Too many standards, not enough clarity

Ask a handful of contracting firm owners about ISO certification and you will hear a common complaint: there are simply too many standards, and no obvious place to start. ISO 9001, ISO 45001, ISO 14001, ISO 27001 — each addresses a different dimension of how a business operates, and tender documents often reference more than one without explaining which matters most for a given firm at a given stage. The result is that many companies either delay certification altogether or pursue the wrong standard first, spending budget and months of effort on something that doesn't move the needle on the tenders they actually want to win.

For most contracting firms, the real decision usually comes down to two standards: ISO 9001 and ISO 45001. Understanding what each one actually covers makes the choice far more straightforward.

ISO 9001: quality management

ISO 9001 is the internationally recognized standard for quality management systems. At its core, it asks a firm to define consistent processes for how work gets planned, executed, checked, and improved — from how a project is scoped and priced, to how materials are procured, to how completed work is inspected before handover. It applies broadly across almost any industry, which is exactly why it tends to be the first ISO certificate most firms pursue: it is relevant to virtually every tender, and it builds the documentation discipline that other standards later build on.

For a contracting firm, ISO 9001 signals to clients and authorities that project delivery is not left to individual judgment alone — there is a documented system behind it, one that produces consistent, verifiable quality regardless of which team or site is involved.

ISO 45001: occupational health and safety

ISO 45001 is the standard for occupational health and safety management systems. It requires a firm to systematically identify workplace hazards, assess risk, and put controls in place to prevent injury and illness — covering everything from site safety procedures to incident reporting and worker training. For contracting specifically, where teams work on active construction sites with heavy equipment, height risk, and constantly changing conditions, this is not a peripheral concern. It is one of the highest-risk categories of work in the entire economy, and clients — particularly on larger and government-linked projects — increasingly treat a documented safety management system as a baseline expectation rather than a bonus.

How to decide which one comes first

In practice, the right starting point depends on two things: the nature of your work and what your target tenders actually require.

  • If your firm is early in its certification journey and your tenders emphasize general quality and delivery reliability, ISO 9001 is usually the more natural first step — it is broader in relevance and often a prerequisite for other management system certifications.
  • If your work involves significant on-site labor, heavy machinery, or elevated safety exposure, and your target clients specifically require evidence of a safety management system, ISO 45001 may need to move up the priority list even if it comes second chronologically.
  • Review your active and upcoming tender documents directly — they often specify exactly which certifications are mandatory versus preferred, which removes the guesswork.
The standard that unlocks your next tender is the right one to pursue first — certification for its own sake rarely justifies the investment on its own.

Can you pursue both together?

Yes, and in contracting it is common practice. Because both standards share a similar structure — the same high-level framework used across modern ISO management system standards — firms often find that documentation and processes built for one accelerate the work on the other. Many contracting firms choose to run both certification projects in parallel, or complete ISO 9001 first and follow quickly with ISO 45001 once the initial documentation habits are in place, rather than treating them as two entirely separate undertakings years apart.

Practical first steps

Whichever standard you prioritize, the starting point is the same: an honest gap assessment of where your current processes stand against the standard's requirements. From there, a realistic implementation plan, staff training, and a period of practical application before the formal certification audit will get you to a credible, defensible certificate — one that holds up under real client and auditor scrutiny, not just on paper.