Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Security Assurance Insight

How Long Does ISO 27001 Certification Take?

The timeline depends less on document count and more on scope, maturity, remediation and evidence history.

Published 2026-09-03 · Tech Turn Technology

There is no universal nine-month rule

A small, mature cloud company may move faster than a larger organisation with unclear ownership, legacy systems and weak evidence. The correct estimate starts with scope and a current-state review.

The main timeline drivers

Scope size, number of systems, supplier dependencies, risk-process maturity, policy quality, technical remediation, evidence history, internal-audit readiness and certification-body scheduling all affect the timeline.

Documentation is not the only delay

A company can write policies quickly and still be unready. Some controls need time to operate so the auditor can inspect a meaningful period of evidence.

A practical sequence

Discovery and scope lead to gap assessment, remediation, ISMS operation, internal audit, management review, corrective actions, Stage 1, Stage 2 and the certification decision. Parallel work is possible, but skipping dependencies usually creates rework.

How to get a useful estimate

Run a readiness review and build a dependency-based remediation plan. Estimate the timeline from the longest control and evidence dependencies rather than from the number of documents still missing.

Need an evidence-based view of your own environment?
Use the Readiness Review to define scope and the first assessment.