How Long Does ISO 27001 Certification Take?
Plan on six to nine months from kickoff to certificate for a first ISO 27001 certification, with a realistic full band of 6 to 12 months and roughly four months as the floor for a small company with a narrow scope and a security program already running. That is the same band we published in our ISO 27001 and SOC 2 comparison, and as of August 2026 nothing in the standard has moved to change it. The constraint is not your auditor's calendar: ISO/IEC 27001:2022 clause 9.2 requires an internal audit of the ISMS and clause 9.3 requires a management review, and ISO/IEC 17021-1, the standard your certification body is itself accredited against, requires the Stage 2 auditor to find the management system implemented and effective rather than merely designed. A system cannot produce records of itself operating until it has operated, which is why every honest timeline has a floor.
Below: the four phases and where the months actually go, the two levers that genuinely compress a schedule, the three that reliably blow it, and the case for not starting this quarter at all.
Key takeaways
- Six to nine months is the realistic center; four months is a floor for a narrow scope, not a target, and 12 months is normal for a first ISMS built from scratch.
- The audit is the short phase. Stage 1 and Stage 2 together are days of auditor time; the ISMS build and the operating period before Stage 2 are months.
- The hard floor comes from ISO/IEC 17021-1 and from clauses 9.2 and 9.3 of ISO 27001: your internal audit and management review have to have happened, over a system that was running, before Stage 2.
- Audit duration is derived by your certification body under ISO/IEC 27006-1, the ISMS-specific standard its own accreditation is assessed against, so it is not something you negotiate down.
- The two things that actually compress a timeline are a narrow, defensible scope and a control set you already run, usually because you already hold a SOC 2.
The four phases, and where the months actually go
Phase one: scope and risk assessment, roughly four to eight weeks. Clause 4.3 makes you define the ISMS boundary, and clause 6.1.2 makes you establish a risk assessment process and run it. This phase looks like paperwork and is not. Every later decision, including which of the 93 Annex A controls you keep, traces back to the risk assessment, and teams that rush it spend the time again later when an auditor asks where a justification came from.
Phase two: build and document, roughly two to four months. Policies, the risk treatment plan, the Statement of Applicability, objectives under clause 6.2, competence records under 7.2, and whatever technical controls the risk treatment says you owe. If you already run a mature security program this phase is mostly writing down what is true. If you do not, it is real engineering work and it will not fit in two months.
Phase three: operate, then audit yourself, roughly two to three months. This is the phase nobody budgets for and it is the one that sets the floor. You run the system: access reviews actually happen, incidents actually get logged, suppliers actually get assessed. Then clause 9.2 says you audit that yourself and clause 9.3 says management reviews the results. Both must produce records.
Phase four: the certification audit, roughly four to ten weeks of elapsed time. Stage 1, a gap between stages for remediation, then Stage 2, then whatever nonconformities need correcting before the certification decision. The auditor days inside that window are few. The elapsed weeks are mostly scheduling and your own remediation.
Add the midpoints and you land between six and nine months. Add a scope you keep renegotiating and you land at twelve.
The floor nobody can sell you past
Read the two constraints together, because separately each looks soft and together they are rigid.
ISO/IEC 27001:2022 clause 9.2 requires internal audits "at planned intervals" that provide information on whether the ISMS conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. Clause 9.3 requires top management to review the ISMS, with defined inputs including audit results and nonconformities. Neither clause can be satisfied by a document dated the week before Stage 2 that describes a system with no history.
ISO/IEC 17021-1, published by ISO and used by every accreditation body in the IAF network, then requires the Stage 2 audit to evaluate the implementation and effectiveness of the management system, explicitly including performance monitoring, internal auditing and management review. That is the auditor's obligation, not a preference, and it is why certification bodies routinely tell prospects they want to see a period of operating records before they will book Stage 2.
How long a period? The standard does not name a number, and anyone who tells you the standard says "three months" is quoting certification-body practice rather than the text. In practice most bodies want enough evidence that a sample is meaningful, which lands in the region of two to three months of records for a small ISMS. The honest way to plan is not to hunt for the minimum; it is to accept that you owe one complete cycle of every periodic control you claimed, plus an internal audit and a management review on top of it.
Audit days are read off a table, not negotiated
The certification audit itself is the most predictable part of the whole project, because the duration is not a commercial decision.
Audit duration is not a line you negotiate. ISO/IEC 17021-1 requires your certification body to determine audit time, and ISO/IEC 27006-1, the ISMS-specific requirements that sit on top of ISO/IEC 17021-1 for bodies certifying information security management systems, is what its accreditation for ISO 27001 is assessed against. The derivation works from your effective number of personnel and is adjusted for risk, complexity and the number of sites; the resulting audit days are then split across Stage 1 and Stage 2, with Stage 1 the shorter of the two. Accreditation bodies check that arithmetic; ANAB in the United States and UKAS in the United Kingdom both assess certification bodies against exactly this.
(One document you will see quoted at you is IAF MD 5. It is worth knowing that it does not govern here: IAF MD 5:2023 is the audit-time document for quality, environmental and occupational health and safety schemes, and says so in its title.)
Two practical consequences. First, if a quote comes in dramatically cheaper than its peers, the interesting question is not the day rate but the day count, so ask which table row it came from. Second, you cannot compress Stage 2 by asking nicely. You compress it by having fewer people in scope or fewer sites, which is a scoping decision made in month one, not a negotiation in month seven.
