Multi-site ISO certification is reshaping how leaders unify quality across acquired and dispersed operations — and 2026 is the year it stopped being optional.
Direct Answer
What Is Multi-Site ISO Certification?
Multi-site ISO certification is a single management-system certificate that covers multiple operating locations under one centrally controlled system, audited by sampling instead of visiting every site every cycle. It is governed by IAF MD 1:2023 Issue 3 and works for ISO 9001, ISO 13485, ISO 14001, and ISO 45001. Done correctly, multi-site ISO certification slashes audit time, ends documentation drift across acquired sites, and gives leadership one operating model the entire organization can execute.
An acquisition closes on a Tuesday. By Wednesday, your operations team is staring at a problem nobody flagged in due diligence: the new facility documents its processes in a different format, follows a different nonconformance procedure, runs a different management review cadence, and reports to a different management-system framework — if it has one at all. Three years later, that single decision to “let the new site keep doing what it's doing” has compounded into a quality system that cannot be audited, scaled, or trusted.
This is the multi-site ISO certification problem, and it is the most expensive integration mistake mid-market and enterprise organizations make in 2026. It is also the most fixable — provided leadership treats it as a strategic decision rather than an operational afterthought.
The companies pulling away from their peers are not necessarily the largest or best-funded. They are the ones who recognized that a properly executed multi-site ISO certification is not a compliance exercise — it is the operating spine that lets a multi-location organization scale without losing control. Increasingly, that spine carries more than one standard — which is why the strongest programs pair multi-site certification with integrated management systems from the first architecture decision rather than bolting them together later. Unify. Standardize. Scale.
The Strategic Shift
Why Multi-Site ISO Certification Is the Defining Move of 2026
Centralize. Standardize. Scale.
Three forces converged in 2025 to make multi-site ISO certification a board-level conversation rather than a quality-department project. The first is acquisition velocity. Mid-market manufacturers, medical-device firms, and industrial operators have spent three years rolling up smaller competitors, regional plants, and adjacent product lines. Each acquisition adds a site — and each site arrives with its own documentation, its own habits, and its own version of “how we do things here.”
The second force is customer expectation. Procurement teams at large OEMs, hospital systems, and government agencies no longer accept “the parent company is certified” when the actual production site is not. They want to see every operating location covered under a single, auditable management system. A patchwork of legacy certificates and uncovered facilities reads as risk — and risk loses contracts.
The third force is the accreditation landscape itself. As of January 1, 2026, the Global Accreditation Cooperation Incorporated (Global ACI) assumed the roles of both IAF and ILAC, creating a single international accreditation organization and a unified Multilateral Recognition Arrangement. The technical document that governs multi-site ISO certification — IAF MD 1:2023 Issue 3 — remains in force, and existing IAF MLA marks remain valid during the transition. But the consolidation signals something larger: regulators, customers, and certification bodies are converging on the expectation that organizations operate as one system, not as a federation of certified silos.
For senior leaders, the strategic question has shifted. It is no longer “should we certify the new site?” The question is “how do we bring every operating location under one multi-site ISO certification, on a timeline that does not strangle operations or burn through capital?
Organizations that answer that question well in the next 24 months will compound advantage. Their cost-to-audit will fall, their internal-audit workload will consolidate, their procurement responses will accelerate, and their capacity to absorb the next acquisition will increase. Organizations that defer it will discover, the hard way, that legacy single-site certificates do not stitch together — and that the cost to retrofit grows every quarter.
The Cost of Inaction
The Hidden Cost of Skipping a True Multi-Site ISO Certification Strategy
Drift. Duplicate. Disqualify.
Most organizations do not actively decide to skip multi-site ISO certification. They drift past it. Each individual decision — keep the acquired site's existing certificate, let the new plant run its own QMS, postpone the integration project until next budget cycle — looks reasonable in isolation. The compounding cost only becomes visible later, usually during a customer audit, a regulatory finding, or a failed bid.
