There is no universal “ISO 27001 in X weeks” timeline. Readiness depends heavily on scope size, current control maturity, evidence quality, and ownership capacity. The certification body’s availability also affects the end-to-end schedule.
Factors that extend the timeline
- Constantly changing ISMS scope
- Missing asset/data/vendor inventories
- No formal risk assessment
- Controls exist but evidence is fragmented
- Unclear policy and control owners
- Joiner/mover/leaver, access review, change, and incident processes do not produce repeatable records
- Internal audit and management review are left to the last minute
Practical phases
1. Scope and gap visibility
Make the system boundary, stakeholders, existing policy/evidence, and material risks visible.
2. Risk and control ownership
Clarify risk assessment, treatment, Statement of Applicability approach, policies, and control owners.
3. Operating controls and evidence
Controls need to run at a defined cadence and produce evidence—not simply be designed on paper.
4. Internal validation
Complete internal audit, management review, nonconformity/corrective actions, and evidence-gap closure.
5. Certification planning
The certification body manages its own scope and Stage 1/Stage 2 process. A consultant should not promise or guarantee certification.
Use the ISO 27001 Readiness Assessment to identify starting gaps and ISO 27001 consulting for the evidence and roadmap model.
Next step
Instead of only reading, run the related free assessment, identify missing evidence, and then scope advisory work around the decision that is actually required.
Frequently asked questions
Does this guide replace company-specific advisory?
No. It provides a general decision framework; scope, regulatory, contractual, and risk context should be evaluated for the company.
What should the first step be?
Write down the current pressure, decision owner, evidence gap, and the output that should exist in the next 30–90 days.
Sources
This content is educational. It is not legal advice, an audit opinion, or a compliance guarantee.