A realistic ISO 27001 certification timeline, phase by phase, plus how long the certificate lasts once you have it and what actually causes the delays.
ISO 27001 certification takes six to twelve months for most organizations starting from scratch. A small single-site company that already has written policies and a tidy asset list can be certified in three to six months. A larger or multi-site organization, or one starting with nothing written down, should plan for twelve to eighteen. The certification audit itself takes days; everything before it is the reason the range is so wide.
The honest version of the answer is that you control most of the timeline and the certification body controls the rest. This page separates the two, because that is the distinction that tells you whether a published timeline is achievable for you or is someone else's best case.
Size matters less than how much is already written down. A thirty-person company with a documented starting point routinely beats a ten-person company with nothing. The ranges below assume a dedicated internal owner who can give the work real hours each week, not someone fitting it around a full-time role.
| Starting point | Typical time to certificate | What drives it |
|---|---|---|
| Small, single site, policies already written | 3 to 6 months | Mostly evidence gathering and the internal audit |
| Small to mid-size, starting from scratch | 6 to 12 months | Writing the ISMS from nothing is the long pole |
| Multi-site, or regulated, or complex scope | 12 to 18 months | Scope negotiation, more controls in play, more evidence |
| Any size, no internal owner assigned | Indefinite | The most common reason a programme stalls |
The ISO 27001 certification timeline has five phases. Only the last two involve the certification body, which is why the first three are where your schedule is actually won or lost.
| Phase | Typical duration | Who controls it |
|---|---|---|
| 1. Define scope and get management commitment | 1 to 3 weeks | You |
| 2. Risk assessment, Statement of Applicability, write the ISMS | 4 to 12 weeks | You |
| 3. Implement controls and gather evidence | 8 to 24 weeks | You |
| 4. Internal audit and management review | 2 to 4 weeks | You, but it is mandatory before stage 2 |
| 5. Stage 1 and stage 2 certification audit | 4 to 10 weeks including the gap | The certification body |
Two things in that table surprise people. The first is that phase 4 is not optional: ISO 27001 requires an internal audit and a management review before a certification body will proceed, and forgetting them is a common reason a stage 2 audit gets postponed. The second is that phase 5 is booked, not requested. Certification bodies have lead times, and in busy periods you may wait weeks for a slot. Book it while you are still in phase 3.
For what the auditor actually does in each of those two visits, see ISO 27001 stage 1 vs stage 2 audit.
An ISO 27001 certificate is valid for three years, and it is conditional for all three. The certification body runs a surveillance audit in each of the two intervening years, then a full recertification audit before the three years expire. Those surveillance audits are shorter than the original stage 2, but they are real: the auditor samples controls, checks that the internal audit and management review actually happened, and looks at how you handled any nonconformities.
This is the part most timeline articles skip, and it changes how you should choose your tooling. A spreadsheet that got you to a certificate leaves you re-assembling evidence from scratch a year later, for an audit you had twelve months to prepare for. The recurring cost of ISO 27001 is not the certificate, it is remembering what you did.
In practice, four things account for most overruns, and none of them is the standard being difficult.
No named owner. A programme shared between three people who all have other jobs moves at the speed of the least available one. One accountable owner with allocated hours is the single biggest predictor of hitting a date.
Scope decided late. Scope is phase 1 for a reason. Changing it in month four means revisiting the risk assessment and the Statement of Applicability, and that is weeks of rework.
Evidence gathered at the end. Evidence collected as you go is a filing task. Evidence reconstructed the week before stage 2 is an archaeology project, and it is where teams discover that a control they believed was operating has no record proving it.
Waiting on the certification body. Entirely outside your control and frequently underestimated. Approach two or three, get their lead times in writing, and book early.
CertAssist does not make an auditor move faster and does not shorten the stage 1 to stage 2 gap. What it addresses is phases 2 to 4, which is where your months go. Every Annex A control is laid out ready to work through with a draft justification and an evidence checklist, so phase 2 starts from a populated document rather than a blank one. Evidence attaches to the control it belongs to as you go, which removes the end-of-project reconstruction. The six registers, risk, suppliers, legal and regulatory, authorities, non-conformities and ISO 27001 maintenance, come pre-populated rather than as empty templates.
The reporting dashboard gives one readiness number, the trend over the last week and month, and a forecast completion date based on the pace you are actually working at rather than the pace you hoped for. That forecast is the useful part when someone asks for a date, because it is derived from your real progress and it moves when the pace does.
CertAssist is US$225 per month, or US$2,475 a year, and that covers every framework it supports rather than ISO 27001 alone. We publish that figure because most of this market does not, which makes the software line the hardest one to budget. For the full picture of what a first year costs, see how much ISO 27001 certification costs.
Speed is not always the thing to optimize. If a customer contract names a date, work backwards from it and book the certification body first. But if the driver is internal enthusiasm rather than an external deadline, a compressed timeline usually produces an ISMS nobody follows, which surfaces at the first surveillance audit rather than at stage 2.
There is also a floor. You cannot evidence an ISMS that has not been operating, and no tool changes that. If someone offers ISO 27001 certification in weeks, they are describing readiness or selling a certificate from a body your customers will not recognize. The point of the certificate is that a third party checked; shortcut the checking and you have bought a PDF.
Most organizations reach certification in six to twelve months from a standing start. A small, single-site company with good documentation already in place can do it in three to six months. Larger or multi-site organizations, or anyone starting with no written policies, should plan for twelve to eighteen months. The audit itself is a small part of that: the bulk is writing the ISMS, implementing controls and gathering evidence.
An ISO 27001 certificate is valid for three years. It is not a one-off: the certification body runs a surveillance audit in each of the two intervening years, and a full recertification audit before the three years are up. Miss a surveillance audit and the certificate can be suspended or withdrawn, so the work does not stop when the certificate arrives.
Usually two to eight weeks. The certification body sets it, and it exists so you can close anything the stage 1 review found before the stage 2 audit begins. If stage 1 raises significant gaps, the gap gets longer, because the auditor will not proceed until you have addressed them.
Not credibly. The standard requires evidence that your ISMS has been operating, including at least one internal audit and one management review, and an auditor will ask for records covering a meaningful period. Anyone promising certification in 30 days is either describing readiness rather than certification, or describing a certificate no serious customer will accept.
It shortens the parts you control, which is the documentation and evidence work, not the parts the certification body controls. It cannot shorten the audit schedule, the stage 1 to stage 2 gap, or the requirement to have run the ISMS for long enough to have records. Treat any claim to compress the audit itself with suspicion.
Flat $225 a month during the launch, normally $375, or $2,475 a year (12 months for the price of 11). All prices in USD.