How long does ISO 27001 certification take? Most organizations complete it in 6 to 12 months. Companies with existing security practices, like a SOC 2 or HIPAA program already in place, can do it in 3 to 6 months. Large, multi-region enterprises should plan for 12 to 18 months. The audit itself, Stage 1 and Stage 2, only takes a few weeks; the rest of that time goes into building the ISMS the auditor will actually test.
That last point is the one most timelines get wrong. Certification is really two timelines layered on top of each other: an implementation timeline (writing policies, deploying controls, collecting three months of operating evidence) and an audit timeline (Stage 1 documentation review, Stage 2 on-site assessment, certification decision). Implementation is almost always the longer of the two, and it's the one you control.
The stakes behind getting this right are concrete. The global cost of a data breach reached US$4.44 million in 2025, and healthcare breaches averaged US$7.42 million, the most expensive of any sector. Enterprise buyers know this, which is why ISO 27001 now shows up as a hard requirement in most security questionnaires rather than a nice-to-have.
This guide is written for CTOs, CISOs, and compliance leads at midmarket and startup companies, particularly fintechs with license obligations, healthcare companies handling protected health information (PHI), and any vendor selling into enterprise accounts. It breaks down every phase of the ISO 27001 audit timeline, what actually drives it faster or slower, and how a security-driven compliance platform, run self-serve or fully managed, changes the math. It draws on public guidance from AuditBoard and ISOQAR, plus delivery data from 6,000+ security audits Konfirmity's team has run over the past decade.
The Short Answer: How Long Does ISO 27001 Certification Take?
Three variables set your timeline: company size, ISMS maturity, and who's doing the implementation work. A 40-person startup with an existing SOC 2 program can be certified inside three months. A 1,500-person multinational building an ISMS from scratch across three regions should plan for a year and a half. Everyone else lands somewhere in between.

The phases are the same regardless of size:
- Pre-audit preparation — gap assessment, ISMS documentation, internal audit
- Stage 1 audit — documentation review
- Stage 2 audit — implementation and on-site assessment
- Report submission, certification issuance, and corrective actions
- Surveillance audits — annual
- Recertification audit — every three years
What changes between a 6-month timeline and an 18-month one is almost entirely how much of phase 1 you're building from zero, and how much of it is automated rather than manual.
Free checklist
The ISO 27001 Audit Preparation Checklist
The exact gap-assessment, scope, and evidence audit preparation checklist we use before every Stage 1 audit. Enter your work email and we'll send the PDF.
The Two Timelines Most Guides Blur Together
Certification splits into two timelines that most guides describe as one thing:
- Implementation timeline: building the ISMS, writing policies, deploying controls (MFA, encryption, logging, access reviews), and running the ISMS long enough to generate real evidence. This is the work that happens before an auditor ever shows up, and it's where most of the schedule risk lives.
- Audit timeline: Stage 1 documentation review, Stage 2 on-site assessment, and the certification decision. These take roughly the same number of calendar days no matter which platform or team is running your program, because the certification body sets that pace, not you.
The practical implication: if someone tells you Stage 1 and Stage 2 "take four to six weeks," that's true, but it's also not the number that determines whether you're certified in three months or twelve. The number that matters is how long it takes to get your ISMS to a state an auditor will pass, which is a function of your starting point and how much of the implementation work is automated versus manual. With a managed compliance platform, teams typically spend 75 hours a year maintaining ISO 27001 after certification, compared with 550 to 600 hours for a fully self-managed program. Most of the gap between a fast timeline and a slow one comes from that difference, not from the audit itself.
What an ISO 27001 Audit Actually Involves
ISO 27001:2022 specifies requirements for establishing, implementing, and continually improving an information security management system (ISMS). Getting certified means implementing risk-based controls, documenting policies and procedures, defining a Statement of Applicability (SoA), and producing evidence that those controls actually operate, not just that they exist on paper.
