certifications7 min read

How to get ISO 21001 certification in 2026: the full roadmap

ISO 21001 is the international management-system standard dedicated to educational and training organisations (EOMS). A voluntary approach, it conditions no French funding — but it durably structures an organisation and gives it recognition that extends beyond France. Here is the complete path to obtaining it, from the initial decision to the certificate, in the edition currently in force: ISO 21001:2025, the second edition published in July 2025, which replaces the 2018 edition.

Before starting: validate the scope and the business case

First question to settle: is certification worth the investment for your profile? The standard addresses any organisation using a curriculum to develop competencies — schools, universities, apprenticeship training centres (CFA), continuing-education providers, in-house training departments. It delivers the most value to organisations targeting international or institutional clients, or seeking consistent management across several sites. For a sole-operator organisation focused on the French market, Qualiopi certification is generally enough — our article on the real cost of ISO 21001 certification helps put figures behind the decision.

Second question: what scope should you certify? You can cover the whole organisation or only part of it (one site, one family of services). A narrower scope reduces the workload and the number of audit days, but limits the commercial use of the certificate.

Step 1 — frame the project and run the gap analysis

Framing comes down to three decisions: a written scope, a designated project lead, and a formal commitment from top management. The latter is not cosmetic: leadership is a full block of requirements in the standard, and the auditor will question management about its policy and objectives.

Then comes the gap analysis: comparing your current practices with the standard’s requirements, chapter by chapter. For an organisation already certified against Qualiopi, this diagnosis often brings good news: needs analysis, satisfaction measurement, complaint handling and continuous improvement already exist. The gaps then concentrate on the management-system layer itself: analysis of the context and interested parties, risk-based thinking, management review.

Step 2 — build the EOMS management system

The core of the work is formalising a coherent system around the learner’s journey:

  • the policy and objectives of the organisation, carried by top management;
  • the process map: needs analysis, course design, admission and entry assessment, delivery, assessment of learning outcomes, feedback handling;
  • the analysis of risks and opportunities, and the resulting actions;
  • the documented information genuinely needed — the standard requires control of processes, not a mountain of procedures;
  • the education-specific provisions that give ISO 21001 its personality: accessibility and equity between learners, ethical conduct in education, protection of learners’ data.

A case study published in 2024 by R. M. G. Bretaña, M. H. Almaguer and M. B. V. Bonilla in Scientia et Technica, on implementing ISO 21001:2018 in postgraduate academic programmes at the University of Havana, illustrates the winning method well: start from the existing pedagogical processes and connect them to the standard’s requirements, rather than imposing a generic documentation system.

Step 3 — let the system run before having it audited

A classic mistake: requesting the audit as soon as the documentation is ready. A management system must have produced real records — surveys actually analysed, non-conformities handled, indicators tracked — to be auditable. Two explicit requirements of the standard mark out this phase:

  1. the internal audit, which checks the system’s conformity and effectiveness with an independent eye;
  2. the management review, where top management analyses the results and decides on improvement actions.

If you already run mock audits for Qualiopi, the logic is identical — our mock-audit method transposes to the ISO 21001 requirements without difficulty.

Step 4 — the certification audit, in two stages

As with other certifiable management-system standards, the initial audit unfolds in two stages: a first review of the documented system and of the organisation’s readiness, then the full audit, on site or partly remote depending on the case. The auditor confronts your actual practices with the requirements: interviews with management and teaching teams, review of learner files, verification of the continuous-improvement loop. The detailed process, including how non-conformities are handled, is covered in our dedicated article on the ISO 21001 certification audit.

Non-conformities raised do not necessarily prevent certification: they call for an action plan, whose relevance conditions the issuing of the certificate.

After the certificate: surveillance and renewal

The certificate opens the classic life cycle of management-system standards: periodic surveillance audits, then a renewal audit at the end of the cycle. Between audits, three habits keep the system healthy: maintaining the rhythm of internal audits and management reviews, systematically exploiting learner feedback, and updating the risk analysis when the organisation evolves.

A point of attention for 2026: organisations certified against the 2018 edition must organise their transition to ISO 21001:2025 according to the timetable communicated by their certification body. For a first certification, target the new edition directly.

And what about Qualiopi?

ISO 21001 gives access to no French public funding: only Qualiopi conditions the CPF (individual training account), OPCOs (sectoral funding bodies), France Travail and the regional councils. The two approaches nonetheless reinforce each other: an EOMS supplies much of the evidence expected by the RNQ (France’s national quality framework) on designing, adapting and evaluating services — detailed indicator by indicator on our /en/indicateurs page. The full articulation between the two frameworks is covered in our comparison of Qualiopi and ISO 21001.

Take action

Before committing, browse the full profile of ISO 21001 certification: scope, steps, frequently asked questions and a free ebook to structure your project. And if your Qualiopi foundation is not yet consolidated, start there — it is what conditions your funding.

FAQ

Frequently asked questions

+How long does it take to obtain ISO 21001 certification?

There is no regulatory duration: everything depends on the gap between your current practices and the standard's requirements. An organisation that is already structured (Qualiopi-certified, for instance) moves much faster than one starting from scratch. As a rule, expect several months between project kick-off and the certification audit, because the system must have genuinely operated before it can be audited.

+Who issues ISO 21001 certification?

Accredited certification bodies such as AFNOR Certification or Bureau Veritas, among others. ISO writes the standard but certifies no one. Requesting several quotes is strongly advised, as the number of audit days proposed — and therefore the price — can vary from one body to another.

+Do you need Qualiopi before aiming for ISO 21001?

No, the two approaches are independent. But if you are a French training organisation living off public and pooled funding, Qualiopi — the mandatory French quality certification — is the absolute priority: it alone conditions access to the CPF (individual training account), OPCOs (sectoral funding bodies) and France Travail. ISO 21001 comes afterwards, as a voluntary structuring approach that reuses much of the evidence already produced.

Read next