Skip to content
itmad
← All articles

How to Get ISO Certification in the UAE: The Process, and What It Actually Costs

Certification cost is mostly a calculation, not a quote — audit duration is set by IAF MD 5, not by the certification body. Here is the process end to end, and how to read a quotation.

Most guides to ISO certification describe the steps and stop short of the two things people actually want to know: what it costs, and why.

Start with what it costs, because that answer is knowable

Certification pricing looks opaque, but the largest component is not a matter of opinion. Audit duration is determined by IAF MD 5, a mandatory document that every accredited certification body must apply.

It works from your effective number of personnel — headcount adjusted for part-time, shift and repetitive work — combined with a risk category for your activity, to produce a required number of audit days. Multiple sites, multiple standards and integrated systems then adjust it further.

Three consequences follow, and they are worth knowing before you request quotes:

Certification bodies have limited room to discount. The day count is set by the rules, not by the sales conversation. What varies is the day rate and travel.

A quote significantly below the others usually means fewer audit days than the calculation requires. That is a non-conformity against the certification body’s own accreditation, and it puts the resulting certificate at risk — which is your problem, not theirs, when a client questions it.

A credible quote requires real information. Any provider who prices before asking your headcount, site count and activities is not applying MD 5. That tells you something.

Beyond the audit itself, budget separately for: implementation work if you need help building the system, training, and annual surveillance audits — typically around a third of the initial audit duration each year, with recertification in year three.

The process, end to end

1. Choose the right standard. ISO 9001 for quality, ISO 14001 for environment, ISO 45001 for occupational health and safety, ISO 22000 for food safety, ISO 27001 for information security. The right answer usually comes from what your clients or regulator are asking for. If a tender named a standard, that is your answer.

2. Define the scope. Which activities, which sites, which locations. Scope drives audit duration, and therefore cost. An unnecessarily broad scope is a permanent expense.

3. Build the management system. Policy, objectives, documented processes, risk assessment, operational controls, monitoring, and clear responsibilities. If you do not have the internal capability, this is where you engage a consultant — and it must be a different organisation from the one certifying you.

4. Train the people who will run it. Awareness for everyone in scope, internal auditor training for those who will audit it. A system nobody understands fails Stage 2.

5. Run internal audits. The single highest-value step, and the most skipped. Your internal audit should be harder than the certification audit. Anything you find yourself costs a fraction of what a certification body finding costs.

6. Hold the management review. Top management reviews audit results, performance, complaints, risks and improvement opportunities. This is a documented requirement, not a formality — and its absence is a common finding.

7. Close out corrective actions before scheduling the certification audit.

8. Stage 1 and Stage 2. Detail below.

9. Certification decision — made independently of the audit team, then annual surveillance and recertification in year three.

Stage 1 and Stage 2

Stage 1 Stage 2
Purpose Readiness Effectiveness
Focus Documentation, scope, context, legal requirements, internal audit and management review completion Implementation across the organisation
Method Document review, limited site presence Interviews, observation, records, process walkthroughs
Outcome Confirmation you are ready, or a list of what to fix first Findings, then the certification decision

Stage 1 exists to stop you failing Stage 2. If Stage 1 raises significant gaps, fix them before proceeding — going ahead anyway is how organisations end up paying for two Stage 2 audits.

Why organisations fail

Auditors are checking whether you do what your system says you do, and whether it works. Failures cluster in four places:

  • Documentation with no implementation — a manual nobody has read
  • No objective evidence — the process happens but leaves no record
  • Weak employee awareness — staff cannot describe their responsibilities under the system
  • Internal audits that found nothing — which tells an auditor your internal audit is not functioning

One thing to check about any certification body

Under ISO/IEC 17021, an accredited certification body cannot provide consultancy on the management system it certifies. Impartiality rules prohibit it. This is not a technicality — it is the basis on which your certificate has value to a third party.

If a provider offers to build your system and then certify it, either they are not accredited, or they are operating against their accreditation. Either way the certificate will not stand up to scrutiny from a client who checks.

itmad is an accredited certification body. We audit; we do not consult on the systems we audit. When you need implementation help, we will say so and stay out of it.

Verify any certification body’s accreditation before appointing it — IAF CertSearch is the global database for accredited management system certificates.

Going deeper

Common questions

How long does certification take? From a standing start, months rather than weeks — implementation is the long pole, not the audit. An organisation with existing structured processes moves considerably faster.

Can we get certified without a consultant? Yes. Many organisations implement internally, particularly with trained internal auditors. Consultancy buys speed, not a different outcome.

Which standard should a small business start with? Usually whichever one a client or tender has asked for. Absent that, ISO 9001 is the common entry point because it addresses how the business runs rather than one specialised risk.

What is the difference between accredited and non-accredited certification? An accredited certificate is issued by a body assessed as competent and impartial by an accreditation body. A non-accredited certificate is issued by an organisation nobody has assessed. Both are printable. Only one is verifiable.

Do we get audited every year? Yes — surveillance audits annually, shorter than the initial certification audit, with a full recertification in year three.


Request a certification proposal — tell us your headcount, sites and activities and we will quote against the audit duration those require.

This article is provided for information only and does not constitute professional or compliance advice. ITMAD accepts no liability for any action taken in reliance on it.