Guide · Certification & tenders
Do you need ISO certification to win tenders?
The short answer: often, yes — and increasingly so. ISO certification is rarely a legal requirement to trade, but it is one of the most common things buyers ask for when deciding who they'll actually award work to. If bids keep stalling at the pre-qualification stage, a missing certificate is one of the first places to look.
Where ISO shows up in a tender
You'll usually meet it in the qualifying stage — a Selection Questionnaire (SQ), Pre-Qualification Questionnaire (PQQ) or supplier assessment — before anyone reads your actual proposal. Certification tends to appear in one of two ways:
- Pass/fail. Some contracts set a certificate as a minimum requirement — no certificate, no place on the shortlist.
- Scored. More often it's a scored criterion: certified bidders gain marks that uncertified ones don't, so you're not excluded outright but you start behind.
Public-sector buyers can require or score certification where it's proportionate and relevant to the contract, and many do. They're often expected to accept equivalent evidence rather than the certificate alone — so it isn't always strictly mandatory — but certification is the simplest, most credible way to clear the bar, and its absence usually costs you marks.
In the UK, public procurement now runs under the Procurement Act 2023, in force since 24 February 2025. At the selection stage, buyers set conditions of participation that a supplier must meet to take part, and relevant management-system certification is commonly required or scored there. Private-sector and construction buyers typically run their own pre-qualification questionnaires (PQQs) or supplier assessments — so in practice you'll meet both.
Which standard matters for which contract
- ISO 9001 — quality. The most widely requested, across almost every sector. If a tender names one standard, it's usually this one.
- ISO 45001 — health & safety. Expected for construction, manufacturing, facilities and any site-based or higher-risk work; a staple of contractor and subcontractor pre-qualification.
- ISO 14001 — environmental. Common where environmental impact matters, and increasingly pulled in through ESG, net-zero and social-value requirements.
- ISO/IEC 27001 — information security. Increasingly asked for wherever you handle client or personal data, provide IT or digital services, or sit in a supply chain with security obligations.
Bigger and higher-risk contracts often ask for a combination — quality plus safety plus environmental is a familiar trio in construction and civils.
One practical point: buyers usually want UKAS-accredited certification — issued by a body accredited by the United Kingdom Accreditation Service. Certificates from non-accredited bodies are often rejected, so the accreditation behind the certificate matters as much as the certificate itself.
In construction specifically, health-and-safety pre-qualification is often handled through SSIP (Safety Schemes in Procurement) member schemes such as CHAS, SafeContractor and Constructionline, which sit alongside ISO 45001 — expect to be asked about both.
Why buyers ask for it. A certificate is a shortcut to trust. Rather than assess every supplier's processes from scratch, a buyer treats independent certification as evidence you run a real, audited management system. It's risk transfer: if something goes wrong, they can show they chose a certified supplier.
Why demand is rising
Requests for certification have been trending up, driven by a few forces at once:
- Supply-chain assurance. Large organisations increasingly push their own standards down to suppliers and subcontractors, so requirements cascade far beyond the original buyer.
- ESG and social value. Environmental and governance expectations in procurement pull ISO 14001 (and the discipline behind it) into more bids.
- Data and security. As more work involves handling data, ISO 27001 is appearing in tenders that never used to mention security.
- Simple competition. Once enough competitors in a sector are certified, it becomes the baseline — and being the uncertified bidder stands out for the wrong reason.
What if you're not certified yet?
Not being certified today doesn't mean sitting out every bid, but it does mean acting deliberately:
- Find out what your target contracts actually ask for. Read the SQ/PQQ requirements for the work you want — don't certify to standards no one's requesting.
- Start before you urgently need it. Certification takes months, and most of that time is building and running the management system so there's evidence to audit. The worst time to start is the week a tender lands.
- Evidence equivalent measures in the meantime. Many tenders accept documented processes, risk management, audits and management review as equivalent — and demonstrable progress beats a blank.
- Build the system, not just the certificate. A certificate maintained as a once-a-year scramble is fragile. A live management system keeps you continuously ready — for the next surveillance audit and the next bid alike.
Where Kavorly fits
Kavorly helps you build and keep the management system that certification depends on — quality, health & safety, environmental and information security — as one live system rather than a folder rebuilt before each audit. Because the evidence stays current as you work, both your certification and your next tender response draw on the same up-to-date record, instead of a last-minute scramble each time. It connects to the Microsoft 365 tools most teams already run.
See the platform underneath → · Running several standards as one system →
This guide is a general introduction, not procurement, legal or certification advice. Certification requirements vary by contract and buyer; always check the specific tender documents, and refer to a certification body for the authoritative route to certification.