Last updated: 29 September 2026
Quick answer: An ISO 27001 certification timeline has five phases: scoping and gap analysis, building the ISMS, operating it long enough to produce records, an internal audit and management review, then the certification body’s Stage 1 and Stage 2 audits. How long it takes depends mainly on your scope, existing controls and resourcing, not on the standard itself.
“How long will ISO 27001 take?” is usually the first question a CISO hears from the board. The honest answer is that it depends, but that is not a plan. What you can give the board is a clear sequence of phases, the dependencies between them and the decisions that speed things up or slow them down.
This guide sets out a realistic ISO 27001 certification timeline, explains what happens in each phase and in the audits, and includes an illustrative plan you can adapt.
What does the ISO 27001 certification timeline look like?
The timeline runs from deciding scope to receiving a certificate, then continues through a three-year cycle of surveillance and recertification. Certification is granted against ISO/IEC 27001:2022, published on 25 October 2022 and amended in 2024 to add climate action wording. ISO reports that more than 70,000 certificates were recorded across 150 countries in its 2022 survey, so the process is well established.
The phases below apply whether you are in the EU, the UK or the US, because the standard and the audit rules are international.
- Scope and gap analysis. Define the ISMS scope and compare current practice with the standard.
- ISMS design. Build the risk method, Statement of Applicability, policies and procedures.
- Implementation and operation. Put controls in place and run the ISMS so it produces evidence.
- Internal audit and management review. Check the ISMS yourself and have top management review it.
- Certification audits. Stage 1 (documentation and readiness) and Stage 2 (effectiveness).
Is there a deadline for the 2022 version?
Yes, and it has now passed. Under the International Accreditation Forum’s transition rules in IAF MD 26, the transition period ended on 31 October 2025, and certificates based on ISO/IEC 27001:2013 expire or are withdrawn at the end of it. Any new certification project in 2026 is therefore against the 2022 version, with its 93 Annex A controls grouped into four themes. ISO lists the 2022 edition as current and under its routine systematic review, so no newer version applies yet.
Common mistake: reusing a pre-2022 control set or template pack. Check that your Statement of Applicability uses the 2022 Annex A structure before your Stage 1 audit; our ISO 27001 Statement of Applicability guide explains how.
What happens in each phase?
Phase 1: scope and gap analysis
Agree what the ISMS covers: business units, locations, systems and services. A tight, clearly bounded scope is the single biggest factor in keeping the timeline short. Then run a structured gap assessment against clauses 4 to 10 and Annex A.
Phase 2: ISMS design
Write the core documented information: ISMS scope, information security policy, risk assessment and treatment methodology, risk treatment plan and Statement of Applicability. A central policy management process helps you version, approve and publish documents consistently.
Phase 3: implementation and operation
Implement the controls selected in your risk treatment plan and start generating records: access reviews, supplier assessments, training completions, incident logs and change tickets. Auditors need evidence that controls operate, so this phase cannot be compressed to a few days before the audit.
Phase 4: internal audit and management review
Clause 9.2 requires an internal audit programme, and clause 9.3 requires management review. Certification bodies generally expect at least one full cycle of both before Stage 2. Raise and track corrective actions for any nonconformities found.
Phase 5: certification audits
Your certification body runs the external audit in two stages, following ISO/IEC 17021-1, the requirements standard for bodies that certify management systems.
What happens in Stage 1 and Stage 2 audits?
Stage 1 checks whether you are ready; Stage 2 checks whether the ISMS actually works.
| Audit | Focus | What auditors typically review | Typical outcome |
|---|---|---|---|
| Stage 1 | Design and readiness | Scope, policies, risk method, Statement of Applicability, internal audit and management review records | Report of areas of concern to fix before Stage 2 |
| Stage 2 | Implementation and effectiveness | Interviews, sampling of records, control testing across the scope | Recommendation for certification, subject to closing any nonconformities |
| Surveillance | Ongoing conformity | Selected clauses and controls, changes, corrective actions | Certificate maintained |
| Recertification | Full reassessment | Whole ISMS before the three-year certificate expires | New three-year certificate |
In practice: leave a gap between Stage 1 and Stage 2 so you can close any concerns raised. Booking them back to back only works if you are confident your documentation is complete.
Planning and tracking every phase in one place keeps the project on schedule. You can start your 14-day free trial of Enactia’s AI-powered GRC platform to manage your ISMS, risks and evidence together.
How long does ISO 27001 certification take in practice?
It depends on your starting point. There is no official duration, and published estimates vary widely, so treat any figure as a planning assumption rather than a benchmark.
