ISO tenders: what is actually asked for
Every guide to ISO tenders tells you which standards exist. Almost none of them counts how often UK buyers name each one — or, more usefully, how often naming it means you must hold it.
Those are different questions with different answers. ISO 9001 is named in more UK notices than any other ISO standard. OHSAS 18001 is the one most often named as an obligation. They are not the same standard, and the gap between them is what this page is about.
-
ISO 9001412 notices, 34.7% obligations
-
ISO 27001224 notices, 21.4% obligations
-
ISO 17025161 notices, 53.4% obligations
-
ISO 14001148 notices, 25.7% obligations
-
ISO 4500193 notices, 12.9% obligations
-
ISO 1348560 notices, 48.3% obligations
-
ISO 1518953 notices, 30.2% obligations
-
ISO 1702041 notices, 51.2% obligations
-
OHSAS 18001 — withdrawn38 notices, 65.8% obligations
Which ISO standards do tenders require?
Before any number, what it counts. We read the published text of each notice — its title and description. We do not read the tender pack, and the pack is where a certification requirement usually lives. So every count here is a floor: standards named out loud, not standards wanted.
Across 745,098 dated UK notices, 16 ISO standards in our taxonomy are named at least once. The distribution is steep: ISO 9001 accounts for 412 notices on its own, and most of the rest appear in double or single figures.
The practical answer to “which ISO standards do tenders require” is therefore narrower than most guides suggest. For the overwhelming majority of UK public work the answer is none of them — and where one is named, it is usually quality, information security or the health-and-safety and environmental pair that travel with quality.
What changes the answer is your sector, not your ambition. A calibration laboratory meets ISO 17025 constantly; a software supplier meets ISO 27001 and almost never meets 17025. The ranking below is the whole market, and your own market is a slice of it.
ISO tender requirements UK: named often versus demanded hard
Sort the same set by obligation rate instead of frequency and a different picture appears — one that matters more if you are deciding what to certify.
ISO 17025 is named in 161 notices and 53.4% of those namings use obligation language. ISO 45001 is named in 93 notices and only 12.9% of those do. A standard can be common and soft, or rare and hard, and the two require completely different decisions.
The most-demanded standard in UK tenders was withdrawn in 2021
This is the finding that says most about how ISO requirements are actually written, and it is checkable in one query.
OHSAS 18001 was replaced by ISO 45001 and formally withdrawn in 2021. It is named in 38 notices in our corpus, and 65.8% of those namings use obligation language — the highest rate of any credential in the ISO set. Its replacement, ISO 45001, is named in 93 notices at 12.9%.
So the standard buyers most reliably insist on is one that no longer exists, and the standard that replaced it is the one they insist on least.
The explanation is mundane and useful: requirement text is copied forward. A specification written in 2016 is reused in 2019, adapted in 2022, and the certification clause survives untouched because nobody on the buying side is auditing it against the standards catalogue. That is not a criticism of buyers — it is how procurement documents are actually produced.
Is ISO certification for tenders becoming more common?
On the evidence of eleven years of notices, no. The commonest ISO standard in UK procurement is flat, and its obligation rate has fallen.
ISO 9001 appears at 8.5 per 10,000 notices in 2015 and 5.2 per 10,000 in 2026 (a part year). Between those points it moves without trending.
Two caveats, both load-bearing. The series is a rate per 10,000 notices, never a raw count, because how much we ingest differs by year and raw counts across years would be invalid. And the 24 February 2025 Procurement Act go-live sits inside this series — notice conventions changed then, so part of the difference between the two colours is a change in how notices are written rather than in what buyers want. 2026 is marked with an asterisk because it is a part year; the rate handles that where a raw count would not.
What a tender notice does not tell you
Every number on this page has the same limit, and it is worth understanding properly rather than treating as a disclaimer.
A UK contract notice is a summary. Its description field averages a few hundred characters — enough to say what is being bought, the value, the deadline and the buyer. It is not the specification, and it is not the supplier questionnaire.
Certification requirements overwhelmingly live in the documents the notice points to: the SQ or PQQ, the ITT pack, the conditions of participation. Those are attachments. Our matcher reads the notice's title and description, so a certification gate can exist today, in a pack, and this page will not see it.
That is why every count here is described as a floor and never as a census, and it is why the honest comparison is between standards rather than against the whole market. Both sides of a comparison are understated in the same direction and by roughly the same mechanism, so the ranking survives even though the absolute numbers are low.
ISO standards for public sector bids: which ones go together
Buyers rarely ask for one standard in isolation, and certification bodies rarely sell one. Knowing the groupings is worth more than knowing the individual numbers.
The integrated management system is the commonest grouping: ISO 9001 for quality, ISO 14001 for environmental management and ISO 45001 for health and safety. They share a high-level structure, so one set of processes and one audit cycle can carry all three — which is normally cheaper than three separate projects and is the reason buyers who ask for one often ask for all three.
The assurance grouping is different in kind: ISO 27001 for information security, Cyber Essentials as the cheaper entry point beneath it, and ISO 42001 where the contract involves AI. These answer questions about risk and data rather than about process quality, and they are asked for by different parts of a buying organisation.
Then there are the sector gates — ISO 17025 for testing and calibration laboratories, ISO 13485 for medical devices, ISO 15189 for medical laboratories. These have high obligation rates precisely because they are not general credentials: when a notice names them, it is because the work genuinely cannot be done without them.
What ISO certification costs, and what we will not tell you
We do not publish a price, and we would treat any page that does with caution unless it names its source.
Certification is quoted per organisation by the certification body, and the quote turns on headcount, the number of sites, the scope of the management system and whether you already hold a certificate the auditor can build on. A company of twelve people at one site and a company of four hundred across nine sites are not buying the same thing, and a single figure covering both is a figure that fits neither.
Our own requirement taxonomy holds cost and lead time deliberately null for every one of the 137 requirements it tracks, with the reason recorded in the source: an invented “£3k, six weeks” is exactly the kind of plausible-looking number this project has been burned by before. We would rather give you the method for getting a real one.
Every ISO standard we measure in UK tenders
The full set, read live, with both numbers for each. This is the table the rest of the page argues from.
The standard-by-standard guides
What each standard asks of you, how it is evidenced in a bid, and what buyers actually do with it.
ISO 9001
Quality management — the most-named ISO standard in UK notices. 412 notices in our corpus.
ISO 27001
Information security — the one most often asked for beside Cyber Essentials. 224 notices in our corpus.
ISO 14001
Environmental management — normally certified with 9001 and 45001. 148 notices in our corpus.
ISO 45001
Health and safety — the least-mandated ISO standard we measure. 93 notices in our corpus.
ISO 42001
AI management systems — what the standard asks of you, clause by clause. one notice in our corpus.
ISO 42001 procurement
How often it is actually asked for, counted across the whole corpus. one notice in our corpus.
Every UK tender certification
One level up: schemes, clearances, registrations and insurances — and why ISO is not what UK tenders mostly ask for.
The Requirements Observatory
The live data behind all of it, across every certification, clearance and scheme UK buyers name.
Questions people actually ask about ISO tenders
Taken from the real search strings this cluster surfaces on, reproduced as typed.
why do tenders ask for iso 9001?
Because it is the cheapest way for a buyer to transfer a question they cannot answer themselves. A contracting authority cannot audit every bidder's processes, so it asks for evidence that somebody accredited has. ISO 9001 certifies that you run a documented, audited quality management system with defined responsibilities, records and corrective action — not that your product is good. That distinction matters when you answer: evidence the system, not the outcome. It is also frequently copied forward from an earlier specification rather than chosen deliberately for this contract, which is why it appears in notices where nothing about the work obviously calls for it.
is iso 9001 required for government tenders?
Not generally. There is no rule requiring ISO 9001 for UK government work, and on our own corpus it is named in a small fraction of notices — a floor, since we read the notice text and not the tender pack. Where it does appear it is more often a hard requirement than a preference, so the honest answer is “rarely asked for, but usually binding when it is”. A specific buyer can require any proportionate certification in a specific procurement; under the Procurement Act 2023 that proportionality is a legal test, not a courtesy. Check the conditions of participation in the pack rather than inferring from the notice.
which iso standards do i need to bid for public sector work?
For most UK public work, none. If you are in technology or handle buyer data, Cyber Essentials first and ISO 27001 if the contracts justify it — Cyber Essentials appears in more notices and costs a fraction as much. If you are in construction, facilities or manufacturing, the integrated trio of ISO 9001, ISO 14001 and ISO 45001 is the usual package, and certifying them together against one process set is cheaper than three separate projects. If you run a laboratory or make medical devices, the sector standards are gates rather than differentiators and you will already know. Beyond that, buy certification because a specific pipeline of contracts demands it, not speculatively.
do iso certifications actually help you win tenders?
