How Long Does ISO 27001 Certification Take?

By July 25th, 2026ISO Audit And Certificate10 min read

How Long Does ISO 27001 Certification Take?

ISO 27001 certification typically takes 3 to 12 months. Organisations of 21 to 200 employees usually need 5 to 8 months. The timeline depends on company size, existing security maturity, and whether one person owns the project internally.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Compliance Team

Realistic Timeline by Organisation Size

The timeline for ISO 27001 certification is not a fixed number. It depends on three variables: the size of the organisation, how much security documentation and control implementation already exists, and whether the organisation dedicates a project owner to the work. The table below shows realistic total timelines based on these variables.

Low maturity means the organisation has no documented information security policies, no formal risk management process, and no existing controls framework. Medium maturity means some policies exist but are not aligned to ISO 27001, and basic controls such as access control and antivirus are in place. High maturity means the organisation already operates a recognised security framework such as NIST or ISO 27001 has been partially implemented.

Organisation sizeLow maturity (months)Medium maturity (months)High maturity (months)
1 – 10 employees4 – 83 – 62 – 4
11 – 50 employees6 – 105 – 83 – 6
51 – 200 employees8 – 126 – 104 – 7
201 – 500 employees10 – 168 – 126 – 10
500+ employees12 – 2010 – 168 – 12

The ranges above assume the organisation has a dedicated project owner working on the ISMS at least half-time. Without a dedicated owner, add 30 to 50 percent to the timeline. The ranges also assume the certification body is booked 4 to 6 months in advance; last-minute bookings can add 2 to 3 months of waiting time.

Phase-by-Phase Breakdown

An ISO 27001 project divides into six phases. Each phase has a typical duration for a mid-size organisation (21 – 200 employees) with medium maturity. The phases are sequential, though some overlap is possible with careful planning.

PhaseDurationKey activitiesCumulative time
1. Gap analysis2 – 4 weeksClause-by-clause review of existing policies and controls against ISO 27001 and Annex A; inventory of what exists and what is missing; gap report with prioritised findings; project plan with timeline and resource estimate2 – 4 weeks
2. ISMS establishment6 – 12 weeksDefine ISMS scope; develop ISMS policy framework (20 – 40 documents); establish document control system; define roles and responsibilities; draft information security policies for each domain8 – 16 weeks
3. Risk assessment4 – 8 weeksAsset inventory and classification; threat identification; vulnerability assessment; likelihood and impact scoring; risk register creation; risk treatment plan development; residual risk acceptance12 – 24 weeks
4. Control implementation8 – 16 weeksImplement Annex A controls per risk treatment plan; deploy technical controls (access control, logging, encryption, SIEM); implement organisational controls (training, supplier agreements, incident response); implement physical controls (secure areas, equipment security); draft Statement of Applicability20 – 40 weeks
5. Internal audit2 – 4 weeksPlan and conduct internal audit; interview process owners; collect and review evidence; report nonconformities; assign and track corrective actions; verify closure of all findings22 – 44 weeks
6. Management review1 – 2 weeksSenior management review of ISMS performance; review of audit results, risk assessment status, incident reports, and stakeholder feedback; formal decision on readiness for certification23 – 46 weeks

The cumulative range for the six phases is 23 to 46 weeks, which aligns with the 5 to 10 month range for a mid-size organisation in the size table above. The total timeline is typically closer to the upper end for first-time certification because organisations underestimate the control implementation and documentation phases.

Person-Hours Required

For a mid-size organisation (21 – 200 employees), the total internal effort ranges from 400 to 800 person-hours spread across the project. This is not a single person’s full-time workload but rather the combined effort of the management representative, IT team, process owners and department heads across meetings, documentation reviews and implementation tasks.

To put this in perspective: 400 to 800 person-hours over a 7-month project means approximately 15 to 30 hours per week in total, or roughly 2 to 4 hours per week per team member across an average team of 8 to 10 contributors. The project owner typically carries the heaviest load at 10 to 20 hours per week during the peak implementation phase.

RoleApproximate person-hoursPercentage of total effort
Project owner / management representative150 – 30035 – 40%
IT team (technical control implementation)100 – 20020 – 25%
Process owners (documentation review, interviews)80 – 15015 – 20%
Senior management (policy approval, management review)20 – 405%
Training and awareness (all staff)50 – 11010 – 15%

Five Things That Delay ISO 27001 Projects

From real project experience, the following five factors are the most common causes of timeline overrun in ISO 27001 certification projects across the GCC.

  1. No dedicated project owner. When the ISMS implementation is added to someone’s existing full-time role with no time allocation, the project stretches by 40 to 60 percent. The single most effective step to shorten your timeline is to appoint a dedicated or at least half-time project owner.
  2. Underestimated risk assessment effort. The risk assessment is the most underestimated phase. A thorough asset inventory and threat identification exercise for 50-plus assets takes considerably longer than most first-time implementers expect. Organisations that budget 2 weeks for the risk assessment typically need 6.
  3. Scope creep. Expanding the ISMS scope mid-project to cover additional departments or systems adds 4 to 8 weeks. Scope should be finalised and documented before the end of the ISMS establishment phase.
  4. Delayed management review. Scheduling the management review meeting can take 3 to 6 weeks if senior stakeholders are not available. Book the management review date at the start of the project, before calendars fill.
  5. Certification body availability. Accredited certification bodies often book Stage 1 and Stage 2 audits 6 to 12 weeks in advance. Booking late is the most common avoidable timeline extension.

