Get a Quote
Monthly Archives

July 2026

Home / July 2026
ISO 14001 for Construction Example Explained
Article, News

ISO 14001 for Construction Example Explained

A leaking fuel bowser, a missed waste collection or concrete washout entering a surface-water drain can turn a routine construction project into an expensive problem. An ISO 14001 for construction example makes the standard easier to apply because it shows what an environmental management system looks like in the reality of live sites, changing subcontractors and tight programme deadlines.

This practical example follows a fictional UK SME contractor, BuildRight Projects Ltd. It carries out commercial refurbishments and small new-build schemes, employs 22 people directly and relies on specialist subcontractors. The business needs ISO 14001 certification to strengthen tender submissions, meet client expectations and demonstrate that environmental controls are managed consistently.

The construction business and its environmental context

BuildRight begins by defining the scope of its environmental management system. Rather than attempting to cover activities it does not control, it includes its head office, estimating, procurement, project management and all construction sites managed by the company. It also recognises that subcontractors, waste carriers and material suppliers can affect its environmental performance.

The company considers the issues that matter most to its operation. These include increasingly strict client environmental requirements, rising disposal costs, local residents’ concerns over dust and noise, legal duties relating to waste, pollution risks and the availability of lower-impact materials. It also identifies opportunities: reducing skip movements, reusing materials where safe and practical, and winning more work from clients that assess environmental credentials during procurement.

This does not need to become a lengthy corporate report. For a small contractor, a concise context document and a clear list of interested parties are usually more useful than pages of generic wording. The key is showing that the business understands the conditions in which it operates and has built its system around them.

ISO 14001 for construction example: identifying aspects

The central working document in this example is an environmental aspects and impacts register. An environmental aspect is an activity that can interact with the environment. The impact is the resulting change, such as pollution, resource depletion or nuisance.

BuildRight lists normal activities, abnormal events and reasonably foreseeable emergencies. It then scores each aspect using a simple method based on severity, likelihood, level of control and legal or client requirements. The scoring method matters less than applying it consistently and reviewing it when a project changes.

For its projects, BuildRight identifies several significant aspects:

  • Fuel storage and plant use, with risks of soil or water contamination, emissions and unnecessary fuel consumption.
  • Waste generation from strip-out, packaging, timber, plasterboard and mixed construction materials.
  • Concrete, cement and washout activities, which can create highly alkaline pollution if poorly controlled.
  • Dust, noise and vehicle movements that may affect neighbours, workers and local air quality.
  • Procurement of materials, including timber sourcing, packaging volumes and the potential to specify recycled or lower-carbon options.

Not every aspect needs the same level of control. A minor office-paper issue should not receive more attention than a fuel spill risk beside a drain. The register helps the company direct time and money where the environmental risk and commercial exposure are greatest.

Turning the register into a workable site plan

For a six-month office refurbishment in Manchester, BuildRight creates a project environmental plan before work starts. The project manager adapts a controlled template rather than writing a new plan from scratch. This is faster, but it still has to reflect the site layout, client rules and nearby risks.

The plan records that the project is close to occupied offices and a public footpath. It identifies the nearest drains, confirms where skips will be located and specifies a designated, bunded area for fuels and chemicals. It also records relevant waste arrangements, emergency contacts and the person responsible for environmental checks.

The controls are practical. Fuel containers are inspected weekly, spill kits are placed near storage areas and plant operators report leaks immediately. Drain covers and washout controls are installed before concrete-related work begins. Waste is segregated where space allows, with clear signage to reduce contamination. Delivery times are planned to limit congestion and unnecessary idling.

There is a trade-off here. Segregating every waste stream can be impractical on a confined city-centre site. BuildRight documents the space constraint and uses a reputable waste provider that can separate mixed loads where appropriate. ISO 14001 does not demand perfection or a zero-waste claim. It expects the business to understand its impacts, meet applicable obligations and improve its control over time.

Setting objectives that can be measured

BuildRight sets environmental objectives that relate directly to its significant aspects. Vague aims such as ‘be greener’ do not give a project manager anything useful to manage. The company instead sets targets for the coming year: reduce mixed waste sent from projects, increase the proportion of waste streams segregated on suitable sites, complete environmental inspections on time and reduce avoidable plant idling.

For the Manchester project, the target is to divert at least 90% of non-hazardous construction waste from landfill, subject to the waste contractor’s reporting data. Another target is 100% completion of weekly environmental inspections. The site team also records fuel use where a project has enough plant activity for meaningful comparison.

A smaller contractor should avoid collecting data simply because it sounds impressive. If fuel is supplied through several subcontractors and cannot be reliably measured, the business may initially focus on controls, plant-maintenance records and idling observations. Honest, usable figures are better than ambitious numbers with no evidence behind them.

Competence, communication and subcontractor control

Environmental performance is often lost at the point where responsibility passes between the main contractor, subcontractor and site labour. BuildRight addresses this at induction. Every worker receives a short briefing on waste segregation, spill response, dust controls, reporting requirements and the location of environmental information.

Subcontractors with higher-risk activities receive more specific controls. The groundworks contractor must follow the fuel-storage arrangements. The demolition contractor provides waste information and follows dust-suppression requirements. Suppliers are told about delivery restrictions and packaging expectations.

The company keeps records of inductions and toolbox talks, but paperwork alone is not proof that controls are working. Site managers carry out visible checks, challenge poor practice early and record corrective actions. If a skip is contaminated or a spill kit has been used, the event is investigated in proportion to the risk. The aim is to prevent recurrence, not merely to close a form.

Checking performance and preparing for audit

Each project manager completes a weekly environmental inspection using a simple checklist. It covers waste areas, chemicals, fuel, drains, dust, housekeeping, permits and previous actions. Photographs can provide useful evidence, especially where the inspection identifies a problem and its later correction.

BuildRight’s compliance lead reviews results monthly. Repeated issues, such as poorly labelled waste bins, trigger a wider action rather than repeated reminders on individual sites. The business also conducts internal audits to test whether the documented system matches what people actually do.

Before certification, BuildRight can expect to show its environmental policy, aspects register, objectives, project plans, legal and other obligations, competence records, inspections, internal audit findings and management review records. It should also be ready to explain how it deals with incidents and corrective actions.

A management review brings those threads together. The directors consider audit results, progress against objectives, complaints, incidents, changes in legislation or client requirements, resource needs and improvement opportunities. For an SME, this can be a focused meeting with clear minutes and actions. It does not need to be an over-engineered board paper.

What this example gets right

The value of this ISO 14001 for construction example is not the number of documents created. BuildRight links risks to site controls, assigns ownership and keeps enough evidence to demonstrate that its system is being used. That is what makes the standard useful for tendering and everyday management alike.

A refurbishment contractor, civil engineering business and housebuilder will have different significant aspects. A highways contractor may place greater emphasis on traffic management, aggregates and drainage. A fit-out company may focus more on waste, material procurement and occupied-building controls. The framework remains the same, but the detail must fit the work.

For SMEs, a digital system with tailored templates and expert guidance can remove much of the administrative drag. ISO-Cert Online helps businesses build practical management systems without turning certification into a lengthy consultancy project.

The best time to build environmental controls is before the next site starts, when drainage, storage, waste routes and responsibilities can still be planned properly. That early decision is often where lower risk, lower waste costs and stronger tender evidence begin.


Ready to get started?

Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.

Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.

What Does ISO 9001 Certification Cost for a Small Company?
Article, News

What Does ISO 9001 Certification Cost for a Small Company?

A tender deadline, a major customer request or a plan to enter a new market can make ISO 9001 feel urgent very quickly. So, what does ISO 9001 certification cost for a small company? For most SMEs, a realistic first-year budget is commonly between £1,000 and £5,000, but the right figure depends on your company’s size, complexity, current systems and how much practical support you need.

The useful question is not simply, “What is the cheapest certificate?” It is, “What will get us certified credibly, without distracting the team or creating unnecessary consultancy bills?” A digital-first route, clear scope and remote assessment can make a significant difference to both cost and speed.

What does ISO 9001 certification cost for a small company?

For a straightforward small business with one site, a limited team and uncomplicated processes, ISO 9001 certification can often be achieved at the lower end of the range. A business with several locations, field teams, regulated work, complex supply chains or little in the way of existing (documented) processes should expect a higher investment.

Your first-year cost usually has three parts: implementing a quality management system, completing the certification audit and allowing for support or training where internal time is limited. Some providers (such as ISO-Cert Online Ltd) package these elements together; others quote each separately. That is why two quotations that appear similar at first glance can produce very different final costs.

A low headline price may cover only an audit, leaving you to create policies, procedures, records and evidence alone. Conversely, an all-inclusive package may include tailored templates, consultancy time, an online portal and support through the audit. For a busy SME, that support can be more cost-effective than asking a director or operations manager to learn the standard from scratch while running the business.

The costs that make up an ISO 9001 budget

Certification audit fees

The audit is the formal assessment of whether your quality management system meets ISO 9001 requirements and is being followed in practice. For a small, low-risk organisation, audit fees are often the most visible part of the quote.

Auditors consider the number of employees, business activities, sites, and the scope you want certified. A ten-person office-based consultancy needs less audit time than a twenty-person manufacturer operating from two premises. If your scope includes design, installation, production and servicing, the assessment is likely to take longer than one covering a single professional service.

Remote audits can reduce costs because there is no auditor travel, accommodation or unproductive site-visit time to pay for. They also make scheduling easier for small teams. However, remote does not mean less rigorous. You still need to demonstrate that your processes work, records are maintained and responsibilities are understood.

Implementation and documentation

ISO 9001 does not require a mountain of paperwork, but it does require a workable management system. You will need to define processes, assign responsibilities, manage risks and opportunities, control documents, record corrective actions and review performance.

If you already have documented workflows, customer feedback processes, supplier controls and regular management meetings, implementation may be relatively light. In that case, customised templates and targeted guidance may be enough. If your systems sit mainly in people’s heads, you may need more hands-on consultancy to turn good practice into consistent, auditable evidence.

Training and internal audit support

Before certification, your business should carry out an internal audit and a management review. These are not box-ticking exercises. They help you find gaps before the external audit and give directors confidence that the system is delivering useful information.

You can train an employee to complete these tasks, use guided online training resources or bring in an experienced consultant. The lowest-cost option is often to manage it internally, particularly where someone already owns quality or operations. The trade-off is time. If that person is stretched, external support may prevent delays and reduce the risk of avoidable findings.

Corrective action and extra audit time

Most well-prepared small companies complete the process without major difficulty, but it is sensible to allow a contingency. If the audit identifies a nonconformity, you may need to provide corrective-action evidence before certification is issued. This does not necessarily mean a large additional bill, but poorly prepared businesses can face extra consultancy or audit time.

Ask at quotation stage what is included if a corrective action is needed. Clear pricing matters more than an optimistic starting figure.

What affects the price most?

Employee numbers matter, but they are not the whole story. A small company can be operationally complex, while a larger office-based business may have very consistent processes. Cost is usually shaped by the certification scope, number of locations, type of work, existing level of control and how quickly you need to achieve certification.

Urgency can increase costs if you need intensive consultancy support, rapid document development or priority audit dates. It can also be managed well. A focused plan, ready-to-use templates and a secure online workspace can help a company prepare quickly without taking shortcuts.

Be accurate when describing your business to a provider. Trying to narrow the scope artificially may make the quote look attractive, but it can create problems if customers expect broader activities to be covered by your certificate. Your scope should reflect the services or products you genuinely need to demonstrate.

First-year cost versus annual renewal

ISO 9001 is not a one-off purchase. After initial certification, you will need ongoing surveillance assessments and a recertification assessment at the end of the certification cycle.

The best way to keep renewal costs under control is to keep the management system alive. Continue internal audits, log customer feedback and issues, review supplier performance, record improvements and hold management reviews. Leaving everything until just before a surveillance audit creates a rush of work and may mean paying for additional support.

Digital document control and progress monitoring can make this far easier. Instead of searching through old folders at renewal time, you have current evidence, assigned actions and a clear record of what has changed.

How to get value rather than just a low price

When comparing ISO 9001 quotations, look beyond the total. Check whether the price includes implementation guidance, tailored documents, internal-audit support, management-review support, remote auditing, certificate issue and ongoing access to your documentation. Also ask whether travel expenses, additional audit days or renewal charges could be added later.

For many SMEs, a package with practical support is the better commercial choice. It reduces the chance of delay, protects internal time and gives staff a system they can maintain after the certificate is issued. ISO-Cert Online is built around that approach, combining online guidance, tailored support and remote delivery to make certification faster and more manageable for small and medium sized businesses.

A sensible budget for your business

If you are a small, single-site company with established processes, start by budgeting at the lower end of the £1,000 to £5,000 first-year range. If you have multiple sites, a complex scope or need substantial help building the system, plan towards the higher end and request a clear, itemised proposal.

The most economical route is rarely the one that leaves your team with the most work. Choose a provider that explains what is included, sets out the timescales plainly and helps you create a quality system that improves how the business runs. Done properly, ISO 9001 should support better customer service, fewer recurring problems and stronger tender opportunities long after the audit is finished.


Ready to get started?

Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.

Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.

Why Do Clients Require ISO Certification in Supplier Tenders
Article, News

Why Do Clients Require ISO Certification in Supplier Tenders

A tender can be lost before the buyer has read a word about your service, price or experience. If ISO certification appears as a mandatory requirement, it is often used as an early pass-or-fail check. The question, ‘why do clients require ISO certification in supplier tenders?’, is therefore not academic. For many UK SMEs, the answer directly affects whether they can compete for work.

Clients are not usually asking for ISO simply to create paperwork. They want a practical, independent indication that a supplier has controlled processes, understands its risks and can deliver consistently. Certification gives procurement teams a quicker way to reduce uncertainty when comparing several potential suppliers.

Why do clients require ISO certification in supplier tenders?

Tendering is a risk-management exercise. A buyer may be responsible for public money, a major contract, sensitive information, site safety or a supply chain that cannot afford disruption. They need confidence that every appointed supplier can meet the required standard without creating avoidable problems later.

ISO certification offers a recognised framework for assessing that confidence. Rather than asking every bidder to explain every policy, process and control from scratch, the client can specify a relevant standard and ask for a current certificate. It is a practical filter, particularly where procurement teams are managing high volumes of responses.

This does not mean certification guarantees perfect performance. A certificate cannot replace references, financial checks, technical evaluation or contract management. What it can do is show that an organisation has put a structured management system in place and had it assessed against a defined standard.

For the supplier, that can turn a difficult reassurance exercise into a straightforward evidence submission. Instead of trying to persuade a buyer that your business takes quality, safety or data security seriously, you can demonstrate that commitment through a recognised certification route.

The risks buyers are trying to control

The ISO standard requested usually reflects the risk attached to the work. Quality failures, accidents, environmental harm and information breaches can all be expensive for the client, even when they are caused by a contractor or subcontractor. Reputational damage can be just as serious.

ISO 9001 is commonly requested where consistent quality, controlled delivery and customer satisfaction matter. It helps show that a business manages processes, deals with issues properly and looks for continual improvement. This is relevant across construction, manufacturing, professional services, facilities management and many other sectors.

ISO 14001 may appear where the client has environmental commitments, planning conditions or supply-chain reporting obligations. Buyers want evidence that suppliers understand their environmental impacts and have a method for reducing waste, preventing pollution and meeting applicable requirements.

ISO 45001 is often central to tenders involving site work, construction, engineering, logistics or maintenance. A client needs assurance that health and safety is actively managed, not left to a generic policy filed away for inspection day.

ISO 27001 is increasingly important for IT providers, software companies, consultants, outsourced service teams and anyone handling confidential or personal information. It gives buyers a structured basis for assessing information security, including access controls, incident management and risk treatment.

Depending on the contract, clients may also look for ISO 22301 for business continuity, ISO 50001 for energy management or ISO 42001 where the responsible management of artificial intelligence is relevant. The requirement should be proportionate to the work. A simple supply arrangement does not always justify the same level of certification as a high-risk, long-term contract.

ISO certification makes procurement quicker and fairer

Procurement teams need a consistent way to evaluate suppliers. Without common requirements, assessments can become subjective. One bidder may provide a detailed quality manual, another may provide a one-page policy, and a third may make broad claims without evidence. Comparing them fairly takes time and leaves room for inconsistency.

Certification creates a common reference point. It does not make every supplier identical, but it helps buyers establish a baseline. This is particularly useful in framework agreements and public-sector procurement, where governance and audit trails matter.

It can also help clients meet their own obligations. Many larger organisations are certified themselves and need to show that they manage supply-chain risks. Requiring relevant ISO standards from key suppliers can support their quality, environmental, health and safety, or information-security objectives.

For SMEs, this is why ISO should be viewed as more than a badge for the website. It is often market access. Once certification is in place, your team can use it across multiple bids rather than rebuilding the same assurance evidence each time.

Mandatory, preferred or scored: read the tender wording carefully

Not every ISO reference means the same thing. The tender documents should tell you whether certification is a condition of bidding, a scored question or simply a preference.

If it is marked as mandatory, failing to provide the requested evidence may lead to exclusion. Some buyers will accept an equivalent management system, proof that certification is in progress, or a clear plan to achieve it before contract award. Others will not. Do not assume an alternative will be accepted because your policies look similar.

