Skip to content
Soni And Soni, Soni And Soni, Advocates & Attorneys

Licence & Approvals

ISO Certification & Consultation Services in India

An ISO certificate tells customers, tender committees and overseas buyers that your business follows an international standard. Soni And Soni helps you choose the right ISO standard, prepare your business for the certification audit, and keep the certificate valid after it is issued.

The ground

What you are actually dealing with

What is ISO certification?

ISO certification means an independent certification body has checked your business and confirmed that it meets an international standard, such as ISO 9001 for quality. The standards are written by ISO, the International Organization for Standardization, but ISO itself does not issue certificates. People also call this ISO registration; it is the same thing, and there is no government register to sign up on.

Who can issue an ISO certificate in India?

Only a certification body can issue it. In India, these bodies are approved (accredited) by NABCB, the National Accreditation Board for Certification Bodies, which is part of the Quality Council of India set up by the Ministry of Commerce and Industry. NABCB is a member of the International Accreditation Forum, so a certificate from a NABCB-accredited body is accepted abroad too. The Bureau of Indian Standards (BIS), India's national standards body, also issues ISO certificates through its Manak Online portal.

How does the ISO certification process work?

You apply to a certification body, which then audits your business in two stages. Stage 1 checks your documents and whether you are ready. Stage 2, held only after Stage 1 is cleared, checks that you actually work the way your documents say. If you pass, the certificate is issued. It is valid for three years, with a shorter check-up audit (surveillance audit) usually once a year, and a full renewal audit at the end of the three years.

Which ISO standard does my business need?

Most businesses start with ISO 9001, the quality standard. When a tender or a customer asks for ISO certification without naming one, this is usually what they mean. Other common standards are ISO 14001 (environment), ISO 45001 (workplace health and safety), ISO/IEC 27001 (information security), ISO 22000 (food safety), ISO 13485 (medical devices), ISO 50001 (energy) and ISO/IEC 20000-1 (IT services). A business can hold more than one and have them audited together.

ISO certification does not replace a legal licence

ISO certification is voluntary. Businesses get it because customers, buyers or tenders ask for it. It does not replace any licence or registration the law requires, such as an FSSAI licence for a food business, a licence under the Medical Devices Rules, 2017 for a medical device maker, or pollution control consents for a factory. A good ISO system makes these easier to manage, but you still need them.

Our part

What we bring to your ISO certification

The steps to certification are the same everywhere. What makes the difference is getting it right the first time and keeping it right afterwards. As a law firm, we look at your certificate together with the legal obligations around your business.

  • 01

    A system that fits your business. Built around the way your team already works, not copied from a template, so people can actually follow it after the audit.

  • 02

    Legal compliance checked alongside ISO. We flag the licences, registrations and consents your business needs, such as an FSSAI licence, pollution control consents or a licence under the Medical Devices Rules, which an auditor will expect to see in order.

  • 03

    Accredited certification bodies only. We steer you away from certificates issued by unaccredited bodies, which tenders and overseas buyers often reject.

  • 04

    Support after the certificate. We stay with you for the yearly surveillance audits, the renewal and moves to new editions such as ISO 9001:2026, so the certificate stays valid.

Scope

What this engagement covers

  • Choosing the right ISO standard and scope
  • Gap analysis and ISO documentation
  • Internal audit and management review
  • Support during Stage 1, Stage 2 and yearly surveillance audits
  • Renewal audits and moving to new editions of a standard
  • ISO 9001, 14001, 45001, 27001, 22000, 13485 and 50001

How it runs

The process, stage by stage

No stage carries a promised date. The certification body's audit schedule is not ours to commit on your behalf. What we commit to is doing our part of each stage without delay.

  1. 01

    Choose the standard

    We agree which ISO standard you need and which sites and activities the certificate will cover.

  2. 02

    Gap analysis

    We compare how your business works today with what the standard requires, and list what is missing.

  3. 03

    Prepare the system

    We write the policies, procedures and records you need, and train your team to follow them.

  4. 04

    Internal audit

    We run a practice audit and a management review, and fix any gaps before the certification body visits.

  5. 05

    Certification audit

    An accredited certification body audits you in two stages and issues the certificate. We stay with you for the yearly audits after that.

Common questions

Questions we are asked most often

No. Only an independent certification body can issue an ISO certificate, after its own audit. A consultant cannot, and neither can ISO itself. We prepare your business for that audit, help you choose an accredited certification body, and support you through the audit and the yearly checks after it.

Related · Licence & Approvals

TelluswhatIPyouneed to protect, and where?