Guide · Updated July 2026

The ISO 27001 timeline

The ISMS needs a history.

The ISO 27001 timeline has a hidden constraint SOC 2 doesn’t: the management system must have operated before anyone will certify it. Records need dates, and dates need calendar.

The phases

ISMS build (6–10 weeks). Scope, risk methodology, the risk assessment, the Statement of Applicability, policies, and control implementation. Parallelizable with automation and hands; this is where done-with-you compresses hardest.

Operating period (6–8 weeks minimum, running through everything). The loop turns for real: controls operate, evidence accrues, incidents get handled per procedure. Certification bodies read record dates at Stage 2 — an ISMS whose every artifact is dated the week before fieldwork tells its own story, badly.

Internal audit + management review (2–3 weeks). The full internal audit, corrective actions opened and closed, and a management review with actual decisions minuted. These are the records Stage 2 samples first.

Stage 1 (1–2 weeks elapsed). Documentation review. Findings here are your cheap fixes — take them seriously.

Stage 2 (2–4 weeks elapsed). Implementation audit with evidence sampling. Pass, receive the certificate, calendar the surveillance audits for years two and three.

Planning backwards

Certificate needed for a deal? Count back 4–6 months. The irreducible core is the operating period plus the two-stage audit — everything before it compresses with effort; the middle only compresses with dishonesty, and that gets expensive at Stage 2. Already SOC 2 audit-ready? Cut the build phase substantially: the one-control-set strategy means you’re adding ISMS machinery to a running program, not starting cold.

Frequently Asked
What's the fastest credible path to the certificate?

Around 4 months with an owner, automation, and an experienced guide: 6–8 weeks of ISMS build, several weeks of genuine operation, internal audit and management review, then Stage 1 and Stage 2. Promises meaningfully faster than that usually mean a rubber-stamp internal audit — which Stage 2 auditors are specifically trained to catch.

Why can't we go straight to Stage 2?

Stage 1 reviews your documentation and readiness; certification bodies require it and use it to plan Stage 2. Treat it as a paid rehearsal — Stage 1 findings are cheap to fix, Stage 2 nonconformities are not.

How long between Stage 1 and Stage 2?

Typically 4–8 weeks — enough to close Stage 1 findings. Longer gaps (over 6 months) can force a Stage 1 repeat, so book both stages as one plan.

Related Guides

What ISO 27001 costs — What ISO 27001 really costs — certification body fees, platform, internal audit, and the ISMS labor — with the surveillance-year costs quotes leave out.

SOC 2 vs ISO 27001 — SOC 2 vs ISO 27001 compared on buyer expectations, cost, timeline, and structure — with the decision rule by market, and when to run both on one control set.