Back to Columns
ISMS & Certification12 min read

The ISMS Timeline: What Six Months Actually Looks Like

September 14, 2026

The ISMS Timeline: What Six Months Actually Looks Like
Share this article

The standard answer to "how long does ISO/IEC 27001 certification take?" is about six months. But unless you understand how those six months are assembled, the schedule falls apart easily.

Most people picture certification as document production. On that model, writing faster should finish sooner. In reality there is a stretch between finishing your documents and sitting the audit that cannot be compressed, because certification requires evidence that the rules you wrote were actually operated — specifically, records of one completed cycle of internal audit and management review.

This article breaks the six months into stages, shows where the internal load falls, explains how to schedule backwards from the audit date, and lists the usual causes of slippage. For the standard itself, see What Is an ISMS (ISO/IEC 27001)? A Complete Guide for Healthcare Companies.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Required records and audit process vary by certification body; agree actual dates with yours.

The Six-Month Plan at a Glance

StageTypical durationMain workWhere the load falls
① Objectives and planning~2 weeksScope, structure, annual plan; begin selecting a certification bodyExecutives
② Risk analysis~1 monthAsset inventory, risk assessment, treatment decisionsAcross every department
③ Building the rules~4 monthsPolicy and objectives, procedures, SoA, incident reporting flowThe ISMS manager
④ Controls and trainingparallel with ③Technical and operational controls, training deliveryIT plus all staff
⑤ Internal audit and correction~2 weeksInternal audit, corrective action, management reviewDepartments plus executives
⑥ Audit (Stage 1 and 2)~1 monthStage 1 (1–2 days) → Stage 2 (2–3 days) → certificationISMS manager plus relevant teams

Because ③ and ④ overlap, the calendar path is ① ② ③ ⑤ ⑥ — about six months. The most misunderstood point is that the time ⑤ requires is not two weeks of work, as the next section explains.

What Happens in Each Stage

① Objectives and planning (~2 weeks)

Two decisions dominate: why you are certifying and what is in scope.

  • Purpose — satisfying client requirements, or establishing internal control? Purpose drives scope
  • Scope — company-wide, or a specific business, site, or service? Scope drives auditor-days and documentation volume
  • Structure — appointing an ISMS manager and officers; defining executive involvement
  • Beginning certification body selection — it is never too early (see below)

Scope can be widened later, but changing it after you start means redoing the asset inventory and risk assessment. It is worth the time. See Defining ISMS Scope and Scope Design for Healthcare Companies.

② Risk analysis (~1 month)

Inventory assets, assess risks, decide treatments. This is the first real bottleneck, because it requires cross-departmental interviews.

  • Where information lives, and in what form (paper, files, databases, SaaS)
  • Who can access it, and where it may be taken
  • The impact if confidentiality, integrity, or availability is lost
  • Treatment decisions: reduce, avoid, transfer, accept

Delays here come not from the standard but from departments not replying. Break requests into small pieces, supply a response format, set deadlines, and chase. Project management quality translates directly into elapsed time. See Building an Information Asset Inventory and Running a Risk Assessment.

③ Building the rules (~4 months)

Policy and objectives, procedures, the Statement of Applicability, incident reporting. The longest stage on the calendar — and the one where having templates changes the load completely.

The critical discipline is not writing an idealised operation. Whatever your procedures claim, the audit checks whether you actually do it. Rules stricter than reality become nonconformities. Describe what you genuinely do, and handle the gaps either as accepted risk or as a dated improvement plan. That is the fastest route in practice. See ISMS Document Structure, Adapting Policy Templates, and Writing the Statement of Applicability.

④ Controls and training (parallel with ③)

Doing what you decided: reviewing access rights, configuring logging, device management, backups, supplier checks — plus training every employee.

The overlooked part of training is chasing the last few people to 100% completion. The audit checks not only that training happened but that there are records showing the intended audience took it. See Designing Security Awareness Training.

⑤ Internal audit, correction, management review (~2 weeks)

The heart of the schedule. Covered in the next section.

⑥ Audit (~1 month)

Stage 1 reviews your documentation and the validity of your scope; Stage 2 examines operation on site. For small organisations, 1–2 days and 2–3 days respectively is a common benchmark. Several weeks usually separate them, to allow for responding to Stage 1 findings.

If nonconformities arise at Stage 2, registration waits until corrective action has been submitted and accepted. See What Stage 1 Looks At, What Stage 2 Looks At, and Common Nonconformities and How to Avoid Them.

Scheduling Backwards: The Audit-and-Review Cycle

Schedules break when this constraint is discovered last.

Certification requires showing that the ISMS is running, not merely that documents exist. Concretely, you need the performance evaluation and improvement cycle the standard calls for: an internal audit performed, a management review that took its results as input, and corrective actions taken — all recorded.

