For most Australian SMEs pursuing ISO 9001, certification takes between three and six months from the start of a gap assessment to the issue of a certificate. Other standards take longer — ISO 13485 for medical devices typically takes nine to eighteen months, ISO 27001 six to twelve, and an Integrated Management System combining ISO 9001 and ISO 14001 sits in the six to ten month range. The rest of this article explains exactly what drives those timelines, what happens at each of the six phases, and four specific things you can do to move faster without cutting corners.

The reason most certification timelines are longer than expected is almost never the standard itself. It is one of four variables that most businesses do not account for when they start planning — and which this article will help you get right from the beginning.

ISO certification timelines — quick reference

StandardFocus AreaTypical SME TimelineMain Complexity Driver
ISO 9001Quality Management3–6 monthsDocumentation volume; depth of existing process maturity
ISO 14001Environmental Management4–8 monthsEnvironmental aspects identification; baseline data collection
ISO 45001Work Health & Safety4–8 monthsHazard and risk assessment depth; WHS system integration
ISO 13485Medical Devices9–18 monthsRegulatory complexity; design control and technical file requirements
ISO 27001Information Security6–12 monthsAsset inventory; risk treatment plan; control implementation
ISO 50001Energy Management6–12 monthsEnergy baseline establishment; metering infrastructure
ISO 22000Food Safety Management6–10 monthsHACCP plan development; prerequisite programme documentation
ISO 42001AI Management Systems6–12 monthsAI system inventory; impact assessment methodology
IMS (9001+14001)Integrated Management System6–10 monthsIntegration planning; shared documentation; combined audit preparation

All timelines assume a dedicated internal lead, active engagement with an experienced consultant, and a certifying body booking made at the start of the implementation process. Organisations starting from scratch with no management system documentation should add four to eight weeks to the documentation phase. Organisations with a mature existing QMS may move faster.

What actually determines your timeline — the four key variables

The 6-phase certification journey

Weeks 1–4

Phase 1 — Gap Assessment

The gap assessment is the foundation of the entire certification program — and the phase that most businesses either skip, rush, or underinvest in. It is a structured review of your current state against the requirements of the target standard, clause by clause, producing two outputs: a gap report that tells you what is missing, and an implementation roadmap that tells you what to do about it, in what order, and how long it will take.

In practice, a gap assessment involves reviewing your existing documentation, interviewing the people who run your key processes, and mapping the current state against each clause of the standard. For ISO 9001, the assessment typically takes two to three days of structured work and produces a report within one to two weeks. For more complex standards like ISO 27001 or ISO 13485, the assessment itself may take three to four weeks.

Weeks 3–12

Phase 2 — Documentation Development

Phase 2 is typically the most time-consuming phase for businesses starting from scratch. The standard requires a documented management system — policies, procedures, SOPs, record templates, and a set of supporting documentation that demonstrates how the requirements are addressed.

For a business with some existing documentation, Phase 2 typically takes four to six weeks. For a business starting from scratch, six to ten weeks is a more realistic planning assumption. Note that Phase 2 and Phase 3 overlap deliberately — documentation does not need to be fully complete before implementation begins.

Weeks 6–20

Phase 3 — Implementation

Phase 3 is where certification programs most commonly stall — and where the gap between a paper system and a functioning one is exposed. Implementation means embedding the documented management system into actual daily operations: training staff, collecting evidence, and running the documented processes consistently enough to generate a meaningful evidence trail.

Most certifying bodies require a minimum of three months of implementation evidence before conducting a Stage 2 audit. This reflects the reality that a system running for six weeks has not been tested against the full range of operational conditions the business faces.

Weeks 14–22

Phase 4 — Internal Audit

An internal audit is a structured self-assessment of your management system against the standard’s requirements — conducted before the certifying body arrives. It is, in effect, a rehearsal for the Stage 2 audit, conducted by people inside the organisation who have been trained to audit against the standard.

A well-run internal audit typically takes two to three weeks including corrective action closure. The internal audit must be conducted by people who did not write the documents they are auditing — an explicit requirement of most ISO standards.

Weeks 18–26

Phase 5 — Certification Audit (Stage 1 & Stage 2)

The certification audit is conducted in two stages. Stage 1 is a document review, typically conducted remotely over one to two days. Stage 2 is the on-site audit — the auditor spends one to three days reviewing implementation evidence, interviewing staff, observing processes, and checking records. This audit determines certification.

The single most important timeline decision in the entire process: book the certifying body’s Stage 2 slot at the end of Phase 1, not at the end of Phase 4.

Ongoing

Phase 6 — Surveillance & Renewal

ISO certification is not a one-time achievement. It is maintained through a three-year cycle: annual surveillance audits in Years 1 and 2, followed by a full recertification audit in Year 3. Surveillance audits are shorter — typically one to two days — and focus on confirming the management system continues to be actively maintained and improved.

The gap assessment is not overhead — it is the plan. A business that skips it saves two weeks and loses two months. Every hour invested in Phase 1 returns multiples downstream.

Over-documenting is a more common delay than under-documenting. Write processes to the depth the standard requires — not to the depth that feels thorough. The auditor needs evidence, not encyclopaedias.

A management system that exists on paper and is not embedded in practice will fail a Stage 2 audit. Three months of implementation evidence is not a hurdle — it is a minimum meaningful test of whether the system actually works.

Finding a non-conformance in your internal audit is good news — it means you found it before the certifying body did. Treat the internal audit as the most valuable investment of the certification process.

Stage 2 audit availability is the most commonly overlooked bottleneck in certification timelines. Book your certifying body the week your gap assessment is complete — not the week before you want to certify.

Certification is the start of the management system’s working life, not the finish line. The surveillance audit in Year 1 will reveal whether the system was built to operate or built to impress.

This is where the connection to a functioning CI program becomes practical rather than aspirational. ISO 9001 clause 10 explicitly requires continual improvement of the management system — not as a nice-to-have, but as a standard requirement. A business with a working CI rhythm satisfies this requirement as a natural output of its normal operations.

How to move faster without cutting corners

These four tactics consistently shorten certification timelines for Australian SMEs — without compromising the quality of the management system or the integrity of the audit.

What about the cost — a realistic range

The question most businesses ask alongside “how long” is “how much.” The ranges below are indicative and will vary based on your organisation’s size, the standard you are pursuing, and the consultancy partner you engage. Innovengg provides fixed-fee proposals after completing a gap assessment — so the investment is confirmed before any work begins.

Cost ElementIndicative RangeNotes
Certifying body fees (Stage 1 + Stage 2)$3,000–$8,000Varies by certification body and organisation size
Annual surveillance audit (Years 1 & 2)$1,500–$4,000Per year; required to maintain certification
Recertification audit (Year 3)$2,500–$6,000Full audit cycle repeated every 3 years
Consultant fees (if used)$8,000–$30,000Depends on scope, starting point, and number of standards
Internal time cost$5,000–$20,000Depends on FTE allocation and organisation complexity

For ISO 9001 in a small to medium engineering or manufacturing business, a realistic all-in investment — certifying body fees plus consultant support plus internal time — typically falls in the $20,000 to $45,000 range. This figure is almost always recovered within the first twelve months through process efficiency gains and the new commercial opportunities that ISO-certified status makes accessible.

A realistic start is better than a perfect plan.

The most common reason ISO certification takes longer than it should is starting later than planned. A free gap assessment with Innovengg will tell you exactly where you stand today, how long your specific certification journey will take, and what it will cost — before you commit to anything. No jargon, no sales pressure, just a clear answer.

Book Your Free Gap Assessment →

Fahmy Hanin

CEO & Founder, Innovengg

Fahmy founded Innovengg on the belief that engineering excellence, delivered with integrity and purpose, creates lasting value for clients and communities across Australia and APAC.

Related Articles & Resources