Skip to content
    August 23, 2026| Top Floor Team| 11 min read

    How Long Does ISO 42001 Certification Take?

    Plan on four to nine months from kickoff to an ISO/IEC 42001 certificate, with six to nine the realistic band if you are standing up a management system for the first time and four to six if you already hold ISO 27001. Those figures come from Konfirmity; Hicomply publishes three to nine months with a nine-to-twelve outlier for companies starting from scratch, and Vanta publishes six to twelve. All three sell compliance software, so treat their low ends as the best case for a customer of theirs rather than as a median. The reason the range has a floor is the thing none of them leads with: Schellman, an audit firm rather than a platform, describes Stage 2 as evaluating "the operating effectiveness of the AIMS", so the calendar is set by how long your evidence takes to accumulate, not by how fast anyone can write documents.

    Below: what the three published bands actually disagree about, how few days the audit really is, where the floor comes from, what an existing ISO 27001 system buys you, and when the honest answer is not to start this quarter.

    Key takeaways

    • Four to nine months is the center. Six to nine is normal without an existing management system; four to six is achievable with a certified ISO 27001 ISMS behind you.
    • The audit is days, not months. Schellman puts Stage 1 at one to two days and Stage 2 at three to nine or more, with four to twelve weeks between them.
    • The floor is structural: Stage 2 tests operation, and at least one management review has to have happened before it. Documents written quickly do not shorten an evidence clock.
    • Published bands differ mostly because they assume different starting points, not because anyone is wrong.
    • Cost and calendar are different questions. This article is the calendar; the money side is published separately and is not restated here.

    The three published bands, and what they actually disagree about

    Line the three up and the spread looks alarming: three to nine, four to nine, six to twelve. Read what each one assumes and the disagreement mostly evaporates.

    Hicomply's low end is explicitly a startup with simple AI usage, which it puts at three to four months, while its own from-scratch tier runs nine to twelve. Konfirmity splits on the same variable and names it: around six to nine months for teams without ISO 27001, frequently compressing to four to six for teams with it. Vanta's six to twelve is a single band with a phase table under it, and its phases add up to roughly the same place once you allow that several of them overlap in practice.

    So the three sources are not offering three answers to one question. They are offering one answer to three questions, and the question you are actually asking is "how long for a company like mine". The variable that decides it is whether you already operate a management system, because that is what determines how much of ISO/IEC 42001 is new work.

    One thing all three do bury, and it is worth stating plainly: none of these bands starts when you decide to certify. They start when the project actually has an owner with hours. The gap between the decision and the first real working session is frequently a month and it is nobody's line item.

    The audit itself is days, and it is not the project

    The certification audit is the most predictable piece of the whole schedule, which is why it is a poor place to look for time savings.

    Schellman, a CPA firm that performs these audits and therefore has an interest in the work looking substantial rather than trivial, publishes the mechanics: the Stage 1 audit typically lasts one to two days, the time between Stage 1 and Stage 2 is typically four to twelve weeks and should not exceed six months, and the Stage 2 audit can last anywhere between three and nine or more days. After certification the certificate is valid for three years with annual surveillance audits of two to five or more days, and Schellman puts surveillance effort at roughly a third of the initial certification review.

    Add the auditor days at the small end and you get under two weeks of anyone sitting with your team. Add the elapsed calendar around them, including the inter-stage gap and whatever nonconformities you have to close before the certification decision, and the audit phase consumes something in the region of two to four months of wall-clock time in which most days involve no auditor at all.

    Two consequences follow. First, compressing the audit is not a lever: the day count follows scope and headcount, and the inter-stage gap exists so you can fix what Stage 1 found. Second, if your certification body is booked out, that queue is pure calendar loss, so sign the certification agreement while you are still building rather than when you think you are ready.

    The floor: Stage 2 tests operation, not design

    This is the part that separates a real schedule from a hopeful one, and it is the same mechanism that sets the floor under ISO 27001.

    Schellman draws the distinction cleanly. Stage 1 reviews documented information: the scope, the required policies, the risk management and impact assessment methodologies, and the Statement of Applicability. Stage 2 reviews the implementation of policies, controls and processes with a focus on operational performance. Design is a Stage 1 question. Operation is a Stage 2 question, and operation cannot be evidenced by a system that has not been running.

    Konfirmity states the practical form of that requirement: a completed impact assessment, a real risk treatment, and at least one management review have to exist before Stage 2, and its own warning is the sentence to remember, that writing the documents in a fast month does not shorten the clock if the evidence still needs time to accumulate.

    That is why the three-month claims are not lies but are also not offers. A company that certifies against ISO/IEC 42001 in three months is a company whose document control, internal audit and management review already ran every month for other reasons, and whose remaining work was the AI-specific layer on top. If that is not you, the number does not transfer, and extrapolating someone else's fast case onto your own project is how a customer commitment gets made that a certification body will not honor.

    What an existing ISO 27001 system actually buys

    The compression is real and it is structural rather than promotional. ISO management system standards share a harmonized clause structure, so context, leadership, planning, support, operation, performance evaluation and improvement cover the same ground in both standards. The internal audit program you run for your ISMS, the document control, the corrective action process and the management review cadence are all requirements you have already met and can point an auditor at on day one.

