Frequently asked questions
Answers before you ask
Common questions about working with ABS — the process, timelines, recognition and the standards we work with. Don't see yours? Ask us.
Getting started
ABS provides consulting, implementation and certification-readiness support. Accredited ISO certificates are issued by independent certification bodies after successful completion of their audit and certification-decision process.
Tell us your scope — the standard you want, your organisation size, number of sites and any existing certifications — and we send a fixed-price proposal within 24 hours. You can use the Request-a-quote form or the contact page.
For most organisations under 200 employees, the full path from kick-off to certificate is around 10–14 weeks, assuming the management system is already operating. Larger or multi-site organisations typically take 4–6 months. You receive a firm timeline with your quote.
Most of it, yes. Gap analysis, documentation review, training and audit preparation are routinely delivered fully remotely. Some standards — for example ISO 45001, where site safety must be observed — involve an on-site element, and your certification body may require an on-site audit. We confirm the approach for your scope upfront.
No. If you already have policies and controls in place, we assess what exists against the standard. Where there are gaps, the Stage 1 report tells you exactly what to close before Stage 2 — you are never left guessing.
The certification process
Stage 1 reviews whether your management system is documented and ready — checking policies, scope and readiness, and surfacing any gaps early. Stage 2 assesses whether the system is genuinely implemented and effective, through interviews, records and observation. See our full process page for the four phases.
A non-conformity is a finding to be addressed, not a failure. You implement corrective action within an agreed timeframe and your certification body verifies it. Certification proceeds once findings are closed. Our approach is to surface gaps during our gap analysis, so material issues rarely appear for the first time at Stage 2.
Certification is maintained through regular surveillance audits — typically annual — and renewed through a recertification audit at the end of the three-year cycle for most ISO standards. If your organisation changes materially, scope changes can be assessed and added at the appropriate point.
Once any Stage 2 findings are closed and the independent certification decision is made, the certificate is issued. For most organisations under 200 employees the full journey is around 10–14 weeks.
Recognition, cost & scope
Yes. We prepare you for certification against internationally recognised standards such as ISO 9001 and ISO 27001. The certificate itself is issued by an independent certification body — we help you select an appropriately accredited one and get you audit-ready. Recognition depends on that body, its accreditation and the relevant accreditation scope, so the certificate carries weight with customers and regulators wherever you operate.
Our consulting fees depend on the standard, organisation size, number of sites and complexity of scope, and every engagement starts with a fixed-price scoping call and a proposal within 24 hours. Note that the independent certification body charges its own separate audit, surveillance and recertification fees, which we identify clearly so there are no surprises.
Yes. Many organisations pursue integrated management systems — for example ISO 9001, ISO 14001 and ISO 45001 together, or ISO 27001 with ISO 27701. Shared structure means evidence can be reused across standards, reducing effort and cost.
IAF does not directly accredit certification bodies. Certification bodies are accredited by accreditation bodies that may be members of the IAF Multilateral Recognition Arrangement. Accreditation and scope should be verified directly through the relevant accreditation body or IAF CertSearch, where applicable.
About the standards
ISO 27001 is the international standard for a risk-based information security management system; SOC 2 is an AICPA attestation focused on whether your controls meet specific trust criteria. ISO 27001 is more widely recognised internationally; SOC 2 is the default in US enterprise and SaaS. Many organisations hold both.
Not every Annex A control is automatically mandatory. The organisation determines applicable controls based on its information security risks, legal obligations and business requirements, and records the justification for inclusion or exclusion in the Statement of Applicability.
No. ISO/IEC 27017 and ISO/IEC 27018 are guidance standards normally used alongside ISO/IEC 27001. Their implementation may be assessed as part of a wider ISMS engagement, subject to the assessment scheme being used.
HACCP is the method for identifying and controlling food safety hazards; ISO 22000 wraps those principles inside a full, certifiable management system. FSSC 22000 builds further on ISO 22000 to become GFSI-recognised.
No — CMMI maturity is confirmed through an appraisal (the current CMMI Appraisal Method) led by a Certified Lead Appraiser, not a certificate. Organisations are "appraised at" a maturity level, and the result is typically valid for three years.
No. SMETA is an ethical audit developed by Sedex; the deliverable is an audit report shared on the Sedex platform, not a certificate. Buyers request it for responsible-sourcing due diligence.