If ISO is weighted within the quality section, a certificate may strengthen your response but will not necessarily win the work alone. You still need to show how your processes will work on that specific contract. Explain responsibility, reporting, risk controls, escalation routes and how you will measure performance.

There is also a timing issue. Starting certification after a tender is published can be possible, but it may not fit the submission deadline. If your business regularly sees the same standard in opportunities, treating it as a last-minute tender task is usually more costly and stressful than putting it in place ahead of time.

What clients want to see beyond the certificate

A valid certificate is valuable evidence, but strong tender submissions connect it to the buyer’s real concerns. If a client is worried about missed service levels, do not simply attach ISO 9001. Explain how you control scheduling, competence, corrective action and customer feedback.

For a contract involving sensitive data, link ISO 27001 to your approach to access permissions, secure devices, supplier controls and incident response. For site-based work, show how ISO 45001 supports risk assessments, worker competence, consultation and reporting.

Keep the evidence precise. Give the certificate number, expiry date, scope and the legal entity it covers. A common problem is submitting a certificate held by a parent company, sister company or previous trading entity when the tendering business is not within scope. Buyers notice these details.

You should also check whether the certificate scope matches the service being tendered. If you are bidding to provide IT support, but the scope only covers office administration, it may raise questions. Clear, relevant certification is more persuasive than a broad claim with unclear coverage.

How SMEs can become tender-ready without unnecessary disruption

The most effective management system is one that reflects how your business actually operates. Copying a large corporate manual may satisfy nobody if staff do not use it. Buyers are increasingly alert to generic policies that have no connection to day-to-day delivery.

Start by identifying the standards that recur in your target tenders. Review recent opportunities, supplier questionnaires and requirements from existing customers. This helps you prioritise the standard with the clearest commercial return rather than paying for certification that your market does not need.

Next, map your existing processes. Most established SMEs already have useful controls: job checks, staff training, supplier approvals, complaint handling, backups, safety procedures or environmental practices. The task is to organise them, identify gaps and make responsibilities and records clear.

A digital-first certification process can reduce the administrative burden significantly. With tailored templates, practical guidance and remote assessment, teams can work through the required evidence without arranging repeated site visits or pausing operations. The right level of support matters, especially where one person is managing compliance alongside their main role.

Speed should never mean cutting corners. Certification needs to be credible, current and properly scoped. However, it does not need to become a six-month paperwork project. For a focused SME with existing processes and responsive leadership, a well-supported route can be far quicker than traditional consultancy models suggest.

Make certification part of your bid strategy

Once certified, keep a tender evidence pack ready. Store your current certificates, policies, insurance details, key procedures, training records, case studies and standard answers in one controlled location. Review it before each submission so dates, names and scopes remain accurate.

It is also worth monitoring renewal dates. An expired certificate submitted in error can create an avoidable compliance issue at precisely the point when a buyer is deciding whether to trust you. Assign ownership internally and keep management-system activities active between audits.

For businesses that need more than one standard, an integrated approach can prevent duplicated documents and repeated effort. Quality, environmental, health and safety and information-security controls often overlap in areas such as leadership, competence, risk, internal audits and corrective actions. Combining them sensibly can keep certification commercially manageable.

The practical aim is not to collect standards for their own sake. It is to make it easy for clients to choose you. When your certification reflects real working practices and is ready to evidence at tender stage, it stops being an obstacle and becomes a clear signal that your business is prepared for larger, more demanding opportunities.


Ready to get started?

Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.

Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.

Should My SME Get ISO 9001 or ISO 14001 First?
Article, News

Should My SME Get ISO 9001 or ISO 14001 First?

If you are asking should my SME get ISO 9001 or ISO 14001 first, the real question is usually simpler: which one will help the business sooner?

For most SMEs, ISO 9001 comes first. It is broader, more widely requested by customers and procurement teams, and usually gives you a clearer framework for getting processes under control. But that is not always the right answer. If your business has significant environmental responsibilities, customer pressure around sustainability, or contracts that require environmental management, ISO 14001 may need to move to the front of the queue.

The right choice depends less on theory and more on what your business is trying to achieve in the next 6 to 12 months.

Should my SME get ISO 9001 or ISO 14001 first for commercial impact?

If your immediate goal is winning work, ISO 9001 is often the better first step.

ISO 9001 is the quality management standard. In practical terms, it helps you run the business more consistently. It focuses on how you manage customer requirements, internal processes, non-conformities, improvement, responsibilities and documented controls. Many SMEs choose it first because it tends to support sales, tendering and day-to-day operations at the same time.

ISO 14001 is the environmental management standard. It is about identifying environmental aspects, managing impacts, meeting compliance obligations and improving environmental performance. That matters a great deal in the right context, but it is usually more specific in its commercial value unless your sector puts environmental performance under the spotlight.

A simple way to judge priority is to ask what is currently blocking growth. If customers are asking for evidence of quality controls, complaint handling, supplier management or consistent delivery, ISO 9001 is likely the faster commercial win. If tender portals, public sector frameworks or larger clients are asking about carbon reduction, waste handling, environmental controls or legal compliance, ISO 14001 may have stronger short-term value.

What ISO 9001 gives an SME first

For smaller businesses, ISO 9001 often creates the strongest foundation because it brings structure without forcing unnecessary bureaucracy.

A good ISO 9001 system helps clarify who does what, how work should be carried out, how mistakes are picked up, and how customer expectations are reviewed. That can make a visible difference quite quickly, especially in businesses where growth has happened faster than process discipline. If you have reached the stage where too much lives in people’s heads, quality certification usually solves more than one problem at once.

It also tends to be easier for directors and operational teams to connect with. The benefits are obvious: fewer errors, clearer accountability, smoother onboarding, better consistency and stronger credibility with buyers. For many SMEs, that makes ISO 9001 the easier standard to justify internally.

