South Africa

ISO certification consultancy in South Africa

South Africa combines a deep mining and manufacturing base with a formal procurement culture. Mine operators require contractors to demonstrate health and safety management before site access, and mine health and safety obligations carry personal liability for managers. Automotive plants in the Eastern Cape and KwaZulu-Natal impose IATF requirements throughout their supplier base. Retail chains require recognised food safety scheme certification from suppliers, and fruit and wine exporters answer to European importers. Public and state owned enterprise tenders use scored criteria where certification and transformation credentials both count. Privacy legislation applies broadly and has made information governance a board level issue.

Chat on WhatsApp
Provinces and cities
8
Priority standards
25
Delivery
Onsite, remote, hybrid

Get a quotation

Tell us what is being asked of you in South Africa.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

Trusted in South Africa

Organisations we have taken through certification, here and elsewhere.

Every organisation above started the same way you are starting: a requirement they had to meet and no certificate yet.

Chat on WhatsApp

Certification in South Africa, sector by sector

Who asks for certification in South Africa

The question worth answering before any other is who is asking. A buyer in South Africa wanting assurance, a tender requiring a certificate, a regulator enforcing a rule and a parent company rolling out a policy will each accept a different scope, and choosing the wrong one is the most expensive mistake available at this stage.

ISO 9001 is asked of organisations in South Africa whatever they do. Beyond that, what you are asked for depends on your sector, and the sections below set out what each of the industries that drive certification in South Africa is actually asked to hold.

Automotive in South Africa

Nothing enters an automotive supply chain uncertified. It is the one sector where the scheme is effectively a condition of trading rather than a differentiator.

What an organisation in this sector in South Africa is typically asked to hold:

  • IATF 16949 — IATF 16949 Automotive Quality Management System
  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System
  • ISO/IEC 42001 — ISO/IEC 42001 Artificial Intelligence Management System
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System

The order matters more than the list. Take the one that is currently blocking something, build the system once, and the second and third certificates cost a fraction of the first because the system is already there.

More on this sector: Automotive.

Manufacturing in South Africa

A factory is usually pushed into certification by its customers rather than by a regulator. The first serious buyer sends a supplier questionnaire, the second sends an auditor, and by the third it is cheaper to hold the certificate than to keep hosting audits.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • IATF 16949 — IATF 16949 Automotive Quality Management System
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • BRC — BRC Global Standards
  • CTPAT — CTPAT Supply Chain Security
  • FSSC 22000 — FSSC 22000 Food Safety System Certification

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Manufacturing.

Public Sector in South Africa

Public bodies certify for the reason they do most things: to be able to show the decision was made properly. Service continuity, information handling and procurement conduct all have to survive scrutiny after the fact.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System
  • ISO/IEC 42001 — ISO/IEC 42001 Artificial Intelligence Management System
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • ISO 26000 — ISO 26000 Social Responsibility Guidance
  • ISO 41001 — ISO 41001 Facility Management System

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Public Sector.

Chemicals in South Africa

Handling, storage and discharge are all watched, and the customers are usually manufacturers with their own audit programmes. Certification answers both audiences with one system.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO/IEC 17025 — ISO/IEC 17025 Testing and Calibration Laboratories
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting
  • ISO 50001 — ISO 50001 Energy Management System

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Chemicals.

Energy in South Africa

Two pressures at once: the cost of what is consumed, and what has to be reported about it. Certification gives the first a method and the second an auditable basis.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO 50001 — ISO 50001 Energy Management System
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System
  • ISO/IEC 17025 — ISO/IEC 17025 Testing and Calibration Laboratories
  • ISO 14001 — ISO 14001 Environmental Management System
  • ISO 14064 — ISO 14064 Greenhouse Gas Quantification and Reporting
  • ISO 37001 — ISO 37001 Anti-Bribery Management System

The order matters more than the list. Take the one that is currently blocking something, build the system once, and the second and third certificates cost a fraction of the first because the system is already there.

More on this sector: Energy.

Tell us what you need for certification in South Africa

Who is asking for it, how many sites, and by when. The more specific you are, the more useful our first reply will be.

