For accredited certification bodies & ISO consultancies

Run your certification body from enquiry to certificate on one platform.

Pipeline, contract review and audit-time calculation, audit checklists, findings and corrective actions, independent technical review and decision, and certificates anyone can verify with a QR code. Built around ISO/IEC 17021-1 so your next accreditation assessment is the easy part.

IAF MD5audit-time engine built in
17021-1lifecycle, end to end
No cardneeded to start
Management system standards supported
ISO 9001ISO 14001ISO 45001ISO/IEC 27001ISO 50001ISO 22000+ your own schemes
Everything a certification body does

One record per client, from the first phone call to the third-year recertification.

No more spreadsheets, shared drives and a CRM that doesn't understand what a Stage 1 is. Every step below is a first-class object with its own permissions, audit trail and documents.

Certification pipeline

A kanban of every case from enquiry to certified, with the stages an accredited body actually uses. Every move is logged with who, when and why.

17021-1 §9.1

Contract review & audit time

The IAF MD5 audit-time engine: personnel, sites, complexity, multi-standard integration and every influencing factor. Stage 1, Stage 2, surveillance and recert days, versioned and approved by a second person.

IAF MD5 · MD1 · ISO 27006

Instant quotes

Your own day rates, application and certificate fees produce a quote and a branded PDF straight from the review. Change the review, the quote follows.

17021-1 §9.1.3

Audit checklists

Clause-by-clause checklists per standard. Record a result, notes and evidence per clause and raise a finding from any line with one click.

17021-1 §9.4
!

Findings & corrective actions

Major, minor, observation, OFI. Client responses, root cause, acceptance rounds and closure, all against the finding, with due dates and reminders.

17021-1 §9.4.8

Technical review & decision

An independent reviewer, a six-point checklist and a recommendation, then a decision that the system refuses to record if the decider was on the audit team, a major is open or the review disagrees.

17021-1 §9.5

Certificates with QR verification

Sequentially numbered, branded certificate PDFs. Every certificate carries a QR code to a public page showing live status, scope and validity, so nobody can fake one.

17021-1 §9.6

Competence & impartiality

An auditor competence matrix per standard and role, enforced at assignment. Conflict-of-interest declarations per case, required before anyone audits, reviews or decides.

17021-1 §5.2 · §7.1

Surveillance & expiry reminders

Surveillance due, recertification due, audits next week, findings overdue. In-app and by email, to the right people, once.

17021-1 §9.6.2

Client portal

Email a client a personal link: they see their audits, download certificates, and answer findings with root cause, corrective action and evidence. Your auditor gets notified, reviews, and closes.

17021-1 §9.4.9

Documents & evidence

Every client, case, audit, finding and certificate has its own document store. Generated PDFs are filed automatically and locked.

17021-1 §8.4

Audit plans, reports & quotes

Branded audit plan with a clause-based agenda, an audit report with findings and clause-by-clause results, and a quotation letter from the contract review. Generated, filed and locked automatically.

17021-1 §9.2.3 · §9.4.8

Your brand, everywhere

Logo, colours, scheme marks, signatory and accreditation wording on every certificate, quote and page your clients see.

Accreditation symbol rules

Multi-tenant, by design

Each body is a sealed workspace. Group companies can run a certification body and a consultancy side by side with hard separation and an automatic two-year impartiality check.

17021-1 §5.2.5–5.2.9
Built for accreditation

Your INAB, UKAS or ANAB assessor will find what they're looking for.

CertifyPilot doesn't just store records, it enforces the rules that accreditation assessors check: who did what, whether they were competent to, whether they declared impartiality, and whether the decision was independent.

  • ✔ Decision-maker cannot be on the audit team, enforced in code
  • ✔ Certification cannot be granted with an open major nonconformity
  • ✔ No assignment without approved competence for that standard and role
  • ✔ Impartiality declaration required before any audit activity
  • ✔ Contract review approved by someone other than its author
  • ✔ Immutable activity log on every record, with IP and user agent on sign-ins
  • ✔ Public certificate validity as required by §9.6.1
How it works

Live in an afternoon.

Create your workspace

Sign up, upload your logo, set your day rates and fees, invite your auditors and reviewers with their competences.

