NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
How Long Does ISO 27001 Certification Take?
Learn

How Long Does ISO 27001 Certification Take?

·Alexander Sverdlov

No standard says how long ISO 27001 certification takes. ISO/IEC 27001:2022 sets requirements for the management system, ISO/IEC 17021-1 sets how certification bodies audit it, and neither prescribes a number of months. What they do prescribe is a sequence, and the sequence is what fixes your calendar: an ISMS that has been running long enough to produce records, including an internal audit and a management review; a stage 1 audit that checks you are ready; a stage 2 audit that looks for evidence that it conforms and performs; and a certification decision that cannot be taken while a major nonconformity is still open.

So the honest answer is that the elapsed time is mostly yours. The audits themselves take days, and the number of days follows the headcount in scope. The months go into building the risk assessment and the Statement of Applicability, operating the controls, and completing the internal audit and management review that a stage 1 auditor will look for. This guide walks through each step, says what an open primary source actually requires at that step, and marks where the time goes. What each step costs is in our companion guide to ISO 27001 certification cost.

StepWhat has to be trueWhere it comes from
Build the ISMSScope, risk assessment, risk treatment and a Statement of ApplicabilityISO/IEC 27001:2022, clauses 4.3, 6.1.2 and 6.1.3
Run itControls operating, with records to show itISO/IEC 27001:2022, clause 8
Check it yourselfAn internal audit and a management reviewISO/IEC 27001:2022, clauses 9.2 and 9.3
Stage 1The certification body judges readiness for stage 2 and tells you its conclusionsISO/IEC 17021-1, clauses 9.3.1.1 and 9.3.1.2
Stage 2The certification body audits evidence of conformity and of performance against your objectivesISO/IEC 17021-1, clause 9.3.1.3
DecisionMajor nonconformities corrected and verified, within 6 months of stage 2; plans accepted for minor onesISO/IEC 17021-1, clause 9.5.2; EA FAQ 36.14
What a stage 1 auditor looks for in an ISO 27001 programme: the clause 4.3 scope, the clause 6.1.2 risk assessment, the clause 6.1.3 Statement of Applicability, clause 8.1 operation, the clause 9.2 internal audit and the clause 9.3 management review

How long does ISO 27001 certification take?

As long as it takes your ISMS to be ready for stage 1, plus the audit sequence, plus the time to close anything major the auditors find. The first part is the variable one. A company that already runs access reviews, change control, supplier checks and incident handling, and keeps the records, is mostly writing down what it does and filling gaps. A company that does none of those things has to start operating them, and an auditor will want to see them operating, not just documented.

Page one for this query offers ranges of three to twelve months and longer, mostly with no stated headcount or scope behind them. A range is only useful if you know which inputs produced it. The inputs that matter are the size of the scope, how much of Annex A you already operate, and whether you can show an internal audit and a management review when stage 1 arrives.

What has to exist before stage 1?

A working management system, not a binder. ISO/IEC 27001:2022 requires you to define the scope (clause 4.3), run an information security risk assessment (clause 6.1.2), and then, under clause 6.1.3, select risk treatment options, determine the necessary controls, compare them with Annex A, and "produce a Statement of Applicability" that records each necessary control, the justification for including it, whether it is implemented, and the justification for excluding any Annex A control. Clause 6.1.3 also requires a risk treatment plan and the risk owners' approval of it and of the residual risks. The Statement of Applicability template and our guide to the 93 Annex A controls cover that step.

Then the checks you run on yourself. Clause 9.2 requires internal audits at planned intervals, and clause 9.3 requires top management to review the ISMS. These are where the calendar bites, because both need something to look at. The ISO and IAF Auditing Practices Group, in its guidance on the two stage initial certification audit, lists among the stage 1 activities "evaluating if internal audits and management reviews are being planned and performed, and whether the level of implementation of the management system substantiates that the client is ready for the stage 2 audit." That guidance was written for ISO 9001, but it describes the same ISO/IEC 17021-1 stage 1 that an ISMS goes through.

What sets the pace of ISO 27001 certification: records from a clause 9.2 internal audit, a clause 9.3 management review, major findings verified before the decision under ISO/IEC 17021-1 clause 9.5.2, and headcount under ISO/IEC 27006-1 clause C.6 setting the audit days
Venvera risk register listing risks by legal entity and category with inherent rating, control effectiveness, residual rating, owners and linked KRIs

What happens between stage 1 and stage 2?

You fix what stage 1 found. ISO/IEC 17021-1 clause 9.3.1.1, quoted by the European co-operation for Accreditation in its certification committee FAQs, states that "the initial certification audit of a management system shall be conducted in two stages: stage 1 and stage 2." Clause 9.3.1.2.3, quoted in the same document, requires that "documented conclusions with regard to fulfilment of the stage 1 objectives and the readiness for stage 2 shall be communicated to the client, including identification of any areas of concern that could be classified as a nonconformity during stage 2." EA adds that those conclusions can be sent immediately or later, but must reach you before stage 2.

No fixed gap between the two stages appears in any open source we could check. The SADCAS assessment checklist for ISO/IEC 17021-1, which an accreditation body uses to assess certification bodies, asks instead whether the interval was determined with consideration given to the client's need to resolve areas of concern. In practice that makes the gap a planning decision between you and the certification body: long enough to fix what stage 1 flagged, short enough that the evidence it saw is still current.

The ISO 27001 audit sequence under ISO/IEC 17021-1 once the ISMS is running: stage 1 and its documented conclusions, fixing the areas of concern, stage 2 on site, closing major nonconformities, and the certification decision

What can hold the certificate back after stage 2?

