Getting ISO Certified: The Need-to-Know about ISO

Richard Brown


Subscribe Contact us

Authors


In 1947, 65 delegates from 25 countries collected to produce the International Organization for Standardization (ISO). An independent, non-governmental body, ISO came together with the intention of sharing knowledge in order to ‘support innovation and provide solutions to global challenges’ (see their official website). Just over 70 years since publishing their first ISO standard in 1951, the ‘Standard reference temperature for industrial length measurements’, the organisation has grown exponentially to encompass 24,992 International Standards across the technology, management, and manufacturing sectors.


Cambridge Management Consulting has spent the best part of two years devoted to earning their certification across three families of these standards – namely, 9001, 14001, and 27001 – through a combined effort of meticulousness, analysis, and a commitment to constant improvement, both internally and for the benefit of our customers and clients.


In this article, we go into further detail about what ISO is and what it means to be certified, specifically the three that Cambridge MC have prioritised; why it matters to be certified; the process to getting there; and how Cambridge MC can help you to achieve the same standardisation. 


What is an ISO?


As aforementioned, an ISO is one in a family of standardisations that establish a benchmark for how an organisation should operate within a particular faculty. At the core of this is ISO 9001, which is focussed on quality management; given its emphases of customer focus, top management, process transformation, and continual improvement, 9001 is the most fundamental and adaptable standard that ISO certifies (being applicable to organisations of any size) and is thus the most widely held. At the time of writing, the ISO official website boasts of over one million organisations across over 170 countries holding an ISO 9001. 


However, ISO does not stop here. This page of their official website lists 17 further standards an organisation might wish to undergo, and these are just their ‘most popular’. Using those standards that we decided to adopt as examples, here is a snapshot of the range of business operations that ISO covers:


ISO 9001: To reiterate, ISO 9001 lies at the core of the ISO project. The most commonly held standard, 9001 assists a business to lay their foundational principles of quality management, which further standards, such as those listed below, can subsequently be layered upon. To summarise, using the values listed in more detail here, ISO 9001 prioritises and optimises an organisation’s customer focus, leadership, people engagement, process approach, improvement, evidence-based decision making, and relationship management.


ISO 14001: An ever more pressing, relevant, and vital standard, ISO 14001 focuses on the environmental impact of an organisation, and how they can optimise their operations to be more sustainable. Not only is this an attractive standard to possess from a business point of view, improving the reputation of your organisation and providing a ‘competitive and financial advantage through improved efficiencies and reduced costs’ (see this brochure on the standard), but it also contributes to the betterment of the world and encourages the same from suppliers and clients by integrating them into your own business systems—hence Cambridge MC’s own choice to earn this certification. 


ISO 27001: The most recent standard under Cambridge MC’s belt, ISO 27001 is the world’s most recognised standard for information security management systems (ISMS). In a world with increasingly frequent and prevalent cyber security risks and traps, this standard assists organisations to become equally aware of them, encouraging proactivity by identifying and addressing any chinks in an organisation’s digital armour, and thus tackling any issues before they arise. In short, ISO 27001 names its core values as risk management, cyber-resilience, and operational excellence. 


These are just several of ISO’s thousands of standardisations designed to streamline the operations and running of an organisation. However, the work does not stop here: though ISO has taken the time and care to design these standards, your organisation must apply the effort to implement them. In the next couple of sections, we break down both why it is desirable to have an ISO and the method behind getting certified, from the lessons we learned going through the process. 


Why we chose to get certified


As with most organisations, the choice to become ISO certified for Cambridge MC came down to one thing: risk management. At the crux of the ISO journey, particularly 9001 but also, for Cambridge MC, when it came to beginning 14001 and 27001, is identifying and addressing the potential risks to our organisation before they arise. Waiting to complete an ISO when and while risks become apparent will only cause them to exacerbate. Beginning the process well in advance allows them to be acknowledged, minimised, and resolved before they have a chance to inflict significant damage upon a business. 


