How long ISO 27001 takes, phase by phase
Preparation is most of the calendar and it is yours. The audit is days, not months. Here is every phase and what moves it.
How long does ISO 27001 take? Months of preparation, then an audit measured in days. The published totals come from a compliance platform and from a certification body:
- Drata states that a small business with existing security processes might achieve certification in as little as six months, and that larger or less prepared organizations may take 12 to 18 months. Source, read 2026-09-28.
- Schellman, an ISO certification body, states that in its experience it can take anywhere from 3 months to a year for an organization to fully prepare for ISO 27001 certification. Source, read 2026-09-28.
The spread is preparation. The audit itself is short, and the certification body sizes it before it starts.
That gives you a useful way to read any estimate. Ask how much of it is you, and how much is the certification body. The first part moves with effort. The second moves with headcount and the body’s calendar.
The phases, in order
Eight phases. The first five belong to you. The last three run on the certification body’s schedule, and they cannot start until the first five have left a paper trail.
| Phase | What it produces | Whose calendar |
|---|---|---|
| Scope and context | What the management system covers, and the interested parties and their requirements (clause 4) | Yours |
| Risk assessment and treatment | A scored risk register, a treatment plan, and the Statement of Applicability (clause 6.1) | Yours |
| Policies and controls | The controls you selected, implemented, with policies that describe them | Yours, plus an engineer |
| Operate and monitor | Records that the controls run: reviews, logs, training, supplier checks (clause 9.1) | Elapsed time |
| Internal audit and management review | An internal audit report, management review minutes, corrective actions (clauses 9.2, 9.3, 10) | Yours |
| Stage 1 | A review of the design and the documents, and a list of areas of concern | The certification body |
| Stage 2 | A test of whether the system operates, with any nonconformities raised | The certification body |
| Closing findings and the decision | Corrections accepted, then the certificate | Both |
Why you cannot rush the middle
Writing is fast. A scope statement or a policy is hours of work, and a platform can draft most of it from your answers. The phase that sets the floor is the one after.
ISO 27001 asks for evidence that the system runs, and it says so in the text of the requirements themselves:
- IAF MD 26 notes that ISO/IEC 27001:2022 uses the wording “Documented information shall be available as evidence” in clauses 9.1, 9.2.2, 9.3.3 and 10.2. Source, read 2026-09-28.
Those four clauses are monitoring, the internal audit, the management review and corrective action. Each one needs something to have happened first. You cannot audit a system internally before it has operated, and a management review needs results to review.
So there is no fixed observation window, unlike a SOC 2 Type 2. There is a practical one. The records have to exist before Stage 1, and they can only be produced by time passing.
How long the audit itself takes
Short, and sized in advance. A certification body works out the number of audit days before it quotes, from your scope.
- A-LIGN states that the Stage 1 audit, the documentation review, usually takes 1-2 days, and that the length of the Stage 2 audit depends on the headcount supporting the ISMS, the number of locations and the complexity of the environment. Source, read 2026-09-28.
- Schellman states that the number of employees in scope plays a part in the total number of audit days needed for Stage 1 and Stage 2, and names it among the factors ISO 27006 considers when calculating audit time. Source, read 2026-09-28.
Between the two stages sits a gap you partly control. Stage 1 raises areas of concern. Anything left open can turn into a nonconformity at Stage 2, so the gap is as long as it takes to close what Stage 1 found, plus whatever the body’s schedule adds.
Book early. The certification body’s calendar is the one date nobody on your team can move, and choosing a certification body is worth starting while the risk assessment is still in draft.
After Stage 2
A clean Stage 2 goes to a certification decision. Findings add time before the certificate is issued.
- Schellman states that identified nonconformities must be corrected, and major ones remediated, before a certificate can be issued, and that correction and remediation time can vary from a matter of weeks to months. Source, read 2026-09-28.
Then the certificate starts a three year cycle. The management system keeps running, and the certification body keeps coming back.
- A-LIGN states that a certificate is valid for three years after the issue date as long as surveillance requirements are met, and that surveillance audits are conducted annually. Source, read 2026-09-28.
- Schellman states that each surveillance review takes about 1/3 of the initial certification audit time and a recertification review about 2/3. Source, read 2026-09-28.
Plan the surveillance visits the day the certificate arrives. Each one wants a fresh internal audit and a fresh management review before it, which means the calendar in year two looks like a shorter copy of year one.
Four things that push the date out
- Records that do not exist yet. An internal audit or a management review cannot be backdated. If neither has happened, that is your critical path.
- Scope that moves. Adding a product, an office or a system midway changes the audit days, and the certification body re-plans.
- Open nonconformities. Each one needs a correction the body accepts before a certificate is issued.
- A late booking. Stage 1 and Stage 2 run on the certification body’s schedule, not yours.
Where we fit in the timeline
Polara G.R.C. covers the five phases that belong to you. Scope, the risk register and the Statement of Applicability, policies drafted from your own stack, evidence attached to the control it proves, and an internal audit and management review run in the product. The output is a handoff package the certification body reads before Stage 1.
We do not shorten the certification body’s part. Nobody honest can. What ISO 27001 certification costs covers the two invoices, and the ISO 27001 product page lists what the readiness work includes.
Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.
If a buyer is also asking for SOC 2, the two calendars overlap more than they differ. SOC 2 vs ISO 27001 compares them, and the SOC 2 timeline gives that side phase by phase.
Questions
How long does ISO 27001 take?
Is there a minimum observation period for ISO 27001?
How long between Stage 1 and Stage 2?
What happens after the certificate is issued?
What slows ISO 27001 down the most?
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.