The road to certification, step by step
The platform knows what the standard demands, so you always know the next thing to do.
1 · Gap assessment
See exactly where you stand against the standard and what is missing.
2 · Build the system
Controls or clause register, risk assessment, mandatory documents from templates.
3 · Internal audit & CAPA
Findings, corrective actions and due dates — nothing slips.
4 · Certify & maintain
Stage 1, Stage 2, surveillance and recertification, tracked by date.
One place for controls, risks, documents and evidence.
Evidence tied to each requirement; export the SoA and records on demand.
A “needs your attention” dashboard puts overdue work first.
Everything an auditor will ask for
Requirement register & SoA
93 Annex A controls, ISO 9001 clauses or ESG disclosures — one interface.
Risk register
Assessment, treatment and residual risk linked to requirements.
Document control
Versioning, approvals, acknowledgements.
Internal audit & CAPA
Findings, corrective actions, due dates.
Certificate lifecycle
Stage 1/2, surveillance, recertification.
Multi-site
Progress per site and per standard.
Multi-standard
Adopt a new standard without learning a new tool.
White-label
Consultancy branding and custom domains.
Certification results, standard by standard
Organizations certified on the platform and the average time for the whole process — from gap assessment to certificate in hand.
| Standard | Certified | Typical timeline | On Chuẩn Việt | Faster by |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | 486 | 10–14 months | 5.2 months | 58% |
| ISO 9001:2015 | 552 | 8–12 months | 3.9 months | 61% |
| ESG (GRI / VN) | 204 | 6–9 months | 3.1 months | 55% |
Aggregated from certification programmes run on the platform; actual timelines depend on scope and starting maturity.
The time you get back
Rigorous enough to hold your certification records
Compliance evidence is sensitive. The platform is multi-tenant by design, with isolation enforced at the database layer — not in the UI.
Tenant isolation
Row-level security: only ACTIVE members can see a workspace.
Role-based access
Admin, member, consultant — permissions scoped by role.
Durable audit trail
Every significant change is recorded and cannot be edited away.
Dates that chase you
Audit, surveillance and recertification dates always in view.