Food and Food Products in South Africa

Retailers and export buyers set the terms here, and they set them above what food law requires. A domestic licence lets you trade; a retailer scheme is what gets you onto the shelf.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO 22000 — ISO 22000 Food Safety Management System
  • BRC — BRC Global Standards
  • FSSC 22000 — FSSC 22000 Food Safety System Certification
  • HACCP — HACCP Food Safety System
  • SEDEX — Sedex and SMETA Audit Readiness
  • SA8000 — SA8000 Social Accountability
  • ISO 45001 — ISO 45001 Occupational Health and Safety Management System

Not all at once. Most organisations start with the one the customer named and add the others as they are asked for, which is both cheaper and easier to sustain than a programme that tries to do everything in one year.

More on this sector: Food and Food Products.

Information Technology in South Africa

Software buyers stopped taking assurances some years ago. What they ask for now is evidence held by somebody who is not you — which is why a certificate closes a deal that a well-written policy does not.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • SOC — SOC 1 and SOC 2 Readiness
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System
  • ISO/IEC 42001 — ISO/IEC 42001 Artificial Intelligence Management System
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • CMMI — CMMI Appraisal Readiness

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Information Technology.

Telecommunication in South Africa

Operators are asked for two things at once: that the network stays up, and that what crosses it stays private. Licence conditions cover some of it, enterprise customers and their own audit departments cover the rest.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System
  • ISO/IEC 42001 — ISO/IEC 42001 Artificial Intelligence Management System
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • CMMI — CMMI Appraisal Readiness
  • SOC — SOC 1 and SOC 2 Readiness

The order matters more than the list. Take the one that is currently blocking something, build the system once, and the second and third certificates cost a fraction of the first because the system is already there.

More on this sector: Telecommunication.

Banking and Finance in South Africa

Financial services buy certification because their own supervisors and their payment partners each ask for evidence, and because an outsourcing arrangement transfers the work but not the accountability.

What an organisation in this sector in South Africa is typically asked to hold:

  • ISO/IEC 27001 — ISO/IEC 27001 Information Security Management System
  • PCI DSS — PCI DSS Compliance
  • ISO 20000-1 — ISO/IEC 20000-1 IT Service Management System
  • ISO/IEC 42001 — ISO/IEC 42001 Artificial Intelligence Management System
  • ISO/IEC 27701 — ISO/IEC 27701 Privacy Information Management System
  • ISO 22301 — ISO 22301 Business Continuity Management System
  • SOC — SOC 1 and SOC 2 Readiness

These overlap more than their titles suggest. A single management system can carry several of them, audited together, which is the difference between one annual audit and three.

More on this sector: Banking and Finance.

Choosing a certification body in South Africa

The body matters more than most organisations expect when they start, and for a reason unrelated to cost: its accreditation is what makes your certificate acceptable to the party that demanded it.

Accreditation is the first question and it has a local edge to it. A certificate is issued by a certification body, but the body is itself accredited by an accreditation body, and it is that second name the buyer's procurement team checks. Where an accreditation body is a signatory to the IAF Multilateral Recognition Arrangement, certificates issued under it are intended to be recognised in the other signatory countries — which is what matters if you are in South Africa and selling abroad, or selling into South Africa from outside it.

After that: sector competence, because an auditor who has audited your industry asks better questions and wastes less of your time; whether the party that triggered this names particular bodies, which is worth asking before you shortlist rather than after; and the diary and the travel, which in a market the size of South Africa can decide the timetable more than the audit itself. Audit days are set by your headcount and scope, so quotes should be comparable — if one is far cheaper, look at the audit days before you look at the price.

Among the bodies most widely recognised, in no particular order: BSI, TÜV, SGS, SIS Certifications, Intertek, DNV, BVQI.

MSCi works with a pool of accredited certification bodies rather than one, and it is worth being plain about why that helps you: bodies differ in audit-day rates, in what it costs to get an auditor to your site, in how soon they can get one there, and in the sectors they are accredited for. Having several to approach means your scope goes to the ones that actually fit it and you get comparable quotes back, rather than taking the first number offered.

What it does not change is the audit. We cannot influence a finding and would not try — the body's independence is the entire value of the certificate, and a consultancy offering otherwise is selling something worthless. We prepare you so the audit is uneventful, and the body decides. Accreditation rules also prohibit the organisation that builds your management system from being the one that certifies it, which is why we prepare and never certify.

Where to start in South Africa

The sequence below is the one that survives the audit. It is deliberately not "buy a set of documents", which is where most projects begin and the reason most of them take twice as long as they should.

