ISO 45001 Certification: Process, Costs and Timeline (2026)
ISO 45001 certification 2026: 7 phases, realistic timeline and costs for SMEs in the DACH region — including checklist and FAQ.
In 2026, ISO 45001 certification is no longer a "nice to have" for many companies — it is a prerequisite in tenders, supplier evaluations and regulated industries. But how long does an initial certification really take, what does it cost, and what steps lie ahead? This guide gives a clear, practical answer — written for managing directors, HSE managers and quality managers in SMEs in the DACH region.
We walk through the process step by step, give realistic cost ranges, highlight typical stumbling blocks and provide a checklist you can use to set up the project plan directly.
What Is ISO 45001 — A Brief Overview
ISO 45001 is the international standard for Occupational Health and Safety Management Systems (OH&S). It replaced OHSAS 18001 in 2018 and follows the same High Level Structure (HLS) as ISO 9001 and ISO 14001. This makes it excellently compatible for an Integrated Management System (IMS).
At its core the standard requires:
- Leadership responsibility for occupational health and safety at the highest level
- Systematic worker participation
- Identification of hazards and assessment of risks and opportunities
- Legal compliance (Occupational Health and Safety Act, national regulations)
- Operational control of hazardous activities
- Emergency preparedness, incident investigation and continual improvement
If you are already using ISO 9001 or ISO 14001, you know the logic. The technical depth is different, however: it is about people, not products or environmental aspects.
Who Needs ISO 45001 Certification in 2026?
Certification is voluntary — but the pressure to demonstrate it has grown noticeably in 2026. Typical drivers:
- Tenders in construction, industry, energy and public sector explicitly require the certification.
- Supply chains: Tier 1 suppliers in the automotive and mechanical engineering industries require ISO 45001 as a minimum standard.
- Supply Chain Due Diligence Act and EU CSDDD directive: companies must demonstrate occupational health and safety in their own organization and along the value chain — a certified system is the simplest evidence.
- Insurers reward a certified OH&S system with lower premiums for employers' liability and general liability insurance.
- Staff retention: visible occupational health and safety is a genuine differentiator in a tight labour market.
ISO 45001 Certification Process — The 7 Phases
An initial certification follows a clearly defined path. The timeframe — depending on company size and maturity level — ranges from 4 to 12 months. Here are the typical phases:
Phase 1 — Preparation and Gap Analysis (Weeks 1–4)
It starts with an honest stocktake: which standard requirements are already being met, where are the gaps? Typically an internal OH&S officer and an external consultant lead the project together. Topics in this phase:
- Defining the scope (sites, activities, outsourced processes)
- Stakeholder and context analysis (Clause 4 of the standard)
- Building the legal register (occupational health and safety legislation, national regulations)
- Gap analysis against all 10 clauses of ISO 45001
Phase 2 — Project Plan and Resources (Weeks 3–6)
The gap analysis generates an action plan with responsible parties, deadlines and effort estimates. Management must visibly take a position here — occupational health and safety is a leadership matter, that is non-negotiable. Whoever takes on the role of Occupational Health and Safety Management Officer should be formally appointed by this point at the latest.
Phase 3 — Hazard Identification and Risks/Opportunities (Weeks 4–10)
The core. This is often where the most time is spent — and the most value is created. The standard requires systematic identification of all hazards, an assessment of risks and the derivation of measures following the STOP principle (Substitution, Technical, Organizational, Personal).
You know the methodology from risk-based thinking in ISO 9001 — only considerably more concrete and with higher legal demands. Important: hazard assessments must be living documents, not a one-off obligation.
Phase 4 — Documentation and Processes (Weeks 6–14)
The standard requires far less documentation than many fear. Mandatory documents are:
- OH&S policy (brief, signed by management)
- OH&S objectives and action plan
- Hazard assessments and legal register
- Procedures for participation, emergencies, incidents, internal audit, management review
- Records of training, incidents, audits, corrective actions
A lean structure always beats a comprehensive one. Organizations that aim for "completeness" here rather than clarity fail later in maintaining it.
