ISO 45001 Certification Cost & Timeline (2026): Complete Buyer's Guide
Get certified in 6 months for $25K — or in 18 months for $250K. The difference is preparation. This guide breaks down real ISO 45001 certification costs and timelines by company size.
Reviewed by The QHSE Standard editorial team
Fact-checked against ISO 45001, OSHA, EU OSH Framework Directive, and CCPS guidance. Independent of vendor influence — see our review methodology.
ISO 45001 certification is one of those projects where the price quoted by the certification body ("just $8K!") is wildly different from what the project actually costs. The real number includes consulting, internal labor, software, training, gap closure, and ongoing surveillance audits. Knowing the full picture upfront prevents the painful "we ran out of budget at month four" conversation with your CFO.
This guide breaks down realistic costs and timelines by company size, based on quotes from accredited certification bodies and real project budgets we've reviewed.
What Is ISO 45001?
ISO 45001 is the international standard for Occupational Health & Safety Management Systems (OHSMS). It replaced OHSAS 18001 in 2018, with all OHSAS certifications expiring by March 2021.
A certified OHSMS demonstrates to customers, regulators, and insurers that you have a systematic, continually improving approach to worker safety — not just a stack of policies in a binder. See our complete ISO 45001 software guide for the technical requirements.
Total ISO 45001 Certification Cost by Company Size
These ranges include everything: consulting, software, certification body fees, internal labor, training, and the inevitable gap-closure expenses.
Small business (10-50 employees)
- Total cost: $15,000 - $40,000
- Certification body fees: $4,000 - $8,000
- Consulting (optional): $5,000 - $15,000
- Software: $0 - $6,000/year
- Internal labor: ~200 hours from EHS + ops leads
- Timeline: 4-8 months
Mid-market (50-500 employees)
- Total cost: $40,000 - $120,000
- Certification body fees: $8,000 - $20,000
- Consulting: $15,000 - $50,000
- Software: $6,000 - $30,000/year
- Internal labor: ~600 hours across team
- Timeline: 6-12 months
Enterprise (500-5,000 employees)
- Total cost: $120,000 - $400,000
- Certification body fees: $20,000 - $60,000 (often per-site)
- Consulting: $40,000 - $150,000
- Software: $30,000 - $150,000/year
- Internal labor: ~1,500 hours across team
- Timeline: 9-18 months
Large enterprise / multi-site (5,000+ employees)
- Total cost: $400,000+
- Certification body fees: $60,000+ (multi-site sampling)
- Consulting: $100,000 - $400,000
- Software: $150,000+/year
- Internal labor: Full-time program manager + cross-functional team
- Timeline: 12-24 months
Where Costs Hide
Quoted certification body fees are usually accurate. The hidden costs that blow budgets:
1. Gap closure (the big one)
Your gap analysis will identify findings: missing risk assessments, undocumented procedures, untrained workers, unmonitored hazards. Each finding has a remediation cost. Budget $10K-$50K in gap closure for mid-market companies.
2. Consultant scope creep
A consultant scoped to "develop the OHSMS" doesn't include training your team, building your risk registers, or sitting in your stage 1 audit. Read the SOW carefully and pad it 20%.
3. Software licensing
You can pass certification with spreadsheets and Word docs, but you'll fail the surveillance audit 12 months later when you can't show evidence of continual improvement, document control, or systematic risk review. Software is effectively required at scale. See our QHSE software pricing guide.
4. Internal labor (the biggest hidden cost)
At a fully-loaded labor rate of $80/hour, 600 hours of internal labor = $48,000. Most companies don't budget for this because it's "people we already pay." Your EHS team's other work suffers — that's an opportunity cost.
5. Training and competency closure
ISO 45001 requires demonstrated competency for safety-critical roles. If you have gaps, expect $2,000-$15,000 in training procurement.
6. Annual surveillance and 3-year recertification
After initial certification, surveillance audits run annually (typically 30-50% of initial audit fee). A full recertification audit is required every 3 years.
