No standard says how long ISO 27001 certification takes. ISO/IEC 27001:2022 sets requirements for the management system, ISO/IEC 17021-1 sets how certification bodies audit it, and neither prescribes a number of months. What they do prescribe is a sequence, and the sequence is what fixes your calendar: an ISMS that has been running long enough to produce records, including an internal audit and a management review; a stage 1 audit that checks you are ready; a stage 2 audit that looks for evidence that it conforms and performs; and a certification decision that cannot be taken while a major nonconformity is still open.
So the honest answer is that the elapsed time is mostly yours. The audits themselves take days, and the number of days follows the headcount in scope. The months go into building the risk assessment and the Statement of Applicability, operating the controls, and completing the internal audit and management review that a stage 1 auditor will look for. This guide walks through each step, says what an open primary source actually requires at that step, and marks where the time goes. What each step costs is in our companion guide to ISO 27001 certification cost.
| Step | What has to be true | Where it comes from |
|---|---|---|
| Build the ISMS | Scope, risk assessment, risk treatment and a Statement of Applicability | ISO/IEC 27001:2022, clauses 4.3, 6.1.2 and 6.1.3 |
| Run it | Controls operating, with records to show it | ISO/IEC 27001:2022, clause 8 |
| Check it yourself | An internal audit and a management review | ISO/IEC 27001:2022, clauses 9.2 and 9.3 |
| Stage 1 | The certification body judges readiness for stage 2 and tells you its conclusions | ISO/IEC 17021-1, clauses 9.3.1.1 and 9.3.1.2 |
| Stage 2 | The certification body audits evidence of conformity and of performance against your objectives | ISO/IEC 17021-1, clause 9.3.1.3 |
| Decision | Major nonconformities corrected and verified, within 6 months of stage 2; plans accepted for minor ones | ISO/IEC 17021-1, clause 9.5.2; EA FAQ 36.14 |
How long does ISO 27001 certification take?
As long as it takes your ISMS to be ready for stage 1, plus the audit sequence, plus the time to close anything major the auditors find. The first part is the variable one. A company that already runs access reviews, change control, supplier checks and incident handling, and keeps the records, is mostly writing down what it does and filling gaps. A company that does none of those things has to start operating them, and an auditor will want to see them operating, not just documented.
Page one for this query offers ranges of three to twelve months and longer, mostly with no stated headcount or scope behind them. A range is only useful if you know which inputs produced it. The inputs that matter are the size of the scope, how much of Annex A you already operate, and whether you can show an internal audit and a management review when stage 1 arrives.
What has to exist before stage 1?
A working management system, not a binder. ISO/IEC 27001:2022 requires you to define the scope (clause 4.3), run an information security risk assessment (clause 6.1.2), and then, under clause 6.1.3, select risk treatment options, determine the necessary controls, compare them with Annex A, and "produce a Statement of Applicability" that records each necessary control, the justification for including it, whether it is implemented, and the justification for excluding any Annex A control. Clause 6.1.3 also requires a risk treatment plan and the risk owners' approval of it and of the residual risks. The Statement of Applicability template and our guide to the 93 Annex A controls cover that step.
Then the checks you run on yourself. Clause 9.2 requires internal audits at planned intervals, and clause 9.3 requires top management to review the ISMS. These are where the calendar bites, because both need something to look at. The ISO and IAF Auditing Practices Group, in its guidance on the two stage initial certification audit, lists among the stage 1 activities "evaluating if internal audits and management reviews are being planned and performed, and whether the level of implementation of the management system substantiates that the client is ready for the stage 2 audit." That guidance was written for ISO 9001, but it describes the same ISO/IEC 17021-1 stage 1 that an ISMS goes through.

What happens between stage 1 and stage 2?
You fix what stage 1 found. ISO/IEC 17021-1 clause 9.3.1.1, quoted by the European co-operation for Accreditation in its certification committee FAQs, states that "the initial certification audit of a management system shall be conducted in two stages: stage 1 and stage 2." Clause 9.3.1.2.3, quoted in the same document, requires that "documented conclusions with regard to fulfilment of the stage 1 objectives and the readiness for stage 2 shall be communicated to the client, including identification of any areas of concern that could be classified as a nonconformity during stage 2." EA adds that those conclusions can be sent immediately or later, but must reach you before stage 2.
No fixed gap between the two stages appears in any open source we could check. The SADCAS assessment checklist for ISO/IEC 17021-1, which an accreditation body uses to assess certification bodies, asks instead whether the interval was determined with consideration given to the client's need to resolve areas of concern. In practice that makes the gap a planning decision between you and the certification body: long enough to fix what stage 1 flagged, short enough that the evidence it saw is still current.
What can hold the certificate back after stage 2?
