Article
Why a second standard costs far less than the first
Clauses 4 to 10 are shared across the ISO management system standards. That is why the second certificate costs far less than the first.
Prem Kumar Dvivedi · 12 September 2026
Organisations tend to budget for a second standard as though it were another first. It is not, and the reason is structural rather than commercial.
The shared spine
Since the harmonised structure was adopted, the ISO management system standards share clauses 4 to 10. Context. Interested parties. Scope. Leadership and policy. Risks and opportunities. Objectives. Competence, awareness, communication, documented information. Operational planning. Monitoring and measurement. Internal audit. Management review. Nonconformity and corrective action.
That is most of a management system, and it is written once. What differs between standards is the operational core — clause 8 — and the specialist requirements around it: aspects and impacts for ISO 14001, hazard identification for ISO 45001, the Statement of Applicability for ISO/IEC 27001, the energy review for ISO 50001.
What that means in weeks
A first certification for a single-site organisation with supportive leadership runs three to six months, and most of it is not documentation — it is generating enough real records to be auditable. A second standard added to a working system is usually six to ten weeks, because the records are already accumulating and only the specialist ones are missing.
The audit cost follows the same logic. A certification body will quote fewer days for an integrated audit than for two separate ones, because the shared clauses are sampled once. You have to ask for it that way: bodies quote what you request, and an organisation that asks for two audits gets two audits.
Where the saving is lost
Two mistakes undo it. The first is running the standards as separate systems — two policies, two objective sets, two internal audit programmes, two management reviews. That doubles the maintenance forever and gains nothing. The second is sequencing them badly: adding a standard while the first system is still unstable means the shared clauses get reworked twice.
The rule of thumb is to let the first system produce one full cycle of records — one internal audit, one management review, one round of corrective actions — before adding to it. The system has to be real before it can be extended.
Which second standard
Usually the one your buyer is asking for, and there is no cleverness required. Where there is a choice: quality and environment integrate most easily; environment and occupational health and safety share the legal register and the emergency arrangements almost entirely; information security and business continuity are natural partners because one asks for the other.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 9001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO 14001:2015: documentation and compliance requirements
Everything ISO 14001:2015 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- ISO 14001:2026: documentation and compliance requirements
Everything ISO 14001:2026 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- ISO 45001:2018: documentation and compliance requirements
Everything ISO 45001:2018 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
