Guide
The ISO 27001 (ISMS) Certification Process and Timeline: 8 Steps from Kickoff to Registration
Getting certified to ISO/IEC 27001 generally takes six to twelve months from kickoff to registration. The path is a straight line: define your team and scope, assess risk and decide on controls, document and operate the system, check yourself through internal audit and management review, then go through the Stage 1 and Stage 2 audits with a certification body. This guide walks through where to start, what evidence to keep at each step, and where the time actually goes.
Published: Last updated:
The Full Picture and How Long It Takes
ISO/IEC 27001 certification starts with defining the scope, then moves through risk assessment, documentation, operation, internal audit and management review, and finally the Stage 1 and Stage 2 audits performed by a certification body. For IT companies of up to roughly 100 people, a six to twelve month timeline is common, and organisations that already have internal rules and security practices in place tend to land at the shorter end.
The biggest factor is not the volume of documents but the accumulation of operating records. Auditors confirm through records that the system is being run the way the documents say, so it is common practice to allow at least around three months of operation after the documents are in place before going to audit. For budgeting, see the cost of ISMS certification.
PDCA and Clauses 4 to 10 of ISO/IEC 27001:2022
The requirements of ISO/IEC 27001:2022 sit in clauses 4 through 10 and map directly onto the PDCA cycle. Building your project plan along this structure makes gaps much easier to spot.
- Plan — Clause 4 (context of the organisation), Clause 5 (leadership) and Clause 6 (planning). Scope, the information security policy, risk assessment and risk treatment, the Statement of Applicability (SoA), and information security objectives all live here.
- Do — Clause 7 (support) and Clause 8 (operation). Competence and awareness, communication, control of documented information, and the day-to-day operation that produces records.
- Check — Clause 9 (performance evaluation). Monitoring and measurement, internal audit, and management review form the self-check set.
- Act — Clause 10 (improvement). Nonconformity and corrective action, plus continual improvement. Findings from internal audits and external audits are closed here.
The Annex A controls, organised in the 2022 edition into four themes (organizational, people, physical and technological, 93 controls in total), are selected on the basis of the Clause 6 risk assessment. The document listing those decisions and their justification is the Statement of Applicability (SoA), which auditors always examine. For the mechanics of assessing risk, see how to run an ISMS risk assessment.
Eight Steps from Kickoff to Registration
- Build the team and define the scope — Obtain management approval, appoint an ISMS lead and a working group, fix the boundary of organisations, sites, services and information assets, and issue the information security policy.
- Gap analysis — Compare current internal rules and practices against clauses 4 to 10 and the Annex A controls, and list what is missing. That list becomes your task backlog.
- Risk assessment, risk treatment plan and SoA — Inventory information assets, identify, analyse and evaluate risks in terms of confidentiality, integrity and availability, decide treatment options against your acceptance criteria, and record the control decisions in the SoA.
- Documentation — Prepare the policy, supporting policies and procedures (access control, asset management, supplier management, business continuity, incident response and so on) and the forms that go with them. Build on the rules you already have, and write at a level people can actually follow. See the ISMS document list for the overall picture.
- Operate and accumulate records — Actually run the system. Keep training records, asset inventory updates, access rights granting and review records, supplier evaluations, incident records and change records. Around three months of operation is a commonly cited minimum.
- Internal audit — Plan the audit and have auditors with sufficient independence cover all requirements and the applied controls. Log findings as corrective actions and close them against a deadline.
- Management review — Report internal audit results, changes in risk, progress against objectives, incidents and interested party feedback to top management, decide on resources and improvement direction, and minute the outcome.
- Select a certification body, apply and be audited — Apply to an accredited certification body, undergo the Stage 1 audit (documentation) and the Stage 2 audit (operation), submit corrective actions for any findings, and proceed through the certification decision to registration.
What Stage 1 and Stage 2 Audits Look At
Stage 1 Audit (Documentation Review)
This audit confirms that the documented ISMS meets the requirements, that the scope and the SoA are consistent, and that you are ready for Stage 2. The policy, the risk assessment method and results, the SoA, and the internal audit and management review records are the main items examined. If readiness gaps come up here, moving the Stage 2 date back is a common outcome.
Stage 2 Audit (Operational Audit)
Through interviews on site and inspection of records, this audit checks whether the system is run as documented. Physical access logs, access rights reviews, training records, supplier evaluations, and vulnerability and incident handling histories are all examined as actual evidence. Findings are classified by severity, and depending on the classification you submit either a corrective action plan or evidence of completed correction before the certification decision.