Phase 5 — Training and Culture (Parallel, Weeks 6–16)
Employees must know the policy, understand their role and have a low-threshold way of reporting hazards. A training matrix documents who received what instruction and when. This is also the point auditors look at most closely at certification.
Phase 6 — Internal Audit and Management Review (Weeks 14–20)
Before the external audit you must demonstrate that the system has completed a complete internal audit and review cycle. Specifically: at least one internal audit covering all standard clauses and at least one documented management review are mandatory before Stage 2 of the certification audit.
More details on audit preparation can be found in our guide to ISO audit preparation.
Phase 7 — Certification Audit (Stage 1 + Stage 2)
The external audit by the accredited certification body runs in two stages:
- Stage 1 (document review and readiness): 1–2 days on-site or remote. The auditor reviews system documentation, the legal register, hazard assessments and system maturity.
- Stage 2 (implementation audit): 2–5 days on-site, depending on headcount and locations. This is where lived practice is checked: employee interviews, site walks, sampling of records.
If no major nonconformities are identified, you receive the certificate within 4–8 weeks. It is valid for 3 years, with annual surveillance audits and a re-certification in the third year.
ISO 45001 Certification Timeline — Realistic Schedule
The most common question in our initial conversations: "How long does it take?" An honest answer depends on the starting point:
| Starting situation | Realistic time to certificate |
|---|---|
| Small company (10–50 employees), no existing management system | 8–12 months |
| SME (50–250 employees), ISO 9001 or 14001 in place | 6–9 months |
| Larger company with established IMS | 4–6 months |
| Transition from OHSAS 18001 (rarely relevant today) | 3–4 months |
A faster implementation than 4 months is technically possible but rarely sensible: the internal audit and review cycle needs time, and auditors reliably recognize rushed implementations.
ISO 45001 Certification Costs 2026
The total costs consist of three blocks — internal effort, consulting and audit fees from the certification body. Here are the key figures for 2026:
1. External Audit Costs from the Certification Body
These are based on headcount and calculated according to IAF MD 5 guidelines. Rough ranges for Stage 1 plus Stage 2 audit:
| Employees | Audit costs — initial certification | Annual surveillance audit |
|---|---|---|
| up to 25 | €4,500 – €7,000 | €1,800 – €2,800 |
| 26 – 75 | €7,000 – €11,000 | €2,500 – €4,000 |
| 76 – 200 | €11,000 – €17,000 | €4,000 – €6,500 |
| 200 – 500 | €17,000 – €28,000 | €6,500 – €10,000 |
Added to these are auditor travel costs, certificate fees (€300–€600) and any surcharges for multi-site structures.
2. Consulting Costs
External consulting accelerates the project and avoids typical mistakes. Usual ranges:
- Full support for SMEs up to 50 employees: €9,000 – €18,000
- 50–250 employees: €15,000 – €30,000
- IMS integration with existing ISO 9001/14001: €6,000 – €14,000
- Funding: BAFA funding ("advisory services for SMEs") covers up to 50% of consulting costs, max. €3,500 grant.
3. Internal Effort
Often underestimated. Allow for:
- OH&S officer: 0.2–0.5 FTE for 6 months
- Managers: 1–2 hours per week on the project
- Employee training: 1–2 hours per person
For an SME with 80 employees this amounts to approximately 250–400 person-days over the project period — a realistic figure that should be communicated openly to management early on.
Common Stumbling Blocks — and How to Avoid Them
From our client projects we have collected the typical causes of delays or audit findings. More on this in our article on the most common reasons ISO audits fail.
- Hazard assessments as drawer documents. When assessments are updated because an audit is approaching — not because something has changed in the plant — every auditor notices.
- Missing worker participation. The standard requires demonstrable participation. "We put it up on the notice board" is not sufficient. Establish safety rounds, walkabouts with employees, a near-miss reporting channel.
- Legal register without maintenance. Legal changes are not incorporated, or responsibility for this is not clearly assigned.
- Policy and objectives too generic. "We want to work safely" is not a policy. Measurable objectives with a link to hazards are mandatory.
- Internal audit too superficial. An internal audit that only checks documentation misses the real weaknesses. Good internal auditing is an investment, not a tick-box exercise.
