Registration in India – Standards, Process, Accreditation, Cost & Renewal

cut-out photo

Get free consultation

Talk to a qualified professional today.
+91
or reach us directly
Quick answer

ISO certification is formal confirmation by an independent accredited certification body that your organisation’s management system meets the requirements of a particular ISO standard. ISO itself does not certify anyone. In India, credible certification comes from a body accredited by NABCB or another accreditation body that is a signatory to the IAF Multilateral Recognition Arrangement — and a certificate from an unaccredited body, however cheap, has no standing with a serious buyer, tender authority or overseas customer. Certification is valid for three years, subject to annual surveillance audits, and the whole process typically takes three to six months. The single most important thing to get right is not the standard you choose but who issues the certificate.

Vakilkaro simplifies ISO certification for Indian businesses with complete end-to-end expert assistance. ISO certification is a globally recognised validation of a business’s commitment to quality, safety and efficiency, and it has become essential for organisations looking to build credibility, improve operations and compete in domestic and international markets.

Our team of experienced ISO consultants handles the entire journey — gap analysis, documentation, implementation, training, internal audit, coordination with an accredited certification body, audit preparation and surveillance support — at a transparent and affordable fee with no hidden charges.

Introduction

What is ISO Certification in India?

ISO certification is formal recognition, issued by an accredited certification body, that an organisation’s management system conforms to the requirements of a specific standard published by the International Organization for Standardization. ISO is an independent, non-governmental body that develops and publishes standards for quality, safety, efficiency and interoperability across industries and countries.

A point that is fundamental and frequently misunderstood: ISO does not certify anyone. ISO writes the standards. Certification against those standards is carried out by independent certification bodies, which are in turn assessed and accredited by national accreditation bodies. That three-tier structure — standard-setter, certification body, accreditation body — is what makes an ISO certificate mean anything, and understanding it is the difference between buying a credential and buying a piece of paper.

ISO certification applies across manufacturing, services, healthcare, food processing, information technology, construction, education and virtually every other sector. Each standard addresses a specific aspect of business operations, which makes the framework applicable to organisations of any size.

Certification is also not a one-off event. It is a three-year cycle with annual surveillance, and it presumes that the management system is actually being operated, not merely documented once and filed away.

Importance

Why is ISO Certification Important for Businesses in India?

Enhanced credibility. An accredited certificate validates that your systems meet an internationally recognised benchmark, and gives customers and partners something verifiable to rely on.

Market expansion. Government tenders, export buyers and multinational customers increasingly require certification as a threshold qualification.

Operational efficiency. The standards force you to document and examine your own processes, which routinely surfaces inefficiencies nobody had measured.

Customer satisfaction. Consistent delivery reduces complaints, returns and rework.

Regulatory alignment. The management system frameworks map closely onto many regulatory requirements in food safety, environment, safety and information security.

Competitive advantage. Where two comparable suppliers compete, the certified one is usually preferred — and sometimes the only one eligible.

Risk management. Particularly under the safety, information security and food safety standards, the certification process is a structured risk-identification exercise.

Employee engagement. Clear processes, defined responsibilities and a culture of improvement measurably improve performance.

Understanding Accreditation — NABCB, IAF and Why It Decides Everything

This section matters more than any other on this page, because everything else follows from it.

The three-tier structure

ISO publishes the standard — for example ISO 9001.

A certification body audits your organisation against that standard and issues the certificate.

An accreditation body assesses the certification body itself — its competence, impartiality and processes — against ISO/IEC 17021-1, and accredits it.

NABCB — the National Accreditation Board for Certification Bodies, operating under the Quality Council of India — is India’s accreditation body for management system certification. NABCB is a signatory to the International Accreditation Forum Multilateral Recognition Arrangement (IAF MLA), which is what makes an NABCB-accredited certificate recognised in other IAF member economies. A certificate from a body accredited by any other IAF MLA signatory — UKAS in the United Kingdom, ANAB in the United States, DAkkS in Germany and others — carries the same international recognition.

