Reconectando con el servidor

Mantén esta pestaña abierta: tu trabajo no se ha perdido.

No hemos podido reconectar

Recarga la página para continuar donde lo dejaste.

La sesión ha caducado

Vuelve a cargar la página para iniciar sesión de nuevo.

Spain's authority is now operating and tick-box channels are under review. Would yours hold up?Act now →
Corporate integrity ›

ISO Certifications

What each company holds certified, when it expires and which audits can be done together

An ISO certificate lasts three years and requires a surveillance audit every calendar year (ISO/IEC 17021-1, clause 9.6.2). Usually the PDF sits in the inbox of whoever handled it, and the expiry is discovered the day a tender asks for the valid certificate. Here each company is a row and each standard a column: status, certification body, number, scope, issue date, expiry and next surveillance audit, with alerts that cannot be switched off. And because Annex SL standards share clauses 4 to 10, the programme detects which surveillance audits by the same body fall in the same quarter and can be audited in a single visit.

4 screens of the programme
app.dsacompliance.net ISO Certifications
01Seven standards per company: status, certification body and days left until expiry
02Surveillance audits by the same body in the same quarter: one visit instead of three
03The certification record, with the surveillance audit proposed from the issue date
04Standards pursued without a programme to back their evidence, and which one would
DSA Compliance

Screens from DSA Compliance v6.2 in a demo environment. All data shown is fictitious.

The obligation, precisely

What the rule requires, and in which article

For information only, not legal advice. Always check against the consolidated text in force.

ISO/IEC 17021-1:2015, 9.1.2
The audit programme for a certification cycle covers three years: a two-stage initial audit, surveillance audits in the first and second years after the certification decision, and a recertification audit in the third, before expiry.
ISO/IEC 17021-1:2015, 9.6.2 and 9.6.5
Surveillance audits take place at least once every calendar year, and the first may not be later than twelve months after the certification decision. Not allowing them at that frequency is a ground for suspending the certificate.
ISO/IEC 17021-1:2015, 9.6.3
The recertification audit is planned in time to decide before expiry and reviews the system's performance over the whole cycle. It requires arriving with a completed internal audit and management review (clauses 9.2 and 9.3 of the harmonized structure).
Annex SL · ISO/IEC Directives, Part 1
Harmonized structure for management system standards: clauses 4 to 10 —context, leadership, planning, support, operation, performance evaluation and improvement— are common to ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001, ISO 37301, ISO 37001 and ISO/IEC 42001.
IAF MD 11
Application of ISO/IEC 17021-1 to the audit of integrated management systems: one certification body can audit several standards in a single visit, with the duration calculated according to how integrated the system is.
Arts. 93, 94 and 140.4 Ley 9/2017
The contracting authority may require quality management and environmental management certificates issued by independent bodies, and the capability must be met on the final date for submitting bids.
Penalty regime

It has no penalty regime of its own: certification is voluntary. The cost is contractual. An expired or suspended certificate no longer proves the capability a tender requires (arts. 93 and 94 of Spain's Ley 9/2017, with the conditions assessed at the bid deadline under art. 140.4) or that a customer's supplier-approval questionnaire asks for.

Rules it covers
ISO/IEC 17021-1Certification cycleAnexo SLHarmonized structureIAF MD 11Integrated auditLey 9/2017Arts. 93 and 94 · ES

The badges identify the obligation the program digitises. They are not certifications or conformity accreditations.

What it leaves as evidence

What gets handed over when somebody asks

  • Map of certifications by company and standard, including those that do not apply, with status and certification body
  • Certificate PDF stored with its certification in the document store
  • Excel certification dossier for tenders and customer supplier-approval questionnaires
  • Log of renewal, expiry and surveillance alerts, with recipient and date
  • Integrable audits detected and scheduled in the external audits programme
  • Link between each standard and the platform programme that backs its evidence
Who it applies to
Companies certified to one or more ISO management system standards
Bidders whose tender documents ask for the valid certificate
Suppliers answering supplier-approval questionnaires from corporate customers
Groups with several companies certified by different bodies
Organisations that apply a standard without certifying and want it on record
International framework

This programme implements certifiable ISO standards. If your organisation already is, here you see which part is solved and which laws it covers in each country where you operate.

ISO 37301 · Compliance management systemsISO 37001 · Anti-bribery management systemsISO 45001 · Occupational health and safetyISO 9001 · Quality and supplier controlISO 42001 · AI management systemsISO 27001 · Information securityISO 14001 · Environmental management
Frequently asked questions

What we get asked about ISO Certifications

Does the programme certify an ISO standard?

No, and no software can. Certification is granted by a body accredited under ISO/IEC 17021-1. The programme records what the body has issued, watches its dates and links each standard to the programme that gathers its evidence.

Is it any use if I only have one company?

Yes. The map has one row per company: with a single company it is one row with seven standards, and it grows to a group of several companies without changing programme.

Why does it warn about renewal 180 days ahead?

Because renewal is requested about six months ahead: the recertification audit requires arriving with a full cycle of internal audit and management review. The window is adjustable per company; the alert cannot be switched off.

What is an integrable audit?

Two or more Annex SL standards certified by the same body in the same company, whose surveillance audits fall in the same quarter. They share clauses 4 to 10, so the body can audit them together under IAF MD 11. The programme counts visits saved, not euros: the fee is set by the body.

Who receives the alerts?

The in-app notification bell, the person named as responsible for each certification and a copy mailbox. They warn that the renewal window is opening, that a certificate has expired and that a surveillance audit is approaching.

What about a standard I pursue that the platform does not back?

The programme says so. It flags the standards with no contracted programme behind them and links to the one that would gather their evidence: information security for ISO/IEC 27001, crime prevention for ISO 37001, health and safety for ISO 45001 or environmental management for ISO 14001, among others.

Vea ISO Certifications running with their cases

A 30-minute guided demo on the real platform, or a one-hour assessment session with a consultant.

Other programmes from Corporate integrity
← The 22 programmes of the platform