The short answer: three different finishing lines
ISO 9001 certifies a management system, Six Sigma drives defects down to a statistical target, and Baldrige scores an entire organisation — they differ in what is assessed, who assesses it and what you hold at the end.
Ask for ISO 9001 and you get a certificate: an external audit body tests your quality management system against the requirements in clauses 4 to 10 of the standard, and either you pass or you do not. There is no score and no ranking — a small workshop and a multinational hold the same document.
Ask for Six Sigma and you get a number: a process improved until it produces no more than 3.4 defects per million opportunities. Nobody certifies the organisation; project teams run the 5 DMAIC phases and the result is a measured defect rate, not a framed certificate.
Ask for Baldrige and you get a score: examiners rate the whole organisation against 7 criteria worth 1,000 points in total, with Results alone carrying 450. Lean and CMMI sit nearby — Lean is a daily practice with no certificate at all, and CMMI rates capability on a 5-level maturity ladder.
ISO 9001: the one that ends in a certificate
ISO 9001:2015 is built from 10 clauses, its requirements live in clauses 4 to 10, and its certificate survives on a fixed 3-year audit cycle.
The 10 clauses run from context and leadership through planning, support and operation to performance evaluation and improvement — the seven areas an auditor can actually test. The first three clauses set scope and terms, so every testable requirement sits in clauses 4 to 10.
Certification is a cycle, not an event. A Stage 1 audit reviews your documentation; a Stage 2 audit tests the system in operation; surveillance audits return every 12 months; and at 36 months a recertification audit opens the next 3-year cycle. The full procedure, with its failure points, sits on the ISO 9001 Certification Step by Step page.
Audits fail in named ways. A major nonconformity — a requirement that is missing or broken — blocks the certificate until it is corrected and re-checked. Minor nonconformities are logged with corrective-action deadlines, and findings left open at surveillance put the certificate at risk.
- Map your processes against clauses 4 to 10 and build the documented system.
- Stage 1: documentation review — the auditor checks the system on paper before visiting.
- Stage 2: certification audit — the system is tested in operation; a major nonconformity stops here.
- Surveillance audit every 12 months — minor nonconformities must be closed on agreed deadlines.
- Recertification at 36 months — a full re-audit opens the next 3-year cycle.