Back to Blog
Compliance6 min read

What ISO 27001 Certification Actually Takes: Timeline and Costs

Most organizations underestimate how long ISO 27001 takes by 6-12 months. Here's a realistic breakdown from scoping through Stage 2 audit.

Every organization that starts ISO 27001 expects it to take less time than it does. Vendors selling readiness software quote 3-6 months. Consultants on the optimistic end say 6-9 months. The realistic answer for an organization building its ISMS from scratch is 9-18 months. Here's why.

What You're Actually Building

ISO 27001 certification isn't a documentation project that culminates in an audit. It requires demonstrating that your ISMS is operational — that the controls are implemented, that people are following them, and that you have evidence of both.

Stage 2 auditors don't just review your policy library. They interview your staff, pull logs, test access controls, and look for evidence that your documented procedures reflect what actually happens. A policy written three weeks before the audit is obvious. The same policy with training records, a recent internal audit against it, and corrective actions from that audit looks very different.

This is why timeline matters: you need operating history, not just documentation.

Realistic Phase Breakdown

Phase 1: Scoping and Context (3-6 weeks)

Define what your ISMS covers — which systems, processes, locations, and data types. This sounds simple; it isn't. Scope too broadly and you've added months of remediation work to cover systems that didn't need to be included. Scope too narrowly and auditors will question whether your certification is meaningful.

Output: Scope statement, organizational context document, list of interested parties and their requirements.

Phase 2: Risk Assessment and Treatment (6-10 weeks)

Build your asset inventory, identify threats and vulnerabilities against those assets, assess likelihood and impact, and develop your risk treatment plan. This is the core of ISO 27001 — it's how you justify which controls you implement and why.

Output: Risk register, risk treatment plan, Statement of Applicability (SoA) — the document that maps every Annex A control to your environment and explains inclusion or exclusion.

This phase is where most organizations slow down. The risk assessment has to be methodical enough to satisfy auditors and specific enough to actually guide decisions. Copying a generic template doesn't work — auditors ask questions that expose whether you actually analyzed your environment or imported someone else's.

Phase 3: Policy and Procedure Development (6-10 weeks, often parallel with Phase 2)

Write or adapt all required policies: information security policy, access control policy, incident response procedure, vulnerability management policy, acceptable use policy, supplier security policy, and others required by Annex A controls you've included in your SoA.

Policies need to reflect how your organization actually operates. A policy written for a 1,000-person enterprise that applies to a 12-person company creates compliance debt — you either operate differently than the policy says, or you maintain overhead that doesn't serve you.

Phase 4: Implementation (8-16 weeks)

Roll out the technical and procedural controls. MFA everywhere, access reviews, vulnerability scanning cadence, patch management process, vendor assessments, incident response testing, user security awareness training. Some of this is new tooling; most of it is formalizing and documenting what you're already doing (or should be doing).

This phase is where organizations encounter the most friction — not because the controls are hard, but because implementation requires coordination across IT, HR, legal, and operations. Plan for it.

Phase 5: Internal Audit (3-5 weeks)

ISO 27001 requires internal audits. This is a formal review of your ISMS against the standard, conducted by someone who wasn't responsible for implementing the controls. It produces findings that feed into corrective actions before the external audit.

Don't skip this or do it as a checkbox. Auditors ask about your internal audit results and what you did about them. An internal audit that found nothing is suspicious. An internal audit that found three issues and produced documented corrective actions demonstrates a functioning management system.

Phase 6: Management Review (1-2 weeks)

A formal meeting (documented with minutes) where leadership reviews the ISMS's performance: results of the internal audit, risk treatment status, security incidents, nonconformities, improvement opportunities. This is required by the standard — clause 9.3.

Phase 7: Stage 1 Audit (2-5 days, usually remote)

The certification body reviews your documentation: ISMS scope, risk assessment, SoA, policies, internal audit results, management review minutes. They're assessing whether you're ready for Stage 2.

Stage 1 typically produces findings — minor nonconformities or observations — that you need to address before Stage 2. Budget 4-8 weeks between Stage 1 and Stage 2.

Phase 8: Remediation (4-8 weeks)

Address Stage 1 findings. Document what you changed and why. Send evidence to the CB before Stage 2.

Phase 9: Stage 2 Audit (2-5 days, usually on-site)

The implementation audit. Auditors interview staff, sample evidence, test controls, and verify that what you documented is what you actually do. If they find major nonconformities, you don't get certified until they're resolved (and re-audited). Minor nonconformities result in conditions on the certificate — you have 90 days to close them.

After Certification: Ongoing Requirements

Certification isn't a finish line. ISO 27001 certificates are valid for three years with:

  • Annual surveillance audits (years 1 and 2): a subset of the Stage 2 scope, typically 1-3 days. Auditors look for evidence the ISMS is still operating and improving.
  • Recertification audit (year 3): similar to the original Stage 2.

Budget for surveillance audits as an ongoing line item. They're not free, and skipping them revokes your certificate.

Cost Ranges

ItemRange
External consultant / readiness support$15,000–$80,000
Certification body Stage 1 + Stage 2$5,000–$20,000
Annual surveillance audits (per year)$3,000–$8,000
Year 3 recertification$5,000–$15,000
Internal staff time (often underestimated)Significant

These ranges are wide because scope, organization size, and existing security posture vary enormously. An 8-person SaaS company with good security hygiene and a narrow scope costs much less than a 100-person company with on-prem infrastructure across multiple locations.

The Decisions That Affect Timeline the Most

Scope definition: Narrow scope = faster certification, less meaningful externally. Broad scope = longer certification, more credible to enterprise buyers. Most organizations start narrow and expand.

Consultant vs. DIY: A consultant who has done dozens of ISO 27001 implementations will catch gaps you won't. The question is whether you have internal bandwidth to do the work vs. pay someone to guide it.

Certification body selection: CBs vary in price, availability, and reputation. Larger CBs (BSI, Bureau Veritas, DNV) are more recognizable. Smaller accredited CBs can be more accessible for initial certification. Pick one accredited by UKAS, ANAB, or equivalent national body — certificates from non-accredited CBs don't count.


SOURCES

  • ISO/IEC 27001:2022, Clause 9 (Performance Evaluation) and Clause 10 (Improvement): iso.org/standard/27001
  • International Accreditation Forum (IAF) — list of accredited certification bodies: iaf.nu
  • UKAS (UK Accreditation Service) — accredited ISO 27001 certification bodies: ukas.com
  • ANAB (ANSI National Accreditation Board) — US accreditation body: anab.ansi.org

Ready to start your ISO 27001 journey? Schedule a consultation to talk through scope, timeline, and what your specific environment requires.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch