Thirty questions about ISO certification in South Africa.
Standards, cost, timing, process, tenders — the questions we get asked most, answered honestly. Filter by topic or search directly.
Find what you're looking for.
01What is ISO certification and why does my business need it?+
ISO certification is formal proof issued by an independent, SANAS-accredited body that your business operates according to an internationally recognised management standard. It signals to clients, procurement officials, and supply chain partners that your processes are consistent, documented, and independently verified. For South African businesses bidding on government tenders or working with large corporates, ISO certification is increasingly a pre-qualification requirement.
02Which ISO standard is right for my business?+
It depends on your industry, clients, and tender requirements. ISO 9001 (Quality Management) suits most businesses. ISO 45001 (Health and Safety) is needed where workers face physical risk. ISO 27001 (Information Security) is essential for ICT companies and data processors. ISO 14001 suits businesses with significant environmental impact. Book a free consultation for a specific recommendation.
03Can a small business get ISO certified in South Africa?+
Yes. ISO standards have no minimum employee or turnover requirement. We have certified businesses with fewer than 10 people. Small businesses often have an advantage: simpler structures and management close to daily operations. Our approach is right-sized certification — compliant and auditable, but practical for a small team to maintain.
04What is the difference between a certification body and an ISO consultant?+
A certification body is the independent organisation that audits your business and issues your ISO certificate. A consultant helps you build the management system, prepare documentation, train your team, and get audit-ready. They play completely different roles and must remain separate — a consultant cannot certify the same client they helped implement.
05What is SANAS accreditation and why does it matter?+
SANAS is the South African National Accreditation System — the national body that accredits certification bodies in South Africa. Government departments and SOEs only accept ISO certificates from SANAS-accredited bodies. Without SANAS accreditation, your certificate may not be recognised for tender purposes or by large corporate clients.
06How do I choose the right certification body in South Africa?+
Check four things: (1) Current SANAS accreditation for your specific standard, (2) Sector experience relevant to your industry, (3) Audit fees and surveillance costs, (4) Turnaround time from application to certificate. Well-known SANAS-accredited bodies in South Africa include BSI, Bureau Veritas, SGS, TUV Rheinland, and DEKRA. Your consultant can help compare quotes.
07What is ISO 9001 and what does it cover?+
ISO 9001 is the international standard for Quality Management Systems, with over one million certified organisations in 170+ countries. It ensures your business consistently delivers products and services that meet customer requirements, and that it continually improves. It applies to every industry. A revised ISO 9001:2026 is expected to be published later in 2026.
08What is ISO 14001 and who needs it?+
ISO 14001 is the standard for Environmental Management Systems. It helps identify environmental impacts, set reduction targets, and demonstrate legal compliance. Mining, construction, manufacturing, chemical, and logistics companies are most commonly required to hold it — either by clients, tender requirements, or environmental regulations.
09What is ISO 45001 and how is it different from OHSAS 18001?+
ISO 45001 is the international standard for Occupational Health and Safety Management Systems. It replaced OHSAS 18001 in 2018 — OHSAS 18001 certificates are no longer valid. ISO 45001 requires stronger management involvement, a more proactive approach to risk, and greater worker participation in safety decisions. In South Africa, it aligns with the OHS Act and is frequently required in construction, engineering, and manufacturing.
10What is ISO 27001 and which businesses should get it?+
ISO 27001 is the standard for Information Security Management Systems. The current version is ISO 27001:2022 with 93 controls. It is essential for ICT companies, software developers, managed service providers, and any business handling sensitive data. In South Africa, it is increasingly required for SITA contracts and for companies processing personal information under POPIA.
11What is the difference between ISO 9001, ISO 14001, and ISO 45001?+
All three use the same High-Level Structure (Annex SL) but address different areas: ISO 9001 covers quality management, ISO 14001 covers environmental management, and ISO 45001 covers occupational health and safety. Many businesses pursue all three together as an Integrated Management System, which is more efficient than running separate systems.
12Can I get multiple ISO certifications at the same time?+
Yes. Pursuing multiple standards simultaneously through an Integrated Management System is often more efficient than certifying separately. Shared documentation, combined internal audits, and a single joint certification audit reduce both the implementation effort and ongoing maintenance costs. Downtown Spares, one of our clients, achieved ISO 9001, 45001, and 14001 simultaneously.
13How much does ISO certification cost in South Africa?+
ISO certification in South Africa typically costs between R15,000 and R150,000 all-in, depending on business size, the standard pursued, and your existing documentation. Most SMEs land in the R30,000 to R80,000 range. This covers consulting fees and the certification body audit fee. Annual surveillance audits (years 1 and 2) cost approximately 20 to 40 percent of the initial audit fee.
14How long does it take to get ISO certified in South Africa?+
Most businesses take 4 to 9 months from starting to receiving their certificate. A well-prepared SME with an experienced consultant typically certifies in 4 to 6 months. Larger or more complex organisations usually need 9 to 12 months. A minimum 3-month documented system operation period is required before the certification audit can take place.
15What are the ongoing costs after I receive my certificate?+
Annual surveillance audits in years 1 and 2 of your 3-year certificate cycle typically cost 20 to 40 percent of the initial audit fee. A full recertification audit is required in year 3. Internal costs include maintaining documentation, conducting annual internal audits, management reviews, and corrective actions. A well-designed system keeps these costs manageable.
