
We are ISO 9001 consultants working with United States companies, including federal contractors. We deliver the work remotely and hold meetings in US business hours. You work directly with a qualified Lead Auditor from the first conversation through to your certification audit, so the person who learns your business is the person who builds your system.
Most companies who come to us are not shopping for a certificate. Something has shifted in their market. A major customer has signaled that certification is becoming a condition of supply, a prime has added it to their approved supplier criteria, or a contract they want to bid on now lists it as a requirement. The risk is rarely losing existing work overnight. It is being quietly passed over in favor of a competitor who already holds it, and never being told that is why.
Who tells you that you need ISO 9001
Almost nobody pursues ISO 9001 unprompted. In our experience the requirement arrives from one of five places, and only one of them involves the federal government:
- A major customer. A large account adds a quality management system requirement to its supplier terms, often after an audit or a quality escape.
- A prime or OEM supplier approval program. Aerospace, automotive, energy, rail, medical device and industrial OEMs commonly require ISO 9001 as the baseline before you can be added to an approved vendor list.
- Bid, tender and panel eligibility. The certificate is a pass or fail gate on the submission form. This is very common in corporate and government procurement for services, including travel management, logistics, facilities, staffing and professional services. No certificate, no bid, regardless of price or capability.
- Distribution, export and offshore delivery. Overseas distributors, buyers and clients frequently treat ISO 9001 as the minimum credential for a supplier they cannot easily visit or audit in person.
- Federal contracting. A contracting officer or a prime flows a higher-level quality requirement down to you. This is the case with the most confusion attached to it, so it is covered separately below.
The good news is that the system you build is the same in every one of these cases. ISO 9001 does not have a federal variant or a commercial variant. There is one standard, and the differences are in scope, in how much documentation your customer expects to see, and in which certification body you choose.
If you are a commercial manufacturer or service business with no federal work at all, everything on this page still applies to you. Skip the FAR section and carry on from there.
ISO 9001 in service businesses
Most people picture a factory when they hear ISO 9001, and most examples online are manufacturing examples. The standard itself is sector-neutral. It refers to “products and services” throughout, and it is used by travel management companies, logistics and freight forwarders, staffing firms, facilities managers, engineering consultancies, laboratories, IT and managed service providers, and professional services firms.
What changes in a service business is where the quality lives. In manufacturing you are largely controlling a physical process and inspecting an output. In a service business the value sits in the parts that are easiest to leave undocumented: how an enquiry is scoped and quoted, how a booking or a job is handed between people, how you select and monitor the third parties you depend on, how a complaint is captured and closed out, and how you know a customer got what they were promised.
That last point about third parties is usually the one that does the most work. Clause 8.4 covers externally provided processes, products and services, and for a service business that is your supplier network. If your delivery depends on other organizations performing, ISO 9001 requires you to have a defensible basis for choosing them and for monitoring how they perform. Many service businesses find that this is the part of the standard that changes how they actually operate, rather than the documentation.
Where the requirement comes from in federal contracting
There is a persistent myth that the Federal Acquisition Regulation requires ISO 9001 across the board. It does not. What the FAR does is give the contracting officer a mechanism to impose it, and set out when they should.
FAR 46.202-4 covers higher-level contract quality requirements. Agencies have to determine when those requirements are necessary and advise the contracting officer which standards to apply. Compliance with a higher-level standard is necessary for complex or critical items, or when the technical requirements of the contract call for:
- control of design, work operations, in-process controls, testing and inspection; or
- attention to organization, planning, work instructions, documentation control and advanced metrology.
FAR 46.202-4(b) then names the standards. In its own words, examples of higher-level quality standards include “overarching quality management system standards such as ISO 9001, ASQ/ANSI E4, ASME NQA-1, SAE AS9100, SAE AS9003, and ISO/TS 16949”, plus product or process specific standards such as SAE AS5553.
The requirement then reaches your contract through the clause at FAR 52.246-11, Higher-Level Contract Quality Requirement. That clause is deliberately blank on the face of it: the contracting officer inserts the title, number, date and any tailoring of the standard they want. If they write ISO 9001 into that blank, ISO 9001 is what you are contractually obliged to comply with.
Verified against acquisition.gov, FAC 2026-01. Requirements change, so check the current text for your solicitation rather than relying on any consultant’s summary, including ours.
The flow-down is why most subcontractors end up here
This is the part that catches small businesses out, and it is worth reading the clause carefully.
FAR 52.246-11 does not stop at the prime. Paragraph (b) requires the contractor to include the applicable requirements of the higher-level standard, and the requirement to flow those standards down further, in any subcontract for critical and complex items, or where the technical requirements of the subcontract involve control of design, work operations, in-process control, testing and inspection.
In practice that means the obligation travels down the supply chain. A prime holding a contract with 52.246-11 in it has to push the same standard onto the subcontractors doing the critical work, and those subcontractors may have to push it further again.