There is another practical point. If you plan to add more standards later, ISO 9001 often gives you the management system basics you will reuse elsewhere. Document control, internal audits, corrective action, management review and risk-based thinking all create useful groundwork for future certifications.

When ISO 14001 should come first

There are cases where ISO 14001 should clearly take priority.

If your business produces waste, uses significant energy, handles chemicals, manages transport fleets, works in construction, manufacturing, engineering or facilities services, or operates under customer scrutiny on environmental issues, ISO 14001 may be the smarter first move. The same applies if you are already being asked for environmental policies, sustainability commitments or evidence of legal compliance.

In those situations, waiting to do ISO 14001 second can slow down opportunities. Some buyers will accept a plan for quality improvement, but they may be less flexible on environmental risk if your operations could affect sites, waste streams, emissions or regulated activities.

There is also a reputational angle. If environmental performance is central to your market position, ISO 14001 can support trust in a way ISO 9001 cannot. A recycling contractor, print business, manufacturer or logistics firm may gain more from demonstrating environmental control than from leading with quality alone.

That is why there is no one-size-fits-all answer. ISO 9001 is usually first, but ISO 14001 becomes first when environmental obligations are commercially material.

A practical way to decide between ISO 9001 and ISO 14001

Instead of comparing standards in the abstract, look at four practical filters.

First, review customer and tender demand. Which certification is actually being requested? If bid documents, supplier questionnaires or prospect conversations mention one standard repeatedly, that is a strong signal.

Second, assess operational pain. If your business is struggling with inconsistency, rework, complaints or unclear processes, ISO 9001 will probably solve more immediate issues. If your main exposure is waste, environmental incidents, legal obligations or resource use, ISO 14001 may deliver more value.

Third, look at risk. Which area creates the bigger downside if ignored? A quality issue may lead to lost clients and poor delivery. An environmental issue can bring legal, contractual and reputational consequences. The higher the risk, the stronger the case to prioritise that standard.

Fourth, think about implementation effort and team readiness. Some SMEs can move faster with ISO 9001 because their existing procedures already cover much of what is needed. Others already track waste, environmental controls or compliance obligations, making ISO 14001 relatively straightforward. The faster path is not always the one people expect.

Can an SME do both together?

Yes, and in some cases that is the best option.

If you already know you will need both standards, implementing them as an integrated management system can save time, reduce duplicated work and make audits more efficient. Both standards share common management system principles, so it makes sense to build one joined-up framework rather than bolt on separate systems later.

For SMEs, this can be especially cost-effective when speed matters. You avoid creating one system now and reworking it again in six months. Policies, objectives, internal audits, corrective actions, management reviews and document control can often be designed to support both standards from the start.

That said, doing both together is not automatically the right move. If the business has limited internal capacity, one urgent tender deadline or no dedicated compliance resource, trying to tackle two standards at once can feel heavier than it needs to. In those cases, starting with the standard that gives the clearest short-term return is often the smarter decision.

The hidden cost of choosing the wrong one first

The biggest risk is not failing an audit. It is spending time and money on a certification that does not move the business forward.

If you choose ISO 14001 first when customers are mainly asking for ISO 9001, you may still miss tender requirements and sales opportunities. If you choose ISO 9001 first but your contracts depend on environmental assurance, you may still face procurement delays or compliance concerns.

There is also an internal cost. SMEs need certification to be practical, not a paper exercise. When the first standard solves a visible business problem, teams engage with it. When it feels disconnected from commercial reality, momentum drops quickly.

That is why the best sequencing decision is usually the one that links certification to a measurable outcome – more bids passed, fewer complaints, lower waste, stronger compliance, better customer confidence or faster supplier approval.

What most SMEs should do next

If you are still undecided, start by mapping the decision against revenue, risk and readiness.

Choose ISO 9001 first if your focus is growth, customer confidence, tender access, process consistency or creating a base for future standards. Choose ISO 14001 first if environmental risk, customer scrutiny, legal obligations or sustainability credentials are already central to how you win and keep business.

If both matter now, consider implementing them together through a streamlined online process so you do not duplicate effort. A digital-first approach with clear templates, remote support and practical consultancy can make that far more manageable for smaller teams than traditional, site-visit-heavy models.

For many SMEs, the fastest route is not just picking the right standard. It is picking a certification approach that keeps disruption low, costs controlled and progress visible. That is where a provider such as ISO-Cert Online Ltd can make the decision easier by helping you focus on what the business actually needs first, rather than selling complexity.

The best first ISO is the one that earns its place quickly – in your operations, in your tenders and in the confidence it gives your customers.


Ready to get started?

Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.

Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.

How Remote ISO Audits Work in Practice
Article, News

How Remote ISO Audits Work in Practice

If you are weighing up certification and wondering how remote ISO audits work, the short answer is this: the audit still follows the same core checks as a traditional assessment, but the evidence and document review happen online rather than during a site visit. For most SMEs, that means less disruption, lower cost and a much more efficient route to certification.

That matters because the old model often slowed smaller businesses down. Travel schedules, meeting room availability and diary clashes could turn a straightforward audit into a drawn-out exercise. A remote audit strips out much of that friction without removing the discipline of the assessment itself.

How remote ISO audits work from start to finish

A remote ISO audit may be carried out through a mix of video calls, screen sharing, digital document review or secure file exchange. The auditor is still looking for the same thing they would look for on site – whether your management system is in place, understood and being followed in practice.

The process normally starts before the audit day itself. You may be asked to provide key documents in advance so the auditor can review your management system, policies, procedures, records and scope, or, if you are a customer of ISO-Cert Online Ltd, you will have the option to upload all of the necessary evidence to the ISO-Cert Unite Portal. Depending on the standard, that might include internal audit records, management review minutes, risk assessments, objectives, training records, corrective actions or operational controls.

Once the review starts, the auditor works through your system much as they would in person. They will test whether your documented approach matches what your team actually does (verified by the documentary evidence provided).

