The path is fixed — gap assessment, implementation, internal audit, then Stage 1 (a documentation review) and Stage 2 (interviews and evidence). Implementation is the long phase, and its length is set by how many of the 93 Annex A controls you already run. Small, single-cloud companies with security operations already running move fastest.
Every certification follows the same path, in the same order. What varies — enormously — is how long each phase runs, and that’s set by your starting posture, not by the standard.
| Phase | What happens | What sets its length |
|---|---|---|
| Gap assessment | Your current state is measured against the 93 Annex A controls and the management-system clauses | Shortest phase. Set by access: how quickly people can show what actually runs, not what the wiki says runs |
| Implementation | Risk assessment, Statement of Applicability, policies, and the controls themselves — including the operational ones: logging, monitoring, vulnerability management | The longest phase, almost always. Set by how many of the 93 controls you already run, and by how long the new ones need to operate before they’ve produced real evidence |
| Internal audit & management review | Someone independent of the implementation checks the ISMS; management formally reviews it | Short — but it can’t start until there’s something to audit, and its findings feed back into implementation |
| Stage 1 | The certification body reviews your documentation and confirms readiness for Stage 2 | Certification-body scheduling, plus how cleanly your documentation maps to the standard |
| Stage 2 | Interviews and evidence: the auditor talks to your people and samples records to confirm controls operate | The audit itself is sized to your organisation; the wait before it is set by Stage 1 findings and the body’s calendar |
The phase most plans skip over entirely is the gap between “control implemented” and “control evidenced”. An access-review process adopted this week has exactly one review on record. A monitoring control switched on yesterday has a day of history. Stage 2 auditors ask for records, not intentions — so new controls need operating time before the audit, and that time sits inside the implementation phase whether you planned for it or not.
That’s the honest reason implementation dominates the calendar. It isn’t the writing. Policies and the Statement of Applicability are days of work for someone who knows the standard. Getting 93 controls assessed, the applicable ones running, and the running ones evidenced is the part that consumes months or doesn’t, depending entirely on where you started.
One more date to plan backwards from: certification bodies book ahead. Companies that treat “find an auditor” as the last task discover the queue after the work is done. Book during implementation — a fixed Stage 1 date also gives the internal work a deadline it will otherwise lack.
And the timeline doesn’t end at the certificate. Surveillance audits come annually; full recertification every three years. Whatever pace you set to get certified, the system has to keep running at a sustainable one afterwards.
Two companies of the same size can land far apart on the calendar. The differences are concrete.
Faster: one cloud environment and little else in scope. A small headcount, which means fewer Stage 2 interviews, fewer accounts to review, fewer laptops to manage. Security operations already running — logging, monitoring and vulnerability management cover a large slice of Annex A’s technological controls, and if they’re live you start with evidence instead of a to-do list. One decision-maker who can approve a policy the day it’s drafted.
Slower: multiple sites or a hybrid cloud-and-office estate. Tool sprawl from growth or acquisitions, where nobody is sure what’s in scope until the gap assessment says so. No existing operational controls, so everything needs building and then operating before it counts. And the quiet killer: part-time ownership. When the person driving certification also ships product, implementation stalls in two-week increments and the calendar drifts with nobody deciding it should.
If a deal is waiting on the certificate, that last one is the lever to pull first. The phases can’t be reordered, but implementation compresses sharply when someone owns it full-time — whether that’s your hire or your provider. The rest of what compresses it is covered in what ISO 27001 actually costs in Australia: the options differ in price precisely because they differ in how much of implementation they take off your team.
They plan the timeline around the audit — “how long does the audit take?” — when the audit is the short part. The certificate date is set almost entirely by implementation and by evidence.
The common shortcut fails for the same reason: buying a policy-template pack to “fast-track” certification compresses the writing, and the writing was never the long pole. Stage 2 is interviews and evidence. The auditor asks your engineer how access reviews work and then asks for the last one. No template answers that. If you want to move the certificate date forward, the lever is starting the operational controls early — so they’re producing evidence while the documentation catches up — not producing documents faster.
Tools hand you a to-do list. We do the list — and run the security behind it. On a timeline, that ordering matters: we stand up the operational controls first, so logging, monitoring and vulnerability management are accumulating evidence while the governance and ISMS build runs alongside, and we hold you to a Stage 1 date booked early rather than found late. The certification audit itself is performed by an accredited certification body — our job is getting you in front of it ready. Book a readiness call and we’ll give you a timeline scoped to your actual gap.
What's the longest phase of ISO 27001 certification?
Implementation. Gap assessment, internal audit and the two audit stages are each short by comparison. Implementation runs as long as it takes to close your gap against the 93 Annex A controls — and for the new controls to run long enough to produce evidence an auditor can sample.
Can policy templates make certification faster?
They shorten the writing, which was never the long part. Stage 2 is interviews and evidence: the auditor checks that controls operate, not that documents exist. A template pack with no operating controls behind it moves your certificate date very little.
What's the difference between Stage 1 and Stage 2?
Stage 1 is a documentation review — the certification body checks your ISMS paperwork and confirms you’re ready. Stage 2 is interviews and evidence — the auditor talks to your people and samples records to confirm the controls actually run.
When should we book the certification body?
During implementation, not after it. Certification bodies schedule ahead, and a fixed Stage 1 date does something useful for you internally: it turns the implementation plan into a deadline.
Does the timeline end at certification?
No. Surveillance audits run annually, and full recertification comes every three years. The system you build has to keep producing evidence between audits, so plan ownership of it past the certificate date.
Does company size change the timeline?
Yes, mostly through scope. More people means more interviews at Stage 2, more systems in scope, more access to review and more evidence to produce. A small single-cloud company has structurally less to implement and less to audit.