Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How long does ISO 27001 certification take?

Last verified

Elapsed time to an accredited ISO/IEC 27001 certificate is typically months, not weeks — often half a year to well over a year. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Timeline guide, last verified 10 September 2026. Ranges are typical and illustrative, not guarantees. Audit-day counts are influenced by IAF MD 5 and ISO/IEC 27006, not by vendor marketing. ISO 27001 is a voluntary standard, not a law. Clauses 4–10 plus a SoA for Annex A still have to operate before Stage 2.

What this page is, and what it is not

Audience: a founder or programme owner setting board expectations.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.

Nobody here can promise your certificate date. The certification body plans audit days; you still have to run the ISMS.

Typical elapsed ranges by scenario

These ranges are observed/typical programme elapsed time, not audit-day counts and not quotes. Last verified 10 September 2026. Not legal advice.

Illustrative elapsed ranges to first certificate (typical, not a guarantee; not legal advice; last verified 10 September 2026)
ScenarioTypical elapsed rangeWhat stretches itKind of text
Small single-site software company with an existing SOC 2 Type II and a narrow ISMS scopeOften about 4–9 months from kickoff to certificateSoA rewrite from TSC language, missing internal audit or management review, Stage 1 findings.Illustrative industry range — not IAF MD 5 itself.
Small company with no prior ISMS and thin documented informationOften about 9–18 monthsWriting Clauses 4–10 from scratch; first internal audit; operating-evidence window.Illustrative range.
Mid-size, several products, one legal entityOften about 9–18 monthsScope arguments, multi-team evidence, supplier controls.Illustrative range.
Multi-site or multi-entity scopeOften 12–24 months or longerIAF MD 5 scales audit days with effective personnel and complexity; travel and sampling add calendar time.Illustrative range plus accreditation-duration constraint.
Stage 1 already passed; waiting on Stage 2Often 1–3 months after Stage 1, sometimes longerCorrective actions, evidence-period requirements, auditor calendar.Illustrative Stage 1→2 gap — not a guarantee.
Surveillance year (not initial certification)Usually days of audit time inside an already-running yearOpen nonconformities, major change of scope.ISO/IEC 17021-1 surveillance practice — partial, not a full recert.

What actually consumes the months

Audit days are the smaller slice. Writing the SoA, running one real internal audit, holding management review, and accumulating operating evidence for implemented Annex A controls consume the rest. A readiness assessment is best practice and can shorten surprises; it is not a mandatory clause. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for a timeline conversation. Last verified 10 September 2026. Not legal advice.

  • Have we labelled every date as typical/illustrative, not guaranteed?
  • Do we know IAF MD 5 / ISO/IEC 27006 constrain audit days for the accredited body?
  • Is internal audit scheduled early enough that Stage 2 can sample the results?
  • Is the Stage 1→2 gap on the plan, with owners for findings?
  • Have we refused vendor “certified in 30 days” claims that skip Clauses 4–10?
  • Does the board understand surveillance years 1 and 2 are part of the cycle, not the end?

What to do now

These steps do not start a clock and do not file.

  • Pick the closest scenario row and treat it as a planning band, not a promise.
  • Ask any certification body to show how they applied IAF MD 5, not only a calendar slogan.
  • Read the cost and certification-process pages in this cluster.
  • Read how to get certified if the sequence is still unclear.
  • Re-verify sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance evidence collection can shorten the hunt for operating evidence; it does not shorten IAF MD 5 audit days by a promised amount. The obligation map tracks what you marked in-scope. Annex A crosswalk density is coverage, not a pass.

ISO 27001 is in the 24-framework library. Human judgment and an accredited certification body remain required.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022; ISO/IEC 27006; IAF MD 5; ISO/IEC 17021-1. Elapsed-month bands on this page are illustrative programme experience, not quotations from those documents. Not legal advice.

Frequently asked questions