Frequently Asked Questions
For more than three decades, Quality Resource Center (QRC) has helped organizations make sense of ISO standards and turn them into working management systems. Below are the questions we hear most often from quality managers, operations leaders, and executives who are weighing certification or already in the middle of an implementation.
If your question isn’t answered here, call us at (800) 244-5409 or use our contact page. A veteran consultant will get back to you, not a sales script.
ISO Basics
What is ISO?
ISO is the International Organization for Standardization, an independent, non-governmental body based in Geneva, Switzerland. It brings together national standards bodies from more than 160 countries to develop voluntary, consensus-based standards that define good practice for products, services, and management systems.
ISO itself does not certify or audit companies. It writes the standards. Certification is handled by independent third-party registrars, and firms like QRC help you build the management system that a registrar will certify against.
What is the ISO 9000 family of standards?
ISO 9000 refers to a family of quality management standards. The two you’ll encounter most often are ISO 9000, which defines the vocabulary and fundamental principles of quality management, and ISO 9001, which contains the actual requirements an organization must meet to become certified. When people say they are “getting ISO 9000 certified,” they almost always mean ISO 9001.
Is ISO 9001:2015 still the current version, and what about ISO 9001:2026?
Yes. ISO 9001:2015 is the current, certifiable version of the standard, and it remains in force. It introduced risk-based thinking, stronger leadership requirements, and a common high-level structure shared across modern ISO management-system standards.
A revision is underway. The next edition, expected to be published as ISO 9001:2026, will refine the standard rather than overhaul it, with emphasis on areas such as climate and organizational context, digital tools, and supply-chain risk. Certified organizations will get a defined transition window once it is released. We track this closely so our clients are never caught off guard. You can read more on our ISO 9001:2026 revision page.
Who uses the ISO 9001 standard?
Organizations of every size and industry use ISO 9001, from single-site machine shops to global manufacturers and service firms. It is intentionally generic, so a hospital, a software company, an aerospace supplier, and a food processor can all build a compliant quality management system around it. Many companies pursue certification because a customer, a government contract, or a supply-chain partner requires it; others do it to tighten operations and reduce defects and rework.
Why is ISO 9001 certification worth pursuing?
Certification does two things. It opens doors, because a growing number of customers and contracts require certified suppliers, and it improves how you actually operate. A well-built quality management system reduces variation, catches problems earlier, clarifies responsibilities, and gives leadership real data to act on. The certificate is the visible result; the operational discipline is where the return on investment lives.
How Certification Works
How does a company achieve ISO certification?
The path is consistent across standards. You start with a gap analysis to see where your current practices fall short of the standard. You then build or refine the required processes and documentation, train your people, and run the system for long enough to generate records. Next you conduct an internal audit and a management review. Finally, an accredited third-party registrar performs a certification audit, usually in two stages, and issues the certificate once you meet the requirements. QRC’s clients who use our full-service implementation program consistently pass their first registrar audit.
Are certified organizations audited after certification?
Yes. Certification is not a one-time event. Registrars conduct surveillance audits, typically annually, to confirm the system is still being used and maintained, and a full recertification audit usually every three years. On top of that, you are expected to run your own internal audits on a regular cycle. Ongoing audit support and QMS maintenance are among the services QRC provides so certification doesn’t lapse.
What is an ISO gap analysis?
A gap analysis is a structured comparison of your current operations against the requirements of the standard you’re targeting. It identifies exactly which processes, documents, and controls you already have, which need work, and which are missing entirely. It becomes the roadmap for the whole project and lets you scope the effort and cost realistically before committing. Learn more on our gap analysis services page.
Is there a glossary of quality terms available?
Yes. ISO and quality management come with a lot of acronyms, from CAPA and NCM to QMS and SPC. We maintain a plain-English glossary of quality terms to help you cut through the jargon.
Working With an ISO Consultant
How long does an ISO 9001 implementation take?
