ISO 27001 certification has no fixed completion time: your schedule depends on your starting controls, the work needed to prove they operate, and your certification body's audit dates. Preparation is only part of the timeline; you must also complete the certification audits and resolve findings before the certification decision. For your 2026 plan, build the deadline around those milestones rather than a promised turnaround.
How long does ISO 27001 certification take?
ISO 27001 does not prescribe a universal preparation period. Your certification body assesses whether your information security management system meets the requirements and operates effectively within your stated scope.
That system is your organised approach to managing information security: responsibilities, risk decisions, working controls, reviews and improvements. You need records showing that the approach works, not just documents describing what you intend to do.
Start with an ISO 27001 gap analysis before certification. Use the results to identify unfinished work before you ask for a credible completion date.
Build your schedule through these milestones:
- Define scope. Agree which services, systems, teams and locations the certificate will cover.
- Assess gaps. Compare your current practices and records with the requirements.
- Treat risks. Put the required safeguards in place and record your decisions.
- Run controls. Collect evidence from normal business activity.
- Review readiness. Complete the internal audit and management review, then address findings.
- Complete certification. Attend the external audits and satisfy the certification body's requirements for a decision.
Some preparation tasks can run together. Others depend on earlier decisions: you cannot assess the right risks until you know the scope, or test a control's operation before you implement it.
Ask your certification body to confirm its audit programme, required evidence, booking dates and process for reviewing findings. An audit booking is not a certificate issue date.
Why this matters
A customer deadline and an audit deadline are different commitments. If a contract requires certification, completing your policies or passing a readiness review does not satisfy that requirement.
For a 2026 sales or procurement deadline, confirm exactly what the buyer needs: a certificate, a defined certification scope, or evidence that your programme is underway. Then plan against the required outcome without describing unfinished work as certification.
This distinction also protects your team from rushed preparation. A deadline built around actual dependencies gives you a clear next action; a headline turnaround gives you a date without explaining how to reach it.
Your starting point changes the work required
Your existing security practices matter only when they cover the intended scope and you can demonstrate them. A working access process helps; an undocumented assumption about access does not.
Use the following comparison to decide where your preparation should start. These are starting situations, not certification tiers or guaranteed delivery times.
| Starting situation | Best for | Existing advantage | Remaining limitation | First action |
|---|---|---|---|---|
| Working controls with reliable records | Teams formalising established security practices | Existing evidence supports the readiness review | Records still need to match the certification scope | Map practices and evidence to requirements |
| Written policies with limited operating evidence | Teams moving from documentation to implementation | Responsibilities and intended processes are described | Documents alone do not prove effective operation | Put controls into use and retain records |
| Inconsistent controls across teams or services | Businesses bringing different practices into one scope | Existing practices provide material to assess | Differences need clear risk decisions and ownership | Agree scope, owners and consistent processes |
Working controls with reliable records
Start by checking coverage, not by rewriting everything. Your existing staff training, access approvals, supplier assessments and incident records can support preparation when they are relevant, current and traceable.
Check whether the records show who acted, what happened and how exceptions were handled. A record that proves a process ran is more useful than a template that nobody uses.
Recommendation: reuse valid evidence, then close the gaps. Do not assume an established IT team automatically means an audit-ready management system.
Written policies with limited operating evidence
Move from instructions to activity. Assign owners, explain the processes to the people using them, and retain the records produced by those processes.
If your policy requires an access review, carry out the review and record its outcome. If the review identifies inappropriate access, retain evidence of the correction as well.
Recommendation: prove the process works before declaring readiness. Publishing policies is a milestone, not the end of preparation.
Inconsistent controls across teams or services
Agree how the management system applies across the scope. Identify shared processes, local differences and the people responsible for each.
Do not force identical technical settings where systems require different safeguards. Instead, document how each approach addresses the relevant risk and how you check that it works.
Recommendation: resolve ownership and coverage before booking against a firm completion promise. An unclear boundary makes both preparation and auditing harder to organise.
What happens before the external audits?
Most of your direct control sits in preparation. You decide the scope, allocate people, implement safeguards and make the records available for review.
Build your 2026 preparation plan around completed outcomes rather than document counts. Each outcome needs an owner and a clear way to verify completion.
Define scope
Describe the business activities, information, systems and organisational boundaries covered by your management system. Include the interfaces and dependencies that affect information security within that boundary.
Keep the scope useful to your customers. A certificate covering an unrelated internal function does not demonstrate that the service they buy falls within the certified management system.
Treat risks
Assess the information security risks within scope and decide how to address them. Record the required controls, responsible owners and treatment decisions.