They help you be eligible, which is a different and more defensible claim than helping you win. Where a certification is a condition of participation, holding it is the difference between a bid and no bid; where it is a scored criterion it earns points against a published weighting you can read in the pack. We do not publish a win-rate uplift for certification and we would be sceptical of anyone who does, because the counterfactual — the same bid without the certificate — is not observable. What is observable is how often each standard is named and how often that naming is an obligation, and both of those are on this page.
what if a tender asks for a standard that no longer exists?
It happens more than you would expect — OHSAS 18001 was withdrawn in 2021 and is still named in UK notices years later, at the highest obligation rate of any credential we measure. Answer with the current standard and make the succession explicit: state that the requested standard was withdrawn, name the date, state that you hold the successor and that it is the successor. Do not silently tick the box, because a scoring panel working from a checklist may record a mismatch. If the requirement is a condition of participation rather than a scored criterion, raise a clarification question — the answer is published to all bidders and it protects your bid.
how do procurement teams verify an iso certificate?
Three things make a certificate checkable, and a good evaluator asks for all three: the certification body, the accreditation behind it, and the scope statement. The accreditation matters most — a certificate from a body with no accreditation for that scheme has not been assessed against the relevant requirements at all, and in the UK, UKAS publishes each accredited body's schedule showing exactly which schemes and scopes it holds. The scope statement matters second, because a management-system certificate covers named activities and sites, and not necessarily the part of your business delivering this contract.
How we counted
Every figure on this page is read from our own corpus when the page loads. Here is exactly what that means and where it stops.
The population. 745,098 UK notices carrying a publication date, ingested from Find a Tender and Contracts Finder under the Open Government Licence v3.0. That is the same population the counts themselves are built from, so numerator and denominator cannot drift apart.
The matcher. One extractor, at classifier version 5, last run in full on 1 August 2026. It matches against each notice's title and description, stores the sentence every match came from, and records separately whether that sentence uses obligation language. It is the same matcher that powers the Requirements Observatory and every per-requirement page — deliberately, because a second matcher is a second truth, and the moment a term changed the two would disagree and nothing would say so.
What it deliberately understates. The extractor rejects matches whose context makes them something else — a standard number appearing inside a serial number, a part code, a postal address. That means the published counts run below a naive string search, and that is the intended direction: a false positive in a published count is worse than a missed match.
The obligation floor. No obligation percentage is shown for a standard named fewer than 30 times. The rule is enforced in the data layer rather than in the template, so no surface on this site can leak a percentage past it. One standard in our set would otherwise read 100% on two notices.
Related reading
UK tender certifications
One level up — every credential class a UK supplier is asked for, and where ISO actually sits among them.
ISO 42001 procurement
The newest standard in the set, counted across the whole corpus, with the accreditation chain that explains the number.
The Requirements Observatory
Every certification, clearance, scheme and registration UK buyers name, with the receipts.
The Procurement Act 2023
Conditions of participation, award criteria, and where a certification can legitimately sit.
Search live tenders
Every open UK notice, filtered by what you can actually win.
Cyber Essentials
Not an ISO standard, and named in more UK notices than most of them.
Sources
- rfp.quest corpus, read live at the moment this page was served. 745,098 UK notices carrying a publication date, ingested from Find a Tender and Contracts Finder under the Open Government Licence v3.0. Requirement counts are produced by the extractor at
src/lib/requirements/extract.ts, classifier version 5, last full run 1 August 2026; matches are against notice title and description only, each with a stored evidence sentence. Counts are floors. Obligation shares are suppressed below 30 matches. - ISO 45001:2018, Occupational health and safety management systems, ISO. The standard that replaced OHSAS 18001; OHSAS 18001 was withdrawn in 2021 following a three-year migration period.
- ISO 9001:2015, Quality management systems — Requirements, ISO. The current edition of the most-named ISO standard in UK notices.
- Find a Tender, Cabinet Office. The UK central digital platform, and one of the two registers this page’s corpus is ingested from.
- Procurement Policy Notes, Cabinet Office. The instrument by which UK government procurement policy is issued — and, notably, none of them mandates an ISO standard.
- Management system standards, ISO. The shared high-level structure that makes the integrated management system practical.
- Procurement Act 2023, legislation.gov.uk. Source for conditions of participation, award criteria and the proportionality requirement on both.
- UKAS schedules of accreditation, United Kingdom Accreditation Service. Each accredited certification body publishes the exact schemes and scopes it holds, with an issue date — the document to check before accepting a certificate.