The standard answer to "how long does ISO/IEC 27001 certification take?" is about six months. But unless you understand how those six months are assembled, the schedule falls apart easily.
Most people picture certification as document production. On that model, writing faster should finish sooner. In reality there is a stretch between finishing your documents and sitting the audit that cannot be compressed, because certification requires evidence that the rules you wrote were actually operated — specifically, records of one completed cycle of internal audit and management review.
This article breaks the six months into stages, shows where the internal load falls, explains how to schedule backwards from the audit date, and lists the usual causes of slippage. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Required records and audit process vary by certification body; agree actual dates with yours.
The Six-Month Plan at a Glance
| Stage | Typical duration | Main work | Where the load falls |
|---|---|---|---|
| ① Objectives and planning | ~2 weeks | Scope, structure, annual plan; begin selecting a certification body | Executives |
| ② Risk analysis | ~1 month | Asset inventory, risk assessment, treatment decisions | Across every department |
| ③ Building the rules | ~4 months | Policy and objectives, procedures, SoA, incident reporting flow | The ISMS manager |
| ④ Controls and training | parallel with ③ | Technical and operational controls, training delivery | IT plus all staff |
| ⑤ Internal audit and correction | ~2 weeks | Internal audit, corrective action, management review | Departments plus executives |
| ⑥ Audit (Stage 1 and 2) | ~1 month | Stage 1 (1–2 days) → Stage 2 (2–3 days) → certification | ISMS manager plus relevant teams |
Because ③ and ④ overlap, the calendar path is ① ② ③ ⑤ ⑥ — about six months. The most misunderstood point is that the time ⑤ requires is not two weeks of work, as the next section explains.
What Happens in Each Stage
① Objectives and planning (~2 weeks)
Two decisions dominate: why you are certifying and what is in scope.
- Purpose — satisfying client requirements, or establishing internal control? Purpose drives scope
- Scope — company-wide, or a specific business, site, or service? Scope drives auditor-days and documentation volume
- Structure — appointing an ISMS manager and officers; defining executive involvement
- Beginning certification body selection — it is never too early (see below)
Scope can be widened later, but changing it after you start means redoing the asset inventory and risk assessment. It is worth the time. See Defining ISMS Scope and Scope Design for Healthcare Companies.
② Risk analysis (~1 month)
Inventory assets, assess risks, decide treatments. This is the first real bottleneck, because it requires cross-departmental interviews.
- Where information lives, and in what form (paper, files, databases, SaaS)
- Who can access it, and where it may be taken
- The impact if confidentiality, integrity, or availability is lost
- Treatment decisions: reduce, avoid, transfer, accept
Delays here come not from the standard but from departments not replying. Break requests into small pieces, supply a response format, set deadlines, and chase. Project management quality translates directly into elapsed time. See Building an Information Asset Inventory and Running a Risk Assessment.
③ Building the rules (~4 months)
Policy and objectives, procedures, the Statement of Applicability, incident reporting. The longest stage on the calendar — and the one where having templates changes the load completely.
The critical discipline is not writing an idealised operation. Whatever your procedures claim, the audit checks whether you actually do it. Rules stricter than reality become nonconformities. Describe what you genuinely do, and handle the gaps either as accepted risk or as a dated improvement plan. That is the fastest route in practice. See ISMS Document Structure, Adapting Policy Templates, and Writing the Statement of Applicability.
④ Controls and training (parallel with ③)
Doing what you decided: reviewing access rights, configuring logging, device management, backups, supplier checks — plus training every employee.
The overlooked part of training is chasing the last few people to 100% completion. The audit checks not only that training happened but that there are records showing the intended audience took it. See Designing Security Awareness Training.
⑤ Internal audit, correction, management review (~2 weeks)
The heart of the schedule. Covered in the next section.
⑥ Audit (~1 month)
Stage 1 reviews your documentation and the validity of your scope; Stage 2 examines operation on site. For small organisations, 1–2 days and 2–3 days respectively is a common benchmark. Several weeks usually separate them, to allow for responding to Stage 1 findings.
If nonconformities arise at Stage 2, registration waits until corrective action has been submitted and accepted. See What Stage 1 Looks At, What Stage 2 Looks At, and Common Nonconformities and How to Avoid Them.
Scheduling Backwards: The Audit-and-Review Cycle
Schedules break when this constraint is discovered last.
