ISO 27001

ISO 27001 Certification Timeline: What to Expect Week by Week

A realistic week-by-week breakdown of the ISO 27001 certification process for small-to-mid businesses — from kickoff to certificate, and what actually causes projects to run long.

Published 21 September 2026 · By Prashant Sharma, Founder of ISO Audit Align

“How long will this take?” is usually the second question after cost, and the honest answer is: it depends more on your team’s responsiveness than on the standard itself. Here’s a realistic week-by-week breakdown for a small-to-mid organisation with a reasonably engaged project sponsor.

The short answer

Most small-to-mid businesses move from kickoff to certificate in 8 to 16 weeks. Larger or more complex environments (multiple sites, legacy infrastructure, regulated industries) can run longer. The certification audit itself is only a few days of that — almost all the timeline is the implementation work leading up to it.

Week by week

Weeks 1–2: Discovery & scoping Defining exactly what’s being certified — which systems, sites, teams, and services sit inside the ISMS boundary. This decision alone can swing your timeline significantly: a tightly scoped ISMS (e.g. “our SaaS platform and the team that operates it”) moves faster than “the entire company, every department, every legacy system.”

Weeks 2–4: Gap analysis & roadmap A clause-by-clause and Annex A control-by-control review of what you already have versus what the standard requires. This produces the actual project plan — not a generic checklist, but a prioritised list of what needs to be built, in what order, and who owns it.

Weeks 3–8: Framework implementation The bulk of the work: policies, procedures, the risk register, and the Statement of Applicability get built and reviewed. This is also where timelines most commonly slip — not because the documents are hard to write, but because review cycles stall. A policy sitting in someone’s inbox for two weeks adds two weeks to your certification date, full stop.

Weeks 6–10: Evidence gathering (runs in parallel) Alongside document creation, you’re collecting proof the controls actually exist — access review logs, onboarding/offboarding records, backup test results, incident response drills. Businesses with reasonably mature IT practices already have much of this; businesses starting from scratch need real lead time here.

Weeks 9–12: Internal audit & review A full internal audit that simulates the real Stage 2 certification audit — the goal is finding and closing non-conformances before they count against you with the actual certification body. This step matters more than most people expect: skipping or rushing it is the single most common reason businesses fail or delay their Stage 2 audit.

Weeks 10–14: Certification audit (Stage 1 + Stage 2) Stage 1 is a readiness review — the certification body checks your documentation is complete enough to proceed. Stage 2 is the real audit: auditors test whether your controls actually operate as documented. Assuming no major non-conformances, the certificate is issued shortly after Stage 2.

What actually blows out the timeline

None of these are about the standard being hard. They’re all about process:

  • Slow document review cycles. The single biggest lever in either direction. Treat draft policy reviews as a same-week priority, not a “when I get to it” task.
  • Certification body scheduling. Popular certification bodies book audit slots weeks or months out — get your Stage 1/Stage 2 dates locked in early, not once you think you’re ready.
  • Scope creep mid-project. Deciding halfway through to add another site or system to the ISMS boundary resets a meaningful chunk of the gap analysis and evidence work.
  • Evidence gaps discovered late. Finding out during the internal audit that you don’t actually have 90 days of access review logs means waiting to generate that evidence — this is why evidence gathering needs to start early, not right before the audit.
  • Key person unavailability. If your IT manager or compliance owner is on leave for three weeks during the evidence-gathering phase, the project pauses with them.

Why hands-on project management changes this

The gap between an 8-week certification and a 20-week certification is rarely the size of the business — it’s whether someone is actively driving the project week to week. Weekly tracking meetings, a clear owner for every outstanding item, and proactively chasing (rather than waiting to be chased) routinely take months off a drifting project.

Budgeting your own timeline

If you want a realistic date rather than a generic range, the inputs that actually matter are: your ISMS scope, how much documentation and evidence already exists, and how fast your team can turn around reviews. Book a free consultation and we’ll map an actual week-by-week plan against your specific situation, not a generic template.

Ready to get certified?

45-minute no-obligation consultation. Honest assessment. Fixed-price proposal.

Book Free Consultation
Chat with us