  • Find out precisely what has been asked for, and by whom. A tender in South Africa naming a standard, a customer's security annex and a regulator's requirement are three different jobs.
  • Fix the scope in writing — which sites in South Africa, which activities, which products. Scope drives cost more than any other single decision, and widening it after the audit is booked is re-work.
  • Score yourself against the standard with the free readiness assessment on this site, then have the gaps confirmed on evidence rather than on a questionnaire.
  • Close the gaps in the work before closing them on paper. A procedure written to satisfy an auditor, rather than to describe what the people doing the job actually do, is the gap an auditor finds.
  • Choose the certification body with the accreditation your buyer recognises, and book the audit against a date the closure plan can actually meet.

We work across South Africa onsite, remotely and as a mix of the two, and the choice is usually decided by where your sites are rather than by preference.

Scroll inside the panel for the rest of it.

Free · 15 minutes · assured discount

Score your certification in South Africa readiness out of 100

Answer the questions an auditor would ask and see where you stand before anybody quotes you a price.

Have it as a document

Send me the certification in South Africa checklist

The questions an auditor asks, to work through in your own time.

Provinces and cities we work across

Gauteng (Johannesburg, Pretoria, Ekurhuleni)

Financial services, mining head offices, engineering and government procurement concentrated in one province.

Western Cape (Cape Town)

Wine, fruit export, food processing and a large technology and business services sector serving overseas clients.

KwaZulu-Natal (Durban, Richards Bay)

Container and bulk ports, chemicals, sugar and automotive assembly with strong export orientation.

Eastern Cape (Gqeberha, East London)

Vehicle manufacturing and component suppliers tied directly to European and Asian carmaker requirements.

Mpumalanga

Coal mining, power generation and synthetic fuels, where contractor safety approval and emissions obligations dominate.

North West province

Platinum and chrome mining with contractor management systems required before any work on operator sites.

Limpopo

Mining, agriculture and cross border logistics into southern Africa, with buyer and operator audit requirements.

Free State

Gold mining, agriculture and chemicals, with grain and food processors supplying national retail chains.

Mining contractor approval and workplace safety liability

Getting onto a South African mine site as a contractor means satisfying the operator that your safety management is real. That includes risk assessments for the specific tasks, medical surveillance arrangements, competency and induction records, control of subcontracted crews, and evidence that incidents lead to changed practice. Legal duties on managers make this personal rather than corporate. We help contractors and suppliers build occupational health and safety systems that stand up to operator audit and inspection, and we run internal audit and drill programmes so gaps are found before an inspector or an incident finds them.

Retail food supply, automotive tiers and data privacy

Supplying the major South African grocery chains means passing a recognised food safety audit and holding the grade, with delisting the penalty for repeated findings. Fruit, wine and nut exporters face separate importer requirements covering residues, hygiene and labour conditions. In the automotive corridor, tier suppliers must hold IATF certification and satisfy customer specific requirements to keep programme business. Across all sectors, privacy law obligations have added questions about how personal information is collected, stored and shared. We help organisations meet these demands with systems that produce usable evidence and reduce repeat audit findings.

Why bring in a consultant here

1

Auditors ask for particular evidence

Someone who has sat through hundreds of certification in South Africa audits knows which records get requested first and which answers collapse under a follow up question. That knowledge is only earned in the room.

2

Surveillance never stops

A certification in South Africa certificate is the start of a three year cycle, not the end of a project. Building for the surveillance audits from day one costs far less than rebuilding before each one.

3

Experience across sectors

Having implemented certification in South Africa in very different operating environments, we can tell you quickly which of your worries are real and which are inherited from someone else's situation.

4

Findings get closed, not logged

Most certification in South Africa audits produce findings. What matters is whether they are closed with genuine corrective action or papered over, because the next auditor reads the last report first.

What clients in South Africa say

Every engagement above ended with an independent assessor, not with us. We prepare you for the audit; the certificate is granted by an accredited body, and that separation is what makes the preparation worth paying for.

Each of these letters was written after the audit was passed, not before it was booked. Tell us your deadline and we will tell you honestly what reaching it takes.

Insights, news and know-how

Guidance from our consultants, with anything about this market first in each column.

All articles →

Blogs

Working notes from the consultants.

See all blogs

News

What has changed, and when it bites.

See all news

Articles

Longer pieces on one subject.

See all articles

Knowledge base

How things are actually done.

See all knowledge base

Working to a deadline in South Africa?

Tell us the date and what is being asked for, and we will tell you whether it is achievable before we quote.

Chat on WhatsApp