Get Demo
↑

How Long Does ISO 27001 Certification Take?

Typical ISO 27001:2022 timelines from gap analysis to Stage 2 certificate — plus the 3-year cycle with annual surveillance. Planning ranges.

Published: September 2026 Compliance · ISO 27001 10–14 min read

Time-to-certificate depends on scope, maturity, and resources. Below is a planning model aligned to Stage 1 / Stage 2 practice and the typical three-year certification cycle with annual surveillance.

Transition note: The IAF MD 26 client transition deadline was 31 October 2025. Build and certify against ISO/IEC 27001:2022.

Typical Phase Durations (Estimates)

Phase
Indicative duration
Gap analysis and scope lock
2–6 weeks
Risk, SoA, policies, controls build
2–6 months
Operate / internal audit / management review
4–12 weeks evidence window
Stage 1 then Stage 2
Often 2–8 weeks apart (CAB-dependent)

After You Are Certified

Plan for surveillance in years one and two and recertification in year three (typical accredited practice).

Operationalize ISO 27001:2022 with Continuous Evidence

CyberSilo CSA tracks SoA and mandatory records; ThreatHawk supports logging and monitoring artefacts for technological controls.

Frequently Asked Questions

What is a typical first-time timeline?

Many SMEs need roughly 3–9 months from serious kickoff to Stage 2, depending on scope and starting maturity. Complex multi-site programmes take longer.

Does the 31 October 2025 date still affect new projects?

That IAF MD 26 date was the end of the 2013→2022 transition for certified clients. New projects should implement ISO/IEC 27001:2022 directly.

What happens after the certificate is issued?

Expect annual surveillance and recertification on a typical three-year cycle.

ISO 27001 hub · 93 controls · SoA · CSA · Certification cost · Stage 1 vs Stage 2

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!