Answers to Common ISO Certification Questions
Browse general questions about ISO certification, or jump to a specific standard for more detail.
General Questions
What is ISO certification?
ISO certification confirms that an organization's management system meets the requirements of a specific ISO standard, verified through assessment by a certification body.
Which ISO certification is right for my business?
The right standard depends on factors such as your industry, business activities, customer or tender requirements and compliance goals. Our experts can help you identify a suitable standard.
What are the most commonly requested ISO standards in India?
Commonly requested standards include ISO 9001 (Quality), ISO 14001 (Environment), ISO 45001 (Occupational Health & Safety), ISO 27001 (Information Security) and ISO 22000 (Food Safety).
How long does the ISO certification process take?
Timelines vary depending on business size, industry, existing processes and the specific standard involved. We can share a realistic estimate after understanding your requirements.
What documents are generally required for ISO certification?
Requirements vary by standard, but commonly include process documentation, policies, records and evidence of implementation relevant to the chosen ISO standard.
Can small businesses and startups obtain ISO certification?
Yes. ISO certification is not limited to large organizations — small businesses and startups can pursue certification with guidance suited to their scale.
Do you provide ISO certification support across India?
Yes, we support businesses across India throughout the certification journey, from initial guidance to certification coordination.
What is the difference between ISO consultancy and certification?
ISO consultancy involves guidance, documentation and implementation support. Certification itself is granted by an independent, accredited certification body after assessment.
ISO 9001 — Quality Management System
What is ISO 9001 certification?
ISO 9001 certification confirms that an organization's Quality Management System meets the requirements of the ISO 9001 standard, verified through assessment by an accredited certification body.
Is ISO 9001 certification mandatory?
No. ISO 9001 certification is voluntary, though it is often requested by customers, tenders or specific business contexts.
How long does ISO 9001 certification take?
Timelines vary based on organization size, existing processes and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 9001 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Can small businesses and startups get ISO 9001 certified?
Yes. ISO 9001 is scalable and applicable to organizations of any size, including small businesses and startups.
What is the difference between ISO 9001 consultancy and certification?
Consultancy involves guidance, documentation and implementation support. Certification itself is granted by an independent, accredited certification body after audit.
Does business size or setup affect ISO 9001 requirements?
Yes, requirements can depend on the nature and scale of your business activities. Our team can guide you on what applies to your specific situation.
Does ISO Certification Hub issue the ISO 9001 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 14001 — Environmental Management System
What is ISO 14001 certification?
ISO 14001 certification confirms that an organization's Environmental Management System meets the requirements of the ISO 14001 standard, verified through assessment by an accredited certification body.
Is ISO 14001 certification mandatory?
No. ISO 14001 certification is voluntary, though it is increasingly requested by customers, tenders or business contexts focused on environmental responsibility.
What are environmental aspects and impacts?
Environmental aspects are the ways your activities, products or services interact with the environment, such as emissions, waste or resource use. Impacts are the resulting effects on the environment.
How long does ISO 14001 certification take?
Timelines vary based on organization size, existing processes and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 14001 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Can small businesses get ISO 14001 certified?
Yes. ISO 14001 is scalable and applicable to organizations of any size, including small businesses.
What is the difference between ISO 14001 consultancy and certification?
Consultancy involves guidance, documentation and implementation support. Certification itself is granted by an independent, accredited certification body after audit.
Does ISO Certification Hub issue the ISO 14001 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 45001 — Occupational Health & Safety Management System
What is ISO 45001 certification?
ISO 45001 certification confirms that an organization's Occupational Health & Safety Management System meets the requirements of the ISO 45001 standard, verified through assessment by an accredited certification body.
Is ISO 45001 certification mandatory?
No. ISO 45001 certification is voluntary, though it is increasingly requested by customers, tenders or business contexts focused on worker safety.
What is a hazard versus a risk in ISO 45001?
A hazard is a source with the potential to cause harm (e.g. moving machinery). Risk is the combination of the likelihood and severity of harm that could result from that hazard.
How long does ISO 45001 certification take?
Timelines vary based on organization size, existing practices and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 45001 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Does ISO 45001 apply to small businesses?
Yes. ISO 45001 is scalable and applicable to organizations of any size, including small businesses.
What is the difference between ISO 45001 consultancy and certification?
Consultancy involves guidance, documentation and implementation support. Certification itself is granted by an independent, accredited certification body after audit.
Does ISO Certification Hub issue the ISO 45001 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO/IEC 27001 — Information Security Management System
What is ISO 27001 certification?
