Six to eighteen months is the honest range for ISO 27001 certification. The upper end depends on your starting maturity. The lower end is close to a hard floor, and it is worth understanding exactly why, because vendors promising certification in eight weeks are describing something other than what a certification body will accept.
The Three Things That Set the Floor
The ISMS has to have operated. Auditors sample records. If your access review process was created last month, there is one record to sample. Certification bodies generally want to see a meaningful period of the system actually running.
Internal audit must have happened. Clause 9.2 requires an internal audit programme covering the ISMS. You cannot audit a system that has not been operating, and the audit itself takes time to plan, conduct, and document.
Management review must have happened. Clause 9.3 requires review at planned intervals with defined inputs — including internal audit results. It is sequentially dependent on the audit, which is sequentially dependent on the ISMS operating.
That chain is why the floor exists. It is not bureaucratic padding; it is the difference between a management system and a document set.
Phase by Phase
Months 1–2: Scoping and gap assessment. Define the ISMS boundary, identify interested parties, and assess against all mandatory clauses and 93 Annex A controls. Output is a prioritised remediation plan.
Months 1–3: Risk assessment and SoA. Build the Clause 6.1.2 methodology, conduct the assessment, produce the risk treatment plan, and complete the Statement of Applicability. Everything downstream depends on this being sound.
Months 2–6: Implementation. Close the gaps. Policies, technical controls, supplier management, training. The most variable phase — an organisation with existing SOC 2 controls moves through this far faster than one starting cold.
Months 4–8: ISMS operation. Run it. Generate records. Perform access reviews, log reviews, and risk reassessments on their stated schedules. This phase overlaps implementation and cannot be skipped.
Months 6–9: Internal audit and management review. Audit the full ISMS, document findings, raise corrective actions, then hold management review with documented inputs and outputs.
Months 7–10: Stage 1 audit. Documentation and readiness review. The certification body confirms your ISMS is defined and you are ready for Stage 2. Findings here are usually about completeness.
Months 9–12: Stage 2 audit. Full certification audit. The auditor tests whether controls operate, interviews staff, and samples evidence. Major nonconformities must be closed before a certificate issues.
The Faster Path
Organisations already holding SOC 2 or operating a mature security programme can compress the implementation phase substantially, because the controls exist and generate records already. Six to nine months becomes genuinely achievable.
What still cannot be compressed is internal audit, management review, and the certification body's own scheduling. CBs book out, and Stage 1 to Stage 2 typically has a gap built in so you can address Stage 1 findings.
Where Timelines Slip
Weak risk assessment. If the Clause 6.1.2 work is thin, the SoA does not trace to it, and Stage 1 sends you back to rebuild the foundation.
Documentation that does not match reality. Templates pass Stage 1 and fail Stage 2, because Stage 2 involves interviewing the people supposedly following the process.
Scope changes mid-project. Adding a product or site means new risk assessment work, new controls, and new records.
Certification body availability. Engage a CB early. Their calendar is a real constraint on yours.
After Certification
The certificate runs three years, with surveillance audits annually and full recertification at the end of the cycle. Surveillance audits are shorter but real — a major nonconformity can suspend certification.
What You Can Start Immediately
Several things gate everything downstream and can begin on day one, in parallel with scoping.
Asset inventory. Needed for risk assessment, and usually slower to compile than expected because information sits across teams.
Risk assessment methodology. Defining criteria and approach takes discussion. Start it before you need the results.
Certification body selection. Their lead times constrain your calendar. Get quotes during your gap assessment, not after remediation.
Controls that need runtime. Anything producing periodic records — access reviews, log reviews, supplier reviews — should start operating as early as possible, because the number of records you can show is a function of how long they have been running.
That last one is the highest-value early action. A control switched on in month one has eight months of records at Stage 2. The same control switched on in month six has two.
The Sequential Dependencies
Some things genuinely cannot be parallelised, and knowing which ones prevents optimistic planning:
- Risk assessment must precede the risk treatment plan and Statement of Applicability
- Controls must be implemented before they can operate
- The ISMS must operate before internal audit can meaningfully assess it
- Internal audit results are a required input to management review
- Stage 1 must complete before Stage 2, with a gap to address findings
That chain is the timeline floor. Everything else is a resourcing question.
Coordinating With Other Frameworks
If you are pursuing SOC 2 alongside ISO 27001, sequencing matters. The control work overlaps substantially, so doing them close together is more efficient than years apart.
A common pattern: SOC 2 first, since it is faster to a usable report, then ISO 27001 building on the same control base. The ISO work then concentrates on the management system layer — risk methodology, SoA, internal audit, management review — rather than starting from nothing.
Running both simultaneously is possible but strains a small team, because the evidence formats and auditor expectations differ even where the underlying controls are the same.
Plan From Your Deadline
If a customer needs your certificate by a date, work backwards from Stage 2 and be honest about the floor. Our ISO 27001 risk assessment tells you where you actually are, which is the only way to know whether your target date is realistic.
See also the implementation checklist, cost guide, and the certification process walkthrough.
