Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 45001 certification timeline 2026: seven phases from scope and gap analysis to certification decision, 6–12 months

ISO 45001 Certification Timeline: The Complete 2026 Guide

The ISO 45001 certification timeline for a single-site organization runs six to twelve months from kickoff to certificate, and the spread comes down to four things: whether you already run an ISO 9001 or ISO 14001 system you can build on, how long it takes to produce an honest hazard identification and risk assessment for every activity and every worker, how quickly you can generate three to six months of operating records that show workers were consulted and incidents were investigated, and how your registrar classifies the OH&S risk of your sector, which decides how many audit days you buy. A fifth factor is new this year: the revision of the standard is at Draft International Standard stage, and you need to decide whether to certify against ISO 45001:2018 now or wait.

This guide walks the ISO 45001 certification timeline phase by phase, gives labelled typical durations for each step, shows the audit-day table your certification body will use to quote you, and sets out what the coming ISO 45001:2027 edition does and does not change about the schedule. Durations are typical ranges from implementation practice, not guarantees; the accreditation rules cited are the current published text.

ISO 45001 certification timeline at a glance

PhaseTypical durationWhat drives it
1. Scope, context and gap analysis2–4 weeksNumber of sites and activities; existing ISO 9001 or ISO 14001 system
2. Hazard identification, risk assessment and legal requirements4–8 weeksNumber of distinct activities and worker groups; contractors; jurisdictions
3. Worker participation, documentation and operational controls3 weeks – 3 monthsWhether a consultation mechanism already exists; templates versus writing from scratch
4. Operating the system and building records3–6 monthsIncident and near-miss records, compliance evaluation, emergency drill, internal audit, management review
5. Selecting and booking the certification body4–8 weeks lead timeRegistrar capacity; runs in parallel with phase 4
6. Stage 1 and Stage 2 auditsStage 1: 1 day · Stage 2: 1–5 days on siteHeadcount and OH&S risk complexity category
7. Nonconformity closure and certification decision2–6 weeksNumber and severity of findings; registrar review queue
Total6–12 monthsShorter with an existing ISO 9001 or ISO 14001 system; longer for multi-site or high-risk operations

If you have read our ISO 14001 certification timeline, the shape will look familiar: the two standards share the Annex SL structure, and a registrar quotes both from the same audit-time document. The differences are in what fills phases 2 and 3, and in how the sector risk category moves the audit-day count.

What makes the ISO 45001 certification timeline different

Three requirements have no equivalent in a quality or environmental system, and each one adds calendar time that first-time implementers leave out of the plan.

Worker participation and consultation (clause 5.4). ISO 45001 requires that workers, including non-managerial workers, are consulted on a listed set of decisions and participate in a listed set of activities, from hazard identification to the choice of controls. An auditor will ask workers on the floor whether that happened, not just look at the procedure. If there is no safety committee, representative or equivalent mechanism today, you have to create one, hold meetings, and record what was raised and what was done, and that takes months of elapsed time, not weeks of writing.

Hazard identification and risk assessment (clause 6.1.2). The assessment must be ongoing and proactive, cover routine and non-routine activities, and explicitly include contractors, visitors and other people at the workplace, plus the way work is organized: workload, hours, fatigue and psychosocial factors. A risk register that lists machines but not people is the most common Stage 2 major nonconformity.

Incident investigation and evaluation of compliance (clauses 10.2 and 9.1.2). Stage 2 auditors look for investigated incidents and near misses with root causes and closed actions, and for at least one documented evaluation of compliance against the legal register. Both are records you can only accumulate by running the system.

The seven phases of the ISO 45001 certification timeline in detail

Phase 1: scope, context and gap analysis (2–4 weeks)

Fix the boundary first: which sites, which activities, which worker groups and which contractors. Then score every clause of ISO 45001:2018 against what you already have. Note that the standard carries a 2024 climate amendment that adds a determination of whether climate change is a relevant issue to clause 4.1 and a note on climate to clause 4.2; heat stress and extreme-weather exposure are the obvious OH&S angles, and a gap analysis that ignores the amendment produces a context analysis the auditor will query. A small site with an ISO 9001 or ISO 14001 system already in place can complete this in two weeks; a multi-site contractor starting cold needs four. Our ISO 45001 gap analysis guide lists what to check.

Phase 2: hazards, risks and legal requirements (4–8 weeks)

This is the phase that stretches the ISO 45001 certification timeline most, and the one that cannot be bought as a template, only accelerated by one. Walk every activity with the people who do it, identify the hazards, assess the risks with a documented method, and decide controls in the hierarchy the standard mandates: eliminate, substitute, engineer, administer, and only then personal protective equipment. In parallel, build the legal and other requirements register (clause 6.1.3): the specific occupational safety regulations, permits, licences and collective agreements binding each activity in each jurisdiction, with a named owner and an evaluation method for each. Four weeks is realistic for a single low-risk site; eight for a manufacturer or contractor with confined spaces, work at height, hazardous substances and mobile plant.

Phase 3: worker participation, documentation and controls (3 weeks to 3 months)

Stand up the consultation mechanism first, because every later phase generates records from it. Then the OH&S policy, roles and responsibilities, objectives tied to the significant risks, operational controls and safe systems of work, contractor management, management of change, procurement controls, and emergency preparedness and response. Starting from a template set, three to five weeks is realistic; writing from a blank page and routing everything through a two-week approval cycle pushes this to three months. Our ten-step ISO 45001 implementation plan gives the order that works, and the ISO 45001 Toolkit (50+ templates, $99) covers every mandatory document and record so that the writing does not become the critical path.

Phase 4: operating the system and building records (3–6 months)

The phase nobody puts in the plan, and the one that decides the ISO 45001 certification timeline. Stage 2 auditors need evidence that the system runs, not that it exists: consultation meetings with actions closed, incident and near-miss reports investigated to root cause, monitoring of the controls you said you would monitor, at least one evaluation of compliance, a tested emergency response, a completed internal audit covering every clause, and a management review that acted on all of it. Three months of operation is the practical floor for a small site; six months is normal for shift-based or seasonal operations where a single quarter does not show the range of work. An organization that reaches Stage 2 after two months of records is either very small or has skipped something the auditor will find.

Phase 5: selecting and booking the certification body (4–8 weeks lead time)

Run this in parallel with phase 4. Get quotes from two or three accredited registrars, check that each one’s accreditation covers your sector code, and ask how they have classified your OH&S risk complexity, because that classification sets the audit days and, through them, a large part of your ISO 45001 certification cost. Lead times of four to eight weeks for a Stage 1 date are typical, and the registrar will need your effective headcount including contractors and shift patterns before it can quote or schedule.

Phase 6: Stage 1 and Stage 2 audits (1 day plus 1–5 days)

Stage 1 reviews your documentation, checks readiness for Stage 2 and confirms scope, sites and applicable legal requirements; for a single site it normally takes one day. ISO/IEC 17021-1 clause 9.3.1.2.4 sets no fixed interval between the stages: the gap depends on how many areas of concern Stage 1 raised and how long you need to resolve them, and two to eight weeks is common. Stage 2 evaluates implementation and effectiveness on site, and for an OH&S system it includes shift work: the certification body has to plan the audit to cover the hours and shift patterns where the risk actually sits, so a three-shift plant should expect at least part of the audit outside office hours.

Phase 7: nonconformity closure and the certification decision (2–6 weeks)

Under 17021-1 clause 9.5.2, the certification body must confirm that every major nonconformity has been corrected and verified before it grants the certificate, and that minors have an accepted corrective-action plan. A clean Stage 2 with a handful of minors can be decided in two weeks; a major that needs new records before it can be verified takes longer. Clause 9.5.3.2 is the hard stop: if the registrar cannot verify closure of a major within six months of the last day of Stage 2, it must conduct another Stage 2 before recommending certification.

How audit days are calculated for an OH&S system

Registrars do not guess about the audit-day part of the ISO 45001 certification timeline. Initial audit time comes from Global ACI-TECH-3-004, the document that carried over IAF MD 5 when Global ACI took over the accreditation-forum role on 1 January 2026, and its Annex C table gives the combined Stage 1 plus Stage 2 time by effective headcount and by the complexity category of your OH&S risk. Unlike the environmental table, there are only three columns, and the “limited” band that head offices enjoy under ISO 14001 does not exist here. The lower bands look like this:

Effective personnelHigh riskMediumLow
1–53 days2.52.5
6–103.533
11–154.53.53
16–255.54.53.5
26–4575.54
46–65864.5
66–85975
86–1251185.5
126–1751296

The category is set by sector. Table OH&SMS 2 in the same document puts construction and demolition, mining, oil and gas, chemicals and pharmaceuticals, primary metals and metal fabrication, aerospace, automotive, hazardous-waste processing, transport of dangerous goods and, less obviously, healthcare and hospitals in the high category; food processing, wood products, plastics moulding, electrical and electronic assembly, passenger transport, hotels and education in medium; and corporate head offices, general business services, telecommunications, financial institutions and public administration in low. Two rules move the headcount itself: contractors and subcontractors working under your control count toward effective personnel, and the reduction for temporary unskilled workers that a quality auditor might allow is in principle not applicable for OH&S, because those workers are themselves a source of risk. A 30-person consultancy is looking at four audit days; a 30-person steel fabricator is looking at seven.

