ISO 27001 Implementation Timeline - Phase by Phase
Nine phases from initial scoping to certificate in hand. Here is how long each phase takes, what it costs, and realistic timelines by company size.
Updated May 2026
Timeline by Company Size
Micro (1-10)
Fastest3-6 monthsSmallest scope, fewest controls. Main bottleneck: finding time alongside day-to-day work. A 0.5 FTE dedicated resource achieves this comfortably.
Total cost: $10K-$25K. See cost by size for full breakdown.
Small (11-50)
Most Common6-9 monthsThe sweet spot for SaaS and service businesses. With a consultant and 0.5-1 FTE internal resource, 6 months is realistic. Without a consultant, add 2-4 months.
Total cost: $15K-$50K. See cost by size for full breakdown.
Medium (51-250)
Standard9-14 monthsMore departments, more systems, more evidence. A full-time ISMS project manager is strongly recommended. Budget for a consultant for gap analysis and policy development.
Total cost: $50K-$150K. See cost by size for full breakdown.
Large (251-1,000)
Complex12-18 monthsMultiple teams, legacy systems, and procurement dependencies slow implementation. Typically requires a dedicated programme manager plus external consultancy.
Total cost: $150K-$350K. See cost by size for full breakdown.
Enterprise (1,000+)
Programme14-24 monthsOften run as a formal programme with a steering committee. May certify a subset first then expand scope. Multi-site global audits span several weeks.
Total cost: $250K-$500K+. See cost by size for full breakdown.
Phase-by-Phase Breakdown
1. Scoping and Planning
2. Gap Analysis
3. ISMS Development
4. Controls Implementation
5. Internal Audit
6. Management Review
7. Stage 1 Audit
8. Stage 2 Audit
9. Certificate Awarded
Phase 4 (Controls Implementation) is the longest and most variable phase. See implementation cost breakdown for detailed per-phase costs.
Fast-Track Certification (4-6 Months)
Fast-track is possible under these conditions:
Requirements
- Narrow scope (one product, one location)
- Experienced consultant or internal ISMS lead
- Compliance platform for evidence automation
- Dedicated resource (minimum 0.5 FTE)
- Existing security controls and policies
- CEO/board actively sponsoring the project
Trade-offs
- 20-30% higher cost (compressed consultant engagement)
- Higher internal resource demand per week
- Less time for organisational culture change
- Risk of minor non-conformances (fixable post-audit)
- Certification body availability may constrain dates
What Accelerates vs Delays Certification
Accelerators
- Dedicated internal ISMS project owner (0.5-1 FTE)
- Experienced consultant from day one
- Compliance platform for automated evidence
- Existing SOC 2, Cyber Essentials, or ISO 9001
- Narrow, well-defined scope
- Board and CEO actively championing the project
Common Delays
- No dedicated resource - project owner changes mid-way
- Scope creep after gap analysis
- Supplier security review backlog
- Legacy systems with no patch management
- Internal resistance to security policies
- CB availability - popular bodies book months ahead
- Non-conformances in Stage 1 requiring rework
Month-by-Month Checklist (Small Organisation, 9-Month Plan)
| Month | Activities | Key Milestone |
|---|---|---|
| 1 | Scope definition, management commitment, appoint ISMS owner, select consultant | Project kickoff |
| 2 | Gap analysis, remediation plan, budget validation, platform selection | Gap report delivered |
| 3-4 | ISMS documentation: policies, risk methodology, risk register, SoA | SoA approved |
| 5-6 | Controls implementation: technical controls, training, supplier reviews | All critical controls live |
| 7 | Internal audit, management review, corrective actions | Internal audit complete |
| 8 | Stage 1 audit, address findings, prepare for Stage 2 | Stage 1 passed |
| 9 | Stage 2 audit, resolve non-conformances, certificate issued | Certificate awarded |