For most organizations working with QRC, a typical ISO 9001 implementation runs about five to seven months from kickoff to the certification audit. The exact timeline depends on the size and complexity of your organization, how mature your existing processes are, and how quickly your team can dedicate time to the effort. Highly regulated or multi-site operations can take longer. A gap analysis early on lets us give you a realistic schedule rather than a generic estimate.
What does an ISO consultant cost, and what drives the price?
There is no single sticker price, because cost scales with the work involved. The main drivers are the size and number of your sites, the number of employees and processes in scope, which standard you’re pursuing, how much documentation already exists, and how much of the work you want to keep in-house versus hand to the consultant. A focused gap analysis, a from-scratch full implementation, and ongoing maintenance are very different levels of effort. We scope every engagement to your situation and quote it transparently. Call (800) 244-5409 for a straight answer on your project.
What is AI-powered ISO consulting?
It means pairing our veteran ISO consultants with modern AI tooling to accelerate the mechanical parts of a project, such as drafting documentation, structuring gap analyses, organizing audit evidence, and monitoring for compliance drift. AI handles the repetitive drafting and cross-referencing; our human experts direct the work, apply judgment, and remain fully accountable for every deliverable. The result is a faster implementation without cutting corners on quality or auditability. See our AI-powered ISO consulting page for details.
What should I look for when choosing an ISO consultant?
Ask about depth of experience across your specific standard and industry, and whether the consultant can deliver a complete solution rather than a partial one. Find out whether you’re hiring a solo freelancer or a firm with a bench of consultants and continuity if someone is unavailable. Confirm they offer the surrounding services you’ll eventually need, including training, internal auditing, corrective action, and ongoing maintenance. QRC has guided 1,000+ organizations to compliant systems since 1992. If you’re in the Bay Area, see our California ISO consultant page.
Industry-Specific and Emerging Standards
Are there specific ISO standards for different industries?
Yes. Many sectors build on ISO 9001 with their own requirements. Aerospace uses the AS9100, AS9110, and AS9120 series. Automotive uses IATF 16949. Medical device manufacturers use ISO 13485. Environmental management uses ISO 14001, and information security uses ISO/IEC 27001. You can see the full range on our ISO consulting services hub.
What replaced OHSAS 18001?
ISO 45001 replaced OHSAS 18001 as the international standard for occupational health and safety management systems. Organizations that were certified to the old OHSAS 18001 have transitioned to ISO 45001, which aligns with the same modern high-level structure as ISO 9001 and ISO 14001, making it far easier to integrate safety with your existing quality and environmental systems. Learn more on our ISO 45001 consulting page.
What is ISO/IEC 27001?
ISO/IEC 27001 is the international standard for an information security management system, or ISMS. It provides a risk-based framework for protecting the confidentiality, integrity, and availability of information, covering people, processes, and technology rather than just IT tools. Customers, regulators, and partners increasingly require it as proof that your data-handling practices are under control. See our ISO 27001 consulting page.
What is CMMC, and who needs it?
CMMC, the Cybersecurity Maturity Model Certification, is a U.S. Department of Defense program that requires contractors and subcontractors in the defense supply chain to demonstrate specific cybersecurity practices before handling sensitive government information. If you hold or want DoD contracts that involve controlled unclassified information, you will need to meet the required CMMC level. The controls overlap heavily with information-security practices, so organizations already working toward ISO 27001 have a strong head start. See our CMMC consulting page for readiness support.
What is IATF 16949?
IATF 16949 is the global quality management standard for the automotive industry, published by the International Automotive Task Force. It replaced the older ISO/TS 16949 and builds on ISO 9001 with automotive-specific requirements around defect prevention, variation reduction, and supply-chain discipline. It is effectively mandatory for suppliers to major automakers. See our IATF 16949 certification services page.
What is R2 certification for electronics recyclers?
R2, short for Responsible Recycling, is a certification standard for the electronics recycling and refurbishment industry. It sets requirements for safely and responsibly managing used electronics, including data security, worker health and safety, environmental protection, and downstream accountability for how materials are handled. It is often implemented alongside ISO 14001 and ISO 45001 as part of an integrated environmental, health, and safety system.
Call (800) 244-5409
Local: (408) 371-9995
Contact Us