    What does not carry over is the AI-specific half. ISO/IEC 42001's Annex A is a reference set of 38 controls across nine objectives, running A.2 to A.10, and applicability is decided through a Statement of Applicability driven by your risk and impact assessments rather than by adopting all of them. Konfirmity's control guide titles A.2 as policies related to AI and A.4 as resources for AI systems, which is the shape of the marginal work: an AI policy, an inventory of the data, tooling, compute and competence each system depends on, and an impact assessment that considers effects on people rather than only on the business.

    Practically, this means the compression lands in the build phase rather than the operate phase. You will still owe an internal audit and a management review covering the AI management system specifically, and those still have to happen over something that was running. Companies that assume ISO 27001 removes the operating period rather than shortening the build are the ones that discover the floor at the worst possible moment.

    What reliably blows the schedule

    A scope nobody will commit to. "All AI use across the company" is not a scope, it is a deferral, and every week the boundary stays open is a week the inventory, the risk assessment and the Statement of Applicability cannot be finished. Certify one product line or one platform and extend later.

    Treating the impact assessment as a document. The AI system impact assessment asks what happens to people when the system is wrong. Teams that write it as a formality produce a page that Stage 1 sends back, and the rework lands in the middle of the inter-stage gap where it costs the most.

    No named owner with hours. This is the failure we see most, and it is invisible in every published timeline because none of them models it. A program owned by everyone in principle and nobody on a calendar does not run slowly; it runs in bursts separated by months.

    Discovering the AI inventory does not match production. Features ship, models get swapped, a team starts calling a different provider. If nobody owns keeping the list current, Stage 2 finds the gap for you.

    When not to start this quarter

    We sell ISO 42001 readiness work, so weigh this against our interest.

    Nobody outside your company has asked. A certificate is only worth what a third party will accept it for. If no customer, regulator or partner has asked how you govern AI, the honest sequence is to adopt the NIST AI RMF, which costs nothing, and buy the certificate when a deal actually names it.

    Your deadline is inside 90 days. There is no ISO 42001 equivalent of a point-in-time report, and no accredited certification body will waive the operating-evidence requirement because your renewal is in March. The move that works is to give the customer your certification date, offer the interim artifacts a reviewer will actually accept in the meantime, which are the AI policy, the system inventory and a written statement of alignment to a named framework, and start the project on a schedule you can keep.

    The product is about to change shape. Certifying an AI management system scoped to a feature set you are rebuilding this year means paying for a scope change at the first surveillance audit. Certify what will still exist in eighteen months.

    Where Top Floor fits

    The part of this that benefits from someone who has done it before is the front of the project, not the end: defining a scope narrow enough to certify and defensible enough to survive Stage 1, running the risk and impact assessments so the Statement of Applicability traces to something real, and putting the operating period in the plan as a named phase rather than letting it arrive as a surprise. That is how our ISO 42001 engagements are shaped, and where a client already holds ISO 27001 we scope it as an extension of the existing management system rather than a parallel one.

    Where the constraint is keeping the system running between audits, the inventory that has to keep matching production and the internal audit and management review that have to keep happening, that is compliance as a service work.

    What nobody can sell you is a way past the floor. A certificate promised in weeks is either unaccredited or has not been scheduled with a certification body yet.

    How to decide this week

    • Write down whether you already run a management system with document control, internal audit and management review. That single answer moves you between the four-to-six and six-to-nine bands.
    • Name the owner and the hours. A program with neither has no timeline, only a hope.
    • Draw the scope on one page and get it agreed by whoever can veto it later.
    • Ask one accredited certification body for a scoping call and a provisional Stage 2 slot. Their queue is part of your calendar.
    • Work backward from any customer date you have already promised, and if the arithmetic does not close, say so to the customer now rather than in month seven.

    Frequently asked questions

    How long does ISO 42001 certification take?

    Four to nine months is the realistic center. Konfirmity puts teams without ISO 27001 at around six to nine months and teams with it at four to six, Hicomply publishes three to nine with a nine-to-twelve tier for organizations starting from scratch, and Vanta publishes six to twelve. All three sell compliance software, so their low ends describe a well-prepared customer rather than a median. The variable that decides where you land is whether you already operate a management system, because that determines how much of the standard is new work.

    How long are the Stage 1 and Stage 2 audits?

    Short, and shorter than most people expect. Schellman publishes one to two days for Stage 1 and three to nine or more days for Stage 2, with typically four to twelve weeks between them and a hard practical limit of six months before Stage 1 has to be repeated. After certification the certificate runs three years with annual surveillance audits of two to five or more days, which Schellman puts at roughly a third of the effort of the initial review. The auditor days are not where your months go; the build and the operating period are.

    Is a three-month ISO 42001 certification realistic?

    Only if you are already most of the way there. Stage 2 evaluates operating effectiveness rather than design, and Konfirmity states that a completed impact assessment, a real risk treatment and at least one management review have to exist before Stage 2. A company that certifies in three months typically had document control, internal audit and management review running already for another standard, so the AI-specific layer was the only new work. If that is not your situation, a three-month plan is a plan to miss, and the cost of missing it is usually a commitment you made to a customer.

    Does holding ISO 27001 make ISO 42001 faster?

    Yes, and the reason is structural. The two standards share a harmonized clause structure, so scope definition, leadership, risk methodology, document control, internal audit, corrective action and management review are requirements you have already met. Konfirmity puts the effect at four to six months rather than six to nine. What does not carry over is the AI-specific half: the Annex A reference controls, the AI system impact assessment, the inventory of data and tooling each system depends on, and human oversight design. ISO 27001 shortens the build phase; it does not remove the operating period before Stage 2.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.