ISO 27001 certification confirms that an organization's Information Security Management System meets the requirements of the ISO/IEC 27001 standard, verified through assessment by an accredited certification body.
Is ISO 27001 certification mandatory?
No. ISO 27001 certification is voluntary, though it is increasingly requested by clients, tenders or vendor security assessments.
What is the CIA triad in ISO 27001?
The CIA triad refers to Confidentiality, Integrity and Availability — the three core principles an Information Security Management System is designed to protect.
What is a Statement of Applicability (SoA)?
The Statement of Applicability is a required ISO 27001 document listing which Annex A controls apply to your organization, and the justification for including or excluding each one.
How long does ISO 27001 certification take?
Timelines vary based on organization size, existing practices and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 27001 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Does ISO 27001 apply to small businesses?
Yes. ISO 27001 is scalable and applicable to organizations of any size, including small businesses.
Does ISO Certification Hub issue the ISO 27001 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 22000 — Food Safety Management System
What is ISO 22000 certification?
ISO 22000 certification confirms that an organization's Food Safety Management System meets the requirements of the ISO 22000 standard, verified through assessment by an accredited certification body.
Is ISO 22000 certification mandatory?
No. ISO 22000 certification is voluntary, though it is increasingly requested by retailers, export buyers or regulatory contexts focused on food safety.
What is HACCP and how does it relate to ISO 22000?
HACCP (Hazard Analysis and Critical Control Points) is a systematic approach to identifying and controlling food safety hazards. ISO 22000 builds HACCP principles into a full management system framework.
What are Critical Control Points (CCPs)?
Critical Control Points are steps in a food process where control measures must be applied to prevent, eliminate or reduce a food safety hazard to an acceptable level.
How long does ISO 22000 certification take?
Timelines vary based on organization size, existing practices and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 22000 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Does ISO 22000 apply to small food businesses?
Yes. ISO 22000 is scalable and applicable to organizations of any size across the food chain, including small businesses.
Does ISO Certification Hub issue the ISO 22000 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 13485 — Medical Devices Quality Management System
What is ISO 13485 certification?
ISO 13485 certification confirms that an organization's Quality Management System for medical devices meets the requirements of the ISO 13485 standard, verified through assessment by an accredited certification body.
Is ISO 13485 certification mandatory?
ISO 13485 itself is voluntary, though it is often expected — and sometimes required — by regulators, distributors and OEM partners in medical device markets.
How does ISO 13485 relate to risk management?
ISO 13485 requires a risk-based approach throughout the device lifecycle, commonly implemented alongside dedicated risk management practices such as those described in ISO 14971.
What is a CAPA in ISO 13485?
CAPA stands for Corrective and Preventive Action — a structured process for investigating nonconformities, addressing root causes and preventing recurrence.
How long does ISO 13485 certification take?
Timelines vary based on organization size, device complexity and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 13485 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Does ISO 13485 apply to small medical device businesses?
Yes. ISO 13485 is scalable and applicable to organizations of any size across the medical device value chain.
Does ISO Certification Hub issue the ISO 13485 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 50001 — Energy Management System
What is ISO 50001 certification?
ISO 50001 certification confirms that an organization's Energy Management System meets the requirements of the ISO 50001 standard, verified through assessment by an accredited certification body.
Is ISO 50001 certification mandatory?
No. ISO 50001 certification is voluntary, though it is increasingly valued for cost reduction, sustainability reporting and stakeholder expectations.
What is an EnPI (Energy Performance Indicator)?
An EnPI is a measure used to track energy performance over time — for example, energy use relative to production output.
What is a Significant Energy Use (SEU)?
A Significant Energy Use is an area, equipment or process that accounts for substantial energy consumption or offers considerable potential for improvement.
How long does ISO 50001 certification take?
Timelines vary based on organization size, existing practices and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 50001 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Does ISO 50001 apply to small businesses?
Yes. ISO 50001 is scalable and applicable to organizations of any size and energy profile.
Does ISO Certification Hub issue the ISO 50001 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 22301 — Business Continuity Management System
What is ISO 22301 certification?
ISO 22301 certification confirms that an organization's Business Continuity Management System meets the requirements of the ISO 22301 standard, verified through assessment by an accredited certification body.
Is ISO 22301 certification mandatory?
No. ISO 22301 certification is voluntary, though it is increasingly requested by clients, regulators and tender processes as evidence of operational resilience.
What is a Business Impact Analysis (BIA)?
