ISO 9001 has a divided reputation among IT service providers. For some it is a sales argument towards enterprise customers, for others a mountain of binders, work instructions and annual audit invoices. Both pictures are accurate — and both are avoidable if you read the standard for what it is: a framework for processes, not a mandate for bureaucracy.
This article describes how an IT service provider with 10 to 20 staff can realistically prepare for ISO 9001:2015, what you must document, what you can safely leave out, what costs to expect and how everyday work actually changes afterwards.
Processes instead of work instructions
The most common mistake in small QM projects: trying to press every activity into a work instruction. The result is PDFs that nobody ever reads again after the audit. Since the 2015 revision, ISO 9001 explicitly requires process-oriented thinking, not collections of procedures. In practice: you describe how value flows through your company, not how someone installs a printer.
For an IT service provider, six to eight core processes are usually enough:
| Process | Owner | Documentation depth |
|---|---|---|
| Sales & quoting | Sales / MD | Flow, approval limits |
| Project delivery | PM / Engineering | Phases, handover to ops |
| Incident & service desk | Support lead | SLA tiers, escalation |
| Change management | Tech lead | RfC flow, rollback plan |
| Procurement & supplier review | Procurement | Criteria, review cycle |
| HR & onboarding | MD / HR | Roles, competence matrix |
| Internal audits & management review | QM officer | Cadence, report format |
| Improvement (CAPA) | QM officer | Reporting path, deadlines |
Each process needs an owner, an objective, measurable KPIs and a description of interfaces. At our shop this fits on one to two A4 pages per process. Anything beyond that is usually the wishful thinking of certification consultants.
What you really must document — and what not
The standard demands fewer concrete documents than most assume. Mandatory items include:
- Scope of the quality management system (typical: “IT services including planning, delivery, integration and operations”)
- Quality policy and quality objectives (measurable, with deadlines)
- Risks and opportunities per core process
- Evidence of resources, competence, calibration of measurement equipment (in our case: network analyzers, server test environments)
- Evidence of audit results, corrective actions, management reviews
Not mandatory: classical quality manuals, detailed instructions for every task, elaborate org charts. If your auditor insists on a “QM manual”, that is an interpretation, not a normative requirement. A well-maintained wiki with the content listed above has been entirely sufficient since the 2015 revision.
At our shop the entire QM documentation lives in a versioned wiki with access control and automatic change history. Alternatives are SharePoint, Confluence or a plain Git repository with Markdown — certifiers accept anything that makes changes traceable and clearly shows the current state.
Realistic cost: what certification costs in 2026
The hard question. For a shop with 15 staff at a single site we see the following ranges in 2026:
| Cost item | Realistic range |
|---|---|
| External preparation / consulting | 6,000 to 15,000 EUR one-off |
| Certification audit stage 1 + 2 | 5,000 to 8,000 EUR one-off |
| Surveillance audit year 1 and 2 | 2,500 to 4,000 EUR each |
| Re-certification after 3 years | 4,000 to 6,000 EUR |
| Internal preparation effort | 15 to 30 person-days |
| Internal ongoing effort | 3 to 6 person-days per year |
The consulting range is so wide because some providers work with templates and weekend workshops, others with on-site sessions and completely new document structures. Our recommendation: find a consultant who documents your existing processes rather than inventing new ones. Anyone selling you a 200-page manual is selling you your own problem.
Comparing certification bodies is worthwhile. In Germany, accredited bodies include TÜV Süd, TÜV Rheinland, DEKRA, DQS and several smaller providers. For an SMB, the reputation of the body makes no difference to most end customers — the certificate is equivalent everywhere as long as accreditation is backed by DAkkS.
Internal audit cadence: what works
The standard requires internal audits “at planned intervals”. That does not mean you must audit every process every year — you need an audit plan that covers all processes across the certification cycle (three years).
At our shop we run this pattern:
Audit plan 3-year cycle (example):
Q1 year 1: Sales, quoting, project delivery
Q3 year 1: Incident, change, service desk
Q1 year 2: Procurement, supplier review
Q3 year 2: HR, onboarding, competence
Q1 year 3: Improvement, CAPA, complaints
Q3 year 3: Cross-check of all core processes
An internal audit takes us two to four hours per process, including the report. It is essential that the auditor is not the process owner — a colleague from another area asks the naive questions that pull the process owner out of operational blindness.
We combine this with a monthly QM standup of 60 minutes, in which all open items from complaints, near-misses and internal reports are discussed. This does not replace formal audits, but it keeps the system alive between the scheduled events.
How daily work actually changes
After certification, less changes than many fear — and more than many hope. What actually happens:
- Onboarding becomes more structured. New colleagues get a documented process instead of piecing together knowledge on their own. That is sensible independent of ISO 9001, but the standard forces the issue.
- Complaints get a process. Before certification, customer complaints often land directly with management and evaporate. Afterwards there is a report, a root-cause analysis and a corrective action with a deadline. That is genuine improvement.
- Supplier selection becomes transparent. We evaluate our hardware, software and cloud suppliers annually on quality, delivery reliability and support. In TrueNAS and Proxmox environments this has repeatedly helped us make long-term decisions on data rather than gut feeling.
- Change management grows a spine. Unplanned changes become rarer because the process makes visible who is changing what, when and why — important for firewall and network rework, for example with OPNsense.
- Backup becomes audited, not just operated. A QMS forces regular restore tests and documented results. This is the point where the standard reaches most directly into the technology, especially for backup strategies.
What does not change: creativity in projects, day-to-day speed, personal relationships with customers. If a QMS damages these things, it has been set up incorrectly — the standard is not to blame.
The three most common pitfalls
- Consultant dependency. Anyone who outsources the entire documentation ends up with a system nobody in-house understands after the certificate. Have someone moderate you, but write it yourself.
- Too many KPIs. Five well-measurable KPIs per process are better than fifteen that are never collected. The auditor wants to see that you measure and react — not that you measure for its own sake.
- Audits without consequence. If internal audit findings vanish into the void, the external auditor will notice by the second surveillance year at the latest. Every finding needs an owner, a deadline and an effectiveness check.
Conclusion
ISO 9001 is achievable at reasonable cost for an IT service provider with 10 to 20 staff, provided you read the standard as a framework for lean, lived processes rather than an invitation to double your administration. Budget 15 to 30 internal person-days plus 11,000 to 23,000 EUR in external cost for the first year, then a running effort of a few days per year. The real benefit is not the certificate itself, but the clarity a well-thought-out process setup brings to your team.
DATAZONE supports IT service providers and mid-market IT teams in preparing for ISO 9001 and building lean QM systems that fit engineering organisations — including process documentation, internal audits and tool selection. If you want to approach certification in a structured way, get in touch.
More articles
TrueNAS Made in USA: Honestly Assessing the Data Privacy Debate for EU Customers
TrueNAS is developed in the US -- is that a GDPR problem? An honest look at CLOUD Act, telemetry, source-available code and support contracts for EU customers.
GDPR Data Processing Agreements: 3 Typical SMB Mistakes
DPA, sub-processors, third-country transfers: the three most common GDPR mistakes in SMBs and how to close them with a solid DPA register.
Cyber Insurance 2026: What Insurers Demand from SMBs
Insurers in 2026 demand increasingly detailed minimum standards — MFA everywhere, documented patch management, EDR, immutable backups, training, incident response plan, segmentation. What is on the pre-contract questionnaire and what gets checked in a claim.