Open nonconformities. Clause 9.5.2 of ISO/IEC 17021-1, quoted in the EA FAQs, requires that before making a certification decision the certification body has, "for any major non-conformities", "reviewed, accepted and verified the correction and corrective actions", and "for any minor nonconformities" has "reviewed and accepted the client's plan for correction and corrective action." A minor finding needs an accepted plan; a major one needs the fix done and verified. And there is a deadline on that verification. EA FAQ 36.14 quotes the standard for initial certification: "If the certification body is not able to verify the implementation of corrections and corrective actions of any major nonconformity within 6 months after the last day of stage 2, the certification body shall conduct another stage 2 prior to recommending certification." A major finding left open for six months does not just delay the certificate; it puts you back in front of a stage 2 audit. That is the most expensive delay in the whole sequence, and the stage 1 conclusions are your early warning of it.

How long do the audits themselves take?

Days, set by headcount. Clause C.6 of ISO/IEC 27006-1:2024, quoted by EA in FAQ 48.5, provides that "the total audit time for on-site audit shall be calculated by considering the total number of persons doing work under the organization's control irrespective of their location." The table that converts headcount into days is inside the standard, which is sold rather than published, so ask your certification body for its calculation. The fee side of the same rule is in our certification cost guide.

Does the timeline end with the certificate?

No. EA's answer on ISO/IEC 17021-1 clause 9.1.3.3, in FAQ 37.12, is that "in each calendar year, at least", there shall be an audit, "whether surveillance or recertification", and that postponing one year's audit into the next is not acceptable. Internal audits and management reviews therefore have to keep producing records every year. If you still hold an ISO/IEC 27001:2013 certificate, IAF MD 26 closed the transition on 31 October 2025 and states that all 2013 certifications "shall expire or be withdrawn at the end of the transition period", so plan for certification against the 2022 edition.

Venvera ISO 27001:2022 dashboard showing control coverage across the 93 Annex A controls, open findings, internal audits and reviews completed, and control status by the four Annex A themes

What the other results get wrong

Page one is almost entirely compliance software vendors and consultancies. Two patterns are worth correcting. The first is a range with no inputs: three to twelve months means little without the headcount, scope and starting point behind it, and two companies quoting the same range may be describing different jobs. The second is a fixed interval between stage 1 and stage 2, or a fixed minimum period of operation, such as three months before stage 2, presented as a rule. We found neither in an open primary source; both are certification body practice, so ask yours rather than plan around someone else's. Meanwhile the deadline that is in the standard, six months to get a major nonconformity verified, rarely appears at all.

An illustrative view of an ISMS approaching stage 1: risks assessed and treated, Statement of Applicability approved, internal audit not yet completed, management review booked

Estimate your own timeline

Answer these before you book stage 1. Every blank row is time to add to the plan.

QuestionYour answerWhy it matters
Is the ISMS scope written down, with products, sites and legal entities?Clause 4.3, and the audit days follow it.
Is the risk assessment done and the treatment plan approved by risk owners?Clauses 6.1.2 and 6.1.3.
Is the Statement of Applicability complete, with justifications?Clause 6.1.3 d).
Which Annex A controls are documented but not yet operating?Stage 2 looks for evidence of conformity and performance.
Has an internal audit covered the whole scope?Clause 9.2; stage 1 looks for it.
Has top management held a management review?Clause 9.3; stage 1 looks for it.
Who owns closing findings between stage 2 and the decision?ISO/IEC 17021-1 clause 9.5.2.

If most rows are empty, start with a baseline. The free compliance check gives you one, and Venvera's ISO 27001 module keeps the risk register, the Statement of Applicability, internal audits and evidence together so the records stage 1 asks for already exist when it starts. The shared risk register guide covers the first step.

The bottom line on how long ISO 27001 certification takes: the calendar is set by your records, not by the audit

Frequently asked questions

Is there a minimum time an ISMS must run before certification?

We found no fixed minimum in an open primary source. What is required is evidence: stage 1 evaluates whether internal audits and management reviews are being planned and performed and whether implementation shows you are ready for stage 2.

How long between stage 1 and stage 2?

No fixed interval. Stage 1 conclusions, including areas of concern, must reach you before stage 2, and the interval should give you time to resolve them. Agree it with your certification body.

Can we be certified with open nonconformities?

With minor ones, if the certification body has accepted your plan for correction and corrective action. Major ones must be corrected and the fix verified before the certification decision, and if that verification cannot happen within 6 months of the last day of stage 2, another stage 2 is required.

Does ISO issue the certificate?

No. ISO states that it does not perform certification or issue certificates. An accredited certification body does.

Does certification end the work?

No. There must be an audit, surveillance or recertification, in every calendar year, so the internal audit and management review cycle has to continue.

Primary sources

Clause references and the clause 6.1.3 text are from ISO/IEC 27001:2022. ISO/IEC 17021-1 clauses 9.3.1.1, 9.3.1.2.3 and 9.5.2 are quoted in the EA certification committee FAQs, and the six month rule for major nonconformities in EA FAQ 36.14; clause 9.1.3.3 in EA FAQ 37.12; ISO/IEC 27006-1 clause C.6 in EA FAQ 48.5. Stage 1 activities are from the ISO and IAF Auditing Practices Group guidance and the SADCAS ISO/IEC 17021-1 assessment checklist; the 2013 transition from IAF MD 26:2023. Certification body practice varies; confirm intervals and audit days with yours.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING