Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 certification process timeline with key stages and durations.

ISO 27001 Certification Timeline: Complete 2026 Guide

The ISO 27001 certification timeline runs four to twelve months for most first-time organizations, and almost none of that time is spent in the audit itself. The audit is a handful of days. Everything before it — scoping, risk work, writing the documents, running the controls long enough to produce records, then auditing yourself — is what sets the date on the certificate.

That distinction matters because it changes what you can actually compress. Buying a faster certification body does not move the date. Starting your internal audit earlier does.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

What the ISO 27001 certification timeline really measures

There are two clocks running, and people conflate them. The first is your implementation clock: defining scope, running a risk assessment, selecting controls, writing the Statement of Applicability, and operating the management system long enough that it has a history. The second is your certification body’s clock: stage 1, the gap between stages, stage 2, then an independent certification decision.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

The second clock is short and fairly predictable. The first one is where projects slip by months. A realistic ISO 27001 certification timeline gives roughly 70% of the calendar to implementation and evidence, and 30% to the audit sequence and the decision that follows it.

The standard itself sets the workload. ISO/IEC 27001:2022, edition 3, published October 2022, carries 93 Annex A controls across four themes — 37 organizational, 8 people, 14 physical and 34 technological. You do not implement all 93. You justify every inclusion and exclusion in the Statement of Applicability, which clause 6.1.3 makes mandatory. That justification exercise, done honestly, is a multi-week task on its own.

The ISO 27001 certification timeline, phase by phase

The ranges below are typical for a company of 20 to 200 people with a single main site or a cloud-hosted product. Larger scopes, multiple legal entities and regulated data stretch every row.

PhaseTypical durationWhat ends it
Scope definition and gap assessment2–6 weeksA written scope statement and a ranked list of gaps
Risk assessment and risk treatment plan3–6 weeksApproved risk treatment plan and a completed Statement of Applicability
Documentation build4–10 weeksPolicies, procedures and registers approved and issued
Control implementation6–16 weeksControls live, running in parallel with documentation
Evidence accumulation6–12 weeksEnough records to sample — typically at least one quarter
Internal audit and management review3–5 weeksBoth completed, findings raised and actioned
Stage 1 audit1–2 days on siteReadiness report from the certification body
Gap between stage 1 and stage 24–8 weeks typicalStage 1 findings closed
Stage 2 audit2–5 days on siteAudit report with any nonconformities
Nonconformity closure and certification decision2–12 weeksCertificate issued

Phases overlap, and the published ISO 27001 certification timeline ranges above assume they do. Documentation and control implementation should run together, not in sequence, and evidence starts accumulating the day a control goes live rather than after everything is approved. Run them properly in parallel and a 12-month ISO 27001 certification timeline compresses to seven or eight.

Four gates that set your ISO 27001 certification timeline

Four specific things gate the date. Miss any one and the stage 2 audit either gets postponed or fails.

1. One completed internal audit. Your certification body will look for evidence that you audited your own management system before asking anyone else to. Not a gap assessment, not a readiness check — a documented internal audit against the standard, with findings.

2. One completed management review. Same principle. Top management has to have met, reviewed the defined inputs, and made decisions that are minuted. A review scheduled for the week after stage 2 is the single most common reason a certification slips a quarter.

3. Enough operating evidence to sample. There is no clause that says “three months of records.” What the standard requires is a management system that demonstrably operates, and an auditor cannot sample records that do not exist. Most certification bodies are comfortable with a quarter of live operation across access reviews, incident handling, change records and supplier checks.

4. Certification body availability. Accredited auditors are scheduled months out. Engage a body while you are still writing documents, not once you are ready — a four-week delay here is common and completely avoidable.

What the audit stages add to the ISO 27001 certification timeline

Initial certification is a two-stage audit under ISO/IEC 17021-1, and the number of audit days is not negotiable guesswork. It is calculated under Annex C of ISO/IEC 27006-1:2024, driven mainly by the effective number of people in scope, the number of sites and the complexity of what you do.

Stage 1 is a documentation and readiness review. The auditor confirms the scope, reads the policy, the risk assessment and the Statement of Applicability, and checks that your internal audit and management review have happened. Stage 2 is the certification audit proper, where the auditor samples evidence to confirm the controls you selected are implemented and working.

ISO/IEC 17021-1 does not prescribe a fixed interval between the two stages. Certification bodies set their own, and four to eight weeks is the norm; longer gaps are usually granted only where stage 1 raised something substantial. If the gap runs too long, some bodies will repeat elements of stage 1 — which adds cost and days you did not plan for.