16How long does a gap analysis take?+
A gap analysis typically takes 1 to 3 days on-site depending on business size and standard. The consultant reviews your processes against the ISO standard and produces a written gap report showing what is in place, what is missing, and what needs to change. This is your roadmap and cost estimate before you commit to the full certification process.
17Does it cost more to certify multiple sites?+
Yes. Each additional site increases certification body audit time and fees. However, if all sites operate under the same management system with consistent processes, you can often achieve multi-site certification on a single certificate at a lower per-site cost than certifying each independently. Correct scope structuring from the start makes a material difference to total cost.
18What factors affect the total cost of ISO certification?+
Key cost drivers include: company size, scope complexity, your current level of documentation and process maturity, the specific ISO standard (ISO 27001 is typically more technical than ISO 9001), the certification body's audit rates, and the number of sites. We are transparent about all of these in the initial consultation so there are no surprises.
19What are the steps to get ISO certified?+
The five stages are: (1) Gap Analysis to identify what needs to be built, (2) System Development to create the required policies, procedures, and records, (3) Implementation and Training where your team uses the system for at least 3 months, (4) Internal Audit to verify the system is working before external assessment, and (5) Certification Audit with a Stage 1 document review followed by a Stage 2 on-site audit.
20What is a gap analysis and why is it important?+
A gap analysis maps your current processes against ISO standard requirements and produces a written report showing what is in place, what is missing, and what needs to change. It provides a realistic cost and timeline estimate before you commit to certification. Skipping it means encountering expensive surprises mid-project that could have been planned for upfront.
21What documents do I need for ISO certification?+
For ISO 9001: Quality Policy, scope documentation, process maps, risk and opportunity register, internal audit programme, management review records, and corrective action records. ISO 14001 adds environmental aspects and legal registers. ISO 45001 adds hazard identification and worker participation records. ISO 27001 requires a Statement of Applicability and risk treatment plan covering 93 controls. All documents are developed in plain language structured to your actual business.
22What is an internal audit and is it mandatory?+
An internal audit is a formal review of your management system conducted before the certification body's external audit. It must be systematic, documented, and conducted by someone not directly responsible for the areas being audited. Yes, it is mandatory. Certification bodies require evidence of at least one complete internal audit cycle before issuing a certificate.
23What is the difference between a Stage 1 and Stage 2 audit?+
The Stage 1 audit is a document review where the certification body assesses your readiness and identifies significant gaps before the main audit. The Stage 2 audit is the full on-site certification audit where the auditor interviews staff, reviews records, and tests whether your documented system is actually being followed. Both stages must be completed before a certificate is issued.
24What happens if I fail my ISO certification audit?+
Certification audits produce findings, not a binary pass or fail. Minor nonconformities give you 90 days to provide evidence of correction. Major nonconformities require a follow-up visit from the auditor before certification is granted. Observations do not block certification. Well-prepared businesses rarely receive major findings. Our pre-certification process is designed to resolve potential major nonconformities before the certification body arrives.
25Do I need ISO certification to bid on government tenders in South Africa?+
ISO certification is not a universal legal requirement but is increasingly non-negotiable in practice. Many SOEs, national departments, and municipalities list ISO 9001 as a mandatory pre-qualification criterion. Under the 80/20 and 90/10 preference point systems, ISO certification typically attracts 5 to 15 additional functionality points. The certificate must be issued by a SANAS-accredited body to be accepted.
26Does ISO certification give me extra points on a tender scorecard?+
Yes. Tenders that include a functionality scorecard regularly award 5 to 15 points specifically for ISO certification. For CIDB Grade 5 and above construction contractors, ISO 9001 is close to expected on formal scorecards. The certificate must be issued by a SANAS-accredited body and must be current at the time of tender submission.
27What industries in South Africa benefit most from ISO certification?+
Engineering and construction, manufacturing and FMCG, ICT and software development, logistics and transport, and professional services including consulting and facilities management all see direct revenue impact from certification. These are the sectors where ISO certification most frequently appears as a mandatory tender requirement or supply chain pre-qualification criterion.
28Can ISO certification help me export my products?+
Yes. ISO 9001 is recognised in over 170 countries and is a baseline quality signal required by many European, Middle Eastern, and Asian buyers. ISO 22000 opens food export markets, ISO 13485 enables medical device exports, and ISO 27001 is increasingly required for South African ICT companies providing services internationally. Certification is one of the most credible steps toward qualifying as a supplier in foreign markets.
29How do I maintain ISO certification after receiving it?+
Maintenance requires passing annual surveillance audits, conducting annual internal audits, holding at least one management review per year, logging and closing corrective actions, and keeping documentation updated as your business changes. Businesses that treat certification as a live operational tool consistently get more value from it than those who maintain the bare minimum.
30Does ISO certification expire?+
Your ISO certificate has a 3-year validity period, but it can be suspended before that if you fail a surveillance audit and do not resolve major findings within the given timeframe. A full recertification audit is required at the end of year 3. Missing a surveillance audit deadline can cause your certificate to lapse, requiring you to restart the process. Schedule surveillance audit dates the moment you receive your certificate.
Question not answered here?
WhatsApp us and we'll answer within a few hours — no obligation.