For an SME, this is often easier than hosting a physical visit. Documents are pulled up quickly, and there is no need to stop half the office to accommodate an assessor walking around the site.

What happens during a remote ISO audit

The auditor will then move through the standard clause by clause. If you are being audited against ISO 9001, the focus may be on quality controls, customer issues and process performance. For ISO 14001 or ISO 45001, there may be more attention on environmental aspects, legal compliance, hazards and operational controls. For ISO 27001, expect deeper scrutiny of access control, incident management and information security risk treatment.

Where a physical site would once have been toured in person, a remote audit may use photos, video or existing records to confirm what is happening on the ground. Whether that is suitable depends on the standard and the nature of your business. A largely office-based company will usually find remote assessment very straightforward. A manufacturing, warehousing or higher-risk operation may need more visual evidence.

How evidence is checked without a site visit

This is the point many businesses worry about most, but in practice it is usually simpler than expected. Auditors do not need paper in front of them to test whether your system works. They need access to credible evidence.

That evidence can include controlled documents, completed forms, records from your management system, screenshots from business software, meeting notes, training logs and performance data. The key is not the format. The key is whether the evidence is current, relevant and consistent.

Customers of ISO-Cert Online Ltd are able to provide such information using numerous means, including email, SharePoint, and the ISO-Cert Unite Portal.

For example, if your procedure says complaints are logged, investigated and reviewed for trends, the auditor will want to see the complaint log, a sample investigation and some sign that the information feeds into management review or improvement activity.

This is why remote audits reward organised businesses. If your documents are version controlled, your records are easy to retrieve and your staff know their responsibilities, the process tends to move quickly. If evidence sits in inboxes, on desktops and in separate folders with no clear ownership, the audit can become slower than it needs to be.

Why remote audits suit SMEs particularly well

For smaller businesses, remote certification is not just a convenience feature. It can solve several practical problems at once.

First, it cuts out travel-related cost and scheduling delays. That makes certification more affordable and easier to arrange around normal operations. Second, it reduces disruption. Third, it fits the way many SMEs already work, with cloud systems, shared drives and online meetings now part of daily operations.

There is also a speed advantage. When documents, corrective actions and audit planning all sit within one digital process, it is often possible to move from implementation to assessment much faster. For a business working towards a tender deadline or customer requirement, that time saving can make a real commercial difference.

That said, remote is not a magic fix for a weak system. If the management system is poorly implemented, inconsistent or created purely for the audit, the online format will not hide that. In some ways, a remote audit can expose poor organisation more quickly because the auditor can ask for specific evidence which may not be available.

How to prepare for a remote ISO audit

The best preparation is not technical. It is operational. You want the audit to feel like a review of a working system, not a scramble for files. This is where the ISO-Cert Unite Portal excels, as the key records are generated within the Portal, and are therefore ‘always’ available. Recertification audits carried out by us utilise the backend of the Portal to check that records (i.e. evidence) are being generated, as prescribed by the relevant standard(s).

If you are not using the ISO-Cert Unite Portal, start by making sure your documents and records are stored logically and can be accessed quickly. Basic issues with permissions or internet access waste time and create avoidable stress. The best course of action is provide the evidence well before the audit is due to take place, by whatever means have been agreed.

Common concerns about remote audits

Some businesses assume a remote audit is less credible or less detailed than a site-based one. It is more accurate to say the method is different. The standard being assessed does not change, and the need for objective evidence does not change either.

Another concern is whether remote audits work for hands-on industries. Often they do, but the answer depends on the risk profile, the type of activities and how well evidence can be shown digitally. A consultancy firm, software provider or office-based service business will typically find remote audits very straightforward. A business with workshop activities, multiple locations or significant safety controls may need more planning and, in some cases, a blended approach.

Getting the most value from the process

The businesses that get the best result from remote audits do not treat them as a box-ticking exercise. They use the process to check whether the system is actually helping the business run better.

A good audit should show where your controls are working, where records are weak and where responsibilities are unclear. That is useful whether your priority is winning tenders, improving consistency, reducing incidents or meeting customer expectations. Fast, affordable certification matters, but so does making sure the system is practical enough to use after the certificate is issued.

For SMEs, that is where a digital-first approach can make a real difference. When templates, guidance, document control and audit preparation are built around the realities of a smaller business, certification becomes easier to manage and easier to maintain. ISO-Cert Online Ltd has built its service around exactly that principle.

Remote ISO audits work best when the process is simple, the evidence is organised and the system reflects how your business really operates. Get those three things right, and the audit becomes far less of a hurdle and far more of a straightforward step forward.


Ready to get started?

Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.

Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.

Article, News

Best ISO Certification for Software and IT Companies

Most tech founders know they need ISO certification. The bit that trips them up is deciding which one to go after first. Get it wrong and you spend six months building a management system that doesn’t open a single door. Get it right and you walk into enterprise procurement conversations with something your competitors can’t match. So, what is the best ISO certification for a software or IT company? The honest answer is: it depends on what your clients are actually asking you to prove right now.

Three standards deserve your attention: ISO 27001 for information security, ISO 9001 for quality management, and ISO 42001 for AI governance. Each solves a different problem. Each appeals to a different buyer. This guide is designed to give you a clear answer, not a list of options with no direction attached.

At ISO-Cert Online Ltd, we work with lean tech teams navigating exactly this choice. The question we get asked most often is some version of: “which ISO certification do I actually need?” The answer is rarely complicated once you understand what each standard does and who requires it.

Why IT Companies Face Growing Pressure to Certify

Enterprise Clients and Public-Sector Contracts Now Expect It

Procurement processes at large enterprises and government bodies have shifted significantly over the past few years. Security and quality questionnaires that used to be optional formalities are now gatekeepers. Supplier approval is increasingly contingent on holding recognised third-party certification, not just answering the right questions on a form.

