What does ISO 9001 certification require?
ISO 9001:2015 requires a documented Quality Management System (QMS) that meets the standard’s clauses 4 to 10: understand your context and interested parties, show leadership with a quality policy, plan around risks and quality objectives, provide resources and competence, control your operations, evaluate performance through internal audits and management review, and drive continual improvement. An accredited certification body then audits it in two stages.
The QMS clauses (4 to 10)
ISO 9001:2015 is organized into requirement clauses 4 through 10: context of the organization (4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9), and improvement (10). You document a QMS that addresses each, scoped to your organization. Clauses 1 to 3 cover scope, references, and terms.
Built on risk-based thinking and continual improvement
The standard is founded on the seven quality management principles (customer focus, leadership, engagement of people, the process approach, improvement, evidence-based decision making, and relationship management) and on risk-based thinking and the plan-do-check-act cycle, rather than a fixed checklist of controls.
Certification is a three-year cycle
An accredited certification body assesses your QMS in a Stage 1 (documentation and readiness) and Stage 2 (implementation and effectiveness) audit, issues a certificate valid for three years, conducts annual surveillance audits, and recertifies at year three.
Where Keel fits
Keel Quality runs the product-quality half of ISO 9001, nonconforming outputs, supplier quality, complaints, and change control, on the same graph as your ISMS, and shares the management-system clauses (internal audit, management review, corrective action) that ISO 9001 and ISO 27001 hold in common, so running both is one program.
FAQ
Is ISO 9001 a security standard?
No. ISO 9001 is about quality management, not information security. It does, however, share management-system machinery with ISO 27001 (internal audits, management review, corrective action), so the two overlap in how you run them.
How long is an ISO 9001 certificate valid?
Three years, subject to annual surveillance audits, after which you go through recertification.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free