Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 timeline showing the phases from kickoff to certification

ISO 27001 Timeline: How Long Does Certification Take?

The ISO 27001 timeline usually runs 3 to 12 months from kickoff to certificate. A small, focused company that starts from prewritten documentation can be audit-ready in three to four months; larger or less-prepared organizations commonly need six to twelve. The single biggest reason you cannot go faster is not paperwork. It is that your information security management system (ISMS) has to actually run long enough to generate evidence, including at least one internal audit and one management review, before a certification body will complete its Stage 2 audit.

Below is a realistic, phase-by-phase breakdown of the ISO 27001 timeline: what stretches it, what shortens it, and how to reach certification without cutting corners.

ISO 27001 timeline showing the phases from kickoff to certification
Typical ISO 27001 timeline from kickoff to certificate.

ISO 27001 timeline by company size

Treat the numbers below as typical ranges, not promises. Where you land depends on your size, how mature your security already is, and how much time your team can commit each week.

Company profileTypical time to certification
Startup or small team (under ~25 people in scope), well-prepared3 – 4 months
Small-to-mid company building the ISMS from scratch4 – 8 months
Mid-market (25 – 200 staff), broader scope6 – 10 months
Large or multi-site organization (200+ staff)9 – 12+ months

Organizations that already hold SOC 2 or Cyber Essentials, or that run a mature security program, move toward the faster end because much of the documentation and many of the controls already exist.

The ISO 27001 timeline, phase by phase

A certification project measured against the requirements of ISO/IEC 27001:2022 moves through seven phases. The durations below assume a small-to-mid company with a dedicated owner.

PhaseWhat happensTypical duration
1. Scope and planDefine the ISMS scope, secure leadership sign-off, and assign an accountable owner2 – 4 weeks
2. Gap analysisCompare current practice against the standard to see what is missing1 – 3 weeks
3. Risk assessment and treatmentRun a documented risk assessment (Clause 6.1.2), decide how to treat each risk, and draft the Statement of Applicability3 – 5 weeks
4. Documentation and controlsWrite your policies and procedures and implement the Annex A controls you selected4 – 12 weeks
5. Operate, internal audit, management reviewLet the ISMS run and produce records; complete at least one internal audit and one management review8 – 12+ weeks
6. Stage 1 auditThe certification body reviews your documentation and readinessRoughly 1 – 2 days on site, plus scheduling
7. Stage 2 audit and decisionThe auditor tests whether your controls work in practice; the certificate is issued if you passUsually 4 – 6 weeks after Stage 1

These phases overlap in practice. You will start writing documentation while you finish the risk assessment, which is why the total is shorter than adding every row.

A realistic six-month example

Here is how those phases typically fall for a 30-person software company doing most of the work in-house:

  • Month 1: Agree the scope, appoint an owner, and run the gap analysis.
  • Month 2: Complete the risk assessment and draft the Statement of Applicability.
  • Months 2 – 3: Write the policies and switch on the Annex A controls you selected.
  • Months 3 – 5: Operate the ISMS, collect evidence, and run one internal audit and one management review.
  • Month 5: Pass the Stage 1 documentation review.
  • Month 6: Clear the Stage 2 audit and receive the certificate.

Slip on ownership or leave the internal audit to the last minute, and the same project quietly becomes a nine-month one.

Why you can’t compress the operating-evidence phase

The standard sets no fixed minimum operating period, but you cannot certify a system that has existed for two weeks, because there are no records to sample. Certification bodies generally expect the ISMS to have operated for around three months before Stage 2, and they require Stage 2 to take place within six months of Stage 1.

Two records they will always ask for are at least one completed internal audit and one management review. This is the phase automation tools cannot skip, and it is why promises of certification “in a matter of weeks” rarely survive contact with a real auditor. Our guide to the ISO 27001 audit walks through exactly what an assessor checks at each stage.

What lengthens or shortens the timeline

Most of the variation between a four-month project and a twelve-month one comes down to five things:

  • Organization size and scope — how many people and sites sit inside your certification boundary.
  • Existing security maturity — starting from mature, documented controls versus a blank page.
  • Time your team can commit — a part-time owner squeezing this between other duties stretches every phase.
  • Documentation approach — writing policies from scratch versus starting from prewritten templates.
  • Overlapping certifications — an existing SOC 2 or Cyber Essentials program means much of the work is already done.

Scope is the lever most teams underuse. Certifying only the part of the business that genuinely needs it means fewer controls to implement, less evidence to gather, and a shorter path to Stage 2. It also lowers the price, as our ISO 27001 certification cost breakdown explains.

How to shorten your ISO 27001 timeline

You cannot skip the audit or the evidence period, but you can stop the avoidable delays that push projects past a year:

  1. Assign a single accountable owner before anything else. Shared ownership is the most common cause of drift.
  2. Start from prewritten documentation instead of a blank page. Drafting policies and the Statement of Applicability by hand is the slowest part of the build.
  3. Tighten your scope to what customers and regulators actually require.
  4. Turn on your controls early so the operating-evidence clock starts sooner.
  5. Run your internal audit and management review in-house and on schedule, not as an afterthought.
  6. Plan around the evidence period rather than trying to shortcut it.

If documentation is your bottleneck, our ISO 27001 Toolkit provides 175 editable Word and Excel templates, including the policies, the risk assessment, and the mandatory Statement of Applicability an auditor expects. It lets you compress phases three and four instead of writing from scratch. Pair it with the ISO 27001 mandatory documents checklist to confirm nothing is missing before Stage 1.

After certification: the three-year cycle

Your certificate is valid for three years, provided you keep the ISMS running. Expect an annual surveillance audit in years one and two. Each is shorter than the initial audit but still a real review, and a full recertification audit at the end of year three restarts the cycle. Budget time for these the same way you would a renewal. For the full route from kickoff to certificate, see our step-by-step guide to getting ISO 27001 certified.

Frequently asked questions about the ISO 27001 timeline

How long does ISO 27001 certification take for a small business?

A well-prepared small company using prewritten documentation can reach certification in three to four months. If you are building the ISMS from scratch with a part-time owner, plan for four to eight months instead.

Can you get ISO 27001 certified in a few weeks?

Realistically, no. Even with everything documented, your ISMS has to operate long enough to produce evidence, including at least one internal audit and one management review, before the Stage 2 audit. Certification bodies generally expect around three months of operating records.

How long is the gap between the Stage 1 and Stage 2 audits?

Typically four to six weeks. The gap gives you time to close any issues Stage 1 surfaces and gather more evidence. Certification bodies usually require Stage 2 to happen within six months of Stage 1.

How long is an ISO 27001 certificate valid?

Three years, as long as you pass annual surveillance audits and keep the ISMS running. A full recertification audit at the end of year three renews it for another three-year cycle.

Does a documentation toolkit speed up the ISO 27001 timeline?

It shortens the documentation phase, which is often the longest part of the build, by giving you ready-to-edit policies and registers. It cannot shorten the operating-evidence period or the two-stage audit, so treat it as a way to reach Stage 1 sooner, not a shortcut to the certificate.

Map these phases onto your own calendar early, protect the operating-evidence period, and the ISO 27001 timeline becomes predictable rather than stressful.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.