Why this determines whether your certificate is worth anything

A tender authority checking your certificate will look for the accreditation mark and verify it

An export buyer will check it against the IAF database

A corporate procurement team will reject an unaccredited certificate at vendor onboarding

An auditor in your customer’s own certification cycle will ask where your certificate came from

Accreditation is not a formality or a premium option. It is the difference between a certificate and a decoration.

The Fake ISO Certificate Problem

India has a substantial market in worthless ISO certificates, and any honest guide to this subject has to say so plainly.

There are operators who will issue an “ISO 9001 certificate” for a few thousand rupees, within days, with no audit, no site visit, and no accreditation behind them. The certificate looks convincing. It carries a number, a logo, a signature and often an impressive-sounding body name. It is entirely worthless.

How to identify one

No accreditation mark. A genuine certificate carries the accreditation body’s mark — NABCB or another IAF MLA signatory — alongside the certification body’s own logo. A certificate carrying only the certification body’s logo is unaccredited.

An “accreditation” from a body you cannot find on the IAF list. There are private outfits with official-sounding names that “accredit” certification bodies and are themselves accredited by nobody. Check the accreditation body against the IAF signatory list.

No audit, or a token one. If nobody visited your premises, examined your records, interviewed your staff and raised findings, no audit took place. A real Stage 2 audit is a working day or several, not a phone call.

Implausible speed. Genuine certification takes months, because the management system has to be implemented and operated before it can be audited. A certificate in 48 hours is not a certificate.

Implausible price. The certification body’s own cost is driven by mandatory audit man-days. A quote far below that cost means the audit days are not being performed.

No surveillance. A genuine certificate brings annual surveillance audits. An operator who takes a one-time fee and never contacts you again was never certifying anything.

Not verifiable. A genuine certificate can be verified on the certification body’s register and, in most cases, on the IAF CertSearch database.

Why it matters commercially, not just ethically. An unaccredited certificate fails at exactly the moment you need it — during a buyer’s vendor audit, at tender scrutiny, or when an overseas customer runs a verification. At that point you have not saved money; you have lost the contract, and often the relationship, and you still have to start the real process from scratch.

Vakilkaro’s position on this is straightforward. We are consultants, not a certification body, and we will tell you exactly which accredited body is issuing your certificate and what its accreditation is. If a quote you have received seems remarkably cheap and fast, that is the reason.

Types

Types of ISO Certification in India

ISO 9001 — Quality Management System

The most widely adopted ISO standard globally. It sets out requirements for a quality management system built on customer focus, leadership commitment, a process approach, risk-based thinking and continual improvement. It is sector-agnostic and is where most organisations begin.

  • Who needs it: manufacturers, service businesses, IT firms, educational and healthcare organisations — essentially any business that wants to demonstrate systematic quality management.

ISO 14001 — Environmental Management System

Helps organisations manage and reduce their environmental impact, meet compliance obligations and achieve environmental objectives.

  • Who needs it: manufacturing plants, chemical and process industries, construction, mining, and any business with a significant environmental footprint or ESG reporting obligation.

ISO 27001 — Information Security Management System

The international standard for managing information security risk systematically, covering people, processes and technology.

  • Who needs it: IT and software companies, BPO and KPO firms, banks and NBFCs, healthcare organisations, e-commerce platforms, and any business handling sensitive customer or financial data.

ISO 45001 — Occupational Health and Safety Management System

A framework for improving worker safety, reducing workplace risk and creating safer conditions. It replaced the earlier OHSAS 18001, which has been withdrawn.

  • Who needs it: construction, manufacturing, chemicals, mining, oil and gas, and any operation with meaningful worker safety risk.

ISO 22000 — Food Safety Management System

Sets out what an organisation must do to demonstrate control of food safety hazards throughout the supply chain.

  • Who needs it: food manufacturers and processors, large restaurant and catering chains, distributors, packaging companies and agricultural producers.

ISO 50001 — Energy Management System. For energy-intensive industries seeking to systematise energy performance improvement.

ISO 13485 — Quality Management for Medical Devices. A distinct standard from ISO 9001, mandatory in practice for medical device manufacturers and often a regulatory requirement in export markets.