Internal, External, and Second-Party Audits
Compliance work here involves three distinct kinds of audits, and mixing them up is a common source of confusion:
- Internal audits (1st party) — the organization checks its own ISMS against ISO 27001. Clause 9.2 requires these at planned intervals, with a documented program and objective auditors. They exist to catch gaps before the certification body does.
- External audits (3rd party) — performed by an accredited certification body. Stage 1 reviews documentation; Stage 2 assesses implementation and evidence. After certification, surveillance audits run annually and recertification runs every three years.
- Second-party audits (2nd party) — audits by customers or partners, typically during procurement due diligence. They look similar to an internal or external audit but sit outside the certification process itself.
What the Audit Is Actually Checking For
Every stage of the audit is testing the same four things:
- Conformance — has the organization defined ISMS scope, performed risk assessments, and documented policies?
- Effective implementation — do controls actually operate as described, and can the organization produce evidence (logs, change records, access reviews, vendor risk assessments) covering the required observation period?
- Continual improvement — do findings from audits feed into corrective actions and management reviews that stick?
- Protection of information assets — does the ISMS, in practice, reduce the likelihood and impact of a breach?
Why This Timeline Matters If You Hold a License, PHI, or Sell to Enterprise
A timeline is only useful if it maps to a real business decision. Three groups of buyers and operators have the most to lose from getting this wrong.
Fintechs and License Obligations
Regulators and banking partners increasingly treat ISO 27001, or an equivalent recognized ISMS, as evidence that a fintech meets the operational-security expectations attached to a money-transmitter, e-money, or banking-as-a-service license. A sponsor bank or regulator asking for proof of an operating ISMS won't accept a policy binder, they'll ask for Stage 1 and Stage 2 reports and evidence of ongoing surveillance. Knowing the real timeline, not the optimistic one, is what lets a fintech commit to a licensing or partnership date it can actually hit.
Healthcare Companies and PHI
Healthcare organizations and their vendors handle protected health information under HIPAA, and healthcare breaches are the costliest category at US$7.42 million per incident. ISO 27001 certification, combined with a HIPAA-specific control set, is how a health-tech vendor demonstrates to hospital systems and payers that PHI is protected by an operating ISMS rather than a checklist. Because health system procurement cycles are long and risk-averse, a vendor that can point to a certification date, and evidence that the ISMS has been running for the required observation period, closes deals that competitors without a clear timeline lose to delay.
Companies Selling to Enterprise Buyers
Enterprise procurement teams are risk-averse by design. They must confirm that a vendor handling PHI, financial data, or other regulated information has real controls in place, and a clear timeline is what lets them do that with confidence. It lets sales and compliance teams:
- Align on realistic dates. Sales can quote accurate certification dates in proposals instead of guessing.
- Plan resources. Knowing Stage 2 requires at least three months of operating evidence determines when to start collecting it, not when the auditor is booked.
- Avoid last-minute scrambles. Delays usually come from underestimating the gap assessment or ignoring the required gap between Stage 1 and Stage 2.
- Win on speed. A vendor that certifies ahead of a competitor closes the deal that was stuck in security review.

Free checklist
The ISO 27001 Audit Preparation Checklist
The exact gap-assessment, scope, and evidence audit preparation checklist we use before every Stage 1 audit. Enter your work email and we'll send the PDF.
Phase 1: Pre-Audit Preparation
Pre-audit preparation is the phase where most of the timeline gets decided: building the ISMS, running a gap assessment and risk assessment, and closing gaps before an auditor ever looks at your documentation.
The gap assessment compares your current security posture against ISO 27001 controls and Annex A requirements, surfacing missing policies, weak technical controls, and gaps in evidence collection. The risk assessment identifies which threats and vulnerabilities are relevant, evaluates likelihood and impact, and defines a risk treatment plan.
Alongside that, you need to document the boundaries of the ISMS: which systems, locations, and processes fall inside scope. That means writing policies (information security, access control, asset management, incident response, business continuity) and building a Statement of Applicability that lists every control and its implementation status. Internal auditors then evaluate the ISMS against ISO 27001, management reviews assess the results and allocate resources, and remediation closes the gaps before Stage 1.
