Choosing
How long ISO 27001 really takes, and which parts cannot be compressed
Every plan for this is built forwards from today, and every plan that works is built backwards from one question: what has to have happened before an auditor can test it? Documentation is fast. Evidence that something ran is not, and no amount of budget shortens it.
Facts checked — 2026-09-11
What you can compress, and what you cannot
| Element | Compressible? | Why |
|---|---|---|
| Documentation | Yes, substantially. | Policies, procedures, scope and the risk method are writing tasks. A focused team produces them in weeks. |
| Periodic controls | No. | A quarterly access review cannot run twice in a fortnight. The control has to have operated, with records. |
| Internal audit | Partly. | It can be scheduled early, but it has to find things and those findings need somewhere to go. |
| Management review | Partly. | It needs the internal audit results to consider, so it sits behind that in the sequence. |
| Audit scheduling | No. | Certification body lead times are theirs, not yours, and they lengthen towards year end. |
Durations here are what we typically see rather than anything the standard specifies — ISO/IEC 27001 sets no timeline. Treat them as planning anchors, not promises.
The realistic answer
For an organisation under roughly 200 people with a contained scope and someone genuinely accountable for the programme, six to nine months from kick-off to Stage 2 is a reasonable expectation. Larger or more distributed scopes, regulated environments, or organisations where nobody owns the work run longer — often considerably.
That range is experience rather than a rule; the standard specifies no timeline at all. What it reflects is a fairly consistent shape: a short, intense documentation phase, then a longer period whose length is set by how often your controls run, then an audit sequence whose dates depend on a third party.
The useful thing is not the number. It is knowing which of those three you can spend money to shorten, and which you cannot.
Why documentation is not the constraint
This surprises people, because documentation is what the programme looks like from outside and it is where most of the anxiety sits. Writing a scope statement, a risk method, a Statement of Applicability and a set of policies is real work, but it is work with no waiting in it. A focused team, or a team with help, can move through it quickly.
The trap is that finishing the documents feels like finishing the programme, and it is roughly the halfway point. What follows is the part with elapsed time in it, and organisations that treat the document set as the deliverable tend to discover the remaining months late, having already told someone a date.
A useful reframe: the documents describe a system. The audit examines the system. Between describing and examining, the system has to run.
The part nobody can shorten
Controls with a periodic cadence have to have operated, visibly, with records, before an auditor can sample them. Access reviews, risk reassessment, supplier reviews, awareness training, backup restoration tests, vulnerability scanning cycles — if your policy says quarterly, then the evidence arrives quarterly, and no budget changes that.
This is the single question that sets your date: what has to run before the audit can test it, and when does it next run? Answer that and the timeline mostly draws itself backwards from the audit.
It also has a design consequence worth taking early. If a control is genuinely important, monthly cadence produces evidence three times faster than quarterly — and organisations sometimes set a quarterly cadence on paper because it sounds achievable, then wait a quarter for a record they could have had in weeks. Choose cadences you can actually sustain, but be aware you are also choosing your evidence rate.
The two governance activities that gate everything
Internal audit and management review sit in the critical path and are routinely scheduled last, which is exactly backwards.
They gate the audit because evaluating whether they are planned and performed is one of the stated objectives of the first certification visit. They also gate each other: a management review needs internal audit results to consider, so the two are a sequence rather than a pair, and a compressed version where both happen in the same week produces records that are technically present and visibly performative.
The sequence that works is: internal audit early enough that its findings can be acted on, corrective actions with dates, then a management review that considers the audit, the findings and what was done about them. That is three or four weeks of elapsed time minimum, and it is why "we will do those at the end" quietly adds a month.
What actually makes programmes late
In practice, rarely the standard. The recurring causes are ordinary: no single accountable owner, so decisions wait; a scope argued about for six weeks because it was treated as administrative rather than commercial; evidence collected manually by someone with another full-time job; and certification body lead times discovered at the point of booking rather than at the start.
That last one is worth acting on immediately. Talk to certification bodies early — not to commit, but to understand their availability, because their calendar is a hard input to yours and it does not flex for you. Lead times lengthen towards the end of the calendar year.
The other reliable accelerant is deciding, at the start, who signs off what. Most delay in these programmes is not work outstanding; it is work finished and waiting for a decision.
Common questions
How long does ISO 27001 certification take?
For an organisation under roughly 200 people with a contained scope and a clear owner, six to nine months from kick-off to the Stage 2 audit is realistic. Larger or distributed scopes run longer. The standard itself specifies no timeline.
Can we get certified faster by spending more?
Partly. Money compresses the documentation phase and the effort of building controls. It does not compress elapsed operating time — a quarterly control produces evidence quarterly regardless — and it does not compress your certification body’s calendar.
What is the single biggest determinant of the date?
How often your periodic controls run. Access reviews, risk reassessment, supplier reviews and training have to have operated with records before an auditor can sample them, so the audit date is planned backwards from the next time each one runs.
When should we schedule internal audit and management review?
Early, and in that order — the review needs the audit’s findings to consider. Both must have genuinely happened before the first certification visit, and squeezing them into one week produces records that look exactly like what they are.
When should we contact a certification body?
At the start, before you are ready to book. Their lead times are an input to your plan rather than a formality at the end, and they lengthen towards year end. Finding out in month seven that the next slot is in month eleven is a common and avoidable way to lose a quarter.
Why do programmes usually slip?
Ordinary reasons, not technical ones: no single accountable owner, scope treated as an admin question and argued for weeks, evidence collected by hand by someone with another job, and certification body availability discovered late. Most delay is finished work waiting on a decision.
The bottom line
Ask what has to run before the audit can test it, and plan backwards from there — that question sets the date more than anything else. Then talk to a certification body in month one, not month seven.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Choosing
SOC 2 Type 1 or Type 2: which one to get, and what each can evidence
A blocked contract argues for a Type 1. Very little else does — and the minimum period you have been told about is not a rule.
Choosing
SOC 2 or ISO 27001 first? A commercial question wearing a technical costume
Your pipeline decides this, not the frameworks — and the two produce very different things to hand a customer.
Choosing
Accredited and unaccredited certification are not the same product
Both produce a certificate. Only one carries independent oversight of the auditor — and it is checkable.