Prepare the Statement of Applicability, which explains the necessary controls and the reasons for their inclusion or exclusion. Make sure it reflects what you actually do, rather than a copied checklist.
Run controls
Put the agreed processes into everyday use. Retain records of activities such as access reviews, training, supplier checks and incident handling where those activities apply.
Match each record to the relevant process or control. Give the auditor a clear route from your stated requirement to the evidence showing how you meet it.
Review readiness
Carry out an internal audit and management review. Use the results to check conformity, examine performance and decide what needs to change.
Record findings, decisions and follow-up actions. Management review needs evidence of leadership decisions, not just an invitation in a calendar.

Operating evidence comes before the final readiness review.
What happens during the certification audits?
Initial certification normally involves Stage 1 and Stage 2 audits. They serve different purposes, so completing the first does not mean you have completed certification.
Your certification body determines the audit arrangements for your organisation. Confirm the plan directly rather than treating another company's audit schedule as your own.
Stage 1: assess readiness
Stage 1 examines your management system documentation and preparedness for Stage 2. It helps the certification body understand your scope and identify concerns that affect the next audit.
Treat the outcome as a decision point. Review the findings, understand the required actions and confirm that you are ready to proceed.
Stage 2: assess implementation
Stage 2 examines implementation and effectiveness. Auditors assess evidence, speak with relevant people and sample how your management system works within scope.
Make control owners available and organise evidence before the audit. An auditor needs to understand the process, not simply receive a folder of unexplained files.
Certification decision: complete the process
The audit team's recommendation is not the final certification decision. The certification body reviews the audit outcome through its decision process.
Findings affect the next steps. Confirm what corrections, corrective actions and supporting evidence the certification body requires, and when it will review them.
Keep certification decision time separate from audit attendance in your plan. That distinction matters when you have promised a customer a certificate by a particular date.
Why the ISO 27001 timeline varies
These factors explain why a single turnaround does not fit every business. Check each one when setting your 2026 target.
- Scope complexity. More varied activities, systems and locations create more processes and interfaces to assess.
- Existing control coverage. Working safeguards reduce implementation gaps only when they address the risks within scope.
- Evidence quality. Relevant, traceable records let you demonstrate operation; incomplete records leave questions unresolved.
- People and ownership. Preparation depends on control owners, leadership decisions and access to the people responsible for the work.
- Audit scheduling. Certification-body availability and agreed audit arrangements affect when external assessment happens.
- Findings and follow-up. Corrections, corrective actions and review of supporting evidence affect the route to a certification decision.
Separate tasks you control from dependencies you must confirm externally. You can assign an access review today; you cannot unilaterally set a certification body's decision date.
Can software shorten ISO 27001 preparation?
Software supports preparation by helping you manage compliance work. It does not remove the need for effective controls, management decisions or an independent certification audit.
OneClickComply is best for growing businesses seeking software to manage ISO 27001 compliance end-to-end. It provides software that automates cyber security compliance, including ISO 27001.
The benefit is support for managing the compliance programme. The boundary is equally clear: your organisation remains responsible for how its management system operates, and the certification body makes the certification decision.
Choose software against your actual preparation tasks. Check whether it supports the work you need to manage and how you will provide evidence to the auditor; do not treat a platform purchase as proof of readiness.
Manage your certification preparation
Explore OneClickComply for end-to-end cyber security compliance management.
How do you set a realistic certification deadline?
Set a provisional date after the gap assessment, then confirm the external audit dependencies. For your 2026 plan, keep preparation completion, audit completion and certificate issue as separate milestones.
Give each unfinished task an owner, an expected completion date and a completion test. Record dependencies so your team knows which delayed task affects the next milestone.
Before committing to a customer deadline, confirm:
- Your scope covers the service the customer expects.
- Required controls operate and have supporting records.
- Your internal audit and management review are complete.
- The certification body has confirmed the audit arrangements.
- Your plan includes addressing findings and the certification decision.
Commit to a certificate deadline only after checking the full route to issue. If dependencies remain open, explain the current milestones accurately.
Does certification finish when the audit ends?
Certification does not necessarily finish when audit interviews end. The certification body still needs to complete the applicable review and decision process.
After certification, you must maintain the management system. Keep reviews, records, internal audits and improvements active rather than treating the certificate as the end of the programme.
Frequently asked questions
One last thing
Your most useful schedule is not a countdown to the audit. It is a list of decisions, working controls and records that must be ready before each milestone.
Use OneClickComply to manage cyber security compliance, but keep your commitment tied to demonstrated readiness and the certification body's process. Seriously Simple Cyber Compliance.