Surveillance visits run at roughly one third of the initial time and take place at least once a calendar year, with the first no more than twelve months after the certification decision (17021-1 clause 9.1.3.3). Recertification in year three is about two thirds of a fresh initial audit. Neither is likely to be quoted below one day.

Should you wait for ISO 45001:2027?

The revision is real and close. The Draft International Standard ballot opened on 16 June 2026 and closed on 8 September 2026; ISO’s own product page now describes ISO 45001:2018 as “expected to be replaced by ISO/DIS 45001 within the coming months,” and certification bodies are planning for publication in mid-2027 with a three-year transition period. The draft’s headline additions are psychosocial risk and mental health, climate-related worker safety, hybrid and remote work, tighter control of outsourced and contracted work, and gender-responsive safety.

None of that is a reason to pause the ISO 45001 certification timeline. Certificates to the 2018 edition will remain valid through the transition, and if the accreditation rules follow the pattern Global ACI set for ISO 9001:2026 and ISO 14001:2026, initial certificates to the old edition will keep being issued for well over a year after publication, and existing certificates will be transitioned at a scheduled surveillance or recertification visit. A project that starts now reaches its certificate in 2027 and transitions inside its first three-year cycle. A project that waits for the 2027 text loses a year of certified status, which is the thing tenders ask for, to avoid a transition audit that is typically a half-day to one-day extension. The one thing worth doing now is writing the new topics into the system on the way in: a psychosocial hazard entry in the risk register, a clause on remote and hybrid workers, and an explicit contractor-control procedure cost nothing extra today and will be the substance of the transition audit later.

Four ways to shorten the ISO 45001 certification timeline

Build on the system you have. If you hold ISO 9001 or ISO 14001, clauses 4, 5.1–5.3, 7, 9.2, 9.3 and 10.3 are largely shared, and an integrated internal audit and management review count for both. This is what turns twelve months into six.

Start consultation in week one. The consultation record is the slowest evidence to accumulate. A committee that meets monthly from the start of the project has six meetings of minutes by Stage 2; one formed in phase 3 has two.

Book the registrar before you are ready. Lead times of four to eight weeks are dead time if you wait until the internal audit is done. Book Stage 1 for the month you expect to finish phase 4, and confirm the sector classification in writing at quote stage.

Run the internal audit as a Stage 2 rehearsal. Use the same shift coverage and the same worker interviews the registrar will use. Most majors at Stage 2 are things an honest internal audit would have found six weeks earlier, when there was still time to build the missing records.

ISO 45001 certification timeline FAQ

Can we get ISO 45001 certified in three months?

Only in a narrow case: a small, low-risk organization that already runs an ISO 9001 or ISO 14001 system with a working consultation mechanism, and a registrar with a Stage 1 slot available. For anyone else, three months of operating records is the floor, and the documentation and risk assessment work sits in front of it.

How long is an ISO 45001 certificate valid?

Three years, with a surveillance audit in each of years one and two and a recertification audit before expiry. If the certificate does expire, 17021-1 clause 9.6.3.2.5 lets the certification body restore it within six months once the outstanding recertification work is done; after that, at least a new Stage 2 is required.

Does the size of the company change the ISO 45001 certification timeline?

Less than the sector does. A 50-person office and a 50-person construction firm need the same three to six months of records, but the audit is 4.5 days for the office and 8 for the contractor, and the risk assessment in phase 2 is a different order of work. Multi-site organizations add time for site sampling and for a legal register that spans jurisdictions.

Is ISO 45001 certification a legal requirement?

No. It is a voluntary standard, and no regulator in the US, UK or EU mandates it, although clients and public-sector tenders increasingly do. Our guide on whether ISO 45001 is a legal requirement covers what the law does demand instead.

The short version

Plan six to twelve months from kickoff to certificate. Spend the first two months on scope, hazards, risks and the legal register with the workers who do the work; stand up consultation before you write procedures; then run the system for at least three months while the registrar’s booking lead time runs in parallel. Expect the audit-day quote to be driven by your sector’s OH&S risk category more than by headcount, and expect ISO 45001:2027 to arrive after your certificate, not before it. For the full picture of the audit stages and what auditors are looking for at each one, see our guide to ISO 45001 certification; to take the document-writing off the critical path, the ISO 45001 Toolkit gives you the policy, risk register, legal register, consultation records and audit templates ready to fill in.

References

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.