Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 implementation timeline: phases and dependencies

Nine phases from scoping to certificate. The sequence and the dependencies are the useful part, because they tell you what you can run in parallel and what you cannot. And one phase does not compress at all, no matter what you spend: the ISMS has to actually operate before Stage 2 can test whether it works.

Updated July 2026

Where these durations come from

The phase durations on this page are our own estimate, and we label them as ours wherever they appear. No standard, accreditation body or certification body publishes an implementation duration, because it depends entirely on where you are starting from. Treat them as a shape to plan against, not as a fact to commit to a board.

The two audit phases carry no duration at all. Audit time is determined by your certification body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C. ISO sells that standard and we have not read those tables, so we do not publish audit days here or anywhere else on this site. Your body can tell you the days it determined and why. See how audit fees are set.

The nine phases and what each depends on

1. Scoping and management commitment

1-4 weeks

Depends on: Nothing. Start here.

Define what the certificate will actually cover and get leadership to own it. Scope is the largest lever you hold over audit time, and it is cheapest to move now. A scope settled here is a scope you are not renegotiating in month six.

2. Gap analysis

2-6 weeks

Depends on: A settled scope

Compare what you do against what the standard requires. The output is a remediation plan and a genuine go or no-go point. Running this against an unsettled scope produces a plan for the wrong organisation.

3. ISMS development

4-12 weeks

Depends on: Gap analysis output

Risk methodology, risk assessment, risk treatment, the policy set, and the Statement of Applicability justifying which Annex A controls apply. This is where the standard's actual requirements live.

4. Controls implementation

8-20 weeks

Depends on: An approved Statement of Applicability

The longest and most variable phase, and the one that crosses the most teams. If a control needs new tooling or a process that does not exist yet, this is where that lands. Coordination is usually the constraint, not the technical work.

5. The ISMS operates

At least one full cycle of the activities

Depends on: Controls being live

The phase most plans omit. Evidence of operation over time cannot be generated retrospectively, and this is what auditors test. It runs concurrently with everything after it, but it has to start.

6. Internal audit

2-4 weeks

Depends on: An operating ISMS with evidence

Required by the standard, and useful in its own right: it finds what Stage 2 would have found, at a point where finding it is cheap. An internal audit of a system that has not run yet has nothing to look at.

7. Management review

1-2 weeks

Depends on: Internal audit output

A required input to certification, not a formality to backfill. Auditors read the minutes and the decisions, and they can tell the difference between a review that happened and one that was written up.

8. Stage 1 audit

Determined by your certification body

Depends on: A documented, reviewable ISMS

Reviews whether the ISMS is designed and documented well enough to be audited: scope, risk assessment, Statement of Applicability, management review. Often runs partly or wholly remotely.

9. Stage 2 audit and certification

Determined by your certification body

Depends on: Stage 1 findings addressed

Tests whether the ISMS is implemented and effective, sampling evidence across the scope. Non-conformities must be closed before the certificate is issued.

Durations for phases 1 to 7 are our own estimate. Phases 8 and 9 carry no duration because audit time is determined by your certification body under ISO/IEC 27006-1:2024.

The constraint that does not compress

Stage 2 tests whether the ISMS is implemented and effective. Effectiveness is demonstrated with evidence of operation: access reviews that happened, risks that were assessed and treated, incidents that were handled, changes that went through the process, training that people actually did, a management review with real decisions in the minutes. None of that can be produced retrospectively, and an auditor sampling across your scope will notice if you try.

This is why the honest planning question is not how fast the project can go, but how early the ISMS can start running. Everything else on this page compresses under pressure or money. This accrues at one week per week, and it is the phase most plans quietly omit because it does not look like work. Start it early and the rest of the schedule has somewhere to be flexible.