ISO 20000-1 — IT Service Management. For IT service providers, frequently required alongside ISO 27001 in enterprise contracts.

ISO 37001 — Anti-Bribery Management System. Increasingly asked for by multinational customers and in public procurement.

ISO 21001 — Educational Organisations Management System. For schools, colleges and training providers.

Standard Versions and Transition Deadlines

Every ISO standard carries a revision year, and it matters — a certificate against a superseded version is not accepted.

The ISO 27001 transition is the live issue. ISO 27001 was revised in 2022, with a substantially restructured set of controls in Annex A. Organisations holding certification against the earlier 2013 version were required to transition within the prescribed period, and certificates against the superseded version cease to be valid at the end of that transition. Any organisation still working to the 2013 control set should confirm its position with its certification body immediately.

Two further points. First, ISO standards are reviewed periodically and ISO 9001 has been under revision, so a new edition may be published with its own transition window — worth confirming before you begin a certification project. Second, OHSAS 18001 no longer exists; it was replaced by ISO 45001 and any certificate referring to it is obsolete.

Which ISO Standards Are Not Certifiable?

This trips up a great many buyers, and some vendors exploit it.

Not every ISO document is a certifiable standard. Some are guidance standards — they contain recommendations rather than auditable requirements, and no accredited body can certify against them. The most commonly misused are:

ISO 26000 — guidance on social responsibility. Not certifiable.

ISO 31000 — guidance on risk management. Not certifiable.

ISO 10002 and related guidance documents on complaints handling — guidance, not requirements.

If someone offers you “ISO 26000 certification” or “ISO 31000 certification”, they are offering something that does not exist in any accredited form. Certifiable standards are those written as requirements — you can recognise them because the standard says “shall”, and because accredited certification bodies list them in their published scopes.

Summary of Major ISO Certifications

Benefits

Benefits of ISO Certification in India

For small and medium enterprises, the benefits are proportionally larger, because certification is one of the few ways a smaller supplier can present the same assurance as a large one:

Customer trust demonstrated without a large marketing budget

Access to government tenders that require certification as a qualification

Process efficiency and reduced operational cost through eliminating rework and waste

Export opportunity, where certification is often a precondition of supplier qualification

Stronger supplier and partner relationships

Improved employee performance through clear processes and defined responsibility

Fewer customer complaints through systematic quality control

Financial benefit over time from reduced waste and rework

A realistic note. The operational benefits are real but they are not automatic. An organisation that treats certification as a documentation exercise — writing procedures nobody follows in order to pass an audit — gets the certificate and none of the benefit, and finds the surveillance audits increasingly uncomfortable. The organisations that gain most are those that use the implementation to actually examine how they work.

Who Should Apply for ISO Certification?

Manufacturing companies producing for domestic and export markets

Service businesses — IT, consulting, financial services

Healthcare organisations — hospitals, clinics, pharmaceutical companies

Educational institutions

Food processing and distribution companies

Construction companies

Government and public sector organisations

Non-profit organisations seeking donor and institutional credibility

Startups establishing quality credentials early

Exporters requiring international certification for market access

Eligibility

Eligibility Criteria

There is no eligibility threshold based on turnover, headcount or age. Any legally registered entity can be certified. What is required is:

A legally registered business entity in India

A defined scope of operations that can be assessed against the chosen standard

Willingness to implement and maintain the management system, not merely document it

Evidence that the system has been operating, including at least one complete cycle of internal audit and management review before the certification audit

Commitment to annual surveillance audits

Adequate documented information and records as the standard requires

On the “minimum operating period”. There is no fixed statutory period. What the certification body actually needs to see is that the system has been implemented and has generated records — internal audit results, management review minutes, corrective actions, performance data. In practice that means around three months of genuine operation for a simple organisation, and longer for a complex one. A business that documents a system on Monday and seeks an audit on Friday will not pass Stage 1.

Bureau of Indian Standards (BIS) — India’s national standards body and India’s member body in the International Organization for Standardization. BIS develops Indian Standards and represents India in international standardisation. It is not the body that issues ISO management system certificates to businesses.

