How long ISO 27001 takes, phase by phase

Preparation is most of the calendar and it is yours. The audit is days, not months. Here is every phase and what moves it.

How long does ISO 27001 take? Months of preparation, then an audit measured in days. The published totals come from a compliance platform and from a certification body:

  • Drata states that a small business with existing security processes might achieve certification in as little as six months, and that larger or less prepared organizations may take 12 to 18 months. Source, read 2026-09-28.
  • Schellman, an ISO certification body, states that in its experience it can take anywhere from 3 months to a year for an organization to fully prepare for ISO 27001 certification. Source, read 2026-09-28.

The spread is preparation. The audit itself is short, and the certification body sizes it before it starts.

That gives you a useful way to read any estimate. Ask how much of it is you, and how much is the certification body. The first part moves with effort. The second moves with headcount and the body’s calendar.

The phases, in order

Eight phases. The first five belong to you. The last three run on the certification body’s schedule, and they cannot start until the first five have left a paper trail.

PhaseWhat it producesWhose calendar
Scope and contextWhat the management system covers, and the interested parties and their requirements (clause 4)Yours
Risk assessment and treatmentA scored risk register, a treatment plan, and the Statement of Applicability (clause 6.1)Yours
Policies and controlsThe controls you selected, implemented, with policies that describe themYours, plus an engineer
Operate and monitorRecords that the controls run: reviews, logs, training, supplier checks (clause 9.1)Elapsed time
Internal audit and management reviewAn internal audit report, management review minutes, corrective actions (clauses 9.2, 9.3, 10)Yours
Stage 1A review of the design and the documents, and a list of areas of concernThe certification body
Stage 2A test of whether the system operates, with any nonconformities raisedThe certification body
Closing findings and the decisionCorrections accepted, then the certificateBoth

Why you cannot rush the middle

Writing is fast. A scope statement or a policy is hours of work, and a platform can draft most of it from your answers. The phase that sets the floor is the one after.

ISO 27001 asks for evidence that the system runs, and it says so in the text of the requirements themselves:

  • IAF MD 26 notes that ISO/IEC 27001:2022 uses the wording “Documented information shall be available as evidence” in clauses 9.1, 9.2.2, 9.3.3 and 10.2. Source, read 2026-09-28.

Those four clauses are monitoring, the internal audit, the management review and corrective action. Each one needs something to have happened first. You cannot audit a system internally before it has operated, and a management review needs results to review.

So there is no fixed observation window, unlike a SOC 2 Type 2. There is a practical one. The records have to exist before Stage 1, and they can only be produced by time passing.

How long the audit itself takes

Short, and sized in advance. A certification body works out the number of audit days before it quotes, from your scope.

  • A-LIGN states that the Stage 1 audit, the documentation review, usually takes 1-2 days, and that the length of the Stage 2 audit depends on the headcount supporting the ISMS, the number of locations and the complexity of the environment. Source, read 2026-09-28.
  • Schellman states that the number of employees in scope plays a part in the total number of audit days needed for Stage 1 and Stage 2, and names it among the factors ISO 27006 considers when calculating audit time. Source, read 2026-09-28.

Between the two stages sits a gap you partly control. Stage 1 raises areas of concern. Anything left open can turn into a nonconformity at Stage 2, so the gap is as long as it takes to close what Stage 1 found, plus whatever the body’s schedule adds.

Book early. The certification body’s calendar is the one date nobody on your team can move, and choosing a certification body is worth starting while the risk assessment is still in draft.

After Stage 2

A clean Stage 2 goes to a certification decision. Findings add time before the certificate is issued.

  • Schellman states that identified nonconformities must be corrected, and major ones remediated, before a certificate can be issued, and that correction and remediation time can vary from a matter of weeks to months. Source, read 2026-09-28.

Then the certificate starts a three year cycle. The management system keeps running, and the certification body keeps coming back.

  • A-LIGN states that a certificate is valid for three years after the issue date as long as surveillance requirements are met, and that surveillance audits are conducted annually. Source, read 2026-09-28.
  • Schellman states that each surveillance review takes about 1/3 of the initial certification audit time and a recertification review about 2/3. Source, read 2026-09-28.

Plan the surveillance visits the day the certificate arrives. Each one wants a fresh internal audit and a fresh management review before it, which means the calendar in year two looks like a shorter copy of year one.

Four things that push the date out

  1. Records that do not exist yet. An internal audit or a management review cannot be backdated. If neither has happened, that is your critical path.
  2. Scope that moves. Adding a product, an office or a system midway changes the audit days, and the certification body re-plans.
  3. Open nonconformities. Each one needs a correction the body accepts before a certificate is issued.
  4. A late booking. Stage 1 and Stage 2 run on the certification body’s schedule, not yours.

Where we fit in the timeline

Polara G.R.C. covers the five phases that belong to you. Scope, the risk register and the Statement of Applicability, policies drafted from your own stack, evidence attached to the control it proves, and an internal audit and management review run in the product. The output is a handoff package the certification body reads before Stage 1.

We do not shorten the certification body’s part. Nobody honest can. What ISO 27001 certification costs covers the two invoices, and the ISO 27001 product page lists what the readiness work includes.

Who certifies you

Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.

If a buyer is also asking for SOC 2, the two calendars overlap more than they differ. SOC 2 vs ISO 27001 compares them, and the SOC 2 timeline gives that side phase by phase.

Questions

How long does ISO 27001 take?
Published estimates run from about six months for a small company that already has security processes to a year or more for one starting from nothing. Most of that is preparation. The Stage 1 audit itself is a day or two, and Stage 2 is sized by headcount, sites and complexity.
Is there a minimum observation period for ISO 27001?
Not in the way a SOC 2 Type 2 has one. What Stage 2 needs is records showing the management system has actually run: monitoring results, at least one internal audit, a management review and corrective actions. Those records take calendar time to exist, which is the practical floor.
How long between Stage 1 and Stage 2?
Long enough to close what Stage 1 found. The certification body lists areas of concern at Stage 1, and anything left open can become a nonconformity at Stage 2. The gap is set by how much Stage 1 raises and by the body schedule.
What happens after the certificate is issued?
The certificate runs three years. The certification body returns for a shorter surveillance audit in each of the two years between, and a recertification audit before expiry starts the next cycle.
What slows ISO 27001 down the most?
Records that do not exist yet. A policy can be written in an afternoon, but an internal audit, a management review and months of monitoring evidence cannot be backdated. Scope changes midway and open nonconformities after Stage 2 are the other two.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.