Documentation Drift Across Sites
Without a unified multi-site ISO certification, each location maintains its own document control system, its own form numbers, its own revision schedules, and its own training records. After eighteen months, the same procedure exists in four versions across four sites — none of them definitive. Internal auditors spend more time reconciling formats than identifying improvements, and corrective actions issued at one site never propagate to the others. The system is alive in name only.
The Audit Time Penalty
Separately certified sites mean separately audited sites. Each site pays the full audit-day calculation under IAF MD 5, with no sampling allowed. A multi-site ISO certification, by contrast, lets a certification body sample sites under the square-root rule, often reducing total audit days by 40-60% across the cycle. For a ten-site organization, that difference compounds into hundreds of hours of leadership time and six-figure annual cost.
Lost M&A Synergy
Acquisition theses almost always promise operational synergy: shared processes, consolidated overhead, faster integration. A fragmented quality landscape blocks all three. Until acquired sites operate under the same multi-site ISO certification umbrella, you cannot share corrective-action data meaningfully, cannot calibrate supplier performance across the enterprise, and cannot present a unified quality story to your largest customers. The synergy promised in the model never materializes — not because the strategy was wrong, but because the operating system that would have enabled it was never built.
The Technical Standard
What Multi-Site ISO Certification Actually Requires Under IAF MD 1:2023
Define. Document. Demonstrate.
IAF MD 1:2023 Issue 3, issued October 18, 2023, is the operative mandatory document for multi-site ISO certification. It works in conjunction with ISO/IEC 17021-1 (the requirements for certification bodies) and IAF MD 5 (audit time determination). Leaders do not need to memorize the document, but they need to understand what it requires of their organization — because eligibility for multi-site ISO certification is not automatic, and the requirements shape every decision in the implementation roadmap.
The Single Management System Test
The foundational requirement of multi-site ISO certification is exactly what it sounds like: every covered site operates under a single, common management system. One quality manual. One set of procedures. One internal-audit program. One management-review process. Sites can have local work instructions tailored to local equipment or regulatory context, but the architecture above the work instructions must be common across the certified scope.
The Central Function Mandate
Multi-site ISO certification requires a clearly identified central function that plans and controls the management system across all sites. This is not necessarily corporate headquarters — it can be a regional center, a quality-of-excellence team, or a designated lead site. What matters is that the central function actually exercises control: it issues procedures, monitors performance, drives corrective action across sites, and conducts management review at the system level. Auditors will visit the central function at every initial audit, every recertification, and at minimum once per year during surveillance.
Sampling Rules and the Square-Root Rule
The economic upside of multi-site ISO certification comes from sampling. Under IAF MD 1:2023, the certification body samples sites rather than auditing every location every cycle. The sample size for an initial audit is the square root of the number of sites (y=√x, rounded up). Surveillance audits use a coefficient of 0.6 (y=0.6√x). For mature systems, recertification can drop to 0.8√x. At least 25% of the sample must be selected at random, and the central function is audited every visit. The audit time per sampled site cannot be reduced by more than 50% from the standard calculation.
Accreditation Timeline
October 18, 2023: IAF issues MD 1:2023 Issue 3, the current technical document governing multi-site ISO certification.
January 1, 2026: Global Accreditation Cooperation Incorporated (Global ACI) commences operations, replacing both IAF and ILAC under one organization.
Throughout transition: Existing IAF MLA marks remain valid; certification bodies, accreditation bodies, and regional groups continue normal operations under MD 1:2023 requirements.
Eligibility — and the Sites That Cannot Be Sampled
Not every organization with multiple sites qualifies for multi-site ISO certification under sampling. Sites must perform similar processes, operate under the same management system, and be centrally controlled. Sites with substantially different processes, products, or risk profiles may need to be audited individually rather than sampled — or may need to be carved out of scope entirely. Eligibility analysis is the first technical decision in any implementation, and getting it wrong invalidates the entire economic case. This is one of the areas where experienced consulting pays for itself many times over; internal auditors trained on MD 1:2023 can flag eligibility risks before they become certification-body findings.
The Roadmap
The Five-Phase Roadmap for Multi-Site ISO Certification
Diagnose. Architect. Deliver.
Every successful multi-site ISO certification follows the same fundamental sequence. Organizations that try to skip phases — typically by jumping straight to documentation rewrites without the diagnostic phase — almost always end up redoing the work later. The roadmap below has been refined across 28 years of MSI implementations, 80+ certifications supported, and 200+ audits attended.
Phase 1 — Diagnose the Existing State
A multi-site ISO certification project starts with an honest inventory. Which sites have current certificates? Under what standard? Issued by which certification body, accredited by which accreditation body? What scope is covered, what is excluded, and what is the next surveillance date? What does each site's existing management system actually look like in practice — not just on paper? This phase typically takes four to six weeks for a five-to-ten-site organization and produces a single map that leadership can use to make architecture decisions.
The diagnostic phase also surfaces the data leadership rarely has at fingertip access: how many internal auditors does the enterprise actually have, what is their training currency, where are corrective-action backlogs concentrated, and which sites are operating with management-review records that have not been refreshed in over a year. None of this information is dramatic in isolation, but together it determines whether the multi-site ISO certification project can begin at Phase 2 or needs remedial work at the site level first.
Phase 2 — Architect the Target State
Architecture is where most multi-site ISO certification programs are won or lost. Decisions made here determine whether the system will scale: where will the central function reside? Which standards will be in scope (a single ISO 9001 multi-site, or an integrated ISO 9001 + ISO 14001 + ISO 45001 program)? What document hierarchy will sites share, and what will remain local? How will internal audits be structured to satisfy IAF MD 1's central-function requirements without exhausting the audit team? Architecture decisions get embedded into procedures during the next phase, and changing them later is expensive. Where more than one standard is in scope, MSI's integrated management systems practice designs the document hierarchy, central function, and combined audit program as one architecture — so the certification body audits a single system rather than three overlapping ones.
If the architecture decision points toward an integrated management system covering multiple ISO standards (ISO 9001 + ISO 14001 + ISO 45001, or broader stacks including ISO 22301 and ISO 27001), the foundational design pattern is Annex SL — covered in MSI's companion piece on multi-site ISO integration. The two pieces fit together: this article addresses the certification mechanics across sites; the integration article addresses the consolidation of multiple standards inside one system. Many enterprises end up doing both at once.
A useful architectural test is the “new acquisition simulation.” Imagine the organization closes another site acquisition in eighteen months. How quickly can that new site be brought into the multi-site ISO certification scope? An architecture that answers “within one surveillance cycle, with two weeks of central-function support” is one that will scale. An architecture that requires re-baselining the entire enterprise every time a site is added is not actually a multi-site system — it is a single-site system pretending to be one.
Phase 3 — Pilot at a Lead Site
Before rolling out across the enterprise, a multi-site ISO certification benefits from a pilot site that proves the architecture works in practice. The pilot tests document control, training, internal audits, and management review against real operating conditions. Issues surface and get fixed before they propagate to fifteen other locations. The pilot also produces concrete artifacts — completed audits, closed corrective actions, populated management-review minutes — that the rollout sites can model their work on.
Choose the pilot deliberately. The right pilot is not the easiest site or the most cooperative leader; it is the site that most resembles the median site in the enterprise. A pilot at the smallest, simplest, friendliest location produces a system that breaks the moment it touches a complex acquired site. A pilot at a representative location produces a system that scales because it has already absorbed real operational variance.
Phase 4 — Roll Out Across Sites
Rollout converts the architecture into operating reality at every covered site. This is where local buy-in matters most. Site leadership must understand why the changes are happening, what authority they retain locally, and how the new central function will support rather than micromanage them. Leadership during ISO rollout is the single largest predictor of whether multi-site ISO certification succeeds or stalls — the technical work is comparatively straightforward.
Phase 5 — Sustain Through Surveillance
A multi-site ISO certification is not a project that ends at certification — it is an operating system that requires sustainment. Annual surveillance audits, central-function management reviews, internal-audit programs, and continual-improvement cycles all need to keep running across the cycle. Most organizations underestimate the central function's ongoing workload by 30-50%, leading to drift between audits. Programs like MSI's SureResults ISO Maintenance Program exist specifically to hold the system steady once certification is achieved.
“The technical work in a multi-site ISO certification is comparatively straightforward. The architecture decisions and the leadership during rollout determine whether the program scales — or stalls.”
Pitfalls To Avoid
Four Common Pitfalls That Stall Multi-Site ISO Certification Programs
Spot. Stop. Sustain.
Across nearly three decades of ISO implementations, four pitfalls account for the overwhelming majority of multi-site ISO certification programs that miss their original timeline. Each one is preventable. Each one is also remarkably easy to fall into when leadership delegates the program to the quality function and stops checking in until the certification audit looms. Experienced ISO consulting support exists largely to catch these four before they cost a cycle.
Pitfall 1 — Treating the Central Function as Optional
The single most common cause of stalled multi-site ISO certification programs is treating the central function as a name on an org chart rather than a working entity with real authority and resources. IAF MD 1:2023 is unambiguous: the central function must plan and control the management system across all sites. If the named central function does not actually issue procedures, monitor performance, or drive corrective action across sites, certification bodies will identify the gap during the Stage 1 readiness review — and certification cannot proceed until it is closed. The fix is structural, not cosmetic: assign named owners, allocate genuine bandwidth, and give the central function the budget and authority it needs to function as a control point.
Pitfall 2 — Copy-Pasting Documentation Across Sites
A multi-site ISO certification requires a single management system, not identical paperwork at every site. Programs that respond by copy-pasting one site's existing procedures to every other location create a different problem: documentation that does not match how work actually happens. Auditors interview operators and observe processes; when the procedure says one thing and the operator does another, the finding is a major nonconformity. The discipline is to harmonize at the level that matters — policy, procedure architecture, common forms — and let work instructions remain local where local conditions genuinely differ.
Pitfall 3 — Underestimating Internal Audit Capacity
Multi-site ISO certification requires internal audits that cover every site over the audit cycle, plus the central function. Most organizations enter the program with internal-audit capacity sized for a single-site certificate and discover, six months in, that they cannot keep pace. The result is rushed audits, shallow findings, and a system that drifts between certification-body visits. The remedy is to size internal-audit capacity at the architecture phase: train more internal auditors than the minimum, cross-train across sites, and consider outsourced internal audit support for peak periods. Internal auditor workshops at the beginning of a multi-site implementation pay back many times over.
Pitfall 4 — Confusing Audit Readiness with System Effectiveness
The least visible pitfall is the most expensive. A multi-site ISO certification can be achieved by an organization whose system is well-documented but ineffective in practice — for one cycle. The system passes its first audit, lapses during the year, and produces a wave of findings at the next surveillance. Effective programs distinguish from the start between can we pass an audit and does the system actually deliver results. They build management reviews around operational outcomes (defect rates, customer complaints, on-time delivery, environmental performance) rather than just compliance metrics. The certification follows the system; it does not substitute for it.
Industry Context
Multi-Site ISO Certification Across Different Industry Contexts
Manufacturing. Medical. Healthcare.
The IAF MD 1:2023 framework is industry-agnostic, but the practical playbook for multi-site ISO certification varies meaningfully by sector. Three contexts illustrate the spread.
Manufacturing & Industrial Operations
For multi-site manufacturing — including chemical, industrial, and discrete-product organizations — multi-site ISO certification typically integrates ISO 9001, ISO 14001, and ISO 45001 into a single integrated management system audited under IAF MD 11. The architectural side of that integration — combining multiple ISO standards into one Annex SL framework — is covered in depth in MSI's companion guide on multi-site ISO integration; this article focuses on the certification mechanics under IAF MD 1. Acquisition-driven organizations face the largest eligibility-analysis workload here: acquired sites often run substantially different processes, requiring careful scope decisions before sampling can be applied. Process optimization work usually accelerates inside this kind of integrated multi-site ISO certification because central data finally becomes comparable across sites.