A BIA identifies an organization's critical activities, the impact of their disruption over time, and the maximum period they can be unavailable before serious harm occurs.
How is ISO 22301 different from disaster recovery planning?
Disaster recovery typically focuses on restoring IT systems. ISO 22301 covers the wider organization — people, processes, suppliers and premises — not just technology.
What are RTO and RPO?
Recovery Time Objective (RTO) is the target time to restore an activity after disruption. Recovery Point Objective (RPO) is the maximum acceptable data loss, measured in time.
How long does ISO 22301 certification take?
Timelines vary based on organization size, existing practices and readiness. We can share a realistic estimate after an initial assessment.
How long is an ISO 22301 certificate valid?
Certificates are typically valid for three years, subject to periodic surveillance audits conducted by the certification body.
Does ISO Certification Hub issue the ISO 22301 certificate?
No. We provide consulting and support services. The certificate itself is issued by an independent, accredited certification body following a successful audit.
ISO 31000 — Risk Management
What is ISO 31000?
ISO 31000 is an international standard that provides principles, a framework and a process for managing risk. It is intended to be applied by any organization, regardless of size or sector.
Is ISO 31000 certification available?
No. ISO 31000 is a guidance standard, not a management system standard — there is no accredited third-party certification scheme for it, unlike ISO 9001 or ISO 27001. Organizations implement its principles and can complete advisory or training engagements, but no accredited body issues an 'ISO 31000 certificate.'
How is ISO 31000 different from the risk clauses in ISO 9001 or ISO 27001?
ISO 9001 and ISO 27001 each require risk-based thinking within their own scope (quality or information security). ISO 31000 is a broader, standalone framework for managing risk across an entire organization, and can inform how those risk-related clauses are approached.
What is risk appetite?
Risk appetite is a statement of how much risk an organization is willing to pursue or retain in order to achieve its objectives. It guides which risks are accepted, treated or avoided.
What is a risk register?
A risk register is a structured record of identified risks, their analysis, evaluation, treatment plans and owners — a core working document in most ISO 31000-aligned frameworks.
How does ISO 31000 relate to Enterprise Risk Management (ERM)?
ISO 31000's principles and process are widely used as the foundation for ERM programs, which apply structured risk management consistently across an entire enterprise.
How long does an ISO 31000 implementation take?
Timelines vary based on organization size, existing risk practices and scope. We can share a realistic estimate after an initial risk diagnostic.
Does ISO Certification Hub issue an ISO 31000 certificate?
We can issue a certificate of completion for our advisory or training engagement. This is not an accredited ISO 31000 certification, since no such accredited scheme exists for this standard.
ISO 10002 — Customer Satisfaction & Complaints Handling
What is ISO 10002?
ISO 10002 is an international standard that provides guidelines for planning, designing, operating, maintaining and improving an effective complaints-handling process, focused on customer satisfaction.
Is ISO 10002 certification available?
No. ISO 10002 is a guidance standard, not a management system standard — there is no accredited third-party certification scheme for it, unlike ISO 9001 or ISO 27001. Organizations implement its guidelines and can complete advisory or training engagements, but no accredited body issues an 'ISO 10002 certificate.'
How is ISO 10002 different from ISO 9001's complaint-related requirements?
ISO 9001 requires organizations to monitor customer satisfaction and handle complaints as part of a broader quality management system. ISO 10002 is a dedicated, detailed set of guidelines focused specifically on how to design and run the complaints-handling process itself.
Does ISO 10002 apply to complaints received through any channel?
Yes. ISO 10002's guidelines are channel-agnostic — they apply whether a complaint arrives by phone, email, chat, social media, in person, or through a formal ticketing system.
What is a complaints register?
A complaints register is a structured record of each complaint received, its assessment, resolution and root cause — a core working document in most ISO 10002-aligned processes.
Can ISO 10002 be combined with other standards?
Yes. ISO 10002 is commonly implemented alongside ISO 9001, ISO 27001 or ISO 31000, feeding complaint and risk data into the same broader management system.
How long does an ISO 10002 implementation take?
Timelines vary based on organization size, number of channels and existing complaint-handling maturity. We can share a realistic estimate after an initial current-state review.
Does ISO Certification Hub issue an ISO 10002 certificate?
We can issue a certificate of completion for our advisory or training engagement. This is not an accredited ISO 10002 certification, since no such accredited scheme exists for this standard.
Still Have a Question?
Our team is happy to help with anything not covered here.
