The short answer
Four to twelve months. A small, well-organised company with procedures already written down can get to three. A company starting from nothing, with no records and nobody free to own it, should plan for a year.
The constraint nobody can sell you around
You can buy documents in a week. You cannot buy the thing an auditor is actually looking for, which is evidence that your quality system has run.
Before the certification audit you need to have completed an internal audit of your own system and held a management review, and both need to have produced something — findings, decisions, actions with names against them. A system switched on last Tuesday has no history, and history is the point. That is the floor under every timeline on this page, and it is why “certified in 30 days” offers are worth reading carefully.
01Find out where you stand
1–4 weeksA gap analysis against all of the requirements. Most companies discover they already satisfy more than they expected and are missing a few things badly — usually the written-down parts rather than the doing parts.
02Build what is missing
2–5 monthsWriting procedures, setting up the registers, getting calibration and supplier records into order. The single biggest variable, and the part a consultant is usually hired for.
03Run it, and let it leave a trail
1–3 monthsThe part that cannot be rushed. You need records showing the system has operated — at minimum a full internal audit and a management review, with evidence they led somewhere.
04Stage 1 audit
1 day, then 2–8 weeksThe body checks you are ready, largely on documentation. Findings here are normal. The gap before Stage 2 exists so you can close them, and should not exceed six months.
05Stage 2 audit
1–3 daysThe real one, on site, looking for evidence the system is used rather than owned. Any nonconformities need a corrective action plan before the certificate issues.
06Certificate issued
2–6 weeks afterAfter the body's own review. Then surveillance annually, and a full recertification every three years.
What makes it slower
Almost always the same thing: nobody owns it. The work lands on someone already running production, gets done in the gaps, and stalls the first busy month. Companies that finish in six months have usually given one person explicit time for it, not explicit responsibility for it.
After that: waiting for a certification body’s calendar, which can add weeks at both stages; scope creep, where a second site or a design function turns out to be in; and records that exist but cannot be found, which is slower than records that never existed.
What makes it faster
Already doing the work. Most of ISO 9001 describes what a well-managed shop does anyway — checking incoming material, keeping gauges calibrated, dealing with complaints, deciding things in meetings. If that is happening and simply isn’t written down, you are closer to the middle of this timeline than the start.
Booking the certification body early also helps more than people expect. Their availability, not your readiness, is often what sets the date.
If someone has given you a deadline
This is the common case, and it is uncomfortable: the requirement usually arrives from a customer with a date attached, and the date is rarely twelve months out.
Two things worth knowing. Certification bodies book up, so that call comes first, not last. And a customer told honestly that you are certified in progress, with a booked Stage 2 date, is generally in a better position than one told nothing — plenty of supplier conditions accept a credible plan where they would not accept silence.
If you have not been asked yet but want to know whether you will be, we keep a live list of public contracts currently requiring it.
Where these numbers come from
Published guidance from certification bodies and consultancies, gathered in August 2026, cross-checked for agreement rather than taken from any single source. Worth saying plainly: nearly everyone publishing a timeline is also selling help against it, so the ranges below the four-month mark deserve more scepticism than the ones above it. The structural constraint — that your system has to have visibly run before it can be audited — is the part that does not vary by who is telling you.