For our business environment, one of the most crucial factors to completing ISO 9001 was growth. Though rapidly growing in clientele and project size, Cambridge MC is still a relatively young company, and was, until not too long ago, relatively small. At this time there was less need for an established QMS system, however, as our team began to expand and multiply, we quickly recognised that it would be an essential factor by the time we could prepare the groundwork. In this way, the QMS system that was built through ISO 9001 at the time has since been able to grow and mature as the company does, expanding to incorporate aspects of the company as they come to fruition. To those start-ups or smaller organisations anticipating growth of this nature, we strongly recommend engaging with ISO 9001 sooner rather than later. 


Since then, achieving 14001 and 27001 have felt like very natural steps. Beyond the reasons listed previously, earning and understanding 14001 was very close to the heart of what Cambridge MC does, given our close proximity and working relationship with our sustainability-led sister-company, edenseven. From there the decision was simple: how do we best demonstrate the principles that we promote. 


With 27001, the thought process boiled down to best practice. As a company that handles large amounts of data day-to-day, without adopting an official plan to reduce and avoid security risks, we could potentially jeopardise the running of both our own company and that of our clients. With ISO 27001, we have closed-up any gaps that could allow these dangers to sneak through.


The ISO Process


Earning the ISO certification, beginning specifically with 9001, took around 18 months in total to complete. With regard to identifying and evaluating the risks that you seek to absolve through gaining the ISO, the process opened with an assessment of the scope that the ISO would cover. This does not have to be static, it can reflect the current nature of your organisation in a way that leaves room for change, growth, and maturity over time, as we experienced at Cambridge MC. This beginning stage is further supplemented by the use of an internal auditor, who assists with identifying and substantiating the scope of the project.


Once your scope is outlined, you can begin filling it in. At Cambridge MC, we conducted this by designing and building out a company manual. This initially represented and reflected the QMS principles of ISO 9001 and our assimilation of them into our working patterns, however it has since evolved to include ISO 14001 and 27001. (The latter of these also depended on the achievement of Cyber Essentials and Cyber Essentials Plus externally to the ISO, making us the first organisation affiliated with Data Connectivity (our primary IT provider) to earn these certifications.)


Once this was completed, we then subscribed to a certifying body, who appointed an external auditor to check that we have since complied with ISO standards not just on paper, but in practice. They had the opportunity to delve as deep into our working operations as they please, and open up as much interpretation within our manual as they deemed appropriate, to affirm that we were performing to standard. Only then could we achieve certification.


The process does not end there. At Cambridge MC, we are not concerned with earning the ISO standardisation in order to get a certificate on our wall or a badge on our website’s homepage, and this is something that ISO itself assures. The certification is only valid for three years, at which point it will need to be renewed via another assessment; in the interim your organisation must undergo frequent surveillance to assure that you are keeping to your principles in the meantime. As such, one of the primary values promoted by the ISO and adopted proudly by Cambridge MC, is continual improvement. 


At Cambridge MC, we demonstrate this through our Weekly Learning and Development (L&D) sessions – an internal seminar every Friday afternoon in which one of our clients or team members has the opportunity to educate the rest of the group on a particular topic or industry. Though optional, these sessions are strongly encouraged and give the chance for the Cambridge MC team to improve their learning and skillset outside of their particular specialism or department. Further to this, we are committed to the principles attached to our ISO certification by regularly reviewing our risk register, processes, policies, procedures, etc. The more assimilated these self-assessments become in our working patterns, the more ingrained the ISO values have become.


Notes:


[1] Given that ‘International Organization for Standardization’ translates to different acronyms in different languages, in line with their founding principles, these delegates decided to standardise it to ‘ISO’, partially derived from the Greek ‘isos’ to mean ‘equal’. ‘Whatever the country, whatever the language, we are always ISO.’


How Cambridge MC can help you


Becoming ISO certified is incredibly beneficial, if not near-essential, to the running of a successful and growth-orientated organisation. Assimilating a widely-recognised and proven standardisation system into one’s business and operating patterns not only allows for minimisation of risks and continued improvement throughout growth phases, but it also proves to current and potential clients and customers that you take these principles seriously.


