ISO 27001 implementation timeline: phases and dependencies
Nine phases from scoping to certificate. The sequence and the dependencies are the useful part, because they tell you what you can run in parallel and what you cannot. And one phase does not compress at all, no matter what you spend: the ISMS has to actually operate before Stage 2 can test whether it works.
Updated July 2026
Where these durations come from
The phase durations on this page are our own estimate, and we label them as ours wherever they appear. No standard, accreditation body or certification body publishes an implementation duration, because it depends entirely on where you are starting from. Treat them as a shape to plan against, not as a fact to commit to a board.
The two audit phases carry no duration at all. Audit time is determined by your certification body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C. ISO sells that standard and we have not read those tables, so we do not publish audit days here or anywhere else on this site. Your body can tell you the days it determined and why. See how audit fees are set.
The nine phases and what each depends on
1. Scoping and management commitment
1-4 weeksDepends on: Nothing. Start here.
Define what the certificate will actually cover and get leadership to own it. Scope is the largest lever you hold over audit time, and it is cheapest to move now. A scope settled here is a scope you are not renegotiating in month six.
2. Gap analysis
2-6 weeksDepends on: A settled scope
Compare what you do against what the standard requires. The output is a remediation plan and a genuine go or no-go point. Running this against an unsettled scope produces a plan for the wrong organisation.
3. ISMS development
4-12 weeksDepends on: Gap analysis output
Risk methodology, risk assessment, risk treatment, the policy set, and the Statement of Applicability justifying which Annex A controls apply. This is where the standard's actual requirements live.
4. Controls implementation
8-20 weeksDepends on: An approved Statement of Applicability
The longest and most variable phase, and the one that crosses the most teams. If a control needs new tooling or a process that does not exist yet, this is where that lands. Coordination is usually the constraint, not the technical work.
5. The ISMS operates
At least one full cycle of the activitiesDepends on: Controls being live
The phase most plans omit. Evidence of operation over time cannot be generated retrospectively, and this is what auditors test. It runs concurrently with everything after it, but it has to start.
6. Internal audit
2-4 weeksDepends on: An operating ISMS with evidence
Required by the standard, and useful in its own right: it finds what Stage 2 would have found, at a point where finding it is cheap. An internal audit of a system that has not run yet has nothing to look at.
7. Management review
1-2 weeksDepends on: Internal audit output
A required input to certification, not a formality to backfill. Auditors read the minutes and the decisions, and they can tell the difference between a review that happened and one that was written up.
8. Stage 1 audit
Determined by your certification bodyDepends on: A documented, reviewable ISMS
Reviews whether the ISMS is designed and documented well enough to be audited: scope, risk assessment, Statement of Applicability, management review. Often runs partly or wholly remotely.
9. Stage 2 audit and certification
Determined by your certification bodyDepends on: Stage 1 findings addressed
Tests whether the ISMS is implemented and effective, sampling evidence across the scope. Non-conformities must be closed before the certificate is issued.
Durations for phases 1 to 7 are our own estimate. Phases 8 and 9 carry no duration because audit time is determined by your certification body under ISO/IEC 27006-1:2024.
The constraint that does not compress
Stage 2 tests whether the ISMS is implemented and effective. Effectiveness is demonstrated with evidence of operation: access reviews that happened, risks that were assessed and treated, incidents that were handled, changes that went through the process, training that people actually did, a management review with real decisions in the minutes. None of that can be produced retrospectively, and an auditor sampling across your scope will notice if you try.
This is why the honest planning question is not how fast the project can go, but how early the ISMS can start running. Everything else on this page compresses under pressure or money. This accrues at one week per week, and it is the phase most plans quietly omit because it does not look like work. Start it early and the rest of the schedule has somewhere to be flexible.
What genuinely accelerates, and what delays
Accelerators
- A narrow scope, settled and written down before anything else starts
- One owner with the authority to ask other teams for evidence and be answered
- The ISMS running early, so evidence accrues while you work on the rest
- A platform absorbing the repetitive evidence collection
- An existing framework already generating evidence and habits
- Leadership that treats management review as a decision forum, not a formality
- Talking to certification bodies early, because their calendar is not yours
Delays
- No dedicated owner, so the project changes hands and restarts
- Scope creep after the gap analysis, invalidating the plan and the quote together
- Evidence held by teams who do not report to the project
- Legacy systems with nothing to inventory them from
- Discovering the supplier register is longer than anyone thought
- Certification body scheduling, left until it is urgent
- Running the project alongside something that wants the same people
A workable sequence
| Stage | Activities | Milestone |
|---|---|---|
| Open | Scope defined and written down, management commitment secured, owner appointed, certification body conversations started | Scope signed off |
| Assess | Gap analysis, remediation plan, go or no-go decision, platform or consultant decision if either | Gap report and a real decision |
| Build | Risk methodology and assessment, risk treatment, policy set, Statement of Applicability | Statement of Applicability approved |
| Implement | Control rollout across teams, training, supplier reviews, asset and supplier registers | Controls live and the ISMS starts running |
| Operate | The ISMS runs. Evidence accrues. This overlaps everything below it and cannot start later than this | Evidence of operation exists |
| Check | Internal audit, corrective actions, management review with decisions recorded | Internal audit complete |
| Certify | Stage 1, address findings, Stage 2, close non-conformities | Certificate issued |
Our own sequencing model, not a published methodology. The dependencies are real; the ordering of work within each stage is a choice.
The timeline does not end at the certificate
Certification runs on a three-year cycle: the two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. The ISMS keeps operating throughout, which means the evidence habits you build during implementation are the ones you live with. A programme that sprints to a certificate and stops has its next problem scheduled for it already, at the first surveillance visit. See the three-year cycle.