What genuinely accelerates, and what delays

Accelerators

  • A narrow scope, settled and written down before anything else starts
  • One owner with the authority to ask other teams for evidence and be answered
  • The ISMS running early, so evidence accrues while you work on the rest
  • A platform absorbing the repetitive evidence collection
  • An existing framework already generating evidence and habits
  • Leadership that treats management review as a decision forum, not a formality
  • Talking to certification bodies early, because their calendar is not yours

Delays

  • No dedicated owner, so the project changes hands and restarts
  • Scope creep after the gap analysis, invalidating the plan and the quote together
  • Evidence held by teams who do not report to the project
  • Legacy systems with nothing to inventory them from
  • Discovering the supplier register is longer than anyone thought
  • Certification body scheduling, left until it is urgent
  • Running the project alongside something that wants the same people

A workable sequence

StageActivitiesMilestone
OpenScope defined and written down, management commitment secured, owner appointed, certification body conversations startedScope signed off
AssessGap analysis, remediation plan, go or no-go decision, platform or consultant decision if eitherGap report and a real decision
BuildRisk methodology and assessment, risk treatment, policy set, Statement of ApplicabilityStatement of Applicability approved
ImplementControl rollout across teams, training, supplier reviews, asset and supplier registersControls live and the ISMS starts running
OperateThe ISMS runs. Evidence accrues. This overlaps everything below it and cannot start later than thisEvidence of operation exists
CheckInternal audit, corrective actions, management review with decisions recordedInternal audit complete
CertifyStage 1, address findings, Stage 2, close non-conformitiesCertificate issued

Our own sequencing model, not a published methodology. The dependencies are real; the ordering of work within each stage is a choice.

The timeline does not end at the certificate

Certification runs on a three-year cycle: the two-stage initial audit, surveillance audits in the intervening years, and a recertification audit before the certificate expires. The ISMS keeps operating throughout, which means the evidence habits you build during implementation are the ones you live with. A programme that sprints to a certificate and stops has its next problem scheduled for it already, at the first surveillance visit. See the three-year cycle.

Frequently asked questions

How long does ISO 27001 take?
Our own estimate for the implementation work is that the phases before the audits total roughly 4 to 11 months for most organisations, with controls implementation the longest and most variable. That is our read of the work rather than a published figure: no standard, accreditation body or certification body publishes an implementation duration, because it depends on where you are starting from. The audits sit on top of that, and their duration is determined by your certification body under ISO/IEC 27006-1:2024. Add certification body scheduling, which is real calendar time and worth starting early.
How long is the Stage 2 audit?
Your certification body determines it, and we do not publish a figure. Audit time is set under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C. ISO sells that standard and we have not read the tables, so we do not reproduce them and we will not reconstruct them from a document written for a different certification scheme. Your body holds the standard, applies Annex C to your scope, and can tell you the audit days it determined and how they split across the stages. That is a fair question to ask.
Can you fast-track ISO 27001 certification?
Parts of it, and not the part that matters most. A narrow scope, an experienced lead, a platform for evidence automation, a genuinely dedicated owner and existing controls all compress the implementation phases. What none of them compresses is the ISMS having to actually operate before Stage 2 can test whether it is effective. Auditors ask for evidence of operation over time, and that evidence accrues at one week per week. Any plan that treats this phase as optional is a plan to fail Stage 2.
What delays ISO 27001 the most?
In our experience the recurring causes are: no genuinely dedicated owner, so the project changes hands and restarts; scope creep after the gap analysis, which invalidates the plan and the quote together; supplier and evidence requests waiting on teams who do not report to the project; legacy systems with no asset tracking to inventory; and certification body scheduling, which is nobody's fault and entirely predictable. The last one is the easiest to fix and the most often left late: start the certification body conversation early, because their calendar is not yours.
When should we contact a certification body?
Earlier than most people do. Booking an audit is calendar time you cannot compress by working harder, and the conversation is useful long before you need the audit: it tells you how the body determines audit time for your scope, what it expects to see at Stage 1, and whether its accreditation actually covers ISO/IEC 27001. Confirm that on the accreditation body's own public register rather than the certification body's brochure. Accreditation for ISO 9001 does not imply accreditation for ISO/IEC 27001.
Does the timeline differ by company size?
Yes, but not in a way anyone can publish a table for. Headcount matters less than how distributed the evidence is and how contested the scope is. A 200-person company with one product and a settled scope can move faster than a 40-person company with three environments, an acquisition and no agreement about what is in scope. Where size does bite is coordination: the more teams that hold evidence, the more of your timeline is other people's calendars.

Updated July 2026