For these reasons, if you are similarly interested in having your organisation become ISO certified, Cambridge Management Consulting is now equipped with the knowledge and experience to help you bring this to fruition. Please get into contact for any insight, advice, or guidance that can help you along your own journey to getting certified. 

About Cambridge Management Consulting


Cambridge Management Consulting (Cambridge MC) is an international consulting firm that helps companies of all sizes have a better impact on the world. Founded in Cambridge, UK, initially to help the start-up community, Cambridge MC has grown to over 200 consultants working on projects in 25 countries. Our capabilities focus on supporting the private and public sector with their people, process and digital technology challenges.


What makes Cambridge Management Consulting unique is that it doesn’t employ consultants – only senior executives with real industry or government experience and the skills to advise their clients from a place of true credibility. Our team strives to have a highly positive impact on all the organisations they serve. We are confident there is no business or enterprise that we cannot help transform for the better.


Cambridge Management Consulting has offices or legal entities in Cambridge, London, New York, Paris, Dubai, Singapore and Helsinki, with further expansion planned in future. 


For more information visit www.cambridgemc.com or get in touch below.


Contact - Africa

Subscribe to our Newsletter

Blog Subscribe

SHARE CONTENT

Pembroke College lawn bathed in sunlight
by Tim Passingham 12 March 2026
CAMBRIDGE | See how Cambridge MC and Pembroke College are creating mutual value through a unique corporate partnership spanning student opportunities, academic collaboration and industry events | READ FULL CASE STUDY
Neon sharks made out of code.
by Simon Crimp 9 March 2026
Cyber Security | Ransomware in 2026 is a board-level resilience issue. Learn the key risks, weak spots and practical questions boards should ask to improve readiness, recovery and response.
The Top 21.2026 at the awards event in Cambridge, UK.
6 March 2026
The #21toWatch Top21.2026 winners have been announced at an awards ceremony at The Glasshouse innovation hub in Cambridge.
Asian business woman near a long window and looking at a tablet.
by Arianna Mortali 6 March 2026
BLOG | A student’s perspective on why women shouldn’t have to ‘play masculine’ to succeed at work – and how valuing empathy, confidence and inclusive leadership can help close gender gaps and build healthier organisations.
Abstract squiggle of circles
by Simon Crimp 19 February 2026
Where should leaders start with AI in 2026? A practical guide to moving beyond pilots, clarifying risk appetite, strengthening governance, improving data readiness, and delivering measurable enterprise value from AI at scale | READ FULL ARTICLE
Close up of a data centre stack with ports and wires visible
12 February 2026
We were approached by one of the fastest growing data centre providers in Europe. With over 20 data centres throughout the continent, they are consistently meeting the need for scalable, high-performance infrastructure. Despite this, a key data centre in Scandinavia had become reliant on a single, non-redundant 1 Gbps internet service from a local provider, posing significant risks to operational continuity. To enhance the reliability of its network and resolve these risks, our client needed to establish additional connectivity paths to ensure the redundancy of its infrastructure. The Ask Cambridge Management Consulting was engaged to address these connectivity challenges by identifying and evaluating potential vendors and infrastructure options to create second and third connectivity paths. This involved exploring various types of connectivity, including internet access, point-to-point capacity, wavelengths, and dark fibre. Additionally, Cambridge MC was asked to provide recommendations for building a local fibre network around the data centre to control and maintain diverse paths. This would allow the data centre to connect directly to nearby points of presence (PoPs) and reduce dependency on external providers, thereby enhancing network resilience and operational control. The goal of this project was to ensure that the Nordic data centre could maintain continuous operations even in the event of a failure in the primary connection. Approach & Skills Cambridge MC approached the project with a focus on ensuring operational continuity and resilience for the data centre. By identifying multiple connectivity paths, we aimed to mitigate the risk of network failures and ensure that the data centre could maintain continuous operations even in the event of a failure in the primary connection. This approach allowed Cambridge MC to provide a comprehensive solution to address both immediate and long-term connectivity needs. We employed a combination of Agile and Waterfall methodologies to manage the project. The initial investigative phase allowed a Waterfall approach, in which our team conducted thorough research and analysis to identify potential vendors and connectivity options. This phase involved detailed interviews with various telecommunications providers and an assessment of publicly available information. Once the initial analysis was complete, the workflow transitioned to an Agile approach for the implementation phase. This allowed Cambridge MC to adapt to new information and feedback from stakeholders, ensuring that the final solution was both flexible and robust. Challenges Lack of information: One of the primary obstacles we faced was the lack of detailed network maps and information from some of the potential vendors. To overcome this, the team conducted extensive interviews with contacts at these companies and leveraged its existing network of industry contacts to gather as much information as possible. Remote location: Another challenge was the remote location of the data centre, which limited the availability of local infrastructure and required us to explore creative solutions for connectivity. Cambridge MC addressed this by proposing the construction of a local fibre network around the data centre, which would allow for greater control and flexibility in connecting to nearby PoPs. Fragmented factors: Additionally, coordinating with multiple vendors and ensuring that their services could be integrated seamlessly posed a logistical challenge. We mitigated this by recommending a phased approach to implementation, starting with the most critical connectivity paths and gradually expanding to include additional options. Outcomes & Results Increased Connectivity: Cambridge MC successfully identified and evaluated multiple connectivity paths for the data centre. By exploring various types of connectivity, including internet access, point-to-point capacity, wavelengths, and dark fibre, we provided a comprehensive solution that significantly enhanced network resilience and reliability. Greater Control & Flexibility: Our recommendations for building a local fibre network around the data centre allowed for greater control and flexibility in connecting to nearby points of presence, ensuring continuous operations even in the event of a failure in the primary connection. New Vendors: The team’s extensive network of industry contacts and deep understanding of the regional telecommunications landscape allowed for a thorough and nuanced evaluation of potential vendors and connectivity options. Scope for Future Work: Cambridge MC identified several future developments with the potential to further enhance international connectivity and provide additional redundancy for the data centre. We also proposed further assistance, including a site visit for a more in-depth analysis of options, issuing RFI/RFP to vendors for capacity and fibre, and conducting similar connectivity studies for other candidate sites in the region.
Neon discs fading from blue to green to purple, cascading diagnolly across the screen.
by Cambridge Management Consulting 28 January 2026
Thames Freeport this week revealed the eight companies selected to participate in the Freeport’s Connectivity Lab, an initiative focused on validating commercially proven technologies in live port and logistics environments.
Aerial view of a data centre warehouse in the English countryside
by Duncan Clubb 13 January 2026
Author
by Matt Lawson 2 January 2026
Emerging as a hub for innovation, Thames Freeport is a unique initiative designed to stimulate trade and transform the lives of people in its region. Leveraging global connectivity and occupying a strategic position with intermodal capabilities across river, rail, and road, Thames Freeport has recognised its opportunity to drive economic regeneration for the local area. Thames Freeport engaged Cambridge Management Consulting to design a clear strategy for innovation over the next three to five years. Key considerations for this innovation strategy included objectives and KPIs, the future of the business ecosystem in the region, physical clusters and assets such as innovation hubs, and opportunities and challenges on the way. The Solution Working with our innovation partner, L Marks, Cambridge MC conducted an innovation strategy project which involved the following: Engaging with a range of stakeholders and partners from local authorities to corporate partners across the Thames Freeport area, leveraging interviews with key individuals to build a common picture of innovation aspirations, opportunities, and challenges. Conducting a series of workshops for the Thames Freeport team to consider visions and objectives, themes and focus areas, physical hubs and overall programme structure, and a three-year roadmap plan. Building a comprehensive innovation strategy which internalised all of the above questions. This was then presented to their board and formed the basis of the public tenders for innovation programmes that were then made public. 
More posts