ISO 27001

How long does ISO 27001 certification take?

24 September 2026 · 8 min read · CertAssist

A realistic ISO 27001 certification timeline, phase by phase, plus how long the certificate lasts once you have it and what actually causes the delays.

ISO 27001 certification takes six to twelve months for most organizations starting from scratch. A small single-site company that already has written policies and a tidy asset list can be certified in three to six months. A larger or multi-site organization, or one starting with nothing written down, should plan for twelve to eighteen. The certification audit itself takes days; everything before it is the reason the range is so wide.

The honest version of the answer is that you control most of the timeline and the certification body controls the rest. This page separates the two, because that is the distinction that tells you whether a published timeline is achievable for you or is someone else's best case.

How long does ISO 27001 certification take by company size?

Size matters less than how much is already written down. A thirty-person company with a documented starting point routinely beats a ten-person company with nothing. The ranges below assume a dedicated internal owner who can give the work real hours each week, not someone fitting it around a full-time role.

Starting pointTypical time to certificateWhat drives it
Small, single site, policies already written3 to 6 monthsMostly evidence gathering and the internal audit
Small to mid-size, starting from scratch6 to 12 monthsWriting the ISMS from nothing is the long pole
Multi-site, or regulated, or complex scope12 to 18 monthsScope negotiation, more controls in play, more evidence
Any size, no internal owner assignedIndefiniteThe most common reason a programme stalls

The ISO 27001 certification timeline, stage by stage

The ISO 27001 certification timeline has five phases. Only the last two involve the certification body, which is why the first three are where your schedule is actually won or lost.

PhaseTypical durationWho controls it
1. Define scope and get management commitment1 to 3 weeksYou
2. Risk assessment, Statement of Applicability, write the ISMS4 to 12 weeksYou
3. Implement controls and gather evidence8 to 24 weeksYou
4. Internal audit and management review2 to 4 weeksYou, but it is mandatory before stage 2
5. Stage 1 and stage 2 certification audit4 to 10 weeks including the gapThe certification body

Two things in that table surprise people. The first is that phase 4 is not optional: ISO 27001 requires an internal audit and a management review before a certification body will proceed, and forgetting them is a common reason a stage 2 audit gets postponed. The second is that phase 5 is booked, not requested. Certification bodies have lead times, and in busy periods you may wait weeks for a slot. Book it while you are still in phase 3.

For what the auditor actually does in each of those two visits, see ISO 27001 stage 1 vs stage 2 audit.

How long does ISO 27001 certification last?

An ISO 27001 certificate is valid for three years, and it is conditional for all three. The certification body runs a surveillance audit in each of the two intervening years, then a full recertification audit before the three years expire. Those surveillance audits are shorter than the original stage 2, but they are real: the auditor samples controls, checks that the internal audit and management review actually happened, and looks at how you handled any nonconformities.

This is the part most timeline articles skip, and it changes how you should choose your tooling. A spreadsheet that got you to a certificate leaves you re-assembling evidence from scratch a year later, for an audit you had twelve months to prepare for. The recurring cost of ISO 27001 is not the certificate, it is remembering what you did.

What actually makes ISO 27001 take longer

In practice, four things account for most overruns, and none of them is the standard being difficult.

No named owner. A programme shared between three people who all have other jobs moves at the speed of the least available one. One accountable owner with allocated hours is the single biggest predictor of hitting a date.

Scope decided late. Scope is phase 1 for a reason. Changing it in month four means revisiting the risk assessment and the Statement of Applicability, and that is weeks of rework.

Evidence gathered at the end. Evidence collected as you go is a filing task. Evidence reconstructed the week before stage 2 is an archaeology project, and it is where teams discover that a control they believed was operating has no record proving it.

Waiting on the certification body. Entirely outside your control and frequently underestimated. Approach two or three, get their lead times in writing, and book early.

How CertAssist shortens the parts you control

CertAssist does not make an auditor move faster and does not shorten the stage 1 to stage 2 gap. What it addresses is phases 2 to 4, which is where your months go. Every Annex A control is laid out ready to work through with a draft justification and an evidence checklist, so phase 2 starts from a populated document rather than a blank one. Evidence attaches to the control it belongs to as you go, which removes the end-of-project reconstruction. The six registers, risk, suppliers, legal and regulatory, authorities, non-conformities and ISO 27001 maintenance, come pre-populated rather than as empty templates.

The reporting dashboard gives one readiness number, the trend over the last week and month, and a forecast completion date based on the pace you are actually working at rather than the pace you hoped for. That forecast is the useful part when someone asks for a date, because it is derived from your real progress and it moves when the pace does.

CertAssist is US$225 per month, or US$2,475 a year, and that covers every framework it supports rather than ISO 27001 alone. We publish that figure because most of this market does not, which makes the software line the hardest one to budget. For the full picture of what a first year costs, see how much ISO 27001 certification costs.

When a faster ISO 27001 timeline is the wrong goal

Speed is not always the thing to optimize. If a customer contract names a date, work backwards from it and book the certification body first. But if the driver is internal enthusiasm rather than an external deadline, a compressed timeline usually produces an ISMS nobody follows, which surfaces at the first surveillance audit rather than at stage 2.

There is also a floor. You cannot evidence an ISMS that has not been operating, and no tool changes that. If someone offers ISO 27001 certification in weeks, they are describing readiness or selling a certificate from a body your customers will not recognize. The point of the certificate is that a third party checked; shortcut the checking and you have bought a PDF.

Related guides

Frequently asked questions

How long does ISO 27001 certification take?

Most organizations reach certification in six to twelve months from a standing start. A small, single-site company with good documentation already in place can do it in three to six months. Larger or multi-site organizations, or anyone starting with no written policies, should plan for twelve to eighteen months. The audit itself is a small part of that: the bulk is writing the ISMS, implementing controls and gathering evidence.

How long does ISO 27001 certification last?

An ISO 27001 certificate is valid for three years. It is not a one-off: the certification body runs a surveillance audit in each of the two intervening years, and a full recertification audit before the three years are up. Miss a surveillance audit and the certificate can be suspended or withdrawn, so the work does not stop when the certificate arrives.

What is the gap between the stage 1 and stage 2 audit?

Usually two to eight weeks. The certification body sets it, and it exists so you can close anything the stage 1 review found before the stage 2 audit begins. If stage 1 raises significant gaps, the gap gets longer, because the auditor will not proceed until you have addressed them.

Can you get ISO 27001 certified in 30 days?

Not credibly. The standard requires evidence that your ISMS has been operating, including at least one internal audit and one management review, and an auditor will ask for records covering a meaningful period. Anyone promising certification in 30 days is either describing readiness rather than certification, or describing a certificate no serious customer will accept.

Does compliance software make ISO 27001 certification faster?

It shortens the parts you control, which is the documentation and evidence work, not the parts the certification body controls. It cannot shorten the audit schedule, the stage 1 to stage 2 gap, or the requirement to have run the ISMS for long enough to have records. Treat any claim to compress the audit itself with suspicion.

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $2,475 a year (12 months for the price of 11). All prices in USD.