How to Compress the Timeline

Organisations that need certification faster than the standard timeline can use the following legitimate compression strategies. None of these compromise the integrity of the certification; they simply reduce the non-value-adding waiting periods in the project.

  • Pre-book the certification body before implementation begins, so audit dates are locked in 4 to 6 months ahead. This alone can save 2 to 3 months compared to booking at the end of implementation.
  • Use an integrated risk assessment tool to streamline the risk assessment phase. Template-based approaches with pre-populated threat libraries can reduce the risk assessment from 8 weeks to 4 weeks.
  • Engage external implementation support to carry the documentation and policy workload, freeing internal teams for control implementation. This is particularly effective when internal teams have limited capacity.
  • Scope narrowly for the first cycle. Certify one core business process or one department first, then expand scope at recertification. This reduces control implementation effort by 30 to 50 percent in the first cycle.
  • Schedule internal audit and management review in parallel. Run internal audit findings review and corrective action closure concurrently with final control implementation activities, rather than waiting until implementation is fully complete.

Book the Certification Body Early

One of the most common timeline failures is waiting until the ISMS is ready before contacting the certification body. The following timeline shows the impact of early versus late booking.

ScenarioImplementation completeBooking madeStage 1 dateStage 2 dateCertificate issued
Early bookingMonth 5Month 1Month 6Month 7Month 8
Late bookingMonth 5Month 5Month 8Month 9Month 10

Booking Stage 1 and Stage 2 audit dates 4 to 6 months in advance is normal practice, and last-minute bookings face 8 to 12 week waits. This alone can add three months to the project timeline with no benefit to the quality of the ISMS.

Surveillance and Recertification Cycle

After initial certification, the ISO 27001 certificate is valid for three years from the certification decision date. The certification body conducts surveillance audits in year one and year two to verify that the ISMS remains effective and continues to comply with the standard.

Surveillance audits are shorter than the initial Stage 2 audit, typically 1 to 2 days depending on organisation size. The auditor samples selected Annex A controls and reviews any changes to the organisation, its risk profile or its ISMS since the previous visit. A surveillance audit is not a full re-assessment, but significant nonconformities found during surveillance can result in certificate suspension.

At year three, a full recertification audit is required. The recertification audit is similar in duration to the initial Stage 2 audit but is typically less intensive because the ISMS is already operational and the auditor has historical evidence to draw on. Plan to schedule the recertification audit 3 to 6 months before the certificate expiry date to allow time for nonconformity closure.

EventTimingDuration (days)
Initial certificationMonth 03 – 10 (Stage 1 + Stage 2)
First surveillance auditYear 11 – 2
Second surveillance auditYear 21 – 2
Recertification auditYear 3 (before expiry)3 – 8

FAQ

How long does ISO 27001 take for a small business?

A small business with 1 to 10 employees and low existing security maturity typically needs 4 to 8 months. If policies and basic controls are already in place, this reduces to 2 to 4 months.

How long is an ISO 27001 certificate valid?

An ISO 27001 certificate is valid for three years from the date of issue. The certification body must conduct surveillance audits in year one and year two for the certificate to remain valid.

How far in advance should we book a certification audit?

Book the Stage 1 audit 4 to 6 months before your target certification date. Accredited certification bodies have limited audit capacity, and last-minute bookings typically face 8 to 12 week waiting periods.

What happens if we are not ready by the Stage 2 audit date?

If the Stage 1 audit reveals significant gaps, the certification body may recommend a delay of 4 to 12 weeks before proceeding to Stage 2. This rescheduling may incur a re-visit fee but is preferable to failing Stage 2.

Can we do the internal audit ourselves while using a consultant?

Yes, but the internal auditor must be independent of the areas they audit. If your consultant has implemented the ISMS, they cannot also perform the internal audit according to ISO 19011 guidelines. Most organisations use a separate internal auditor or outsource internal audit to a different consultancy.

Does the timeline change for ISO 27001:2022 vs 2013?

The 2022 revision added 11 new Annex A controls and reorganised the four themes. Organisations implementing 27001:2022 for the first time do not need a transition period, but the additional controls may add 2 to 4 weeks to the implementation phase.

Bitrixme provides consultancy, gap analysis, implementation support, internal auditing and training. Certification audits are conducted by an independent accredited certification body. We prepare you for that audit; we do not issue the certificate.

Related Reading

Estimate your timeline: use our free timeline estimator tool for a phase-by-phase projection. Then contact Bitrixme for a scoping call, or message us on WhatsApp.