Quality Council of India (QCI) — the apex accreditation body, under which NABCB operates.

National Accreditation Board for Certification Bodies (NABCB) — accredits the certification bodies that issue ISO management system certificates in India, against ISO/IEC 17021-1.

International Accreditation Forum (IAF) — the global body whose Multilateral Recognition Arrangement gives an NABCB-accredited certificate recognition in other member economies.

The practical takeaway. ISO certification is not a government licence and no Indian statute makes it compulsory in general terms. It derives its authority entirely from the credibility of the accreditation chain — which is precisely why an unaccredited certificate has no authority at all.

Documents

Documents Required

Additional documentation

Organisation chart showing structure and reporting lines

List of products or services within scope

Quality manual or management system documentation, where already prepared

Process flow charts and standard operating procedures

Records of internal audit and management review

Previous audit reports, where applicable

List of key personnel with qualifications and competence records

Site plan or layout of the premises

Applicable statutory licences relevant to the scope — for example FSSAI for a food business, or pollution control consents for a manufacturing unit

A note on statutory compliance. Auditors do check whether the organisation holds the legal permissions its operations require. A food business without a valid FSSAI licence, or a factory operating without pollution control consent, will attract a non-conformity in an environmental or food safety audit — the management system standards expressly require compliance obligations to be identified and met.

Defining Your Scope Statement

The scope statement printed on your certificate is what a customer or tender authority actually reads, and it is the most commonly mishandled element of the whole exercise.

The scope defines what activities, products, services and sites are covered by the certification. A certificate whose scope says “manufacture of industrial fasteners at Unit I, Jaipur” does not cover your second plant, your trading division or your service arm — however genuine the certificate is.

What goes wrong in practice:

The scope is drawn too narrowly, and does not cover the product line the tender is for

The scope omits a site, so the customer’s audit finds uncertified operations

The scope is drawn too broadly, covering activities the organisation cannot actually evidence, which produces non-conformities at audit

The wording does not match the language the customer or tender document uses, so the certificate is rejected as not on point

  • The right approach is to work backwards: identify what the certificate needs to say for the customer, buyer or tender you are targeting, and build the scope — and the implementation — to support exactly that.

Requirements

Compliance Requirements

Documented information — the policies, procedures and records the standard requires, maintained and current

Internal audits at planned intervals, conducted by competent people independent of the activity audited

Management review at planned intervals, covering the prescribed inputs and producing decisions and actions

Corrective action addressing the root cause of non-conformities, not merely the symptom

Continual improvement, evidenced rather than asserted

Training and competence records for everyone with a role in the system

Monitoring of customer feedback and systematic handling of complaints

Compliance obligations identified, evaluated and met

Surveillance audits attended annually

Step-by-step Process

How to Apply for ISO Certification — Step by Step?

  • Step 1: Identify the relevant standard. IT and data-handling businesses to ISO 27001; manufacturers to ISO 9001; food businesses to ISO 22000; construction to ISO 45001. Often more than one applies.
  • Step 2: Gap analysis. A structured comparison of current practice against the standard’s requirements, producing a list of what exists, what needs improvement and what must be created. This is what makes the rest of the project predictable.
  • Step 3: Implement the management system. Documentation, processes, procedures and controls — designed around how the organisation actually works rather than copied from a template.
  • Step 4: Train employees. Everyone with a role in the system needs to understand the requirements and their part in them. Auditors interview staff, and staff who do not know the policy exists are a finding.
  • Step 5: Operate the system. Let it run and generate records. This is the step organisations most want to skip, and the one that determines whether the audit is comfortable.
  • Step 6: Internal audit. A complete internal audit covering all clauses and all areas, with findings recorded and corrective actions taken.
  • Step 7: Management review. A formal review meeting evaluating audit results, performance data, customer feedback and improvement opportunities, with documented decisions.
  • Step 8: Select an accredited certification body. Verify the accreditation, confirm the standard is within its accredited scope, and check the man-days quoted.
  • Step 9: Submit the application with the scope, headcount, site details and supporting documents.
  • Step 10: Stage 1 audit — documentation and readiness review. The auditor reviews the documented system, evaluates site-specific conditions, and confirms readiness for Stage 2. Stage 1 findings are opportunities to correct before the decisive audit.
  • Step 11: Stage 2 audit — on-site assessment. The auditor evaluates whether the system is actually implemented and effective, through records, observation and interviews across the organisation.
  • Step 12: Address non-conformities. Root cause analysis, correction, corrective action and evidence, submitted within the period the certification body allows.
  • Step 13: Certification decision and certificate issue. The decision is taken by someone independent of the audit team. The certificate is valid for three years subject to surveillance.

