How Long Does ISO 27001 Certification Take?
ISO 27001 certification typically takes 3 to 12 months. Organisations of 21 to 200 employees usually need 5 to 8 months. The timeline depends on company size, existing security maturity, and whether one person owns the project internally.
Published: July 2026 | Last updated: July 2026 | Author: Bitrixme Compliance Team
Realistic Timeline by Organisation Size
The timeline for ISO 27001 certification is not a fixed number. It depends on three variables: the size of the organisation, how much security documentation and control implementation already exists, and whether the organisation dedicates a project owner to the work. The table below shows realistic total timelines based on these variables.
Low maturity means the organisation has no documented information security policies, no formal risk management process, and no existing controls framework. Medium maturity means some policies exist but are not aligned to ISO 27001, and basic controls such as access control and antivirus are in place. High maturity means the organisation already operates a recognised security framework such as NIST or ISO 27001 has been partially implemented.
| Organisation size | Low maturity (months) | Medium maturity (months) | High maturity (months) |
|---|---|---|---|
| 1 – 10 employees | 4 – 8 | 3 – 6 | 2 – 4 |
| 11 – 50 employees | 6 – 10 | 5 – 8 | 3 – 6 |
| 51 – 200 employees | 8 – 12 | 6 – 10 | 4 – 7 |
| 201 – 500 employees | 10 – 16 | 8 – 12 | 6 – 10 |
| 500+ employees | 12 – 20 | 10 – 16 | 8 – 12 |
The ranges above assume the organisation has a dedicated project owner working on the ISMS at least half-time. Without a dedicated owner, add 30 to 50 percent to the timeline. The ranges also assume the certification body is booked 4 to 6 months in advance; last-minute bookings can add 2 to 3 months of waiting time.
Phase-by-Phase Breakdown
An ISO 27001 project divides into six phases. Each phase has a typical duration for a mid-size organisation (21 – 200 employees) with medium maturity. The phases are sequential, though some overlap is possible with careful planning.
| Phase | Duration | Key activities | Cumulative time |
|---|---|---|---|
| 1. Gap analysis | 2 – 4 weeks | Clause-by-clause review of existing policies and controls against ISO 27001 and Annex A; inventory of what exists and what is missing; gap report with prioritised findings; project plan with timeline and resource estimate | 2 – 4 weeks |
| 2. ISMS establishment | 6 – 12 weeks | Define ISMS scope; develop ISMS policy framework (20 – 40 documents); establish document control system; define roles and responsibilities; draft information security policies for each domain | 8 – 16 weeks |
| 3. Risk assessment | 4 – 8 weeks | Asset inventory and classification; threat identification; vulnerability assessment; likelihood and impact scoring; risk register creation; risk treatment plan development; residual risk acceptance | 12 – 24 weeks |
| 4. Control implementation | 8 – 16 weeks | Implement Annex A controls per risk treatment plan; deploy technical controls (access control, logging, encryption, SIEM); implement organisational controls (training, supplier agreements, incident response); implement physical controls (secure areas, equipment security); draft Statement of Applicability | 20 – 40 weeks |
| 5. Internal audit | 2 – 4 weeks | Plan and conduct internal audit; interview process owners; collect and review evidence; report nonconformities; assign and track corrective actions; verify closure of all findings | 22 – 44 weeks |
| 6. Management review | 1 – 2 weeks | Senior management review of ISMS performance; review of audit results, risk assessment status, incident reports, and stakeholder feedback; formal decision on readiness for certification | 23 – 46 weeks |
The cumulative range for the six phases is 23 to 46 weeks, which aligns with the 5 to 10 month range for a mid-size organisation in the size table above. The total timeline is typically closer to the upper end for first-time certification because organisations underestimate the control implementation and documentation phases.
Person-Hours Required
For a mid-size organisation (21 – 200 employees), the total internal effort ranges from 400 to 800 person-hours spread across the project. This is not a single person’s full-time workload but rather the combined effort of the management representative, IT team, process owners and department heads across meetings, documentation reviews and implementation tasks.
To put this in perspective: 400 to 800 person-hours over a 7-month project means approximately 15 to 30 hours per week in total, or roughly 2 to 4 hours per week per team member across an average team of 8 to 10 contributors. The project owner typically carries the heaviest load at 10 to 20 hours per week during the peak implementation phase.
| Role | Approximate person-hours | Percentage of total effort |
|---|---|---|
| Project owner / management representative | 150 – 300 | 35 – 40% |
| IT team (technical control implementation) | 100 – 200 | 20 – 25% |
| Process owners (documentation review, interviews) | 80 – 150 | 15 – 20% |
| Senior management (policy approval, management review) | 20 – 40 | 5% |
| Training and awareness (all staff) | 50 – 110 | 10 – 15% |
Five Things That Delay ISO 27001 Projects
From real project experience, the following five factors are the most common causes of timeline overrun in ISO 27001 certification projects across the GCC.
- No dedicated project owner. When the ISMS implementation is added to someone’s existing full-time role with no time allocation, the project stretches by 40 to 60 percent. The single most effective step to shorten your timeline is to appoint a dedicated or at least half-time project owner.
- Underestimated risk assessment effort. The risk assessment is the most underestimated phase. A thorough asset inventory and threat identification exercise for 50-plus assets takes considerably longer than most first-time implementers expect. Organisations that budget 2 weeks for the risk assessment typically need 6.
