Pipeline, contract review and audit-time calculation, audit checklists, findings and corrective actions, independent technical review and decision, and certificates anyone can verify with a QR code. Built around ISO/IEC 17021-1 so your next accreditation assessment is the easy part.
No more spreadsheets, shared drives and a CRM that doesn't understand what a Stage 1 is. Every step below is a first-class object with its own permissions, audit trail and documents.
A kanban of every case from enquiry to certified, with the stages an accredited body actually uses. Every move is logged with who, when and why.
17021-1 §9.1The IAF MD5 audit-time engine: personnel, sites, complexity, multi-standard integration and every influencing factor. Stage 1, Stage 2, surveillance and recert days, versioned and approved by a second person.
IAF MD5 · MD1 · ISO 27006Your own day rates, application and certificate fees produce a quote and a branded PDF straight from the review. Change the review, the quote follows.
17021-1 §9.1.3Clause-by-clause checklists per standard. Record a result, notes and evidence per clause and raise a finding from any line with one click.
17021-1 §9.4Major, minor, observation, OFI. Client responses, root cause, acceptance rounds and closure, all against the finding, with due dates and reminders.
17021-1 §9.4.8An independent reviewer, a six-point checklist and a recommendation, then a decision that the system refuses to record if the decider was on the audit team, a major is open or the review disagrees.
17021-1 §9.5Sequentially numbered, branded certificate PDFs. Every certificate carries a QR code to a public page showing live status, scope and validity, so nobody can fake one.
17021-1 §9.6An auditor competence matrix per standard and role, enforced at assignment. Conflict-of-interest declarations per case, required before anyone audits, reviews or decides.
17021-1 §5.2 · §7.1Surveillance due, recertification due, audits next week, findings overdue. In-app and by email, to the right people, once.
17021-1 §9.6.2Email a client a personal link: they see their audits, download certificates, and answer findings with root cause, corrective action and evidence. Your auditor gets notified, reviews, and closes.
17021-1 §9.4.9Every client, case, audit, finding and certificate has its own document store. Generated PDFs are filed automatically and locked.
17021-1 §8.4Branded audit plan with a clause-based agenda, an audit report with findings and clause-by-clause results, and a quotation letter from the contract review. Generated, filed and locked automatically.
17021-1 §9.2.3 · §9.4.8Logo, colours, scheme marks, signatory and accreditation wording on every certificate, quote and page your clients see.
Accreditation symbol rulesEach body is a sealed workspace. Group companies can run a certification body and a consultancy side by side with hard separation and an automatic two-year impartiality check.
17021-1 §5.2.5–5.2.9CertifyPilot doesn't just store records, it enforces the rules that accreditation assessors check: who did what, whether they were competent to, whether they declared impartiality, and whether the decision was independent.
Sign up, upload your logo, set your day rates and fees, invite your auditors and reviewers with their competences.
Add organisations and contacts, or send us your spreadsheet and we'll load it. Open cases for anything in flight.
Contract review, quote, plan the audit, checklist, findings, review, decision, certificate. Your assessor sees the whole trail.
Gap analyses, implementations, internal audits and retained support, each with its client, standards, documents and dates. When your client is ready, they walk into certification with a complete file.
Start free for 14 days. Cancel anytime. Prices in EUR, excluding VAT.
Authenticator-app MFA with recovery codes, mandatory for admins and reviewers.
TLS everywhere, encrypted secrets at rest, sealed workspaces per body, nightly backups, EU hosting.
Every change to a record, every sign-in and every failed attempt is logged with IP and device.
Adversarial code review of authentication, tenancy and uploads with all findings fixed and regression-tested.
Content-Security-Policy, HSTS, strict cookies, single-use invitations, throttled logins.
Export your register any time. GDPR-ready processing terms for every customer.
No. It's built to the level an accredited body needs, which means an unaccredited body or one preparing for accreditation gets a system that already behaves the way assessors expect. Consultancies use the separate consultancy workspace.
It implements the IAF MD5 chart and the multipliers for complexity, multi-site, multi-standard integration, and the ISO/IEC 27006 and ISO 50003 variants. Every factor you tick is recorded on the contract review, versioned, and approved by a second person. We validated it line by line against a working certification body's spreadsheet.
Checklists are structured by clause number and heading. The requirement wording is ISO copyright and is not included; if you hold a licence, it can be added per clause.
Yes. Send us your client list and register and we'll load it as part of onboarding on Professional and Enterprise plans.
In the EU, with nightly backups. Enterprise customers can request a dedicated instance.
Choose a plan and keep going. If you don't, your workspace is paused, not deleted, and you can pick up where you left off.
Start a trial, or book a 30-minute walkthrough and we'll set it up with you.