Audit Man-Days and Why They Matter

This is a technical point with a very practical use: it is the single most reliable way to tell whether a certification quote is genuine.

Under IAF mandatory documents, the duration of a certification audit is not discretionary. It is determined by a published table based principally on the number of effective personnel in scope, adjusted for the complexity and risk of the activity, the number of sites, and other defined factors. A certification body accredited by NABCB or any other IAF signatory must conduct at least the prescribed number of audit days.

Why this is useful to you:

Audit days are the certification body’s main cost. A quote materially below what the mandatory duration implies means the audit days are not being performed — which means the body is either unaccredited or non-compliant, and the certificate is at risk.

It allows you to compare quotes on a like-for-like basis rather than on headline price

  • It tells you what to expect: for a small organisation the initial certification audit is typically a small number of days across Stage 1 and Stage 2; for a larger multi-site organisation it is considerably more

Surveillance audits are conducted at roughly a third of the initial audit duration, and recertification at around two-thirds

When we help a client select a certification body, comparing the man-days each has quoted against the applicable table is one of the first checks we run.

How to Choose an ISO Certification Body?

What to check

Accreditation status. Accredited by NABCB or another IAF MLA signatory — and verify it on the accreditation body’s own register rather than taking the certification body’s word.

Accredited scope. Accreditation is granted for specific standards and specific industry sectors. A body accredited for ISO 9001 in engineering may not be accredited for ISO 22000 in food. Check that your standard and your sector are within its accredited scope.

Man-days quoted, against the applicable IAF duration table.

Auditor competence in your industry — a food safety audit conducted by an auditor with no food sector experience helps nobody.

Geographic coverage for all your sites.

International recognition in your target markets.

Fee transparency, including surveillance and recertification costs across the three-year cycle, not just the initial audit.

An impartiality rule worth knowing. Under ISO/IEC 17021-1, a certification body cannot provide management system consultancy to an organisation it certifies, and must observe a cooling-off period before certifying an organisation it previously consulted for. A single firm offering to both build your system and certify it is either not accredited or is breaching its accreditation conditions.

This is why Vakilkaro is a consultant and not a certification body. We prepare you, and an independent accredited body audits you. That separation is what makes the certificate credible — and any provider offering you both should be asked how they reconcile that with the standard.

Certification bodies operating in India with NABCB accreditation include Bureau Veritas Certification, TÜV entities, DNV Business Assurance, BSI Group India, SGS India and a number of others. Accredited scopes differ between them and change over time, so the right body depends on your standard, your sector and your locations — which is part of what we assess.

Integrated Management System — Certifying Multiple Standards Together

Most modern management system standards share a common high-level structure — the same clause numbering, the same core requirements on context, leadership, planning, support, operation, evaluation and improvement. This is deliberate, and it has a practical consequence.

An organisation seeking, say, ISO 9001, ISO 14001 and ISO 45001 can implement them as a single Integrated Management System rather than three parallel systems. The benefits are substantial:

One set of documentation rather than three overlapping sets

One internal audit programme and one management review

A combined certification audit with a reduced total man-day count compared with three separate audits

Lower surveillance cost across the cycle

A system your people can actually operate, rather than three competing bureaucracies

For any organisation that will hold more than one certification, integrating from the start is materially cheaper and easier than integrating three established systems later.

Timeline

Timeline for ISO Certification

Small organisations with simple operations typically certify in two to three months. Larger organisations with multiple sites and complex processes may take six to twelve.

The phase most often compressed, and least compressible, is phase 4. The system must actually run and produce records before it can be audited. Attempting to shortcut it produces a Stage 1 finding and a delayed Stage 2.

Common Challenges

Cost

ISO Certification Cost in India

Two points on cost that matter.

First, budget for the cycle, not the certificate. The initial audit is roughly half of what you will spend over three years once surveillance and recertification are included. A quote that covers only the initial audit is not a complete picture.

Second, an unusually low certification body fee is a warning, not a bargain. The body’s cost floor is set by the mandatory audit duration. Below that floor, something is not being done.

Contact Vakilkaro for a personalised estimate based on your standard, size, sector and number of sites.

Validity, Surveillance and Renewal

An ISO certificate is valid for three years, subject to successful annual surveillance.

The three-year cycle

Year 0 — initial certification audit, Stage 1 and Stage 2, certificate issued

Year 1 — first surveillance audit. Under IAF requirements this must be conducted within twelve months of the certification decision date — not twelve months from the certificate’s printed date, which is sometimes later

Year 2 — second surveillance audit

Year 3 — recertification audit, to be completed before the certificate expires

Renewal process

Begin the recertification process well before expiry — six months is a sensible lead

Conduct a full internal audit covering all clauses and all areas

Hold a management review evaluating the three-year performance of the system

Close all outstanding non-conformities with evidence

Apply to the certification body for recertification

Undergo the recertification audit, which considers the performance of the system over the whole cycle

Receive the renewed certificate for the next three-year cycle

If the certificate expires. Under the applicable IAF rules, where recertification activities are not completed before expiry, the certification body may restore certification within a limited period after expiry provided the outstanding activities are completed — beyond that, a full initial certification, including Stage 2, is required. In the meantime the organisation is not certified, and cannot represent itself as such.

Consequences of losing certification

Removal from the certification body’s register and the IAF database

No further right to use the certification mark in marketing or on documents

Disqualification from tenders and contracts requiring certification

Loss of customer confidence, particularly where the customer’s own certification depends on supplier assurance

Disruption to export activity where certification is a market access condition

Certificate Suspension and Withdrawal

Between audits, a certificate is not unconditional. A certification body may suspend certification where:

A surveillance audit is not permitted or not conducted within the required interval

Major non-conformities are not closed within the time allowed

Fees remain unpaid

The certification mark is misused

The organisation fails to inform the body of significant changes — a change of ownership, site, scope, key personnel or a serious incident

Suspension is typically for a limited period, during which the organisation must not claim to be certified. If the cause is not resolved, certification is withdrawn, and restoration requires a fresh application.

The obligation to notify changes is the one organisations most often overlook. A new site, a new product line, a change of management representative or a significant incident should be reported to your certification body rather than discovered by it at the next surveillance audit.

How to Verify an ISO Certificate?

Take the certificate number and the issuing body’s name from the certificate

Check the accreditation mark — NABCB or another accreditation body

Confirm that accreditation body is an IAF MLA signatory

Visit the certification body’s own website and use its certificate verification facility

Confirm the scope, sites and validity dates shown match the certificate presented

Confirm status is currently valid — not suspended, withdrawn or expired

Cross-check on the IAF CertSearch global database and on the NABCB register

This process takes a few minutes and should be run on every supplier who presents a certificate to you — just as your customers will run it on yours.

Common Mistakes to Avoid

Buying an unaccredited certificate because it is cheap and quick. It fails at the moment you need it.

Not checking the certification body’s accredited scope for your standard and your sector.

Ignoring the man-day count and choosing on headline price.

Getting the scope statement wrong — too narrow for the tender, or covering sites and activities you cannot evidence.

Certifying against a superseded version of the standard, or missing a transition deadline.

Believing ISO 26000 or ISO 31000 can be certified. They cannot.

Using a template management system that describes processes you do not have.

Skipping the operating period and seeking an audit before the system has generated records.

Not conducting a genuine internal audit and management review before Stage 1.

Missing the first surveillance audit window, which is measured from the certification decision date.

Not notifying the certification body of changes in sites, scope, ownership or key personnel.