Illustrative plan for a mid-sized organisation
The worked example below assumes a single-site organisation with a clear scope, an existing set of basic security controls and a part-time project lead. It is an illustration for planning, not a prediction.
| Phase | Illustrative duration | Key dependency |
|---|---|---|
| Scope and gap analysis | 2 to 4 weeks | Agreement on scope from management |
| ISMS design | 4 to 8 weeks | Risk method agreed; risk owners available |
| Implementation and operation | 8 to 16 weeks | Budget and IT capacity for control changes |
| Internal audit and management review | 2 to 4 weeks | Independent internal auditor available |
| Stage 1 to Stage 2 | 4 to 8 weeks | Certification body availability; closing Stage 1 concerns |
Phases overlap in real projects, so the total is usually shorter than the sum of the rows. Larger scopes, multiple sites or weak baseline controls extend it; reusing controls from SOC 2, NIST CSF or NIS2 programmes shortens it.
What speeds up or slows down certification?
The biggest levers are scope, ownership and evidence.
- Speeds up: a narrow initial scope, a named executive sponsor, early booking of the certification body, reuse of existing controls and a single evidence repository.
- Slows down: unclear scope boundaries, missing risk owners, controls documented but not operated, supplier information that is hard to collect, and last-minute internal audits.
A connected risk management process, where each risk links to its controls and evidence, removes much of the late scramble. If you are also working on NIS2 or DORA, our article on the DORA, NIS2 and EU AI Act overlap shows how to reuse ISMS work across regulations.
Does the process differ in the EU, UK and US?
The standard and audit stages are the same everywhere. The main difference is which accreditation body oversees your certification body.
| Region | Accreditation | Regulatory relevance of ISO 27001 |
|---|---|---|
| EU | National accreditation bodies in each member state | Strong evidence for NIS2 risk-management measures and DORA ICT risk work |
| UK | UKAS, the UK’s national accreditation body | Supports UK GDPR security obligations and public sector supplier requirements |
| US | ANAB and other IAF-member accreditation bodies | Often requested alongside SOC 2 by international customers |
Common mistake: choosing a certification body that is not accredited by an IAF member. Unaccredited certificates may not be accepted by customers or regulators, so check before you sign.
What happens after you are certified?
Certification starts a three-year cycle. Surveillance audits take place during the cycle, typically annually, and a recertification audit is required before the certificate expires. Keep the ISMS running between audits: risk reviews, internal audits, management reviews and corrective actions. Our ISO 27001 framework page explains how continuous control monitoring supports this.
Key takeaways
- The ISO 27001 certification timeline has five phases, ending with Stage 1 and Stage 2 audits.
- The transition to ISO/IEC 27001:2022 ended on 31 October 2025, so new projects use the 2022 version.
- Complete at least one internal audit and management review before Stage 2.
- Scope, ownership and evidence quality drive duration more than company size alone.
- Certification begins a three-year cycle of surveillance and recertification.
Frequently asked questions
How long does ISO 27001 certification take?
There is no fixed duration. It depends on your scope, existing controls, resources and certification body availability. Many organisations plan in months rather than weeks, because controls must operate long enough to produce evidence. Use a phased plan with clear dependencies and review it after the gap analysis.
What is the difference between Stage 1 and Stage 2 audits?
Stage 1 reviews your ISMS design and readiness, including scope, policies, risk methodology, Statement of Applicability and internal audit records. Stage 2 tests whether the ISMS is implemented and effective through interviews, record sampling and control checks. Certification is recommended only after Stage 2.
Can we still certify to ISO 27001:2013?
No. Under IAF MD 26, the transition period ended on 31 October 2025 and certificates based on the 2013 version expired or were withdrawn at that point. New certifications and recertifications are to ISO/IEC 27001:2022, including its updated Annex A control set.
Do we need an internal audit before certification?
Yes. Clause 9.2 requires an internal audit programme and clause 9.3 requires management review. Certification bodies generally expect evidence of both before Stage 2. The internal auditor should be objective and impartial, so either use someone independent of the areas audited or an external provider.
How long is an ISO 27001 certificate valid?
Certificates are normally issued for three years. During that period the certification body carries out surveillance audits, typically annually, to confirm the ISMS still conforms. Before expiry, a recertification audit reviews the whole ISMS so a new three-year certificate can be issued.
Conclusion: plan the phases, not just the date
A credible ISO 27001 certification timeline is built from phases and dependencies, not a target date alone. Fix your scope early, run the ISMS long enough to generate evidence, complete internal audit and management review, and give yourself room between Stage 1 and Stage 2. That gives your board a date it can rely on.
To see how one platform can support your ISO 27001 project from gap analysis to surveillance, contact us or book a demo or start your 14-day free trial.