ISO 27001 has become a near-mandatory line item in tender requirements for software vendors handling sensitive data, operating in regulated supply chains, or bidding on government technology contracts. ISO 9001 appears regularly in commercial tenders as evidence of operational maturity and process consistency. If your software company is scaling into enterprise or public-sector markets, certification is no longer a nice-to-have. It is a prerequisite.

Why Cyber Essentials Alone Won’t Get You There

Cyber Essentials is a useful baseline. It covers five core technical controls, it is fast to achieve, and it opens the door to UK public-sector procurement at the entry level. For many small businesses, it is a sensible first step. But it has a ceiling, and that ceiling arrives quickly.

Enterprise clients with serious due diligence processes do not treat Cyber Essentials as meaningful assurance. It carries little weight with international buyers. Its five technical controls are a floor, valuable, but a floor nonetheless: firewalls, secure configuration, access control, malware protection, and patching. ISO certification builds the operational house on top of that foundation, and it is what closes deals that Cyber Essentials alone cannot.

What Is the Best ISO Certification for a Software or IT Company?

Before diving into each standard, consider the simplest diagnostic: what is the most immediate commercial obstacle in your sales pipeline? Is it security due diligence? Delivery credibility? AI governance questions? The best ISO certification for a software or IT company is the one that removes that specific obstacle. With that frame in mind, here are the three standards that matter most.

ISO 27001: The Strongest Play for Data Security and Enterprise Access

What It Actually Requires from a Software Company

ISO 27001 builds an Information Security Management System (ISMS) around 93 Annex A controls, organised into four categories: organisational, people, physical, and technological. The organising principle is the CIA triad: confidentiality, integrity, and availability. The standard is not prescriptive about which tools you use. It requires you to assess your specific risks and apply proportionate controls. (See a useful explainer on the scope and purpose of ISO/IEC 27001.)

For software companies, the highest-impact controls centre on secure coding practices (Annex A control 8.28), vulnerability management, access control, encryption, and cloud security. The standard does not assume you have a large security team. It assumes you have real information assets worth protecting and asks you to build a systematic approach to protecting them.

When ISO 27001 Should Be Your First Certification

ISO 27001 is the right first choice when your clients handle sensitive data, when you are targeting enterprise or government contracts, or when your sales pipeline keeps stalling at the security questionnaire stage. If security due diligence is what is blocking your deals, this is what removes that obstacle.

For a UK SME software company, implementation typically takes three to six months, with initial investment running from roughly £4,000 to £15,000 depending on consultancy support and audit fees. The 2022 version is the current standard, the transition deadline for existing certifications passed in October 2025, so any new implementation should be built to ISO 27001:2022 from the outset.

Cloud Providers: The ISO 27017 and ISO 27018 Extensions Worth Knowing

For SaaS companies and cloud service providers, two extensions to ISO 27001 are worth understanding. ISO 27017 adds seven cloud-specific controls covering multi-tenancy, virtualisation, and shared responsibilities between cloud providers and their customers. ISO 27018 focuses on protecting personally identifiable information in public cloud environments and maps directly to GDPR obligations. For a practical guide to how ISO 27017 certification operates in cloud environments, see the linked guide.

These are not separate certifications. They extend your ISO 27001 scope and are referenced on your existing certificate. If your product handles large volumes of customer personal data or serves privacy-conscious enterprise buyers, these extensions strengthen both your compliance position and your commercial credibility with exactly the clients who scrutinise it most carefully.

ISO 9001: The Quality Standard IT Companies Underestimate

How Quality Management Applies to Software Development

ISO 9001 is not an IT-specific standard, and that is precisely where its value lies. It builds a Quality Management System (QMS) around consistent process delivery, customer satisfaction, and continuous improvement. For software companies, that means structured development lifecycles, documented testing protocols, and requirement validation, alongside defect tracking, SLA monitoring, and corrective action processes.

Its universal recognition across all sectors makes it valuable for companies selling into non-technical procurement environments. Buyers in facilities management, professional services, manufacturing, or local government care about delivery consistency and operational reliability. They are not evaluating your encryption standards. ISO 9001 speaks directly to what they are assessing.

When ISO 9001 Makes More Sense as Your First Step

If your clients are not asking about data security but are asking about delivery consistency, project governance, or subcontractor compliance, ISO 9001 is often the smarter first move. It is typically less technically demanding than ISO 27001, and initial costs run slightly lower, roughly £3,000 to £12,000 for a UK SME.

ISO 9001 is also a strong foundation for an integrated management system later. Its process discipline aligns naturally with ISO 27001 and ISO 14001. If you plan to pursue multiple certifications over time, starting with ISO 9001 gives you the documented process infrastructure that makes subsequent implementations significantly faster.

ISO 42001: The Standard Built for Companies Using AI

What ISO 42001 Actually Governs

ISO 42001 AI Management Certification Explained is the international standard for Artificial Intelligence Management Systems (AIMS). It provides a framework for the responsible development, deployment, and monitoring of AI systems, covering risk assessment, transparency, data governance, human oversight, and accountability. Like ISO 27001 and ISO 9001, it is a management system standard: process-focused, auditable, and certifiable.

Critically, it applies to any organisation developing, using, or operating AI tools, it does not require you to have built AI from scratch. If your team uses AI-driven features within your product, or relies on third-party AI tools in your operations, ISO 42001 has direct relevance. The standard explicitly requires third-party AI supplier governance, including evaluating suppliers’ AI practices at onboarding and monitoring them on an ongoing basis; for practical guidance on strengthening supplier checks see this piece on ISO 42001 and third-party compliance.

Who Needs to Think About It Now

ISO 42001 is worth considering if your product incorporates machine learning or AI-driven features, if you operate in a regulated sector where AI accountability is becoming a client requirement, or if enterprise clients are beginning to ask how you govern AI use internally. In financial services, healthcare, and government technology markets, these questions are already appearing in due diligence questionnaires.