Budgeting only for the initial audit and being surprised by surveillance and recertification costs.

Letting the certificate lapse, after which a full initial certification may be required.

Engaging a single provider to both consult and certify, which no accredited body may do.

Why Choose Vakilkaro?

Why Choose Vakilkaro for ISO Certification?

Experienced ISO consultants across ISO 9001, 14001, 27001, 45001, 22000, 50001, 13485, 20000-1 and 37001

We are consultants, not a certification body — which is what the impartiality rules require, and what makes your certificate credible

Accredited body selection — we verify accreditation, accredited scope for your standard and sector, and man-days quoted, so you are not sold a worthless certificate

Complete gap analysis producing a clear, costed roadmap before you commit

Documentation built around your processes, not a template — because auditors identify templates immediately

Employee training so your people can answer an auditor’s questions

Internal audit and management review conducted properly before Stage 1, which is what maximises first-time pass rates

Scope drafting aligned to the tenders, buyers and markets you are actually targeting

Integrated Management System design where you need more than one standard, reducing cost across the cycle

Audit coordination and non-conformity closure with the certification body

Surveillance and recertification support, with dates diarised so certification is never lost by oversight

Transparent pricing across the full three-year cycle, with no hidden charges

Pan-India service across all states

Contact Vakilkaro today and begin your ISO certification properly — because a certificate is only worth what the accreditation behind it is worth.

Questions, answered

Frequently asked questions

Formal recognition by an independent accredited certification body that your management system meets a specific ISO standard. ISO itself does not certify anyone — it publishes the standards. In India, credible certification bodies are accredited by NABCB or another IAF MLA signatory.

National Accreditation Board for Certification Bodies (NABCB), which works under the umbrella of Quality Council of India, provides accreditation to the certification bodies according to ISO/IEC 17021-1. NABCB is signatory to International Accreditation Forum (IAF) Mutual Recognition Arrangement (MLA). It is because of that, an NABCB accredited certificate carries international recognition.

Check for an accreditation mark from NABCB or another IAF signatory; verify the accreditation body on the IAF signatory list; verify the certificate on the certification body’s register and on IAF CertSearch; and ask whether a real audit took place. No accreditation mark, no audit, implausible speed or implausible price all point the same way.

ISO 9001 (quality), ISO 14001 (environment), ISO 27001 (information security), ISO 45001 (health and safety) and ISO 22000 (food safety). ISO 9001 is by far the most widely held.

Not generally. It is voluntary as a matter of law, but becomes effectively mandatory in practice where a government tender, an export buyer, a corporate customer or a sector regulation requires it.

No cut-off for turnover, number of employees or age. Any legal entity may obtain certification, so long as it uses the process, allows time to develop data and agrees to annual surveillance.

Typically three to six months for most organisations; two to three months for a small, simple operation; six to twelve months for large or multi-site organisations. The system must actually operate before it can be audited.

Consultation and gap analysis, documentation, training, and cost for the audit conducted by the certification body – with surveillance audits during years two and three and recertification during year three. Plan the budget for three years, not just the first one.

As such, since audit duration is determined using IAF-mandated tables depending on staff size and complexity, audit days are the main source of expenditure for the certification body. A quotation lower than that floor simply means the days are not being conducted.

Audit time as prescribed in the table, based on effective personnel, complexity, risk, and number of sites. Surveillance audit is to be carried out after one-third of the audit period, while the re-certification audit after two-thirds of the audit period.

Three years with annual surveillance audits. The first surveillance audit shall be carried out within 12 months of the date of the certification decision.

Where recertification is not completed before expiry, restoration may be possible within a limited period if outstanding activities are completed; beyond that, a full initial certification including Stage 2 is required. In the meantime you are not certified.

Yes — for a missed surveillance audit, unclosed major non-conformities, unpaid fees, misuse of the certification mark, or failure to notify significant changes. During suspension the organisation must not claim to be certified.

Stage 1 reviews the documented system and site-specific conditions and confirms readiness. Stage 2 is the on-site assessment of whether the system is actually implemented and effective. Stage 1 findings are an opportunity to correct before the decisive audit.