What actually compresses the timeline
A narrow, defensible scope. Scope drives headcount in scope, which drives audit days, which drives the sampling burden, which drives your evidence workload. A scope of "the platform and the teams that build and run it" certifies far faster than "the company". The word that matters is defensible: a scope carved to exclude the messy part is a scope your auditor will challenge at Stage 1, and challenges cost weeks.
An existing SOC 2. Our comparison piece puts the control overlap between SOC 2 and ISO 27001 at roughly 70 to 80 percent, and the practical effect on a timeline is larger than that number suggests. If you already run access reviews, change management, vendor assessments and incident handling, and you already have the evidence habit, the remaining ISO work is the management-system layer: risk assessment methodology, Statement of Applicability, internal audit program, management review. That is writing and discipline, not new engineering, and it is why companies coming from a SOC 2 Type II land near the four to five month end.
Booking the certification body early. Not a compression exactly, but a de-risking. Bodies schedule out, and a Stage 2 you cannot book until eight weeks after you are ready is eight weeks of pure calendar loss. Sign the certification agreement while you are still building.
What reliably blows it
Scope that keeps moving. Every scope change re-opens the risk assessment, the Statement of Applicability, and the evidence set. Two scope changes will cost you more than any single technical gap.
Nobody owns clause 9. Internal audit and management review are the two deliverables that require someone with authority and independence, and they are the two most often left unassigned until the month they are needed. Our piece on outsourcing the ISO 27001 internal audit covers who is allowed to do it and the impartiality constraint that decides the answer.
Evidence that exists but was never collected. Access reviews that happened in Slack threads, supplier assessments that live in someone's inbox, an incident that was handled well and never written up. The control operated; the record does not exist. At Stage 2 an unrecorded control is an absent control, and reconstructing three months of records after the fact is both slow and visibly reconstructed.
When you should not start this quarter
We sell ISO 27001 readiness work, so weigh this accordingly. Three situations where starting now is the wrong call.
No customer is asking, and none is about to. ISO 27001 is procurement-driven for most companies. If nobody in your pipeline has requested it and you sell only into North America, a certificate is a nine-month project bought against a hypothesis. Ask two prospects directly whether it would change their answer before you spend the quarter.
You are mid-migration. If the environment that would be in scope is being rebuilt this year, you will certify an ISMS that describes a system you are about to retire, then pay for a scope change at the first surveillance audit. Certify the thing that will still exist in eighteen months.
Your deadline is inside 90 days. There is no ISO equivalent of a SOC 2 Type I, and no accredited body will shortcut the operating-evidence requirement. If the deal closes this quarter, the honest move is to tell the customer your certification date and offer interim evidence, not to start a project that will miss.
Where Top Floor fits
Where we are useful is the management-system layer and the sequencing: defining a scope that survives Stage 1, running the risk assessment so the Statement of Applicability traces to something, and building an evidence habit that makes the operating period produce records rather than regret. That work sits inside our ISO 27001 and compliance-as-a-service engagements. Where the constraint is the clause 9.2 internal audit and the impartiality it demands, that is audit and assurance work and it is deliberately a separate line.
What we cannot do is remove the floor. Anyone promising a certificate in weeks is either describing an unaccredited certificate or has not read ISO/IEC 17021-1.
How to decide this week
1. Write down the actual deadline and who set it. A customer name and a date, or no deadline at all. Most ISO timelines are set by a hypothetical buyer.
2. Draw the scope boundary on a whiteboard and count the people inside it. That headcount is the input to the audit-day table; nothing else you do this week moves the audit as much.
3. Ask one certification body for its next available Stage 1 and Stage 2 slots. Their calendar, not yours, is often the binding constraint.
4. Name the person who will run the internal audit and the person who will chair the management review, and check that the first is independent of what they will audit.
5. Pick the date you will start the operating period, and treat it as the real start of the project. Everything before it is preparation; the clock the auditor cares about starts there.
Frequently asked questions
Can you get ISO 27001 certified in three months?
Only in narrow circumstances, and not from a standing start. A three-month certification requires an ISMS whose controls are already operating with records, a very small scope, an internal audit and management review that can be completed immediately, and a certification body with availability. Companies that manage it are usually converting an existing SOC 2 Type II program rather than building one, because ISO/IEC 17021-1 requires the Stage 2 auditor to see the system implemented and effective, and that evidence has to already exist. From a genuine standing start, six to nine months is the realistic range.
How long is the gap between Stage 1 and Stage 2?
Commonly four to eight weeks, set by how much remediation Stage 1 surfaces and by your certification body's calendar. Do not let it stretch indefinitely: certification bodies place a limit on how stale a Stage 1 can be before it has to be repeated, because its findings describe a system that may have changed, so a long delay can cost you the Stage 1 fee and days a second time. Ask your body for its published limit before you plan a pause.
Does ISO 27001 certification expire?
Yes. An accredited certificate runs on a three-year cycle: surveillance audits during years one and two, then a full recertification audit before the certificate expires. Miss a surveillance audit and the certificate can be suspended, and a suspended certificate is not something you can show a customer. Our piece on surveillance and recertification audits works through the cycle and the effort it carries in years two and three.
Is ISO 27001 faster the second time?
Substantially, for the same scope. Recertification in year three reuses the ISMS you have been operating, and the planning convention certification bodies work to puts recertification audit time at roughly two-thirds of what an initial certification audit would take if it were run at that point. The elapsed timeline shrinks even more than the audit days do, because the long phases in a first certification are the build and the first operating period, and by year three both already exist. The exception is a major scope or organizational change, which can put you back into something close to a first-time project.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.