Read More

ISO/IEC 17021-1 · YOUR CERTIFICATION JOURNEY

ISO Certification Process

Achieving ISO certification demonstrates your organization’s commitment to quality, security, and continual improvement. At Decrypt Certification Body, we make the certification journey clear, transparent, and efficient, ensuring that every assessment is conducted with impartiality, competence, and in accordance with ISO/IEC 17021-1 requirements.
Our certification process follows internationally recognized practices, from your initial application through certification, surveillance audits, and recertification. The objective is not only to verify compliance with the applicable ISO standard but also to help your organization maintain an effective management system that delivers ongoing value.
  1. Begin your certification journey by contacting the Certification Body to request an application form. Once the completed application and supporting documents are received, the Certification Body reviews the application, conducts a competence, risk, and impartiality assessment, determines the audit duration in accordance with IAF MD 5, and issues a quotation and audit proposal.

    • Contact the Certification Body to request an application form
    • Complete and submit the application with the required information and supporting documents
    • The Certification Body reviews the application and conducts a competence, risk, and impartiality assessment
    • Audit duration is determined in accordance with IAF MD 5
    • The Certification Body issues a quotation and audit proposal for approval
  2. Once the quotation is accepted, the Certification Body and the client enter into a certification agreement, and an audit programme is established to plan the certification activities.

    • The client accepts the quotation and certification terms
    • The Certification Body issues the Certification Agreement for acceptance
    • An audit programme is established based on the certification scope and audit cycle
    • The Certification Body prepares and shares the audit plan with the client for review and approval
    • Audit dates are confirmed, and the audit team is appointed
  3. The Stage 1 Audit evaluates the organization’s readiness for certification by reviewing the management system documentation and determining preparedness for the Stage 2 Audit.

    • The Certification Body reviews the management system documentation and assesses readiness for certification
    • Key processes, scope, legal and regulatory requirements, and site-specific conditions are evaluated
    • Any areas of concern, gaps, or opportunities for improvement are identified and communicated to the client
    • The audit team prepares the Stage 1 Audit Report with a recommendation on readiness to proceed
    • The Certification Body reviews the report and makes the final decision on whether to proceed to Stage 2
    • Once readiness is confirmed, the Stage 2 Audit Plan is shared with the client for review and confirmation, including availability of relevant personnel for interview sessions
    BranchReady → proceed to Stage 2. Not ready → close gaps and re-plan before continuing.
  4. The Stage 2 Audit evaluates the implementation and effectiveness of the management system through the collection of objective evidence using risk-based sampling techniques.

    • The audit team conducts the Stage 2 Audit in accordance with the approved audit plan
    • Activities include interviews with relevant personnel, review of documented information, observation of processes, and sampling of activities, records, and sites (where applicable)
    • Any nonconformities, observations, or opportunities for improvement are discussed with the client during the closing meeting
    • The audit team prepares the Stage 2 Audit Report and provides a recommendation for certification
    • The report and recommendation are submitted to the Certification Body for technical review and certification decision
    • Where nonconformities are identified, the client implements corrective actions and submits evidence for review within the agreed timeframe
  5. Where audit findings are identified, the client must address them through a structured findings handling process before the Certification Body can make a certification decision. Corrective action plans should be submitted within 2 months, and all corrections and corrective actions should be completed within 6 months.

    • Determine the root cause of the finding
    • Develop a plan for corrections and corrective actions
    • Implement the planned corrections and corrective actions
    • Verify the effectiveness of the corrections and corrective actions
    Findings Classification
    Major nonconformity (MaNCF) — Certification cannot proceed until effective corrective actions have been verified.
    Minor nonconformity (MiNCF) — Corrective action plans are required, and implementation is verified before or during subsequent certification activities, as applicable.
    Observation (OBS) — Identifies a potential weakness that does not constitute a nonconformity but should be monitored.
    Opportunity for improvement (OFI) — Suggests areas where the management system could be further enhanced.
    BranchFindings must be closed to the Certification Body’s satisfaction before a certification decision can be made.
  6. Following successful completion of the audit process and closure of any applicable nonconformities, the Certification Body conducts an independent certification decision to determine whether certification can be granted.

    • The audit report, corrective action evidence (where applicable), and audit recommendation are submitted to the Certification Body
    • An independent reviewer, who was not involved in the audit, reviews the certification file
    • The Certification Body verifies that all certification requirements have been satisfactorily met
    • A certification decision is made to grant, defer, or deny certification
    • Where certification is granted, the certificate is issued and the client’s certification details are published in the Certification Body’s directory
    BranchGranted → certificate issued and the certification cycle commences. Deferred or denied → return to corrective action before a further decision.
  7. Once certification has been approved, the Certification Body issues the certificate and formally recognizes the organization’s management system as conforming to the applicable ISO standard.

    • The Certification Body issues the Certificate of Conformity
    • The certificate specifies the certification scope, applicable standard, sites (where applicable), and validity period
    • The certified organization is listed on IAF CertSearch, enabling customers and interested parties to verify the validity of the accredited certification
    • The client may use the certification mark in accordance with the Certification Body’s logo and mark usage requirements
    • Certification is valid from the date of issue and remains subject to successful surveillance and recertification audits throughout the cycle
  8. Following certification, the Certification Body conducts surveillance activities throughout the certification cycle to verify the continued effectiveness and conformity of the management system.

    • Surveillance audits are conducted at least once every calendar year
    • Surveillance audits are planned in accordance with the established audit programme
    • The audit team uses risk-based sampling to assess continued implementation and effectiveness
    • Any nonconformities identified are managed through the findings handling process
    • Other surveillance activities may include reviews of certification mark usage, publicly available information, complaints, and significant changes
    • Continued satisfactory performance during surveillance activities is required to maintain certification
  9. Before the certification expires, the Certification Body conducts a recertification audit to confirm the continued suitability, adequacy, effectiveness, and conformity of the management system.

    • The recertification audit is scheduled before the certificate expiry date
    • The audit evaluates the overall performance and effectiveness of the management system throughout the certification cycle
    • Results of previous surveillance audits, effectiveness of corrective actions, changes to the management system, and commitment to continual improvement are considered
    • Any nonconformities identified are managed through the findings handling process
    • The audit team prepares a recertification audit report and recommendation for review by the Certification Body
    • Upon a positive certification decision, a new certificate is issued, commencing the next certification cycle
New 3-Year Cycle
Recertification restarts the programme.
Certification is a living cycle, not a one-time badge. Your certificate stays valid through at least one surveillance audit each year and a full recertification every three years, so the trust it signals to your customers never goes stale.

Get Started

Ready to Get Certified and Close More Deals?

Tell us about your company and we’ll get back to you with a clear path to certification – including timeline and pricing.

Consultation form

This field is for validation purposes and should be left unchanged.
Name(Required)