Germany

ISO certification consultancy in Germany

German demand is set by the automotive and machinery supply chains and by European regulation. Carmakers and tier one suppliers require IATF certification, customer specific requirements and increasingly information security assurance for engineering data and prototypes. Machinery, pressure equipment and medical device manufacturers must complete conformity assessment before placing products on the market. Energy intensive industries face emissions obligations and rely on energy management for relief and reporting. Privacy regulation is enforced strictly, and supply chain due diligence legislation has pushed German buyers to ask suppliers about labour and environmental conditions well beyond their own factory gates.

Chat on WhatsApp
States and cities
8
Priority standards
20
Delivery
Onsite, remote, hybrid

Get a quotation

Tell us what is being asked of you in Germany.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

Trusted in Germany

Organisations we have taken through certification, here and elsewhere.

Every organisation above started the same way you are starting: a requirement they had to meet and no certificate yet.

Chat on WhatsApp

Certification in Germany, sector by sector

Who asks for certification in Germany

The question worth answering before any other is who is asking. A buyer in Germany wanting assurance, a tender requiring a certificate, a regulator enforcing a rule and a parent company rolling out a policy will each accept a different scope, and choosing the wrong one is the most expensive mistake available at this stage.

ISO 9001 is asked of organisations in Germany whatever they do. Beyond that, what you are asked for depends on your sector, and the sections below set out what each of the industries that drive certification in Germany is actually asked to hold.

What Germany asks for that other markets do not

Most of what follows in this brief applies wherever you trade. These do not — they are specific to Germany, and an organisation that has worked through an international standard elsewhere can still arrive here and find something it has never been asked for before.

  • GDPR — GDPR Compliance
  • TISAX — TISAX Information Security Assessment

These sit alongside the international standards rather than replacing them, and they are usually the ones that hold up a launch, because they are the ones nobody planned for.

Automotive in Germany

The tiers set the rules. A supplier's own standards matter less than the OEM's, and the OEM's requirements are written as a certification scheme with no room to negotiate.

What an organisation in this sector in Germany is typically asked to hold:

  • IATF 16949 — IATF 16949 Automotive Quality Management System
  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • TISAX — TISAX Information Security Assessment
  • GDPR — GDPR Compliance
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting

The order matters more than the list. Take the one that is currently blocking something, build the system once, and the second and third certificates cost a fraction of the first because the system is already there.

More on this sector: Automotive.

Manufacturing in Germany

Supplier approval is where this starts. A plant that cannot show a system is one that gets audited by every customer separately, which costs more over a year than certification does.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • TISAX — TISAX Information Security Assessment
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • ISO 50001 — ISO 50001 Energy Management System
  • IATF 16949 — IATF 16949 Automotive Quality Management System

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Manufacturing.

Chemicals in Germany

Chemical operations carry obligations to a regulator, a neighbour and a customer at the same time, which is why the management system here tends to cover safety and environment together.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting
  • ISO 50001 — ISO 50001 Energy Management System
  • ISO/IEC 17025 — ISO/IEC 17025 Testing and Calibration Laboratories

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Chemicals.

Energy in Germany

Energy-intensive operations certify because efficiency has become a reporting obligation as well as a cost line, and reported figures now attract the same scrutiny as financial ones.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO 50001 — ISO 50001 Energy Management System
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO/IEC 17025 — ISO/IEC 17025 Testing and Calibration Laboratories
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO 37001 — ISO 37001 Anti-Bribery Management System

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Energy.

Oil and Gas in Germany

This sector certifies because the operators demand it of their supply chain, and because the consequences of the incident that certification is meant to prevent are borne publicly.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • ISO 50001 — ISO 50001 Energy Management System
  • ISO 26000 — ISO 26000 Social Responsibility Guidance
  • ISO 37001 — ISO 37001 Anti-Bribery Management System

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Oil and Gas.

Tell us what you need for certification in Germany

Who is asking for it, how many sites, and by when. The more specific you are, the more useful our first reply will be.

Electricals and Electronics in Germany

Product conformity comes first — a product that cannot be placed on the market is not a commercial proposition — and the management system is what makes conformity repeatable across production runs.

What an organisation in this sector in Germany is typically asked to hold:

  • CE Mark — CE Marking Conformity
  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Electricals and Electronics.

Information Technology in Germany

Nothing here is driven by a regulator. It is driven by the customer's procurement team: a security questionnaire before the contract, an annex naming a standard inside it, and a right to audit that somebody will eventually use. The certificate is what stops each of those becoming a three-week project.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • SOC — SOC 1 and SOC 2 Readiness
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System
  • TISAX — TISAX Information Security Assessment
  • GDPR — GDPR Compliance
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • CMMI — CMMI Appraisal Readiness

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Information Technology.

Telecommunication in Germany

Carrier contracts and enterprise tenders in this sector both tend to name standards directly, and the interconnect agreements that sit underneath them assume a management system is already there.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System
  • GDPR — GDPR Compliance
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • CMMI — CMMI Appraisal Readiness
  • SOC — SOC 1 and SOC 2 Readiness
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Telecommunication.

Banking and Finance in Germany

Banks, insurers and NBFCs carry two burdens: what the regulator requires and what the card schemes require, and the second is not optional for anybody who touches cardholder data. Certification is how both are demonstrated to somebody who will not take your word for it.

What an organisation in this sector in Germany is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • PCI DSS — PCI DSS Compliance
  • GDPR — GDPR Compliance
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • SOC — SOC 1 and SOC 2 Readiness
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System
  • ISO 41001 — ISO 41001 Facility Management System

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Banking and Finance.

Choosing a certification body in Germany

The body matters more than most organisations expect when they start, and for a reason unrelated to cost: its accreditation is what makes your certificate acceptable to the party that demanded it.

Accreditation is the first question and it has a local edge to it. A certificate is issued by a certification body, but the body is itself accredited by an accreditation body, and it is that second name the buyer's procurement team checks. Where an accreditation body is a signatory to the IAF Multilateral Recognition Arrangement, certificates issued under it are intended to be recognised in the other signatory countries — which is what matters if you are in Germany and selling abroad, or selling into Germany from outside it.

After that: sector competence, because an auditor who has audited your industry asks better questions and wastes less of your time; whether the party that triggered this names particular bodies, which is worth asking before you shortlist rather than after; and the diary and the travel, which in a market the size of Germany can decide the timetable more than the audit itself. Audit days are set by your headcount and scope, so quotes should be comparable — if one is far cheaper, look at the audit days before you look at the price.

Among the bodies most widely recognised, in no particular order: BSI, TÜV, SGS, SIS Certifications, Intertek, DNV, BVQI.

MSCi works with a pool of accredited certification bodies rather than one, and it is worth being plain about why that helps you: bodies differ in audit-day rates, in what it costs to get an auditor to your site, in how soon they can get one there, and in the sectors they are accredited for. Having several to approach means your scope goes to the ones that actually fit it and you get comparable quotes back, rather than taking the first number offered.

What it does not change is the audit. We cannot influence a finding and would not try — the body's independence is the entire value of the certificate, and a consultancy offering otherwise is selling something worthless. We prepare you so the audit is uneventful, and the body decides. Accreditation rules also prohibit the organisation that builds your management system from being the one that certifies it, which is why we prepare and never certify.

Where to start in Germany

The sequence below is the one that survives the audit. It is deliberately not "buy a set of documents", which is where most projects begin and the reason most of them take twice as long as they should.

  • Find out precisely what has been asked for, and by whom. A tender in Germany naming a standard, a customer's security annex and a regulator's requirement are three different jobs.
  • Fix the scope in writing — which sites in Germany, which activities, which products. Scope drives cost more than any other single decision, and widening it after the audit is booked is re-work.
  • Score yourself against the standard with the free readiness assessment on this site, then have the gaps confirmed on evidence rather than on a questionnaire.
  • Close the gaps in the work before closing them on paper. A procedure written to satisfy an auditor, rather than to describe what the people doing the job actually do, is the gap an auditor finds.
  • Choose the certification body with the accreditation your buyer recognises, and book the audit against a date the closure plan can actually meet.

We work across Germany onsite, remotely and as a mix of the two, and the choice is usually decided by where your sites are rather than by preference.

Scroll inside the panel for the rest of it.

Free · 15 minutes · assured discount

Score your certification in Germany readiness out of 100

Answer the questions an auditor would ask and see where you stand before anybody quotes you a price.

Have it as a document

Send me the certification in Germany checklist

The questions an auditor asks, to work through in your own time.

States and cities we work across

Baden-Wuerttemberg (Stuttgart, Karlsruhe)

Automotive engineering, machine tools and precision components where carmaker and tier one requirements set the standard.

Bavaria (Munich, Nuremberg, Ingolstadt)

Vehicle assembly, electronics, aerospace and medical technology with demanding supplier qualification processes.

North Rhine-Westphalia (Cologne, Duesseldorf, Ruhr)

Chemicals, steel, logistics and energy intensive industry facing emissions, energy and process safety obligations.

Lower Saxony (Wolfsburg, Hannover)

Automotive assembly and agricultural machinery, plus food processing supplying European retail groups.

Hesse (Frankfurt)

Banking, data centres and pharmaceuticals, where information security and privacy assurance drive supplier selection.

Hamburg and the north

Port logistics, aviation manufacturing and wind energy supply chains serving European and global customers.

Saxony (Dresden, Leipzig)

Semiconductors, automotive plants and electronics assembly with high volume manufacturing quality and process control requirements.

Rhineland-Palatinate and Saarland

Chemicals, automotive components and machinery makers supplying French and German assembly plants under tier one requirements.

Automotive and machinery supplier requirements

Holding business with a German carmaker or machine builder means meeting more than a certificate. Suppliers face customer specific requirements, production part approval processes, capability studies and escalation regimes when quality slips. Handling development data and prototypes brings its own assessed information security expectations across the automotive network. We help suppliers build quality management that survives customer audits, connect product conformity work to design and change control, and put in place information security appropriate to the sensitivity of the engineering data they receive rather than a generic policy set.

Energy, emissions and supply chain due diligence

Energy intensive German operations use certified energy management to support reporting obligations and to make efficiency projects defensible, and emissions accounting is now expected by customers as well as regulators. Supply chain due diligence duties have made large buyers responsible for conditions at their suppliers, so questionnaires about working conditions, environmental controls and grievance mechanisms now reach small manufacturers abroad and at home. We help organisations set up energy and greenhouse gas measurement that stands up to verification, and supplier assessment processes that produce evidence rather than unread self declarations.

Why bring in a consultant here

1

Your team already has a day job

Running certification in Germany in house means taking your most capable people off revenue work for months. For most organisations that hidden cost is larger than the fee for doing it properly.

2

Integration saves real money

If certification in Germany sits alongside other standards you hold, running them as one system means one document set and one audit rather than paying for the same work several times over.

3

The standard says what, never how

certification in Germany is written to apply to every organisation on earth, which is exactly why it never tells you what to do in yours. Turning a clause into your process, on your sites, with your people, is the actual work.

4

Scope decides the price

Getting the certification in Germany scope wrong is expensive in both directions. Too wide and you pay for audit days you never needed. Too narrow and the certificate does not cover what your customer asked about.

What clients in Germany say

Every engagement above ended with an independent assessor, not with us. We prepare you for the audit; the certificate is granted by an accredited body, and that separation is what makes the preparation worth paying for.

Each of these letters was written after the audit was passed, not before it was booked. Tell us your deadline and we will tell you honestly what reaching it takes.

Insights, news and know-how

Guidance from our consultants, with anything about this market first in each column.

All articles →

Blogs

Working notes from the consultants.

See all blogs

News

What has changed, and when it bites.

See all news

Articles

Longer pieces on one subject.

See all articles

Knowledge base

How things are actually done.

See all knowledge base

Working to a deadline in Germany?

Tell us the date and what is being asked for, and we will tell you whether it is achievable before we quote.

Chat on WhatsApp