Adoption is still early compared to ISO 27001 and ISO 9001, which means there is a real competitive edge available now. Being the vendor in your market that can demonstrate certified AI governance is a genuine commercial differentiator. That window will not stay open indefinitely. If you want a practical breakdown of the key steps to ISO 42001 certification, the Cloud Security Alliance have a helpful explainer. For ethical and governance framing, see our piece Ethical AI Made Practical: Why ISO 42001 Certification Matters.

Matching the Right Standard to Your Business Goals

Start with the Question Your Clients Are Actually Asking You

The decision is simpler than most people make it. If you are losing deals because buyers do not trust your data handling, ISO 27001 is your answer. If you are failing tender quality criteria or struggling to demonstrate consistent delivery processes, ISO 9001 solves that problem. If AI governance is appearing in due diligence questionnaires, ISO 42001 is worth getting ahead of now rather than in eighteen months.

Do not pursue a certification because it sounds impressive. Pursue the one that removes a real commercial obstacle. The best ISO certification for a software or IT company is always the one that unlocks your next revenue opportunity, not the one that looks most technical on your website.

Can You Run More Than One Standard at the Same Time?

Yes, and for many software companies it is the efficient route. ISO 27001 and ISO 9001 share overlapping clauses across the Annex SL structure: Clauses 4 through 10 covering context, leadership, planning, support, operations, performance evaluation, and improvement map directly between both standards. A combined implementation means one set of management reviews, one internal audit programme, and one certification audit. An Integrated Management System (IMS) approach can deliver both certifications for less time and cost than two sequential projects.

ISO 42001 is best layered in once the foundational management system is established. Its governance requirements build naturally on the risk management and document control infrastructure that ISO 27001 and ISO 9001 already require you to have in place.

What About IT Service Management Certification?

For managed service providers and IT support businesses, it is worth noting that ISO 20000, the international standard for IT service management (ITSM), sits alongside these three. If your clients are primarily buying managed IT services and evaluating you against ITSM maturity, ISO 20000 may be the more targeted choice. That said, the majority of software and IT companies find ISO 27001 or ISO 9001 delivers broader commercial return as a first certification, with ISO 20000 as a subsequent layer where service delivery contracts specifically call for it.

Getting Certified Without a Dedicated Compliance Team

Why Traditional Certification Routes Are Built for the Wrong Customer

Most established certification bodies design their processes around large enterprises with in-house compliance teams, document-heavy audit packs, and on-site assessors. For a ten-person SaaS company or a lean IT services firm, that model creates unnecessary friction: expensive consultants, unclear timelines, and an audit process that assumes resources you simply do not have.

The result is that many tech founders delay certification, or abandon it entirely, not because the standards are genuinely beyond them, but because the process was never designed with them in mind. The certification itself is achievable. The route to it is often the problem.

What a Purpose-Built Remote Certification Model Looks Like

We built ISO-Cert Online Ltd specifically to close that gap. Our fully remote audit model delivers accredited ISO certification without a single on-site visit, using a smart document portal that guides your team through the process step by step. There is no assumption that you have a compliance manager or a legal team. The process is structured for businesses without dedicated compliance staff. For more on how digital tools and automation speed certification, see Harnessing Technology: Digital Tools and AI for Streamlined ISO Certification.

Our advertised starting price of £875 removes the financial unpredictability that makes traditional certification feel risky for smaller businesses. Whether you are pursuing ISO 27001, ISO 9001, ISO 42001, or an integrated certification combining more than one standard, the process is purpose-built for lean teams that need to move efficiently without sacrificing accreditation quality.

The Decision Is Simpler Than It Looks

So, what is the best ISO certification for a software or IT company? ISO 27001 is the right first choice for most IT and software businesses where data security and enterprise access are the priority. ISO 9001 is the smarter starting point when your clients care more about delivery consistency and operational reliability. ISO 42001 is the forward-looking standard for companies building with or operating AI, and its early-adoption window is open now.

There is no universally correct answer across all software businesses. But there is a correct answer for your business, and it is determined by one straightforward question: what is your most immediate commercial obstacle? Start with the certification that removes it. Build from there. The companies that get this right are not the ones that researched longest. They are the ones that decided fastest and acted on it.

Frequently Asked Questions

What Is the Best ISO Certification for a Software or IT Company?

For most software and IT companies, ISO 27001 is the strongest first choice because it directly addresses the security due diligence that enterprise and public-sector buyers apply. If your clients are more focused on delivery quality than data security, ISO 9001 may be the better starting point. The right answer depends on which commercial obstacle you need to remove first.

What Is the Best ISO Certification for a SaaS Company?

ISO 27001 is typically the best ISO certification for a SaaS company, particularly one handling customer data or targeting enterprise buyers. The optional ISO 27017 and ISO 27018 extensions add cloud-specific and data-privacy controls that reinforce your position with privacy-conscious clients. If you are also embedding AI features into your product, ISO 42001 is worth planning for as a follow-on.

What Is the Best ISO for IT Services and Managed Service Providers?

IT service management businesses should evaluate ISO 27001 alongside ISO 20000, which is the dedicated IT service management (ITSM) certification. ISO 27001 tends to carry broader commercial value across more buyer types, but if your contracts explicitly reference ITSM standards or service delivery frameworks, ISO 20000 may be the more targeted choice.


Ready to get started?

Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.

Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.

Privacy Settings
We use cookies to enhance your experience while using our website. If you are using our Services via a browser you can restrict, block or remove cookies through your web browser settings. We also use content and scripts from third parties that may use tracking technologies. You can selectively provide your consent below to allow such third party embeds. For complete information about the cookies we use, data we collect and how we process them, please check our Privacy Policy
Youtube
Consent to display content from - Youtube
Vimeo
Consent to display content from - Vimeo
Google Maps
Consent to display content from - Google
Spotify
Consent to display content from - Spotify
Sound Cloud
Consent to display content from - Sound
Get a Quote