- Emergency preparedness without drills. Fire safety concept yes, evacuation drill no — a classic finding.
- Incident investigation without root cause analysis. The standard requires identifying the causes, not just treating the symptoms. Methods such as the 5 Why analysis are helpful here.
ISO 45001 as Part of an Integrated Management System
If you are already certified to ISO 9001 or ISO 14001, introducing ISO 45001 is significantly more efficient. The HLS ensures that clause structure, context analysis, interested parties, management review, internal audit and improvement processes are largely identical.
In an IMS project the following elements are shared:
- Policy (one combined Q, E and H&S policy or three coordinated individual policies)
- Context and interested parties
- Document control and records
- Internal audit and management review
- Corrective and preventive actions
The subject-specific elements — hazard assessment, emergency preparedness, environmental aspects, quality planning — remain separate by nature. Anyone not yet clear on the difference between consulting and certification should resolve that before the project start — the role separation is an accreditation requirement.
Choosing a Certification Body
Pay attention to the following criteria:
- DAkkS accreditation for ISO 45001 — not every body has this scope.
- Industry experience of the assigned auditors (construction, chemicals, logistics, manufacturing).
- Language — for multilingual teams: is German and English offered?
- Multi-site and IMS experience if you want to audit in combination.
- Transparent pricing — request a fixed-price quote including the following three years.
The standard practice is to request quotes from three bodies (e.g. TÜV SÜD, DQS, Dekra, GUTcert, LRQA, DNV, TÜV Nord) and compare by total cost over the certificate cycle — not just for initial certification.
Checklist — Are You Ready for the Stage 2 Audit?
How We Support You with ISO 45001 Certification
We guide SMEs in the DACH region through the entire project — lean and pragmatic: from the gap analysis through developing hazard assessments, maintaining the legal register and training your managers to accompanying the audit. Our approach avoids documentation ballast and focuses on lived occupational health and safety practice — so the system holds after certification, not just shines on audit day. Find out more and arrange a no-obligation initial conversation on our ISO 45001 consulting page or directly via the contact form.
Frequently Asked Questions about ISO 45001 Certification
Is ISO 45001 certification mandatory?
No, there is no legal obligation to certify. The underlying requirements from occupational health and safety legislation are mandatory, however. Certification is contractually required in many industries — especially in construction, industry and in the supply chains of automotive and mechanical engineering companies.
How long does an initial certification typically take?
For an SME with 50–250 employees and an existing ISO 9001 or 14001 system, 6–9 months is realistic. Without prior experience with management systems, you should plan for 8–12 months.
What does ISO 45001 cost including all follow-on costs over 3 years?
For an SME with approximately 80 employees, total external costs (consulting + initial certification + 2 surveillance audits) typically range between €25,000 and €45,000, depending on site structure, risk profile and maturity level.
Can we combine ISO 45001 with ISO 9001 and ISO 14001?
Yes, and in 2026 this is the most economically sensible path for most clients. Combined audits save 20–35% of audit time and an IMS handbook is considerably easier to maintain than three separate systems.
Who may conduct internal audits?
Internal auditors must be checked for competence and independence. Thorough training is sufficient — a separate personal certification is not prescribed. External auditors with accreditation may not simultaneously consult and certify.
How long is the certificate valid?
Three years. Within this period two surveillance audits take place (annually, approximately 30–50% of the initial effort). In the third year, re-certification takes place.
What funding is available in 2026?
BAFA funding for advisory services for SMEs covers up to 50% of pure consulting costs, maximum €3,500 grant. The audit costs of the certification body are not eligible for funding. Some employers' liability insurance associations grant bonuses for demonstrated OH&S management.
Related Articles
- What Does an Occupational Health and Safety Management Officer Do?
- ISO Audit Preparation — without internal expertise
- The Most Common Reasons ISO Audits Fail
- ISO Consulting vs. Certification Body — the difference
- Risks and Opportunities in ISO 9001 — practical guide
- Understanding ISO 14001 — Fundamentals, Quiz and Explainer Video
- Internal Audit According to ISO 9001 — how to get it right