How Long Does ISO 27001 Certification Take? Realistic Timeline
For a typical single-site small business, ISO 27001 certification in Australia takes 4 to 6 months from gap analysis to certificate. Mid-market organisations with 50 to 250 employees usually take 6 to 9 months. Large or complex multi-site organisations can take 9 to 18 months. These are not marketing numbers, they are the real range across actual client engagements.
Timeline is usually the second question after ISO 27001 certification cost in Australia in every real planning conversation. If you have seen claims of certification in 6 weeks or less, that number usually describes only part of the real process, more on that further down. Here is the honest, phase-by-phase breakdown of where the time actually goes.
Quick answer: 4-6 months (small business) | 6-9 months (mid-market) | 9-18 months (large/complex)
Assess — Typically Month 1
Gap analysis and scoping. Your current security posture is compared against the standard’s 93 Annex A controls, producing a clear roadmap of what needs to be built, fixed, or evidenced. The quality of this phase directly affects how smoothly everything after it goes.
Build — Typically Month 1-2
ISMS design and documentation: your risk assessment methodology and risk treatment plan, your Statement of Applicability across all 93 controls, and a full policy documentation set. This phase can run concurrently with the tail end of Phase 1.
Implement — Typically Month 2-4
This is usually where the most real-world time goes: technical and organisational control implementation, organisation-wide security awareness training, and structuring evidence collection so it is audit-ready rather than scrambled together at the last minute. Companies with more mature existing controls move through this phase faster than companies building from scratch.
Certify — Typically Month 4-6
Internal audit and management review come first, required before any certification body will proceed. Then Stage 1 (a documentation and readiness review, usually booked 2-4 weeks out and taking 1-3 days) and Stage 2 (the full implementation audit, usually 2-6 weeks after Stage 1 and taking 2-5 days).
If Stage 1 finds a genuine gap, remediation before Stage 2 can add 6-10 weeks, which is exactly why Phase 1 and 2 being done properly matters so much. This is consistent with the ISO/IEC 27001 standard itself, which requires a functioning ISMS with genuine operating history, not just documentation, before certification.
What Speeds It Up or Slows It Down
Faster
A single site, existing security maturity (particularly if you already follow the Essential 8, since its controls map directly onto ISO 27001 Annex A), engaged stakeholders from day one, and a narrow, well-defined ISMS scope.
Slower
Multiple sites or business units in scope, building security controls from scratch with no existing framework, late stakeholder involvement (engineering or legal finding out about requirements mid-project rather than from the start), and a weak internal audit that misses gaps a Stage 1 auditor then catches, forcing remediation and re-audit.
Why Some Providers Claim 6 Weeks
You will find providers advertising ISO 27001 certification in as little as 6 weeks, sometimes framed as a “fast track” or “accelerator” package. It is worth understanding what these numbers usually do and do not include.
Most of these fast timelines describe the documentation and platform-setup phase only, often powered by a compliance automation platform, not the full certification journey. What they typically compress or exclude: the minimum period certification bodies generally expect your ISMS to have been operating before Stage 2 can proceed (most require at least around 3 months of the ISMS actually running, not just documented), and realistic Stage 1 and Stage 2 audit body scheduling lead time, which alone often adds several weeks regardless of how fast your internal work moves.
None of this means fast providers are lying, exactly, but a 6 week claim usually is not describing the same finish line as certificate in hand, and it is worth asking any provider quoting an unusually fast timeline exactly what is included in that number before you commit to it. CyberSapiens has 0 failed audits, ever, and holds its own ISO 27001:2022 certificate, meaning our team has been through the exact process our clients go through, timelines included.
What Happens After Certification
Your certificate runs on a 3 year cycle: lighter surveillance audits in years 1 and 2 checking your ISMS has not degraded, then a full recertification audit in year 3 to start the cycle again. This ongoing commitment is worth factoring into your timeline thinking from the start, certification is the beginning of a maintained program, not a one-time finish line.
This is exactly the structured path we ran for Blue Polaris, a global AI consultancy: one structured engagement through gap analysis, build, implementation and certification, resolving 99% of identified risks and closing 6 critical gaps before Stage 2. You can read more on our ISO 27001 certification in Australia page.
You can independently verify any ISO 27001 certificate, including your own once issued, through the IAF CertSearch database, the international accreditation verification database.
FAQs
How long does ISO 27001 certification take for a small business?
Typically 4 to 6 months from gap analysis to certificate for a single-site small business with a well-defined scope.
Can ISO 27001 certification really be done in 6 weeks?
Some providers advertise timelines this fast, but they usually describe only part of the full process, often the documentation phase, not the complete journey including the ISMS operating period and audit body scheduling. A genuine 6 week finish, certificate in hand, is not realistic for most organisations.
What is the difference between Stage 1 and Stage 2 audit timing?
Stage 1 is a readiness and documentation review, usually booked 2 to 4 weeks out and taking 1 to 3 days. Stage 2, the full implementation audit, usually happens 2 to 6 weeks after Stage 1 and takes 2 to 5 days.
What happens if we fail Stage 1?
Stage 1 findings typically require remediation before Stage 2 can proceed, which can add 6 to 10 weeks to your timeline. This is exactly why a thorough internal audit and management review before Stage 1 matters.
Does having Essential 8 or SOC 2 already in place speed up ISO 27001?
Yes, significantly. Essential 8 controls map directly to many ISO 27001 Annex A controls, and SOC 2 control sets overlap heavily with ISO 27001, so organisations with existing alignment can reuse controls and evidence, reducing both cost and timeline.
Content Reviewed By
Ketki Tidke
Cyber Security and GRC Lead Auditor — ISO 27001 Lead Auditor
Ketki is a certified ISO 27001 Lead Auditor specialised in Governance, Risk and Compliance, with experience consulting public, private, and government clients. She evaluates threats, risk impacts, and regulatory requirements across multiple industry frameworks.
Get Your Timeline Estimate
Tell us about your organisation and we’ll give you a realistic, honest timeline, not a marketing number.
Get Your Timeline Estimate