Realistic Timeline (Mid-Market Example)
For a 250-person manufacturing company starting from scratch:
Month 1: Project setup and gap analysis
- Executive sponsor named, budget approved
- Cross-functional steering committee formed
- Gap analysis conducted (internal or consultant-led)
- Output: prioritized list of 30-80 gaps to close
Months 2-4: System design and gap closure
- OHSMS scope defined (sites, processes, exclusions)
- Risk and opportunity register built
- Hazard identification and risk assessment refresh
- Document control structure established
- Training matrix updated and gaps closed
- Software platform deployed (if applicable)
Month 5: Operational evidence period
- System operates "live" for at least 3 months
- Internal audits conducted across all clauses
- Management review held
- Corrective actions from internal audits closed
Month 6: Stage 1 (Documentation Audit)
- Certification body reviews documented system
- Identifies any major nonconformities before stage 2
- Output: report listing required corrections before stage 2
Months 7-8: Gap closure and stage 2 readiness
- Address stage 1 findings
- Final internal audit cycle
- Mock stage 2 audit (highly recommended)
Month 9: Stage 2 (Certification Audit)
- On-site, 3-7 days depending on company size
- Auditor reviews evidence of system operation
- Output: certification recommendation, with any minor/major nonconformities
Months 9-10: Certification issued
- Minor NCs closed and verified
- Certificate issued by accredited registrar
- Marketing announcement, customer notifications, RFP updates
How to Cut Cost and Timeline
1. Don't reinvent the wheel
If you have ISO 9001 or ISO 14001, use the High Level Structure common to all ISO management systems. Many clauses overlap — leverage your existing documentation. See our ISO management software guide for managing multiple standards together.
2. Use a platform with pre-built ISO 45001 content
Modern EHS platforms ship with pre-mapped clause-to-requirement frameworks, document templates, and audit checklists. This alone can cut consulting hours by 30-50%.
3. Build internal audit capability
Trained internal auditors find issues before the certification body does. Two of your safety leads going through Lead Auditor training (~$2,500/person) pays for itself within one project.
4. Don't over-scope your OHSMS
Limit initial certification to your highest-risk site or business unit. Expand scope at the first surveillance audit. This cuts initial cost dramatically.
5. Pick the right certification body
Accredited registrars are not interchangeable. Get quotes from 3-5 (BSI, DNV, SGS, TUV, Lloyd's Register, UL DQS, ABS QE). Prices can vary 30-50% for the same scope.
How Software Reduces Cost
Modern QHSE platforms cut ISO 45001 implementation effort 30-50% by:
- Pre-mapping content to ISO 45001 clauses (no need to design your own document architecture)
- Built-in risk assessment templates aligned to ISO 31000
- Document control with version history and acknowledgement tracking
- Internal audit modules with clause-by-clause checklists
- Automatic management review dashboards
- Action tracking for nonconformities and improvement opportunities
For a mid-market company, this is the difference between a 12-month and an 8-month project. Compare platforms in our Compare EHS Platforms hub.
FAQs
How long does ISO 45001 certification last?
The certificate is valid for 3 years, with annual surveillance audits. Recertification is required every 3 years.
Can I get certified at one site and add others later?
Yes. Many multi-site organizations certify their highest-risk site first and expand scope at surveillance audits. Some registrars offer multi-site sampling for 5+ similar sites.
Is ISO 45001 mandatory?
No, certification is voluntary. But it is increasingly required by Tier 1 customers, government tenders, and infrastructure prequalification systems (FPAL, Achilles, Avetta). Many companies certify because they have to bid for work that requires it.
Can we transition from OHSAS 18001 cheaper than starting fresh?
The OHSAS 18001 → ISO 45001 transition deadline passed in March 2021. Anyone certifying today is starting fresh against the 2018 standard, though existing OH&S documentation can be reused.
What's the difference between ISO 45001 and OHSAS 18001?
ISO 45001 has a stronger emphasis on worker participation, leadership accountability, and risk-based thinking. The High Level Structure aligns it with ISO 9001 and 14001 for integrated management.
Do I need a consultant?
For first-time small businesses, yes — a consultant cuts your timeline 40% and reduces project risk. For repeat ISO certifiers (already have 9001/14001), often no, especially if you have an EHS lead with audit experience.
Ready to find software that fits your ISO 45001 timeline? Take our Get Matched quiz and we'll suggest 3 platforms with built-in ISO 45001 templates, sized for your company.
Software covered in this category
Browse all platforms →- Risk & Compliance4.4
Origami Risk
Integrated risk, safety, and insurance management platform
Read review - Risk & Compliance4.4
Onspring
No-code GRC & business operations
Read review - Risk & Compliance4.3
Enhesa
Global EHS & product regulatory intelligence
Read review
Looking for the Right QHSE Software?
Take our 60-second quiz and get personalized recommendations.
Get Matched — Free