# How long does ISO 27001 take?

> The work takes weeks, the waiting takes months. What an ISO 27001 run consists of, what sets the pace, and how to plan backwards from a tender deadline.

Source: https://fmcybersecurity.com/en/insights/compliance/how-long-does-iso-27001-take/
Locale: English
Other locale: https://fmcybersecurity.com/insights/compliance/hvor-lang-tid-tar-iso-27001/

## Metadata

- Date: 2026-08-11
- Author: johan-vorgaard
- Topic: compliance
- Format: article

How long ISO 27001 takes depends less on the standard and more on how quickly your company makes decisions. The certification work itself is measured in weeks. What stretches a project into months is waiting: for documents to be approved, for decisions to be made, for busy people to find an hour.

I plan certification runs backwards from tender deadlines, and the first meeting always opens with the same question: can we have the certificate before the bid goes in? The honest answer has three parts: the work itself, the pace you set, and an audit calendar you do not own.

## What an ISO 27001 run consists of

An ISO 27001 run is five steps of work followed by an external audit. The run builds an information security management system, an ISMS: the policies, roles, and routines that show you manage security on purpose. (If the standard is new to you, start with [what ISO 27001 is and why tenders require it](/en/insights/compliance/what-iso-27001-is-and-why-tenders-require-it/).)

1. Map what you are protecting: which systems, which data, which risks.
2. Write the documentation: policies, routines, and the Statement of Applicability, the document that goes through the standard's 93 controls and records which apply to you and why.
3. Put the controls into operation and collect evidence that they run: access reviews, logs, training records.
4. Run an internal audit, done by someone independent of the work being audited.
5. Hold a management review, where leadership checks that the system works and decides what changes.

After that, an accredited certification body audits you in two stages: Stage 1 reviews the documentation, Stage 2 checks that the system runs in practice. Go through both and the body issues the certificate. None of the five steps is large for a well-scoped company. The calendar risk sits between the steps.

## What decides the pace

The same five steps take weeks in one company and months in another, and the difference is rarely the security work itself.

A traditional project is slow because it waits. In the slow projects I have seen, the pattern repeats: the policy sits in a review round until the next management meeting, the risk assessment waits for an hour with a person who is fully booked, and decisions without an owner travel up the organisation and settle nowhere. LRQA, one of the accredited certification bodies, plans for [three to six months](https://www.lrqa.com/en-us/insights/articles/preparing-for-iso-270012022-transition-by-october-2025/) of gap-closing alone for a small firm in its own guidance.

A fast run turns that around. Decisions are made in the meeting where the question comes up, not after it. Questions get answers the same day. And the documentation grows as a byproduct of doing the work, instead of becoming a separate writing project afterwards.

We run that pattern as a package in [Secured by FM CyberSecurity](/en/secured/): a typical run reaches certification-ready in four to six weeks, and how quickly you answer our questions decides where in that window you land. Certification-ready means the system, the documentation, and the evidence are ready for the certification body's audit. Every step still happens. What disappears is the waiting.

## The audit runs on the certification body's calendar

Certification-ready is not certified. An accredited certification body performs the audit itself, and the body sets the dates. How far out those dates sit varies by body and by season, so contact one early in the run and ask for Stage 1 and Stage 2 dates in writing.

If you are planning against a tender deadline, count backwards: the deadline, minus the audit window, minus four to six weeks of work, tells you when to start. Add margin for clearing non-conformities, the findings you must fix before the certificate is issued.

## A certificate is a three-year cycle

An ISO 27001 certificate is valid for three years, and the work does not stop the day it is issued. The certification body returns each year for a shorter surveillance audit that confirms the system still runs, and in year three a recertification audit renews the cycle. A certificate is a running commitment, not a one-off exam. The evidence you need each year is the same evidence you built in the first run, kept current.

## Next step

If you are planning the run with your own team, the step-by-step route is in our [ISO 27001 checklist for Norwegian SMBs](/en/insights/compliance/iso-27001-checklist-for-norwegian-smbs/). If you are a small or medium-sized business without a security team, the whole run is packaged in [Secured by FM CyberSecurity](/en/secured/), which is also where the guarantee lives: if the audit does not go through within the agreed window, we cover the next attempt, and gross negligence on the customer side voids it.

Or talk to [our ISO 27001 practice](/en/services/iso27001/) about the deadline you are planning against. A 30-minute conversation is enough to put dates on a calendar.

Drafted with AI assistance, reviewed and edited by Johan Vorgaard and the FM CyberSecurity editorial team.

## FAQ

### Can ISO 27001 go faster than four to six weeks?

Not with us, and we do not promise it. Four to six weeks to certification-ready is the fastest we plan, because the weeks that remain once the waiting is removed are work the auditor checks: controls in operation, an internal audit, and a management review. Where you land inside that range depends mostly on how quickly your side answers questions.

### What slows an ISO 27001 project down?

Waiting, more than working. Documents sit in review rounds, decisions queue for the next management meeting, and the people who hold the answers are busy with other things. The standard asks for less than most companies fear. The calendar cost sits in the gaps between the tasks, not in the tasks.

### How long is an ISO 27001 certificate valid?

Three years. The certification body returns each year for a shorter surveillance audit that confirms the system still runs, and in year three a recertification audit renews the cycle. Budget the yearly work from the start, because a system that lies idle between audits puts the certificate at risk.

### When is the audit, once we are certification-ready?

When the accredited certification body has capacity, on its own calendar. Ask for Stage 1 and Stage 2 dates in writing early in the run, then hold your tender deadline against them. The body issues the certificate after Stage 2, once any non-conformities are cleared.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
