Skip to main content
RiskZeroCertifiers

Guide

How long does ISO 27001 certification take? A realistic timeline

A stage-by-stage ISO 27001 certification timeline, from first decision to certificate, with the factors that speed it up or slow it down, from auditors who run them.

By RiskZero Certifiers4 min read

The honest answer is “between four and fifteen months from the day you decide to do it”, which is not very useful. So here is the timeline broken into the parts you control and the parts we control, with what moves each one.

The two halves of the timeline

ISO 27001 certification has two distinct phases:

  1. Building the ISMS. Everything up to the point where your information security management system is operating and has evidence to show for it. You do this, with or without consultants. It usually takes three to nine months.
  2. Certification. Stage 1, Stage 2, closure of findings, and the certification decision. The certification body does this with you. For an audit-ready ISMS it takes eight to twelve weeks.

Most timelines slip in the first half. The second half is fairly predictable once you have booked dates.

Phase 1: building the ISMS

Weeks 1 to 4: scope, leadership, and context

Decide what the certification will cover, get leadership to sign the policy and allocate resources, and write down the interested parties and their requirements. Organizations that skip proper scoping pay for it later when the auditor asks why corporate IT is excluded from a scope that includes the product it runs on.

Weeks 4 to 12: risk assessment and Statement of Applicability

Identify information assets, assess risks, decide on treatment, and produce the Statement of Applicability listing which of the 93 Annex A controls apply and why. This is the intellectual core of the ISMS and the part that most distinguishes a good one from a paperwork exercise.

Weeks 8 to 24: implementing controls

Policies, procedures, technical controls, supplier reviews, training, and the records that prove they happen. How long this takes depends almost entirely on where you started. A company with an existing security program may be mostly done; a company starting from nothing needs months.

Weeks 20 to 30: internal audit and management review

The standard requires at least one internal audit and one management review before certification. These need to be real: an internal audit that finds nothing is a red flag to an external auditor. Allow time to act on what the internal audit finds.

Accelerators: an existing SOC 2 program, a compliance automation platform with evidence already connected, a dedicated ISMS owner, and leadership that treats the deadline as real.

Decelerators: an ISMS owner who has a day job, a scope that keeps changing, and consultants who deliver templates rather than an operating system.

Phase 2: certification

Week 0: contract and dates

Once you have signed with a certification body, dates for Stage 1 and Stage 2 are reserved. Lead time for dates varies between bodies from two weeks to three months. Ask before you sign.

Week 2 to 4: Stage 1

One to two days, mostly remote. The auditor reviews the ISMS design and readiness and reports areas of concern. Read our guide to Stage 1 versus Stage 2 for what is examined.

Week 4 to 8: addressing Stage 1 concerns

Typically two to six weeks. If Stage 1 was clean, Stage 2 can follow quickly. Accreditation rules limit the gap to six months, after which Stage 1 must be repeated.

Week 6 to 10: Stage 2

Two to eight days depending on the size and complexity of the scope, on site or remote. Findings are discussed as they arise.

Week 8 to 14: closing findings and the decision

Minor nonconformities need a corrective action plan, usually accepted within a week or two. A major nonconformity needs to be fixed and the fix verified, which can add two to eight weeks. The independent certification decision follows and the certificate is issued.

Putting it together

Starting point ISMS build Certification Total
Existing SOC 2 or similar program, dedicated owner 2 to 4 months 2 to 3 months 4 to 7 months
Some security controls, no formal program 5 to 8 months 2 to 3 months 7 to 11 months
Starting from scratch, part-time owner 8 to 12 months 3 months 11 to 15 months

Three things that reliably save time

  1. Book the audit before you are ready. Reserving Stage 1 and Stage 2 dates sets a deadline and secures the auditor. You can move them if needed.
  2. Run the internal audit early. It is the best rehearsal for Stage 2, and it gives you time to fix what it finds.
  3. Get the package attested before it is submitted. SRG’s readiness attestation, performed before the package reaches the certification body, is where the gaps get closed. It prevents the most expensive delay of all: a Stage 2 that raises a major nonconformity you did not see coming.
  • timeline
  • planning
  • stage 1
  • stage 2

Read next

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.