A Month-by-Month Schedule (10-Month Model)
This example assumes an IT company of roughly 50 to 100 people using partial external support. Adjust it to your own situation, since timings shift with the state of the organisation.
| Timing | Main activities | Deliverables and records to keep |
|---|---|---|
| Month 1 | Kickoff, team setup, scope definition | Management approval record, org chart, information security policy |
| Month 2 | Gap analysis, project plan finalisation | Gap analysis results, task list, master schedule |
| Months 3-4 | Asset inventory, risk assessment, risk treatment plan, SoA | Asset inventory, risk register, risk treatment plan, SoA |
| Months 4-5 | Drafting policies, procedures and forms; management approval | Document register, policies and procedures, approval records |
| Months 6-8 | Company-wide training, start of operation, evidence accumulation | Training records, access rights review records, supplier evaluations, incident records |
| Month 8 | Internal auditor training, internal audit | Audit plan, checklist and report, corrective action records |
| Month 9 | Management review, application to a certification body | Management review minutes, application documents |
| Months 9-10 | Stage 1 audit, correction, Stage 2 audit, correction, registration | Audit reports, corrective action reports, certificate |
Starting the selection of and application to a certification body three to four months before the Stage 1 audit gives you room to negotiate dates. Busy seasons make preferred dates hard to secure, so requesting quotes in parallel with the start of operation is a practical approach.
Four Common Stumbling Blocks
- Setting the scope too wide — Covering every entity, site and service on the first attempt inflates the asset inventory, the documentation work and the evidence gathering all at once. Narrowing to the main service and head office first, and expanding at recertification, is a legitimate option.
- Treating documentation as the finish line — Policies produced by filling in a template tend to drift from what people actually do. Stage 2 looks at records of the system running, not at the documents themselves. Write at a level someone other than the author can execute.
- Doing the work but keeping no records — It is very common for activities to happen without the date, the person responsible, the target and the outcome being recorded. Training, access rights reviews, supplier evaluations and backup checks should be recorded at the moment they are performed.
- Internal audit as a formality — An audit that only ticks boxes produces zero findings and no improvement. Secure auditor independence and sample the actual records.
After Certification: Surveillance and Recertification Audits
Certification is not the end point, because maintenance audits continue. Commonly, a surveillance audit takes place roughly once a year after registration, and a recertification audit every three years. Surveillance audits are often narrower in scope than the initial audit, but internal audit and management review still need to be carried out every year.
In other words, the operating cycle you build during the certification project should be designed on the assumption that it runs every year. If evidence collection depends on one person doing it by hand, the burden rises sharply from the second year and records start going missing.
Keeping Progress and Evidence in One Place
A certification project touches the asset inventory, the risk register, the SoA, document version control, training completion, internal audit findings and corrective actions, and management review minutes. Spreading all of that across spreadsheets and shared folders makes it hard to see how far along you are and which evidence is missing, and the gap shows up as a scramble just before the audit. Linking risks, controls, documents and records inside a single tool makes progress and gaps visible on the spot, and lets you run maintenance the same way in later years.
If you want to work out which stage you are at and what to tackle next, start with the ISMS readiness self-check.
Frequently asked questions
- What is the shortest realistic timeline for ISO 27001?
- It depends on your size and on how developed your existing rules are, but around six months is a commonly seen floor. Rushing the documentation alone does not help, because without a period of operating records there is not enough evidence for the Stage 2 audit. Since roughly three months of operation is generally treated as a minimum, work backwards from that.
- Can a small company get certified?
- Yes. The requirements of ISO/IEC 27001 can be applied proportionally to the size of the organisation, so a handful of people can be certified with documentation and operation that match the scope and the risks. The one point that needs attention is the independence of the internal audit: assign auditors who do not work on the activities being audited, or bring in an external auditor.
- How many audits are there?
- For initial certification it is usually two: the Stage 1 audit covering documentation and readiness, and the Stage 2 audit covering operation. Corrective actions are submitted for any findings and verified as needed. After registration, surveillance audits roughly once a year and a recertification audit every three years follow.
- Can we do this in-house without a consultant?
- Some companies do. The deciding factors are whether someone can interpret the requirements, whether you can train internal auditors, and whether you have the hours to spend. Partial use of external help, for example for the gap analysis and the internal audit only, is also common. In every case, operating the system and keeping the records remains your own job.
- What should we decide internally before we start?
- Three things: the scope (which organisations, sites and services), the reason for certifying and the target date, and who runs the project. Scope in particular drives the risk assessment, the policies you need and the audit effort. If a customer or tender requirement is the motivation, confirm the required scope first to avoid rework.
Check where your ISMS stands in 5 questions
Answers are processed only in your browser and are never sent from this app.
Start the self-checkThis article is for general information only and does not guarantee any audit outcome or certification. Schemes and costs change, so confirm the latest details with certification bodies.
Related articles
ISO 27001 (ISMS) Certification Cost: Audit, Consulting and Maintenance Breakdown
ISO 27001 certification typically costs JPY 1.5M-7M in year one and JPY 400K-2M a year to maintain. See the breakdown by company size and 5 ways to cut it.
How to Run an ISMS Risk Assessment: 6 Steps from Asset Inventory to the Statement of Applicability
A practical six-step ISO/IEC 27001 risk assessment: set risk criteria, inventory assets, analyse and evaluate risk, then treat it via the SoA.
Required Documents for an ISMS (ISO 27001): Documented Information and Records, Organized
ISO/IEC 27001 documents in two layers: the documented information the standard explicitly requires, and the policies teams build around Annex A controls.