What's included
ISO 9001 certification is not a documentation project. A certification body needs to see records of a system that has actually been running, which is why the internal audit and management review sit before the external audit rather than beside it:
- Gap analysis & planning, Scope and context of the organization, certification body selection, a structured gap analysis against the standard, and the project plan that comes out of it. Milestone: gap analysis complete.
- Process mapping & risk, Core process mapping, interested parties and their requirements, the risk and opportunity register, and quality objectives with measurable KPIs.
- QMS documentation, Quality policy and manual, documented procedures, work instructions and forms, document control and the records retention schedule. Milestone: documentation released.
- Implementation & training, Awareness training for all staff, process owner training, and a period of actually running the processes so there are records to audit.
- Internal audit & corrective action, Internal auditor training, the full internal audit programme, nonconformity reports and corrective actions closed out with evidence.
- Management review, Compiling the review inputs, the management review meeting itself, and the actions arising. Milestone: certification readiness confirmed.
- Certification audit, Stage 1 documentation and readiness review, closure of Stage 1 findings, the Stage 2 implementation audit, nonconformity closure and the certification decision. Milestone: certificate issued.
- Surveillance, The continual improvement cycle, a second internal audit round and the year-one surveillance audit that keeps the certificate valid.
Who uses this template
Quality managers and operations leads across manufacturing and services use this to gain ISO 9001 certification. It runs from gap analysis and QMS documentation through internal audit and management review to the Stage 1 and Stage 2 audits and ongoing surveillance, turning the standard into a paced project rather than a scramble before the auditor arrives.
How to customize it
- Pick your certification body early and enter their real availability, audit slots are booked months ahead and they set your outer date.
- Extend the implementation period if your processes have long cycles; you need records covering a representative period, not a fortnight.
- Add one row per process area during mapping and internal audit so coverage is visible rather than assumed.
- Insert a corrective action row per major nonconformity once Stage 1 findings land; each has its own evidence and closure date.
- Mark documentation released, readiness confirmed, Stage 2 complete and certificate issued as milestones, those are the board-level dates.
- If you already hold another management system certificate, shorten the documentation phase and reuse the shared clauses rather than rewriting them.
Scheduling tips
- Do not write documents you will not follow. Auditors test the system against your own procedures, so an over-specified manual creates nonconformities that a simpler one would not.
- Run the internal audit as if it were the real thing. It is the cheapest possible rehearsal, and findings raised internally are improvements rather than nonconformities.
- Leave real time between Stage 1 and Stage 2. Four to eight weeks is normal; closing findings properly costs less than a repeat audit.
- Get management review inputs collected in advance. The meeting is a required record with a defined input list, and assembling it on the day produces a thin record an auditor will notice.
- Keep the surveillance cycle on the chart. Certification is the start of an annual rhythm, and organizations that drop the schedule after the certificate scramble twelve months later.
- Baseline at documentation release. Everything before it is set-up; after it, variance against the audit dates is what matters.
Related templates
- Internal Audit Plan Template
- Project Management Gantt Chart Template
- SOC 2 Compliance Timeline Template
- Browse all Gantt chart templates
Frequently asked questions
How long does ISO 9001 certification take?
Typically 6-12 months for an organization starting from scratch, and faster where a documented system already exists. This template runs about eighteen months because it carries through to the first surveillance audit; the certificate itself lands around month twelve.
What is the difference between a Stage 1 and Stage 2 audit?
Stage 1 is largely a documentation and readiness review that checks whether your QMS is capable of being audited. Stage 2 tests whether it is actually implemented and effective, using records and interviews. Both are separate phases here with a closure period between them.
Do I need an internal audit before certification?
Yes. The standard requires internal audits and a management review to have been carried out, and a certification body will look for those records at Stage 1. That is why both sit before the external audit in this plan.
What happens if the auditor raises a nonconformity?
Minor findings are usually closed with a corrective action plan and evidence within a set period; major findings can require another visit. The template includes a closure bar after each stage for exactly this.
Is the ISO 9001 plan template free?
Yes. Free Excel, PowerPoint and CSV downloads, and free online editing with no sign-up.