Annual audit to confirm continuing compliance (less comprehensive than initial audit and often covering a selection of requirements each year) If you fail, you can be suspended.

Findings of non-compliance with requirements. Non-conformities are either major, indicating a serious breach that must be resolved prior to certification, or minor, involving an isolated breach that requires action during an agreed time frame.

The description on the certificate of what activities, products, services and sites are covered. It is what a customer or tender authority actually reads. A scope that omits your product line, your service arm or a site does not cover them, however genuine the certificate.

The current edition — ISO 9001:2015, ISO 14001:2015, ISO 45001:2018, ISO 22000:2018 and ISO 27001:2022. Certificates against superseded versions cease to be valid at the end of the transition period, and any organisation still on the older information security control set should confirm its position immediately.

No.It was replaced by ISO 45001 and has been withdrawn. A certificate referring to OHSAS 18001 is obsolete.

No. Both are guidance standards containing recommendations rather than auditable requirements, and no accredited body can certify against them. Anyone offering such certification is selling something that does not exist.

No.Under ISO/IEC 17021-1 a certification body may not provide management system consultancy to an organisation it certifies, and must observe a cooling-off period. A provider offering both is either unaccredited or in breach of its accreditation.

Yes, and it is common. Because the standards share a common high-level structure, they are best implemented as a single Integrated Management System with one documentation set, one internal audit programme and a combined audit — which is materially cheaper across the cycle than three separate systems.

Yes. There is no minimum size, turnover or headcount. The process and cost are proportionate to the organisation, and smaller businesses generally certify faster and at lower cost.

BIS is India’s national standards body and India’s member in ISO; it develops Indian Standards and administers the ISI mark for products. ISO is the international standard-setting body. BIS does not issue ISO management system certificates to businesses — accredited certification bodies do.

Accreditation is the assessment of a certification body by an accreditation body such as NABCB. Certification is what a certification body grants to your organisation. Both levels are necessary for the certificate to be credible.

A global database of certificates issued by bodies accredited by IAF MLA signatories, searchable by certificate number or organisation name. It is the most reliable way to verify a certificate internationally.

No.FSSAI registration or licence is the mandatory legal requirement for any food business in India under the Food Safety and Standards Act, 2006. ISO 22000 is a voluntary international management system standard. They are complementary — most food exporters hold both, FSSAI for legal operation and ISO 22000 for buyer requirements.

The information security management standard, increasingly required by enterprise clients in banking, financial services, government and multinational sectors. It applies to IT and software companies, BPOs, fintechs, healthcare organisations and e-commerce platforms handling sensitive data.

The occupational health and safety management standard, replacing OHSAS 18001. Particularly relevant to construction, manufacturing, chemicals, mining and any operation with significant worker safety risk, and frequently required in infrastructure tenders.

Major non-conformities must be closed with evidence within the period the certification body allows before the certificate can be issued; minor ones may allow issue subject to an agreed corrective action plan. Thorough preparation — a genuine internal audit and management review before Stage 1 — is what maximises the first-time pass rate.

Substantially. Buyers in Europe, the United States, Japan and the Gulf routinely require certification for supplier qualification — ISO 9001 generally, ISO 22000 for food, ISO 13485 for medical devices. The certificate must be accredited, current, and its scope must cover the product being supplied.

Any significant change — new or closed sites, changes to scope or activities, change of ownership or legal status, change of key personnel including the management representative, and any serious incident, accident or regulatory action. Failure to notify is a ground for suspension.

Because we start by making sure the certificate will be worth something — verifying the certification body’s accreditation and accredited scope, checking the man-days quoted, drafting a scope that matches the tenders and buyers you are targeting, building the system around your actual processes, and running a genuine internal audit before Stage 1. We are consultants, not a certification body, and we tell you exactly who is auditing you and what their accreditation is. Contact Vakilkaro today and begin your ISO certification journey — because your business deserves a certificate that holds up when someone checks it.

Ready when you are

Ready to get started with iso certification?

One free call. A real expert. A clear quote, no surprises.

₹2,999+ govt feeGet free quote