After stage 2, the report goes to an independent reviewer inside the certification body who makes the certification decision. That review typically takes two to six weeks. Where stage 2 raised a major nonconformity, the certificate is held until it is closed, and most bodies allow roughly 90 days for initial certification before a partial re-audit is triggered. Minor findings are usually accepted with a corrective action plan and verified at the first surveillance audit. Our guide to ISO 27001 nonconformities covers the major-versus-minor distinction in detail.

Three realistic scenarios

FastTypicalSlow
Elapsed time4–5 months7–9 months12–18 months
Starting pointSOC 2 or equivalent program already runningSome security controls, no management systemNothing documented, scope still contested
ScopeOne product, one entity, cloud onlyOne entity, a couple of officesMultiple entities, on-premise estate, regulated data
Documentation approachTemplates tailoredTemplates plus consultant reviewWritten from scratch internally
Main risk to the dateCertification body availabilityEvidence period and internal auditScope churn and executive attention

The slow column is not a story about incompetence. It is almost always a scope that keeps moving. Every scope change re-opens the risk assessment, which re-opens the Statement of Applicability, which re-opens the documents. Freeze the scope early and defend it — it is the highest-leverage decision in the whole ISO 27001 certification timeline.

Life after the certificate: the three-year cycle

The certificate is valid for three years, and the cycle starts on the date of the certification decision, not on the last day of your stage 2 audit. Two dates then matter permanently.

The first surveillance audit must take place no more than 12 months from the certification decision date. That is a boundary, not a target, and missing it puts the certificate at risk. Surveillance audits then continue at least annually except in the recertification year, and each one takes roughly a third of the initial audit time. The recertification audit happens in year three, before expiry, and takes around two thirds of the initial audit time. If you want the detail, see our guide to the ISO 27001 surveillance audit.

One planning note for 2026: the 2013 to 2022 transition period closed on 31 October 2025, so every valid certificate now sits against ISO/IEC 27001:2022. The 2024 climate amendment, which added climate considerations to the context and interested-parties clauses, is a free amendment and does not require a separate transition project — but auditors do ask whether you have considered it.

How to compress an ISO 27001 certification timeline

Four things reliably save months. Freeze the scope in week one and write it down. Start the documentation set from tailored templates rather than a blank page — document authoring is the largest single block of effort in most projects, and it is the one place where a purchased starting point converts directly into calendar time saved. Run controls and documentation in parallel so evidence starts accruing early. And book the certification body before you feel ready.

Three things do not help, whatever you are told. Paying for an expedited audit does not shorten the evidence period. Skipping the gap assessment saves two weeks now and costs six later — our ISO 27001 gap assessment guide explains what the four outputs should be. And treating the internal audit as a formality reliably produces a major nonconformity at stage 2.

Cost tracks the timeline closely, because most of the spend is people-time rather than audit fees. The full breakdown is in our ISO 27001 certification cost analysis, and if you are still deciding whether to start at all, is ISO 27001 worth it works through the payback case.

Frequently asked questions

How long does ISO 27001 certification take for a 30-person company?
Six to nine months is realistic from a standing start, which is the middle of the published ISO 27001 certification timeline range. Four to five is achievable if you already run a SOC 2 program, because the control evidence largely exists and the work is mapping it to Annex A and building the management system layer on top.

Can I be certified without a full three months of records?
Sometimes, but it is the auditor’s call, not yours. The requirement is a management system that demonstrably operates. With a narrow scope and dense records some bodies accept less, but planning for under a quarter of evidence is planning to be postponed.

What happens if we fail stage 2?
You do not usually “fail” outright. You receive nonconformities. Majors must be corrected and verified before the certificate is issued, typically within about 90 days for initial certification; miss that and a partial or full re-audit follows. Minors are normally closed out with a plan and checked at the first surveillance audit.

Does buying a documentation toolkit actually shorten the ISO 27001 certification timeline?
It shortens one phase — documentation — which is typically four to ten weeks of the project. It does nothing for the evidence period or the audit schedule. Treat it as removing the blank-page problem, not as a shortcut to the certificate.

When does the three-year clock start?
On the certification decision date, which is usually two to six weeks after your stage 2 audit ends. Your first surveillance audit is due within 12 months of that date.

Where to start

The single largest block of elapsed time in an ISO 27001 certification timeline is producing the documented information the standard requires — the policies, the risk methodology, the Statement of Applicability, the registers and the audit records. Starting those from tailored templates rather than a blank page is the one lever that moves the date without cutting corners on evidence.

Our ISO 27001 Toolkit is built for exactly that phase: 165 templates in Microsoft Office format, aligned to ISO/IEC 27001:2022 and its 93 Annex A controls, with example text you tailor rather than invent. It is $99 and it replaces the slowest part of the schedule.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.