Photo: Unsplash
If you are searching for how to get ISO 17100 certified, you are usually past curiosity and into execution: clients are asking for proof, RFPs list ISO 17100, or leadership wants a formal quality system for translation services.
ISO 17100:2015 specifies requirements for translation service providers (TSPs). It is not an interpreting standard, and raw machine translation plus post-editing is typically outside the model the standard expects. Certification is generally granted by a certification body after Stage 1 and Stage 2 audits—not by self-declaration alone.
This guide walks a practical sequence from gap analysis through certificate maintenance, with owners and evidence in mind. SecureSlate’s role in this journey is helping you keep policies, assignments, and recurring reviews organized—not replacing linguistic QA.
This guide covers:
- How to confirm fit and scope before spending on a CB
- A step-by-step path: gap analysis → documents → competence → live projects → internal audit → CB → Stage 1/2 → maintenance
- Decision points teams commonly miss (revision proof, subcontractors, confidentiality)
- How to avoid process theater that fails Stage 2 sampling

GIF via GIPHY
Related guides:
- What is ISO 17100:2015? Everything you need to know
- ISO 17100 certification checklist
- ISO 17100 requirements: a complete breakdown
- ISO 17100 audit: what auditors look for
- How much does ISO 17100 certification cost?
- Explore the ISO 17100 collection
Key takeaways
- Certification is a sequence, not a binder—document processes, then prove they operate on real projects before Stage 2.
- Gap analysis first prevents rewriting SOPs that do not match how your TMS and vendors actually work.
- Competence records and second-person revision are the two most common blockers to “how to get ISO 17100 certified” timelines.
- Choose the CB after internal readiness, not before—quotes are more accurate when scope and sample volume are clear.
- Maintenance starts on certificate day—surveillance, competence refresh, and CAPA loops keep the certificate valid.
Before you start—fit and scope
Ask three questions:
- Do we deliver translation services as a TSP (not only interpreting or pure software)?
- Can we commit to human translation plus mandatory second-person revision for in-scope work?
- Is leadership willing to fund process discipline, not just a logo on the website?
If the answer to any is “no,” pause. Read Who needs ISO 17100 certification? and What is ISO 17100:2015? Everything you need to know before contracting a CB.
Write a draft scope statement (languages, domains, entities, exclusions). Keep interpreting and pure MT+PE out of scope unless you have a deliberate CB-aligned rationale.
Step-by-step path to ISO 17100 certification
Use this path as your program spine. Parallelize where possible (for example, competence file cleanup while SOPs are drafted), but do not skip live project evidence.
| Step | Outcome | Typical owner | Rough readiness signal |
|---|---|---|---|
| 1. Gap analysis | Prioritized gap register | Quality lead | Gaps mapped to clauses/process areas |
| 2. Document processes | Controlled SOPs + policies | Ops + Quality | Document index with versions |
| 3. Competence records | Complete linguist files | Talent / Vendor Mgmt | Files for all active assignees |
| 4. Run projects to standard | Sampleable project packs | Project Mgmt | Multiple complete T+R projects |
| 5. Internal audit | Findings closed or timed | Quality | Audit report + CAPA |
| 6. Choose CB | Signed audit agreement | Compliance | Scope, dates, fees agreed |
| 7. Stage 1 / Stage 2 | Certificate issued (if successful) | Quality + Ops | Nonconformities addressed |
| 8. Maintain | Surveillance-ready system | Leadership + Quality | Annual review cadence live |
Step 1: Perform a gap analysis
Compare current practice to ISO 17100 themes: resources, pre-production, production, and post-production.
Practical gap questions:
- Do project records always show a translator and a different reviser?
- Can you retrieve competence proof for every person on last quarter’s projects?
- Are client requirements and agreements captured before production starts?
- Is there a defined complaints and corrective-action path?
Score each gap by severity and effort. Pair this step with the ISO 17100 certification checklist so remediation has owners from day one.
Step 2: Document processes
Write procedures that match reality. Auditors sample whether people follow the documents—not whether the documents sound impressive.
Minimum document set commonly includes:
- Quality / translation service process overview
- Project intake and feasibility
- Resource selection (translator/reviser assignment rules)
- Production and revision workflow
- Delivery, client feedback, and complaints/CAPA
- Confidentiality and information handling
- Internal audit and management review
If you already run ISO 9001, reuse structure carefully and clarify what is translation-specific—see ISO 17100 vs ISO 9001: what's the difference?.
