Short answer: Most small and mid-sized Malaysian organisations achieve certification in 3 to 6 months. Simpler businesses that already have documented processes can move faster; larger or multi-site operations, or those starting from scratch, take longer. The certification body also needs your system to have been running for a short period before the audit, so there is a minimum "operating" time you cannot skip.

The phases of an ISO certification project

Certification follows a fairly consistent path regardless of the standard (ISO 9001, 27001, 14001, 45001, 22301 or 37001). The timeline below assumes a typical SME with reasonable engagement from the team.

PhaseWhat happensTypical time
Gap analysisReview current state vs. the standard; plan the work.1–2 weeks
Design & documentationBuild the procedures, policies and records required.3–8 weeks
Training & implementationTrain the team; roll the system out; start using it.3–8 weeks (overlaps)
Operate the systemRun the system so there are records to audit.3–6 weeks minimum
Internal audit & management reviewTest the system; fix findings; leadership review.1–2 weeks
Stage 1 & Stage 2 certification auditCertification body audits; you close any findings.2–6 weeks

What speeds it up

  • Existing documentation. If your processes are already written down, there is less to build.
  • A dedicated process owner. A Management Representative with real time allocated keeps momentum.
  • Leadership buy-in. Decisions get made quickly and staff take it seriously.
  • Consulting support. A guide who has done it before avoids the common dead-ends.
  • Right-sized scope. Certifying what you actually do — not everything imaginable.

What slows it down

  • Starting from a blank page with no documented processes.
  • The project being "everyone's job" and therefore no one's.
  • Multiple sites or complex, high-risk operations.
  • Waiting too long to book the certification body.
  • Trying to build an over-complicated system nobody follows.

Does the standard change the timeline?

The framework is similar across standards, but the content differs. ISO 27001, for example, includes a risk assessment and Statement of Applicability; ISO 22301 needs a business impact analysis and continuity tests. These specifics can add time, which is why a realistic plan is set at the start rather than guessed at.

Get a realistic date for your business

The best way to know your timeline is a short conversation about where you stand today. Book a free consultation and Irvin will map out a realistic schedule — and show you the HRD Corp claimable training that fits into it.

Frequently asked questions

IT
Written by Irvin T.

HRD Corp accredited ISO trainer & consultant. ISO 9001, 27001, 14001, 45001, 22301 & 37001. About Irvin →