What is requiredWhy it cannot be compressed
A period of operating under the proceduresAuditing immediately after writing rules leaves nothing to examine
The internal audit itselfPlan, perform, report — each takes days
Correcting nonconformitiesFindings must actually be fixed, and the fix recorded
Management reviewAn executive forum; it needs scheduling, and it consumes the audit results

Working back from the Stage 2 date:

  1. Stage 2 audit
  2. ← before that: management review completed
  3. ← before that: internal audit performed and corrective action closed
  4. ← before that: a period during which the procedures were genuinely in use
  5. ← before that: procedures finalised and training completed

How much of step 4 you can secure determines how easily you can explain yourself at audit. Sitting the audit right after go-live leaves thin records and invites findings. Even on an accelerated timeline, this is the one part you cannot cut.

One more factor: the certification body's availability. Auditor assignments can fill months ahead, so "we are ready, let's audit next month" may not be possible. That is why body selection starts in stage ①. Secure the dates first and schedule everything backwards from them.

Note also that the management review must be conducted by top management and cannot be delegated, and that auditors must not audit their own work — which makes internal audit hard for a small organisation to satisfy alone. See Running an Internal Audit and Conducting a Management Review.

Why Timelines Slip

CauseWhat happensPrevention
Scope changed after startingAsset inventory and risk assessment redoneConfirm client requirements in ① and fix scope
Departments do not replyStage ② stalls for a month or twoSupply formats and deadlines; have the request come from leadership
The project owner lacks authorityCross-department coordination stallsGive the ISMS manager explicit delegated authority
Procedures stricter than realityCannot be operated; nonconformities at auditDescribe the current state; accept or plan the gaps
Training stragglersA scramble just before the auditSplit deadlines; make completion visible to department heads
Internal audit scheduled lateStage ⑤ cannot compress; the audit date movesProvisionally book the audit in ①, then fix the audit date backwards
No availability at the certification bodyMonths of waiting after you are readyStart selection in ①; hold dates early
Executive calendars unavailableThe management review cannot happenFix it as a standing annual forum at the start of the year
Technical controls take unexpected effortStage ④ dragsEstimate implementation difficulty right after the risk assessment

The two most common in practice are departments not replying and executive scheduling. Neither has anything to do with the difficulty of the standard; both are internal logistics. Which also means that with those designed properly, six months is a comfortably realistic target.

What Can and Cannot Be Shortened

Compressible

  • Narrowing scope — less documentation and fewer auditor-days
  • Using templates — a large reduction in stage ③
  • Reusing what exists — existing procedures, registers, and logging lighten ①②③
  • Outsourcing project management — chasing departments and reviewing documents moves outside; you keep the decisions
  • Outsourcing internal audit — shortens plan-to-report time and helps satisfy the independence requirement

Not compressible

  • The period of operating under the procedures
  • One full cycle of internal audit → correction → management review
  • The gap between Stage 1 and Stage 2
  • The certification body's calendar

"We want it in three months" is a common request, but given the four items above, only the preparation side can compress. To attempt it: narrow scope, use templates, outsource project management and internal audit, and above all book the audit dates first. All four together, or not at all.

Life After Certification

Certification is not an endpoint; it runs on a three-year cycle.

WhenWhat happens
Every yearInternal audit, management review, risk assessment update, training
Years 2 and 3Surveillance audit
Year 4Recertification audit

Designing the annual cycle during year one is what makes year two stable. Build solely to pass the audit and year two's internal audit is where it stops. See Preparing for Surveillance Audits and The Full Cost of ISMS Certification.

Healthcare vendors are often asked for three-ministry guideline compliance when deploying into hospitals. Running that on a separate cycle doubles the burden, so design for integration from the start: Integrating ISMS Documents with the Three-Ministry Guidelines and The Three-Ministry Two-Guideline Framework.

Conclusion

  1. The standard timeline is about six months: two weeks planning, one month risk analysis, four months building rules (controls and training in parallel), two weeks audit and correction, one month certification audit
  2. What sets the duration is not document volume but the requirement for records of one completed internal audit and management review cycle
  3. Schedule backwards from the Stage 2 date: review → internal audit and correction → a period of real operation → finalised procedures
  4. Certification body calendars fill up, so start selection in the first two weeks and hold dates early
  5. Slippage is caused by departmental delays and executive scheduling, not by the standard's difficulty — both are preventable logistics
  6. Only preparation compresses (scope, templates, project management, outsourced internal audit). Operating history, the audit cycle, and the Stage 1–2 gap do not

Pottech works to a standard six-month path to first certification. We provide templates for procedures, registers, and training, and we lead project management — including chasing departments and coordinating dates with the certification body — so your team can focus on decisions and training. Because we can serve as internal audit manager and internal auditors, stage ⑤ compresses more easily. An accelerated timeline is available as an option.

See ISMS Certification Support for scope and pricing, or contact us to work backwards from the date you need.

References and Sources

Note: required records, audit process, and scheduling differ by certification body. Durations vary with organisation size, scope, and how much is already in place. Schemes and interpretations change over time.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.