Step 3: Build competence records
Translator qualification paths commonly documented under ISO 17100 practice include:
- A translation degree, or
- Another degree plus about two years of relevant translation experience, or
- About five years of full-time professional translation experience
For each linguist, store which path applies and the supporting artifacts. Revisers need clear competence evidence for the language pair/domain and assignment rules that prevent self-revision.
Details: ISO 17100 translator and reviser competence requirements.
Step 4: Run projects to the standard
Certification bodies typically sample real work. Run a period where in-scope projects consistently:
- Capture requirements and agreements
- Assign qualified translators
- Assign a second qualified reviser
- Record queries, changes, and delivery
- Route issues into feedback/CAPA when needed
Technology can support terminology and consistency, but do not assume raw MT+PE projects will satisfy ISO 17100 sampling expectations.
Step 5: Run an internal audit
Audit against your procedures and the standard’s process areas. Sample projects end-to-end. Close major gaps before inviting Stage 1.
Deliverables: audit plan, findings, owners, due dates, and objective evidence of closure.
Step 6: Choose a certification body
Select a CB experienced with translation/language services where possible. Ask about:
- Accreditation status and geographic coverage
- Scope wording they expect
- Remote vs on-site Stage 1/2 options
- Surveillance cycle and typical fee structure
Get quotes after your gap register is realistic. Cost drivers are covered in How much does ISO 17100 certification cost?.
Step 7: Complete Stage 1 and Stage 2
Stage 1 typically reviews documentation readiness and identifies major gaps early.
Stage 2 typically samples implementation: competence files, project records proving translation + revision, agreements, complaints/CAPA, and technical resources.
Address nonconformities on the CB’s timeline. For auditor focus areas, see ISO 17100 audit: what auditors look for.
Step 8: Maintain the certificate
Certificates are not permanent “set and forget” assets. Plan surveillance audits, competence refresh, internal audits, and management reviews. Process drift—especially skipping revision under deadline pressure—is a common surveillance finding.
Ongoing practices: Maintaining ISO 17100 compliance: ongoing best practices.
Common pitfalls that delay certification
- Policies without projects: beautiful SOPs, empty sample packs
- Same-person “revision”: translator self-checks labeled as revision
- Freelancer files incomplete: NDAs exist, degrees/experience proofs do not
- Scope marketing mismatch: website claims exceed certificate scope
- Security afterthought: confidentiality promised in sales decks but access reviews absent
Fix these before Stage 2. They are cheaper to remediate internally than under CB finding pressure.
Streamline certification readiness with SecureSlate
Getting certified is a cross-functional program. SecureSlate helps you keep the non-linguistic control plane audit-ready: owners, policies, evidence links, and recurring reviews.
Teams typically use SecureSlate to:
- Break the certification path into owned tasks with due dates and status
- Centralize confidentiality, access, and vendor policies that sit beside quality SOPs
- Schedule internal audits and management reviews so they actually happen
- Attach evidence to checklist items for Stage 1 pack assembly
- Reduce scramble before surveillance by keeping reviews continuous
SecureSlate does not replace translators, revisers, or your CB—it helps you prove the system around them is controlled.
FAQ: how to get ISO 17100 certified
How long does ISO 17100 certification take?
It varies. Mature TSPs with clean project data may move from gap analysis to Stage 2 in a few months; organizations rebuilding competence files and workflows may need longer. Confirm timelines with your CB.
Do we need a consultant?
Optional. Consultants can accelerate documentation and coaching. Many teams succeed with an internal quality lead plus a strong checklist—see ISO 17100 certification checklist.
Is Stage 1 always required?
Certification schemes commonly use Stage 1 then Stage 2 for initial certification. Ask your CB how they structure remote/on-site work for your size and scope.
Can a single freelancer get certified?
ISO 17100 is aimed at TSPs as organizations providing translation services. Solo operators should confirm feasibility and scope with a CB; competence and second-person revision still need a credible model.
What happens after we fail Stage 2?
Typically you remediate nonconformities and undergo follow-up verification per the CB’s rules. Use findings as a CAPA backlog with owners—not as a reason to abandon the system.
Does ISO 17100 certification expire?
Certificates are commonly issued for a defined cycle with surveillance in between and recertification later. Maintenance is part of “how to get ISO 17100 certified” long-term.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice, certification advice, or a guarantee of certification outcomes. Requirements and audit practices should be confirmed against ISO 17100:2015 and with your certification body, qualified counsel, or auditor. Timelines and costs vary by organization and market.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
No credit card required
