Back to Insights
Procain Insights

How long ISO 27001 really takes

Cybersecurity5 min read

The honest answer for most organisations starting without a formal management system is nine to fifteen months from the decision to the certificate. Shorter is possible with a narrow scope and a dedicated team. Much shorter usually means either the scope is very small or corners are being cut that the surveillance audit will find.

The reason estimates vary so much is that the timeline is driven less by the standard than by three things specific to you: how wide your scope is, how much evidence you already generate, and how quickly your organisation makes decisions.

Where the time actually goes

Scoping and gap analysis: four to eight weeks

Deciding what is in scope is the single most consequential decision in the project, and rushing it costs more later than it saves now. Scope determines the size of everything that follows.

The gap analysis then establishes what already exists. Most organisations discover they are doing perhaps half of what the standard expects, informally and without evidence. The work is less about inventing controls than about formalising and evidencing what already happens.

Risk assessment: four to six weeks

This is the spine of the whole system. The methodology needs to be defined and defensible, assets identified, risks assessed and treatment decided.

The common mistake is producing an enormous risk register that nobody can maintain. A register with sixty well-understood risks that gets reviewed is worth more than one with four hundred that does not.

Building what is missing: two to five months

The widest range, because it depends entirely on the gap analysis. Typically it involves writing policies that did not exist, formalising processes that ran informally, and implementing whatever technical controls the risk treatment called for.

Policies are quick. Getting people to actually follow them is what takes months, and it cannot be compressed by writing faster.

Operating the system: three months minimum

This is the constraint people miss. Certification requires evidence that the management system has been operating, not just that it has been designed. Access reviews conducted, incidents logged and handled, changes approved, suppliers assessed, training delivered.

You cannot produce three months of operating records in three weeks. This phase sets a floor on the timeline regardless of how fast everything else goes.

Internal audit and management review: three to four weeks

Both are required before certification. The internal audit must be conducted by someone independent of the areas being audited, and it must find things. An internal audit with no findings suggests it was not a real audit, and auditors notice.

Management review is a documented meeting where leadership considers the system's performance and makes decisions. It needs minutes and it needs to have genuinely happened.

Certification audit: four to twelve weeks including the gap between stages

The audit comes in two stages. Stage one reviews documentation and readiness, and typically identifies things to fix. Stage two is the full assessment.

The gap between them is usually four to eight weeks, partly to allow remediation and partly because of certification body scheduling. Book early; availability is a real constraint and it is outside your control.

After stage two, expect several weeks for any minor nonconformities to be closed and the certificate to be issued.

What makes it faster

A narrow scope. One service, one location, one team certifies far faster than an entire organisation. Starting narrow and widening at the next cycle is a legitimate and common approach.

Existing evidence. If you already run change management, log incidents, review access and track assets in tools that produce records, a large part of the evidence problem is solved.

One person who owns it. A named individual with time allocated and the authority to make decisions. Projects distributed across several people's spare capacity take twice as long.

Decisions made quickly. Risk acceptance, policy approval and scope changes all require someone to decide. Organisations where these take weeks add months.

What makes it slower

Scope creep. Widening the scope mid-project restarts significant portions of the work.

Treating it as a documentation exercise. Producing a beautiful policy set that describes an organisation that does not exist. Auditors interview staff, and the gap between the documents and the reality becomes visible quickly.

Underestimating the evidence period. The most common cause of a slipped date is realising in month six that the required operating records only started in month five.

Leadership involvement in name only. The standard requires demonstrable leadership engagement, and management review minutes that show a fifteen-minute agenda item do not satisfy it.

After the certificate

The certificate runs for three years with surveillance audits, usually annually, and a full recertification at the end of the cycle. The management system has to keep operating throughout, which means the internal audit programme, the management review and the risk assessment updates continue on their own cycles.

Organisations that treat certification as a project and then stop find the first surveillance audit uncomfortable, because the evidence trail stops shortly after the certificate was issued.

A realistic plan

If someone asks for a date, the defensible position is:

  • Narrow scope, good existing practice, dedicated owner: eight to ten months.
  • Typical mid-sized organisation, moderate scope: twelve to fifteen months.
  • Wide scope, multiple sites, starting from very little: eighteen months or more, and probably worth splitting into phases.

Build in the three-month operating period explicitly, and book the certification body early. Those two things account for most of the schedule slippage that projects experience.

A note on what consulting can and cannot do

Consulting support shortens the parts that depend on knowing what is required: scoping, methodology, gap analysis, structuring the documentation, preparing for the audit. It does not shorten the period during which the management system has to be seen to operate, and it cannot make your organisation approve things faster.

Certification itself is issued by an accredited certification body, which must be independent of anyone who helped you prepare. Any arrangement that blurs that line is not worth having.

Want this looked at in your own environment?

Talk to an expert →