Chemical and bulk-processing operations face additional considerations under environmental and occupational-health regulations. Sites operating under EPA, OSHA, or DOT oversight benefit substantially from integrating ISO 14001 and ISO 45001 into the multi-site ISO certification scope, because the central function then drives unified compliance reporting alongside operational quality. Mid-market industrial holding companies in active acquisition mode often find this integration is what finally makes site-level reporting consistent enough for board-level oversight. MSI builds these programs standard by standard and site by site — ISO 9001 quality management consulting, ISO 14001 environmental management consulting, and ISO 45001 health and safety consulting — under one integrated architecture rather than three parallel projects.
Medical Device Manufacturers
Medical-device organizations operate under ISO 13485 and, in the United States, FDA Quality System Regulation (21 CFR 820). Multi-site ISO certification under 13485 has stricter eligibility requirements: the central function must demonstrate genuine control over design, manufacturing, and post-market surveillance across sites, and any site performing design activities is generally not eligible for sampling reduction. MSI's ISO 13485 medical device consulting handles that eligibility analysis before the certification body raises it, not after. Aligning design and development procedures across sites is often the longest pole in a 13485 multi-site implementation.
Healthcare Delivery Organizations
Hospital systems and multi-site healthcare providers increasingly pursue multi-site ISO certification under ISO 9001 alongside the emerging ISO 7101 healthcare quality standard. The central-function requirement maps naturally to system-level quality leadership, while site-level adaptations accommodate clinical and regulatory variance. MSI's ISO 7101 healthcare quality consulting is built for exactly this multi-facility structure. ISO 7101 in healthcare is reshaping how multi-facility provider organizations approach unified quality systems.
For multi-hospital systems, the value of multi-site ISO certification often shows up first in cross-facility patient-safety reporting and incident learning. When every facility documents events in the same structure under one management system, system-level patterns become visible — and corrective actions can be deployed across the network rather than re-discovered facility by facility. The integration with digital transformation initiatives in healthcare amplifies these benefits, because shared data structures finally produce shared insights.
The Two-Axis Decision
How Multi-Site ISO Certification and Integrated Management Systems Fit Together
One architecture. Two axes. Every site.
Direct Answer
Multi-site ISO certification answers the question how many locations sit under one certificate. An integrated management system answers the question how many standards sit under one system. They are two different axes of the same architecture, and organizations that resolve both at once — one document hierarchy, one audit program, one management review, every standard, every site — capture compounding savings that neither decision delivers alone. A multi-site ISO certification built on top of an integrated management system is the most economical configuration available to a multi-location enterprise in 2026.
Most leadership teams treat these as one decision. They are not. A ten-site manufacturer can be certified to ISO 9001 alone across every location — a wide, shallow system. A single-site medical-device firm can run ISO 9001, ISO 13485, and ISO 14001 together — a narrow, deep system. The organizations that win are the ones that recognize they are making both decisions, and design for both from the beginning rather than executing one and retrofitting the other eighteen months later.
The vertical axis is standards. That is the domain of the Harmonized Structure — the ten-clause architecture ISO publishes in Annex SL, which lets ISO 9001, ISO 14001, and ISO 45001 share the same context clause, the same leadership clause, and the same internal-audit and management-review requirements. Annex SL exists precisely so that standards can be operated together rather than side by side. MSI's integrated management systems consulting practice is built on exactly this: one system carrying every standard in scope, not three systems wearing a shared cover page.
The horizontal axis is sites. That is the domain of IAF MD 1:2023 and everything covered earlier in this article — the central function, the sampling rules, the eligibility test. Multi-site ISO certification is what turns a system that works at one plant into a system that carries a certificate across twelve.
Why the Two Axes Compound
The audit-day economics stack. IAF MD 11 permits a reduction in audit time when multiple standards are audited as one integrated management system rather than sequentially. IAF MD 1 permits sampling across sites. Applied to the same certificate, those two reductions multiply rather than merely add — which is why a three-standard, twelve-site enterprise running one integrated multi-site ISO certification can end up carrying a fraction of the audit burden of a peer running separate certificates per standard per location.
The operational economics stack harder. One document hierarchy instead of fifteen. One corrective-action database, so a nonconformance found at a plant in Germany propagates to a plant in Texas without anyone rekeying it. One internal audit program whose auditors are competent across quality, environmental, and safety rather than three separate audit teams competing for the same operators' time. One management review where leadership sees quality, environmental, and safety performance on the same page — which is the only way a board actually acts on any of it. MSI client experience suggests the central-function workload of an integrated multi-site program runs materially lower than that of parallel single-standard programs at the same footprint, and the difference widens with every site added.
Where This Bites Hardest: Regulated Industrial Manufacturers
The pressure is most acute for industrial equipment manufacturers operating across borders in regulated or hazardous environments — process instrumentation, energy equipment, chemical processing, industrial automation. These organizations rarely have the luxury of choosing one axis. Their customers require quality management at every producing location. Their regulators require demonstrable environmental control, in line with the systematic approach reflected in EPA environmental management system guidance and ISO 14001. Their workforce exposure profile makes occupational health and safety non-negotiable, consistent with the program structure OSHA recommends for safety and health management. Three standards, a dozen sites, several jurisdictions — and typically a documentation estate assembled from decades of acquisitions.
For these organizations, treating multi-site ISO certification and standards integration as separate projects is the single most expensive sequencing error available. Build the integrated architecture first, then certify it multi-site, and the certification body audits one coherent system. Certify each standard separately at each site first, and integration becomes a demolition project. The same logic applies with even sharper edges to acquisition-driven growth — which is why post-acquisition compliance integration runs on a hundred-day clock rather than a hundred-week one.
The Sequencing Test
There is a simple question that resolves the sequencing for most enterprises: will more than one standard ever be in scope at more than one site? If the honest answer is yes — and for industrial, medical-device, and healthcare organizations it almost always is — then the integrated architecture is the foundation and multi-site ISO certification is the structure built on it. Reverse that order and the foundation gets poured after the walls go up. Organizations still deciding which standards genuinely belong in scope will find MSI's ISO consulting decoder ring a fast way to sort the field before committing capital.
Build It As One System
One Document Architecture. Every Standard. Every Site.
If your organization is carrying ISO 9001, ISO 14001, and ISO 45001 — or expects to — across more than one operating location, the integrated build is the cheaper path and the faster one. MSI designs the document hierarchy, the central function, the combined internal audit program, and the single management review that a certification body can audit as one system under IAF MD 1 and MD 11. Twenty-eight years, 80+ certifications supported, 200+ audits attended, and 600+ professionals trained stand behind that architecture.
See MSI's Integrated Management Systems Practice →
Already scoped and ready to execute? SurePath delivers the turnkey build across sites. Prefer to talk it through first? Call 760-434-9141 for a planning session.
Questions Answered
Frequently Asked Questions About Multi-Site ISO Certification
How long does a multi-site ISO certification typically take?
Direct Answer: A multi-site ISO certification typically takes 9–18 months from kickoff to certificate issuance for a five-to-ten-site organization, depending on starting maturity and standards in scope. Organizations with strong existing single-site systems can move faster; organizations starting from scratch or integrating recent acquisitions usually need the full 18 months.
Can we keep our existing single-site certificates during the transition?
Direct Answer: Yes. During the move to multi-site ISO certification, existing single-site certificates remain valid through their current cycle. Most organizations transition site-by-site as each surveillance window opens, eventually consolidating onto one multi-site certificate at recertification. The certification body coordinates the transition; planning the sequence is a leadership decision.
What disqualifies a site from being sampled under IAF MD 1?
Direct Answer: Multi-site ISO certification sampling requires sites to share similar processes, operate under one management system, and be centrally controlled. Sites with substantially different products, materially different risk profiles, or design activities (under ISO 13485) typically cannot be sampled and must be audited individually or excluded from the multi-site scope. Eligibility analysis happens during Phase 1 of the roadmap.
Does Global ACI replacing IAF affect our certification?
Direct Answer: No. The transition to Global Accreditation Cooperation Incorporated on January 1, 2026 does not change multi-site ISO certification requirements. IAF MD 1:2023 remains the operative document, existing IAF MLA marks continue to be valid, and certification bodies operate without interruption. Over time, the IAF MLA mark phases to a new Global ACI mark per published guidance.
Can we integrate ISO 9001, 14001, and 45001 into one multi-site certificate?
Direct Answer: Yes. Integrated multi-site ISO certification across ISO 9001, ISO 14001, and ISO 45001 is the most common configuration for industrial manufacturers and is audited under IAF MD 11 in conjunction with MD 1:2023. Integration usually reduces total audit days by another 20–30% over running three separate multi-site programs. MSI's integrated management systems practice designs that single certificate architecture from the outset.
Should we integrate the standards first, or certify multi-site first?
Direct Answer: Integrate first. If more than one standard will ever be in scope at more than one location, build the integrated management system architecture — one document hierarchy, one central function, one audit program — and then certify it multi-site under IAF MD 1. Reversing the order means certifying separate systems and then dismantling them, which is the most expensive sequencing error in multi-site ISO certification.
Take The Next Step
Plan. Pilot. Prevail.
If multi-site ISO certification is on your 2026 leadership agenda — whether you are integrating recent acquisitions, consolidating legacy single-site certificates, or planning a green-field multi-location rollout — the next move is a structured leadership conversation, not a documentation exercise. MSI's ISO Executive Decision Briefs are short, focused videos for senior leaders deciding scope, sequence, and ROI before committing capital to a multi-site program.
Each brief is built around the questions executives actually ask: which standards belong in scope, where the central function should live, how to phase the rollout across sites without breaking operations, and what the realistic timeline looks like. No pitch deck. No hard sell. Just the decision framework used by consultants who have supported 80+ certifications, attended 200+ audits, and trained 600+ professionals across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
Watch the ISO Executive Decision Briefs →
Carrying more than one standard? Start with MSI's integrated management systems practice. Already past the decision phase? Explore SurePath, MSI's turnkey ISO certification program built for multi-site implementations. Need ongoing support after certification? See SureResults. Want to verify fit first? Check the Industries We Serve page. Or call 760-434-9141 for a planning session.
Related MSI Reading
The Companion Piece on Standards Consolidation
This article covers the certification mechanics of running one ISO certificate across multiple sites under IAF MD 1:2023. For organizations also consolidating multiple ISO standards (ISO 9001 + ISO 14001 + ISO 45001, plus ISO 22301 / ISO 27001 stacks) into one Annex SL framework, MSI's enterprise guide on multi-site ISO integration is the companion piece. Many enterprises run both plays at once: integrating standards and certifying multi-site under sampling. When you are ready to build rather than read, MSI's integrated management systems page is where that architecture gets designed.
About MSI
Management Systems International (MSI) is a veteran-owned, female-owned ISO consulting firm founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality — including multi-site ISO certification programs — across manufacturing, technology, medical device, government, healthcare, and other regulated industries.
References & Further Reading
- IAF MD 1:2023 Issue 3 — Audit and Certification of a Management System Operated by a Multi-Site Organization
- Global Accreditation Cooperation Incorporated (Global ACI)
- ANAB — IAF Mandatory Documents 1, 5 and 11 explained
- ANAB Training — Making IAF MD 1 Work for You
- ISO — Management System Standards and the Harmonized Structure (Annex SL)
- ANSI — Annex SL (Annex L) of ISO Management System Standards
- ISO 9001 — Quality Management Systems
- ISO 9001:2015 standard page
- ISO 13485:2016 standard page
- ISO 14001:2015 standard page
- ISO 45001:2018 standard page
- ISO/IEC 17021-1 — Requirements for certification bodies
- U.S. EPA — Environmental Management Systems (EMS)
- OSHA — Recommended Practices for Safety and Health Programs
- U.S. FDA — Medical Devices
- NIST Manufacturing Extension Partnership (MEP)