Key Actions During Pre-Audit Preparation
- Plan the audit schedule backward from your target certification date, accounting for holiday periods and busy quarters (product launches, fundraising) that could constrain team availability.
- Build real policies, not templates. Start from an ISO 27001:2022-aligned template, but adapt it to how the organization actually operates. Auditors test whether a policy is practiced, not whether it reads well.
- Train the team and run readiness checklists. Tabletop exercises for incident response and change management make sure people know what evidence to produce when the auditor asks.
- Automate evidence collection. Tools that capture change tickets, vulnerability scans, vendor assessments, and access review logs remove the largest source of manual effort in this phase.
Example: An Eight-Week Prep Schedule for a Mid-Size Company
Below is a hypothetical eight-week pre-audit schedule for a mid-size technology vendor with 150 employees and some existing security practices.
| Week | Activities |
|---|---|
| 1 | Initiate project, define ISMS scope, appoint ISMS lead and internal auditor. |
| 2–3 | Conduct gap assessment against Annex A controls; perform risk assessment; draft risk treatment plan. |
| 3–4 | Develop policies and procedures; create Statement of Applicability; implement missing technical controls (MFA, encryption, logging). |
| 5 | Train staff on security policies, incident response, and change management; configure evidence collection tools. |
| 6 | Conduct internal audit; identify nonconformities; begin remediation. |
| 7 | Management review of internal audit findings; assign corrective actions. |
| 8 | Complete remediation; run a final readiness check; schedule the Stage 1 audit. |
A larger organization should add several weeks to nearly every row here, particularly documentation and technical implementation. Keeping an ISO 27001 audit preparation checklist next to this schedule is what keeps a team from missing a control while they're heads-down on documentation. For a deeper walkthrough of this phase, see our ISO 27001 audit preparation guide.
Phase 2: Stage 1 Audit, Documentation Review
Stage 1 is an external audit focused entirely on documentation. The auditor reviews the ISMS scope, policies, risk assessment, Statement of Applicability, and internal audit records to confirm you're ready for Stage 2. This phase typically takes a few days to a few weeks, depending on how complex your documentation is.
By the end of Stage 1, the certification body issues a readiness report identifying any nonconformities and recommending remediation, which you're expected to address before Stage 2 is scheduled.
What Typically Delays Stage 1
- Documentation that doesn't reflect what the organization actually does.
- No documented risk assessment or Statement of Applicability.
- Ambiguous ISMS scope boundaries.
- References to an outdated version of ISO 27001.
Konfirmity has found that up to 40% of organizations entering Stage 1 without a managed security program have to reschedule Stage 2 because their evidence isn't complete. Expert-led delivery closes that gap by making sure documents are audit-ready the first time, which cuts the back-and-forth with the certification body.
Phase 3: Stage 2 Audit, Implementation and On-Site Assessment
Where Stage 1 asks whether the organization says the right things, Stage 2 checks whether it does them. Auditors visit, physically or remotely, to sample controls, observe operations, and interview personnel: they review log files, change tickets, access reviews, vulnerability scans, and incident reports, and cross-check that evidence against the documented policies.
Stage 2 typically lasts 4 to 6 weeks. Some certification bodies require a 4 to 6 week gap between Stage 1 and Stage 2 for remediation and evidence collection, and per ISOQAR, Stage 2 should be scheduled no more than six months after Stage 1, with the ISMS having operated for at least three months before Stage 2 begins. That three-month operating window is usually the real bottleneck, not the audit itself.
What Auditors Test During Stage 2
Stage 2 auditors test seven areas in particular:
- Risk assessment process and risk treatment plans.
- Control implementation: access control (least privilege), encryption, patch management, vulnerability remediation.
- Operational evidence: logs from SIEM platforms, change management systems, identity providers, vendor risk tools.
- Training records: onboarding checklists, annual security awareness records, phishing simulations.
- Incident management: ticketing system logs, incident timelines, root cause analysis.
- Physical security: keycard access logs, CCTV retention policies, environmental controls.
- Business continuity and disaster recovery: backup schedules, restoration tests, failover drills.
Day by Day: What a Stage 2 Audit Looks Like
| Day | Activities |
|---|---|
| 1 | Opening meeting; review Stage 1 findings; confirm audit plan and scope. |
| 2–3 | Interviews with IT operations, DevOps, product teams; sample change management tickets; observe deployment pipelines. |
| 4–5 | Review of vendor risk management; evidence of third-party due diligence; sample contracts and DPAs. |
| 6–7 | Physical site visit; inspect data centre racks and server rooms; check CCTV logs and visitor access logs. |
| 8 | Review of incident response procedures; examine incident tickets and post-mortems. |
| 9 | Review of business continuity and disaster recovery plans; sample test results. |
| 10 | Closing meeting; discuss findings; confirm next steps and timeline for report submission. |
For more on what to expect during this phase, see our ISO 27001 external audit guide.
What Happens After Stage 2

After Stage 2, the auditor compiles evidence and submits a report to the certification body's review committee. Per ISOQAR, this typically takes up to three months, and the certificate is only issued once every nonconformity is closed. If you pass, the ISO 27001 certificate is valid for three years.
If the auditor finds nonconformities, you'll need a corrective action plan describing how and when each issue gets resolved. Minor nonconformities are usually fixed with updated policies or training; major ones, like missing logs or ineffective access control, can delay certification outright. Certification bodies often allow three months for remediation before the certificate is issued. For a look at the findings that come up most often, see our guide to common ISO 27001 audit findings.
Certification Maintenance and the Three-Year Cycle
ISO 27001 certification isn't a one-time event:
- Surveillance audits happen annually (more often for high-risk scopes). Auditors review a subset of controls to confirm the ISMS still operates as designed, including whether management reviews and internal audits happened on schedule.
- Internal audits must run at planned intervals, quarterly or biannually, across the three-year cycle, with evidence available for surveillance.
- Recertification happens at the end of year three: a full audit similar to Stage 2, which you need to plan for well ahead of time rather than treating as a last-minute scramble.
How Company Size and ISMS Maturity Change Your Timeline
Two variables move the timeline more than anything else: how big and distributed the organization is, and whether it already has security controls in place from a program like SOC 2 or HIPAA.
- Small tech vendors typically have a narrower ISMS scope and fewer business processes. With dedicated support, gap assessment and documentation can wrap in 2 to 4 months, with Stage 1 and Stage 2 adding another 2 to 3 months, for a 6 to 8 month total.
- Large enterprise suppliers run complex systems across multiple data centers and teams. Defining scope, implementing controls, and gathering evidence across departments can take 6 to 12 months or more, and external audit phases extend when auditors need to visit multiple sites or sample more controls.
- ISMS maturity is the biggest lever. Organizations with existing controls, like a SOC 2 Type II or HIPAA program, can reuse evidence and cut preparation time significantly. Organizations starting from zero can spend months just writing policies and training staff.
Example: Small Tech Vendor Selling to Healthcare
A startup providing cloud-based analytics to healthcare providers pursues ISO 27001 to satisfy HIPAA Business Associate Agreements and win enterprise deals. With 40 employees and some existing SOC 2 practices, an eight-month timeline could look like this:
- Months 1–2: Gap assessment, risk assessment, policy drafting, and implementing missing controls (encryption at rest, vendor risk assessments). Roughly 150 hours of internal time plus 80 hours of external assistance.
- Month 3: Internal audit and management review; remediation of minor findings; Stage 1 scheduled.
- Month 4: Stage 1 audit (documentation review), 3 days; readiness report received; minor documentation issues remediated.
- Month 5: Evidence collection; operate under the new ISMS for at least three months.
- Month 6: Stage 2 audit (4 days); minor corrective actions; report submitted.
- Months 7–8: Certification issued after report review and closure of findings.
With managed delivery, a company at this stage typically invests roughly 75 hours per year maintaining compliance, versus 550 to 600 hours self-managed, thanks to automated evidence collection, pre-built policy templates, and a dedicated compliance advisor. You can calculate your compliance ROI using your own team size and hourly rates.
Example: Large Enterprise Supplier
A multinational SaaS vendor with 1,500 employees needs to meet enterprise clients' security addenda across three regions, with an ISMS scope spanning multiple products, development pipelines, support operations, and third-party data centers. A 12 to 18 month timeline might look like this:
- Months 1–3: Gap assessment across all business units; risk assessment with cross-functional workshops; map controls to Annex A and other frameworks (SOC 2, HIPAA).
- Months 3–6: Policy harmonization and control implementation; integrate logging and evidence collection across cloud platforms; deploy SSO and MFA everywhere.
- Months 7–8: Internal audit across regional teams; management reviews; budget allocated for improvements.
- Month 9: Stage 1 audit; documentation review across global operations; remediation.
- Months 10–12: Operating period under the new ISMS; evidence collected from multiple sites; staff trained on incident response and vendor risk workflows.
- Months 13–15: Stage 2 audit spanning multiple sites, remote and on-site, over 4 to 6 weeks; nonconformities addressed.
- Months 16–18: Certification issued after major findings close; first surveillance audit planned within 12 months.
Sample 12-Month Timeline
| Phase | Start Date | End Date | Duration | Key Outputs |
|---|---|---|---|---|
| Gap Assessment & Risk Analysis | Jan 1 2027 | Feb 28 2027 | 8 weeks | Risk register, SoA draft |
| Policy Development & Implementation | Mar 1 2027 | Jun 30 2027 | 17 weeks | Policies, procedures, controls deployed |
| Internal Audit & Management Review | Jul 1 2027 | Jul 31 2027 | 4 weeks | Internal audit report, corrective actions |
| Stage 1 Audit | Aug 15 2027 | Aug 20 2027 | 1 week | Stage 1 audit report |
| Stage 2 Audit | Oct 1 2027 | Nov 15 2027 | 6 weeks | Stage 2 report, corrective actions |
| Certification Decision & Issue | Dec 1 2027 | Jan 15 2028 | 6 weeks | ISO 27001 certificate |
| Surveillance Audit #1 | Nov 2028 | Nov 2028 | 1 week | Surveillance report |
| Surveillance Audit #2 | Nov 2029 | Nov 2029 | 1 week | Surveillance report |
| Recertification Audit | Dec 2030 | Jan 2031 | 6 weeks | Recertification report |
Free template
The ISO 27001 Timeline Planner
A printable planner version of the schedule above, sized to your headcount and ISMS maturity. Enter your work email and we'll send the PDF.
Self-Managed vs. Self-Serve Automation vs. Managed Delivery
Whether you run this program self-managed, on self-serve automation software, or through managed delivery changes your timeline more than any other decision. The real ISO 27001 certification cost shows up in hours, not the audit invoice. Stage 1 and Stage 2 take roughly the same number of calendar days regardless of approach, the certification body sets that pace. What actually changes is who does the implementation work in the months before the auditor shows up.
| Approach | Typical Time to Certification | What's Actually Happening |
|---|---|---|
| Self-managed (no platform) | 9–14 months | Manual policy writing, manual evidence collection, one team owns everything |
| Self-serve automation (Secureframe, Vanta, Drata) | 3–8 months | Automated evidence collection; you still own implementation and control design |
| Konfirmity (managed) | 4–6 months | We implement the controls in your stack and operate them daily, not just track them |
These ranges reflect timelines we've observed across customer engagements and publicly discussed case studies; your own timeline still depends heavily on starting maturity and scope, so treat them as planning guidance, not a guarantee.
Best Practices for Staying on Schedule

Efficient Documentation Review
- Centralize policies and evidence in a compliance management tool or shared repository. Organized documentation is one of the fastest ways to keep an auditor moving.
- Keep documents current. Policies should reference the latest ISO 27001:2022 clauses and reflect actual practice, not a generic template. Outdated documents are a direct cause of findings.
- Map cross-framework controls. If you already have SOC 2 or HIPAA controls, map them to Annex A. This cuts duplicate evidence collection significantly.
Preparing Teams for Auditor Visits
- Run mock interviews. Simulate audit questions with engineers and administrators so they can describe the change management process and access review cadence without hesitation.
- Assign subject-matter experts for each control area (vulnerability management, vendor risk) and make sure they're available during Stage 2.
- Confirm physical readiness ahead of site visits: access badges work, visitor logs are complete, CCTV retention meets policy.
Automating Evidence Collection
- Integrate ticketing systems (Jira, ServiceNow) and code repositories (GitHub) so change logs, deployment records, and access reviews capture themselves instead of being assembled by hand before the audit.
- Run continuous monitoring: vulnerability scanning, configuration management, and log aggregation produce real-time evidence of control operation. Automation reduces the average cost of detecting and escalating a breach by US$1.76 million.
- Use a status dashboard to track progress against milestones, open nonconformities, and readiness for the next surveillance audit.
- Reserve at least six weeks between Stage 1 and Stage 2 for remediation, and avoid last-minute change freezes purely to look tidy for the audit, auditors expect to see evidence of normal, ongoing change management.
Frequently Asked Questions
It starts with pre-audit preparation: gap analysis, risk assessment, and an internal audit. Then comes Stage 1 (documentation review) and Stage 2 (implementation audit). After certification, the organization undergoes annual surveillance audits and a recertification audit every three years.
Yes. After certification, accredited bodies run surveillance audits every year to confirm the ISMS still operates effectively, reviewing a subset of controls, management reviews, and internal audit results. Failing to maintain surveillance can lead to suspension of the certificate.
Typically 4 to 6 weeks, to allow time for remediating documentation issues and collecting additional evidence. Certification bodies generally require Stage 2 to happen within six months of Stage 1, with the ISMS having operated for at least three months before Stage 2.
1st party audits are internal audits the organization runs on itself to assess its ISMS and find gaps, they must be objective, impartial, and documented. 2nd party audits are run by customers or partners to verify compliance with their own security requirements, usually during procurement due diligence. 3rd party audits are run by accredited certification bodies to certify that the ISMS meets ISO 27001 requirements, including Stage 1, Stage 2, surveillance, and recertification audits.
Two stages. Stage 1 is a documentation review, usually a few days, checking that your ISMS scope, policies, and Statement of Applicability hold together. Stage 2 is evidence sampling and interviews, usually 1 to 2 weeks, where auditors verify the controls actually operate day to day rather than just existing on paper.
Gap assessment, control implementation, internal audit, Stage 1, Stage 2, and certification issuance, followed by ongoing surveillance audits and recertification every three years.
Most Stage 2 audits run 1 to 2 weeks of active auditor time, though the calendar window is often longer to accommodate interviews, site visits, and evidence sampling across teams. See the access control and evidence checklist above for what auditors sample during that window.
Turn This Timeline Into a Certification Date
See your real ISO 27001 timeline, not a guess
Book a demo and we'll map your certification date against your current ISMS maturity, self-serve or with our CISO-led team running it for you.
Book a demo
Conclusion
Understanding the ISO 27001 audit timeline matters most for enterprise-focused vendors, fintechs with license obligations, and healthcare companies handling PHI, because for all three, the cost of getting it wrong isn't just a failed audit, it's a stalled deal or a regulator asking hard questions. It's not enough to produce policies or "pass an audit"; you need to operate a living ISMS that holds up under scrutiny from auditors, customers, and regulators. Planning each phase, gap assessment, documentation, internal audit, Stage 1, Stage 2, and ongoing surveillance, is what turns an open-ended "sometime next year" into a certification date you can put in a sales proposal.
At Konfirmity, we start with security and arrive at compliance. Konfirmity is a security-driven compliance platform you can run self-serve or have fully managed; with the managed service, our team embeds controls into your stack and operates them daily. Across more than 6,000 security audits and 25+ years of combined expertise, our clients reach certification faster, with fewer findings, and with far less internal effort than a self-managed program requires.