- Scope creep. Expanding the ISMS scope mid-project to cover additional departments or systems adds 4 to 8 weeks. Scope should be finalised and documented before the end of the ISMS establishment phase.
- Delayed management review. Scheduling the management review meeting can take 3 to 6 weeks if senior stakeholders are not available. Book the management review date at the start of the project, before calendars fill.
- Certification body availability. Accredited certification bodies often book Stage 1 and Stage 2 audits 6 to 12 weeks in advance. Booking late is the most common avoidable timeline extension.
How to Compress the Timeline
Organisations that need certification faster than the standard timeline can use the following legitimate compression strategies. None of these compromise the integrity of the certification; they simply reduce the non-value-adding waiting periods in the project.
- Pre-book the certification body before implementation begins, so audit dates are locked in 4 to 6 months ahead. This alone can save 2 to 3 months compared to booking at the end of implementation.
- Use an integrated risk assessment tool to streamline the risk assessment phase. Template-based approaches with pre-populated threat libraries can reduce the risk assessment from 8 weeks to 4 weeks.
- Engage external implementation support to carry the documentation and policy workload, freeing internal teams for control implementation. This is particularly effective when internal teams have limited capacity.
- Scope narrowly for the first cycle. Certify one core business process or one department first, then expand scope at recertification. This reduces control implementation effort by 30 to 50 percent in the first cycle.
- Schedule internal audit and management review in parallel. Run internal audit findings review and corrective action closure concurrently with final control implementation activities, rather than waiting until implementation is fully complete.
Book the Certification Body Early
One of the most common timeline failures is waiting until the ISMS is ready before contacting the certification body. The following timeline shows the impact of early versus late booking.
| Scenario | Implementation complete | Booking made | Stage 1 date | Stage 2 date | Certificate issued |
|---|---|---|---|---|---|
| Early booking | Month 5 | Month 1 | Month 6 | Month 7 | Month 8 |
| Late booking | Month 5 | Month 5 | Month 8 | Month 9 | Month 10 |
Booking Stage 1 and Stage 2 audit dates 4 to 6 months in advance is normal practice, and last-minute bookings face 8 to 12 week waits. This alone can add three months to the project timeline with no benefit to the quality of the ISMS.
Surveillance and Recertification Cycle
After initial certification, the ISO 27001 certificate is valid for three years from the certification decision date. The certification body conducts surveillance audits in year one and year two to verify that the ISMS remains effective and continues to comply with the standard.
Surveillance audits are shorter than the initial Stage 2 audit, typically 1 to 2 days depending on organisation size. The auditor samples selected Annex A controls and reviews any changes to the organisation, its risk profile or its ISMS since the previous visit. A surveillance audit is not a full re-assessment, but significant nonconformities found during surveillance can result in certificate suspension.
At year three, a full recertification audit is required. The recertification audit is similar in duration to the initial Stage 2 audit but is typically less intensive because the ISMS is already operational and the auditor has historical evidence to draw on. Plan to schedule the recertification audit 3 to 6 months before the certificate expiry date to allow time for nonconformity closure.
| Event | Timing | Duration (days) |
|---|---|---|
| Initial certification | Month 0 | 3 – 10 (Stage 1 + Stage 2) |
| First surveillance audit | Year 1 | 1 – 2 |
| Second surveillance audit | Year 2 | 1 – 2 |
| Recertification audit | Year 3 (before expiry) | 3 – 8 |
FAQ
How long does ISO 27001 take for a small business?
A small business with 1 to 10 employees and low existing security maturity typically needs 4 to 8 months. If policies and basic controls are already in place, this reduces to 2 to 4 months.
How long is an ISO 27001 certificate valid?
An ISO 27001 certificate is valid for three years from the date of issue. The certification body must conduct surveillance audits in year one and year two for the certificate to remain valid.
How far in advance should we book a certification audit?
Book the Stage 1 audit 4 to 6 months before your target certification date. Accredited certification bodies have limited audit capacity, and last-minute bookings typically face 8 to 12 week waiting periods.
What happens if we are not ready by the Stage 2 audit date?
If the Stage 1 audit reveals significant gaps, the certification body may recommend a delay of 4 to 12 weeks before proceeding to Stage 2. This rescheduling may incur a re-visit fee but is preferable to failing Stage 2.
Can we do the internal audit ourselves while using a consultant?
Yes, but the internal auditor must be independent of the areas they audit. If your consultant has implemented the ISMS, they cannot also perform the internal audit according to ISO 19011 guidelines. Most organisations use a separate internal auditor or outsource internal audit to a different consultancy.
Does the timeline change for ISO 27001:2022 vs 2013?
The 2022 revision added 11 new Annex A controls and reorganised the four themes. Organisations implementing 27001:2022 for the first time do not need a transition period, but the additional controls may add 2 to 4 weeks to the implementation phase.
Bitrixme provides consultancy, gap analysis, implementation support, internal auditing and training. Certification audits are conducted by an independent accredited certification body. We prepare you for that audit; we do not issue the certificate.
Related Reading
Estimate your timeline: use our free timeline estimator tool for a phase-by-phase projection. Then contact Bitrixme for a scoping call, or message us on WhatsApp.