Import your clients

Add organisations and contacts, or send us your spreadsheet and we'll load it. Open cases for anything in flight.

Run the next audit in CertifyPilot

Contract review, quote, plan the audit, checklist, findings, review, decision, certificate. Your assessor sees the whole trail.

Gap analysis · Burren FoodsActive
ISO 27001 implementation · Fintech CoActive
Internal audit · Atlantic LogisticsCompleted
Ready for certification → target CBHandover
For ISO consultancies

Manage engagements, not just emails.

Gap analyses, implementations, internal audits and retained support, each with its client, standards, documents and dates. When your client is ready, they walk into certification with a complete file.

See the consultancy workspace →

Pricing

Simple plans. No per-certificate fees.

Start free for 14 days. Cancel anytime. Prices in EUR, excluding VAT.

MonthlyAnnual save 2 months

Starter

Small bodies getting their register out of spreadsheets.
€149 /month
Billed monthly
  • 3 users included
  • Up to 100 active certificates
  • Pipeline, clients & contacts
  • IAF MD5 contract review & quotes
  • Audits, checklists, findings & CAs
  • Technical review & decisions
  • Branded certificates with QR verification
  • 10 GB documents
  • Email support
Start free trial
Most popular

Professional

Accredited bodies that want every §5–§9 control enforced.
€349 /month
Billed monthly
  • 10 users included
  • Unlimited certificates
  • Everything in Starter
  • Client portal for findings & evidence
  • Competence matrix & assignment checks
  • Impartiality declarations
  • Reminders by email
  • Google Drive / Microsoft 365 sync
  • 100 GB documents
  • Data migration & onboarding
  • Priority support
Start free trial

Enterprise

Multi-scheme bodies, groups and anyone with a procurement team.
Custom
Annual contract
  • Unlimited users
  • Everything in Professional
  • Multiple workspaces & related-body controls
  • Single sign-on (SSO)
  • API access & exports
  • Custom certificate & report templates
  • Dedicated instance / data residency
  • Named contact & SLA
Talk to us

Consultancy

ISO consultants managing engagements and client files.
€79 /month
Billed monthly
  • 3 consultants included (+€19/user)
  • Unlimited engagements
  • Clients, contacts & documents
  • Related-body separation controls
  • 25 GB documents
  • Email support
Start free trial

Compare all features →

Security & trust

Your client files deserve better than a shared drive.

Two-factor authentication

Authenticator-app MFA with recovery codes, mandatory for admins and reviewers.

Encrypted, isolated, backed up

TLS everywhere, encrypted secrets at rest, sealed workspaces per body, nightly backups, EU hosting.

Audit trail on everything

Every change to a record, every sign-in and every failed attempt is logged with IP and device.

Independently reviewed

Adversarial code review of authentication, tenancy and uploads with all findings fixed and regression-tested.

Hardened by default

Content-Security-Policy, HSTS, strict cookies, single-use invitations, throttled logins.

Your data is yours

Export your register any time. GDPR-ready processing terms for every customer.

Questions

Frequently asked

Is CertifyPilot only for accredited bodies?

No. It's built to the level an accredited body needs, which means an unaccredited body or one preparing for accreditation gets a system that already behaves the way assessors expect. Consultancies use the separate consultancy workspace.

How does the audit-time calculation work?

It implements the IAF MD5 chart and the multipliers for complexity, multi-site, multi-standard integration, and the ISO/IEC 27006 and ISO 50003 variants. Every factor you tick is recorded on the contract review, versioned, and approved by a second person. We validated it line by line against a working certification body's spreadsheet.

Do you include the text of the ISO standards?

Checklists are structured by clause number and heading. The requirement wording is ISO copyright and is not included; if you hold a licence, it can be added per clause.

Can we migrate from spreadsheets or another system?

Yes. Send us your client list and register and we'll load it as part of onboarding on Professional and Enterprise plans.

Where is our data hosted?

In the EU, with nightly backups. Enterprise customers can request a dedicated instance.

What happens after the trial?

Choose a plan and keep going. If you don't, your workspace is paused, not deleted, and you can pick up where you left off.

See it with your own clients in it.

Start a trial, or book a 30-minute walkthrough and we'll set it up with you.

Start free trialBook a demo