Insights · 5 min read
The full granting path: from application to decision, in one map
Certification is not an inspection followed by a certificate. It is a defined sequence with named stages, an independent decision point, and a…
Published by CAS — Conformity Assessment Services · 4 September 2026
Certification is not an inspection followed by a certificate. It is a defined sequence with named stages, an independent decision point, and a three-year cycle that begins the day the certificate is issued. Most of the friction organizations experience comes from not knowing which stage they are in.
Here is the whole path.
Stage 0 — Application review
Before anything is scheduled, the certification body reviews the application to establish that it can actually do the work. That means confirming the requested scope falls inside its accredited scope, that it holds the competence for your sector, and that no impartiality conflict exists.
That last check is not a formality. ISO/IEC 17021-1 clause 5.2.7 bars a certification body from certifying an organization that received management system consultancy from a related body for two years after that consultancy ends. Clause 5.2.10 does the same for individual personnel. If either applies, the honest answer at this stage is no — and it is far better received now than after a contract is signed.
The application review also gathers what determines audit duration: the effective number of personnel including part-time, seasonal and shift workers, the number of sites, the processes in scope, and the complexity of your activities.
Stage 0.5 — Audit duration, calculated not quoted
Audit days are not a commercial variable. They are calculated under IAF MD 5, from your effective headcount and complexity, with defined limits on how far a certification body may adjust the result.
This is why a body that quotes you a day-count on a phone call, before knowing your headcount and sites, is guessing. And why two quotes that differ substantially for the same organization deserve a question about which one did the calculation.
Stage 1 — The readiness audit
Stage 1 is not an introductory visit. It is an audit with defined outputs, conducted to establish whether you are ready for Stage 2.
The team examines your documented information, evaluates your site conditions, reviews your understanding of the standard's requirements, checks that internal audits and management review have been planned and performed, and confirms the scope, processes and any statutory requirements. It ends with documented findings and, where readiness is not established, a clear statement of what must change.
Stage 1 findings are not nonconformities against certification. They are a readiness assessment. Treating them as a scorecard misreads the stage.
The interval between stages
There is a gap between Stage 1 and Stage 2, and it exists for you. It is time to address what Stage 1 surfaced.
The certification body sets it based on what it found. If Stage 1 revealed that internal audits had not covered the full scope, the interval has to be long enough for that to be genuinely fixed — not long enough for a document to be produced.
Where the interval becomes long enough that conditions may have changed, Stage 1 may need to be repeated. That is not an administrative penalty; it is the only way the readiness conclusion remains true.
Stage 2 — The certification audit
Stage 2 evaluates implementation and effectiveness. Not whether procedures exist — whether the system works and delivers what the standard requires.
The audit team gathers evidence of performance against objectives, conformity with all applicable requirements, operational control, internal auditing and management review, management responsibility, and the links between policy, objectives, and results.
Findings are classified. A major nonconformity affects the capability of the management system to achieve intended results. A minor one does not, on its own. Both require correction and corrective action, and the distinction determines what happens next — not whether you are judged harshly.
Here is where the most common misunderstanding sits: correction is not corrective action. Fixing the instance is correction. Finding why it happened and removing that cause is corrective action. A response that only does the first is incomplete, and it will come back.
The decision — and who takes it
The audit team does not decide.
The certification body makes the certification decision through personnel who did not carry out the audit. This is a structural separation, required by ISO/IEC 17021-1, and it exists to prevent a team from ratifying its own work.
The decision is based on the audit report, the findings and their resolution, and any other relevant information. It is granted where there is sufficient objective evidence of conformity, and not granted where there is not.
Which is why no certification body can promise you an outcome. The people you talk to are not the people who decide, and the decision rests on evidence rather than on relationship.
After the certificate: a three-year cycle
The certificate is the beginning of the cycle, not the end of the process.
Surveillance audits are conducted at least annually — the first within 12 months of the Stage 2 decision. They are not repeat full audits, but each one must cover internal audits and management review, actions on previous findings, complaints handling, progress toward objectives, continuing operational control, changes, and use of marks.
Recertification happens before the certificate expires. It reviews the performance of the system over the full cycle, including all prior surveillance reports, and considers the system as a whole.
Suspension, reduction, withdrawal. A certification can be suspended — under clause 9.6.5.3 a suspended certification is temporarily invalid — reduced in scope, or withdrawn. These are defined outcomes with defined triggers, not discretionary punishments.
What this means practically
Know your stage. Most frustration comes from expecting Stage 2 behaviour during Stage 1, or reading a Stage 1 finding as a failure.
Ask how the days were calculated. Not what they cost — how they were derived. The answer tells you whether the body follows IAF MD 5 or estimates.
Answer findings with causes, not documents. Corrective action asks why. A response that only produces a revised procedure has answered a different question.
Plan for the cycle. Surveillance is not an interruption of business as usual; it is the mechanism by which the certificate keeps meaning something between issue and expiry.