Open nonconformities. Clause 9.5.2 of ISO/IEC 17021-1, quoted in the EA FAQs, requires that before making a certification decision the certification body has, "for any major non-conformities", "reviewed, accepted and verified the correction and corrective actions", and "for any minor nonconformities" has "reviewed and accepted the client's plan for correction and corrective action." A minor finding needs an accepted plan; a major one needs the fix done and verified. And there is a deadline on that verification. EA FAQ 36.14 quotes the standard for initial certification: "If the certification body is not able to verify the implementation of corrections and corrective actions of any major nonconformity within 6 months after the last day of stage 2, the certification body shall conduct another stage 2 prior to recommending certification." A major finding left open for six months does not just delay the certificate; it puts you back in front of a stage 2 audit. That is the most expensive delay in the whole sequence, and the stage 1 conclusions are your early warning of it.
How long do the audits themselves take?
Days, set by headcount. Clause C.6 of ISO/IEC 27006-1:2024, quoted by EA in FAQ 48.5, provides that "the total audit time for on-site audit shall be calculated by considering the total number of persons doing work under the organization's control irrespective of their location." The table that converts headcount into days is inside the standard, which is sold rather than published, so ask your certification body for its calculation. The fee side of the same rule is in our certification cost guide.
Does the timeline end with the certificate?
No. EA's answer on ISO/IEC 17021-1 clause 9.1.3.3, in FAQ 37.12, is that "in each calendar year, at least", there shall be an audit, "whether surveillance or recertification", and that postponing one year's audit into the next is not acceptable. Internal audits and management reviews therefore have to keep producing records every year. If you still hold an ISO/IEC 27001:2013 certificate, IAF MD 26 closed the transition on 31 October 2025 and states that all 2013 certifications "shall expire or be withdrawn at the end of the transition period", so plan for certification against the 2022 edition.

What the other results get wrong
Page one is almost entirely compliance software vendors and consultancies. Two patterns are worth correcting. The first is a range with no inputs: three to twelve months means little without the headcount, scope and starting point behind it, and two companies quoting the same range may be describing different jobs. The second is a fixed interval between stage 1 and stage 2, or a fixed minimum period of operation, such as three months before stage 2, presented as a rule. We found neither in an open primary source; both are certification body practice, so ask yours rather than plan around someone else's. Meanwhile the deadline that is in the standard, six months to get a major nonconformity verified, rarely appears at all.
Estimate your own timeline
Answer these before you book stage 1. Every blank row is time to add to the plan.
| Question | Your answer | Why it matters |
|---|---|---|
| Is the ISMS scope written down, with products, sites and legal entities? | Clause 4.3, and the audit days follow it. | |
| Is the risk assessment done and the treatment plan approved by risk owners? | Clauses 6.1.2 and 6.1.3. | |
| Is the Statement of Applicability complete, with justifications? | Clause 6.1.3 d). | |
| Which Annex A controls are documented but not yet operating? | Stage 2 looks for evidence of conformity and performance. | |
| Has an internal audit covered the whole scope? | Clause 9.2; stage 1 looks for it. | |
| Has top management held a management review? | Clause 9.3; stage 1 looks for it. | |
| Who owns closing findings between stage 2 and the decision? | ISO/IEC 17021-1 clause 9.5.2. |
If most rows are empty, start with a baseline. The free compliance check gives you one, and Venvera's ISO 27001 module keeps the risk register, the Statement of Applicability, internal audits and evidence together so the records stage 1 asks for already exist when it starts. The shared risk register guide covers the first step.
Frequently asked questions
Is there a minimum time an ISMS must run before certification?
We found no fixed minimum in an open primary source. What is required is evidence: stage 1 evaluates whether internal audits and management reviews are being planned and performed and whether implementation shows you are ready for stage 2.
How long between stage 1 and stage 2?
No fixed interval. Stage 1 conclusions, including areas of concern, must reach you before stage 2, and the interval should give you time to resolve them. Agree it with your certification body.
Can we be certified with open nonconformities?
With minor ones, if the certification body has accepted your plan for correction and corrective action. Major ones must be corrected and the fix verified before the certification decision, and if that verification cannot happen within 6 months of the last day of stage 2, another stage 2 is required.
Does ISO issue the certificate?
No. ISO states that it does not perform certification or issue certificates. An accredited certification body does.
Does certification end the work?
No. There must be an audit, surveillance or recertification, in every calendar year, so the internal audit and management review cycle has to continue.
Primary sources
Clause references and the clause 6.1.3 text are from ISO/IEC 27001:2022. ISO/IEC 17021-1 clauses 9.3.1.1, 9.3.1.2.3 and 9.5.2 are quoted in the EA certification committee FAQs, and the six month rule for major nonconformities in EA FAQ 36.14; clause 9.1.3.3 in EA FAQ 37.12; ISO/IEC 27006-1 clause C.6 in EA FAQ 48.5. Stage 1 activities are from the ISO and IAF Auditing Practices Group guidance and the SADCAS ISO/IEC 17021-1 assessment checklist; the 2013 transition from IAF MD 26:2023. Certification body practice varies; confirm intervals and audit days with yours.