Certification requires showing that the ISMS is running, not merely that documents exist. Concretely, you need the performance evaluation and improvement cycle the standard calls for: an internal audit performed, a management review that took its results as input, and corrective actions taken — all recorded.
| What is required | Why it cannot be compressed |
|---|---|
| A period of operating under the procedures | Auditing immediately after writing rules leaves nothing to examine |
| The internal audit itself | Plan, perform, report — each takes days |
| Correcting nonconformities | Findings must actually be fixed, and the fix recorded |
| Management review | An executive forum; it needs scheduling, and it consumes the audit results |
Working back from the Stage 2 date:
- Stage 2 audit
- ← before that: management review completed
- ← before that: internal audit performed and corrective action closed
- ← before that: a period during which the procedures were genuinely in use
- ← before that: procedures finalised and training completed
How much of step 4 you can secure determines how easily you can explain yourself at audit. Sitting the audit right after go-live leaves thin records and invites findings. Even on an accelerated timeline, this is the one part you cannot cut.
One more factor: the certification body's availability. Auditor assignments can fill months ahead, so "we are ready, let's audit next month" may not be possible. That is why body selection starts in stage ①. Secure the dates first and schedule everything backwards from them.
Note also that the management review must be conducted by top management and cannot be delegated, and that auditors must not audit their own work — which makes internal audit hard for a small organisation to satisfy alone. See Running an Internal Audit and Conducting a Management Review.
Why Timelines Slip
| Cause | What happens | Prevention |
|---|---|---|
| Scope changed after starting | Asset inventory and risk assessment redone | Confirm client requirements in ① and fix scope |
| Departments do not reply | Stage ② stalls for a month or two | Supply formats and deadlines; have the request come from leadership |
| The project owner lacks authority | Cross-department coordination stalls | Give the ISMS manager explicit delegated authority |
| Procedures stricter than reality | Cannot be operated; nonconformities at audit | Describe the current state; accept or plan the gaps |
| Training stragglers | A scramble just before the audit | Split deadlines; make completion visible to department heads |
| Internal audit scheduled late | Stage ⑤ cannot compress; the audit date moves | Provisionally book the audit in ①, then fix the audit date backwards |
| No availability at the certification body | Months of waiting after you are ready | Start selection in ①; hold dates early |
| Executive calendars unavailable | The management review cannot happen | Fix it as a standing annual forum at the start of the year |
| Technical controls take unexpected effort | Stage ④ drags | Estimate implementation difficulty right after the risk assessment |
The two most common in practice are departments not replying and executive scheduling. Neither has anything to do with the difficulty of the standard; both are internal logistics. Which also means that with those designed properly, six months is a comfortably realistic target.
What Can and Cannot Be Shortened
Compressible
- Narrowing scope — less documentation and fewer auditor-days
- Using templates — a large reduction in stage ③
- Reusing what exists — existing procedures, registers, and logging lighten ①②③
- Outsourcing project management — chasing departments and reviewing documents moves outside; you keep the decisions
- Outsourcing internal audit — shortens plan-to-report time and helps satisfy the independence requirement
Not compressible
- The period of operating under the procedures
- One full cycle of internal audit → correction → management review
- The gap between Stage 1 and Stage 2
- The certification body's calendar
"We want it in three months" is a common request, but given the four items above, only the preparation side can compress. To attempt it: narrow scope, use templates, outsource project management and internal audit, and above all book the audit dates first. All four together, or not at all.
Life After Certification
Certification is not an endpoint; it runs on a three-year cycle.
| When | What happens |
|---|---|
| Every year | Internal audit, management review, risk assessment update, training |
| Years 2 and 3 | Surveillance audit |
| Year 4 | Recertification audit |
Designing the annual cycle during year one is what makes year two stable. Build solely to pass the audit and year two's internal audit is where it stops. See Preparing for Surveillance Audits and The Full Cost of ISMS Certification.
Healthcare vendors are often asked for three-ministry guideline compliance when deploying into hospitals. Running that on a separate cycle doubles the burden, so design for integration from the start: Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Two-Guideline Framework.
Conclusion
- The standard timeline is about six months: two weeks planning, one month risk analysis, four months building rules (controls and training in parallel), two weeks audit and correction, one month certification audit
- What sets the duration is not document volume but the requirement for records of one completed internal audit and management review cycle
- Schedule backwards from the Stage 2 date: review → internal audit and correction → a period of real operation → finalised procedures
- Certification body calendars fill up, so start selection in the first two weeks and hold dates early
- Slippage is caused by departmental delays and executive scheduling, not by the standard's difficulty — both are preventable logistics
- Only preparation compresses (scope, templates, project management, outsourced internal audit). Operating history, the audit cycle, and the Stage 1–2 gap do not
Pottech works to a standard six-month path to first certification. We provide templates for procedures, registers, and training, and we lead project management — including chasing departments and coordinating dates with the certification body — so your team can focus on decisions and training. Because we can serve as internal audit manager and internal auditors, stage ⑤ compresses more easily. An accelerated timeline is available as an option.
See ISMS Certification Support for scope and pricing, or contact us to work backwards from the date you need.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Information Security | Information-technology Promotion Agency (IPA)
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: required records, audit process, and scheduling differ by certification body. Durations vary with organisation size, scope, and how much is already in place. Schemes and interpretations change over time.