So the typical sequence is not “we decided to get ISO 9001”. It is “our prime sent us a flow-down and we have a deadline”. If that is you, the useful questions are which standard exactly, what tailoring the contracting officer applied, and what scope it actually has to cover. Those three answers change the size of the project considerably, and they are the first things we work through with you.
What certification involves
The sequence is the same wherever you are: a gap analysis against the standard, building the management system, implementing it so people actually work that way, an internal audit, a management review, then the certification body’s Stage 1 and Stage 2 audits. Stage 1 tests your system and documentation against the standard. Stage 2 tests whether you are running it, using objective evidence.
For a small to medium contractor with reasonable records, three to six months is realistic. Faster than that usually means the records do not yet exist to audit. Much slower and projects lose momentum. The full certification process is set out here.
Two points specific to federal work. First, your certificate needs to come from an accredited certification body, and in the United States that accreditation generally comes through ANAB. Second, the scope on the certificate matters more than the certificate does. A certificate whose scope does not cover the work in the contract will not satisfy a flow-down, and scope is decided by you, not by the auditor.
For budgeting, see what ISO 9001 certification costs in the US, which breaks down consulting, certification body audits and the annual cost of keeping it.
Working with an Australian consultant, honestly
We are based in Australia. That is the first objection worth addressing rather than burying.
The time zones work better than you would expect. Brisbane runs fourteen hours ahead of US Eastern time and does not observe daylight saving. Early morning here is late afternoon on the East Coast the previous day, so a standing call lands inside your business hours without either of us working through the night.
Management system work is document and interview based. Building a system, running internal audits and preparing for certification are all deliverable remotely, and have been for years. Your certification body auditor is the one who needs to be in the room, and they will be local to you.
ISO 9001 is a single international standard. It is identical in Sydney, San Diego and Stuttgart. What changes between countries is the regulatory furniture around it, which for federal work means the FAR, your contract clauses and your accreditation route. That part we work through with you rather than assume.
We already support US government contractors on ISO 9001, so this is not a first attempt at an unfamiliar market.
We are a member of the American Society for Quality. ASQ membership is not a certification and we would not present it as one, but it does mean we sit inside the same professional quality community your own people and auditors do, and work to the same body of knowledge.
ISO 27001 is usually the next requirement
Quality is rarely the only requirement a federal contractor is handed. Where the work touches government information, an information security requirement tends to follow, and ISO 27001 is the international standard for that.
The practical advantage is that ISO 9001 and ISO 27001 share the same high-level structure: context, leadership, planning, support, operation, performance evaluation, improvement. Built together they share one document set, one internal audit program and one management review. Built separately, five years apart, by two different consultants, they become two systems nobody maintains.
If ISO 27001 is on your horizon, it is worth saying so before we design the ISO 9001 system, not after.
Frequently asked questions
We are not a federal contractor. Is ISO 9001 still relevant to us?
Yes, and most certified companies worldwide have no government work at all. ISO 9001 is a general quality management standard. The most common driver we see is a major customer or an OEM supplier approval program, not a contracting officer.
Is there a different version of ISO 9001 for commercial companies?
No. There is one standard, ISO 9001, and it is the same document whoever your customers are. What changes is the scope of your certification and how much evidence a particular customer wants to see. If your work is in aerospace, automotive or medical devices you may later be asked for a sector standard such as AS9100 or IATF 16949, each of which is built on ISO 9001.
Does the FAR require ISO 9001?
Not automatically. FAR 46.202-4 sets out when a higher-level quality standard is necessary and names ISO 9001 as an example of one. The requirement reaches your contract through the clause at FAR 52.246-11, where the contracting officer specifies which standard applies. Check your solicitation and contract for that clause.
My prime says I need ISO 9001. Is that legitimate?
Usually, yes. FAR 52.246-11(b) requires the contractor to flow the higher-level standard down into subcontracts for critical and complex items, and into subcontracts whose technical requirements involve control of design, work operations, in-process control, testing and inspection. Ask your prime which standard, which version, and what scope they expect it to cover.
How long does it take?
Three to six months is realistic for a small to medium contractor with reasonable records. Anything faster usually means the evidence an auditor needs does not exist yet.
Who issues the certificate?
An accredited certification body, not us and not ISO. In the United States that accreditation generally comes through ANAB. A consultant cannot also be your certification auditor, and any firm offering both is not one to use.
Can you do the work in our time zone?
Yes. Brisbane is fourteen hours ahead of US Eastern with no daylight saving, so our early morning is your late afternoon. Meetings run by Teams, Zoom or phone.
Been handed a flow-down with a deadline?
Send us the clause and we will tell you what it actually requires, what scope you need, and whether the timeline is achievable. Free consultation by Teams, Zoom or phone, in your business hours. No obligation and no sales pitch.
Talk to an ISO 9001 consultant →










