The path is fixed — gap assessment, implementation, internal audit, then Stage 1 (a documentation review) and Stage 2 (interviews and evidence). Implementation is the long phase, and its length is set by how many of the 93 Annex A controls you already run. Small, single-cloud companies with security operations already running move fastest.
Every certification follows the same path in the same order. The length of each phase varies widely, and is set by your starting posture rather than by the standard.
| Phase | What happens | What sets its length |
|---|---|---|
| Gap assessment | Your current state is measured against the 93 Annex A controls and the management-system clauses | Shortest phase. Set by access: how quickly people can demonstrate what runs in production |
| Implementation | Risk assessment, Statement of Applicability, policies, and the controls themselves — including the operational ones: logging, monitoring, vulnerability management | The longest phase in most engagements. Set by how many of the 93 controls you already run, and by how long the new ones need to operate before they have produced evidence |
| Internal audit & management review | Someone independent of the implementation checks the ISMS; management formally reviews it | Short, though it cannot start until there is something to audit, and its findings feed back into implementation |
| Stage 1 | The certification body reviews your documentation and confirms readiness for Stage 2 | Certification-body scheduling, plus how cleanly your documentation maps to the standard |
| Stage 2 | Interviews and evidence: the auditor talks to your people and samples records to confirm controls operate | The audit itself is sized to your organisation; the wait before it is set by Stage 1 findings and the body’s calendar |
Most plans omit the interval between a control being implemented and that control being evidenced. An access-review process adopted this week has one review on record. A monitoring control switched on yesterday has a day of history. Stage 2 auditors sample records, so new controls need operating time before the audit, and that time sits inside the implementation phase.
That interval is why implementation dominates the calendar. Policies and the Statement of Applicability are days of work for someone who knows the standard. Getting 93 controls assessed, the applicable ones running, and the running ones evidenced is the work that consumes months, in proportion to the starting gap.
Certification bodies also book ahead, which makes the Stage 1 date a planning input rather than a final task. Booking it during implementation both secures the slot and gives the internal work a fixed deadline.
The timeline continues past the certificate: surveillance audits annually, full recertification every three years. Whatever pace gets you certified, the system has to run at a sustainable one afterwards.
Two companies of the same size can land far apart on the calendar, on concrete differences.
Faster: one cloud environment and little else in scope. A small headcount, producing fewer Stage 2 interviews, fewer accounts to review and fewer laptops to manage. Security operations already running — logging, monitoring and vulnerability management cover a large share of Annex A’s technological controls, and where they are live the project starts with evidence rather than a to-do list. One decision-maker who can approve a policy the day it is drafted.
Slower: multiple sites or a hybrid cloud-and-office estate. Tool sprawl from growth or acquisitions, where the scope is unknown until the gap assessment establishes it. No existing operational controls, so everything needs building and then operating before it counts. And part-time ownership, which is the most common cause of drift: where the person driving certification also ships product, implementation stalls in two-week increments and the calendar moves without a decision being taken.
Ownership is therefore the first constraint to address where a deal is waiting on the certificate. The phases cannot be reordered, and implementation compresses sharply once someone owns it full-time, whether that is your hire or your provider. What ISO 27001 costs in Australia covers the rest, because the options differ in price in proportion to how much of implementation they take off your team.
Planning the timeline around audit duration misreads where the time goes. The audit is the short phase; implementation and evidence accumulation set the date.
The common shortcut fails for the same reason. A policy-template pack compresses the writing, and the writing is not the long phase. Stage 2 is interviews and evidence: the auditor asks an engineer how access reviews work, then asks for the last one. Moving the certificate date forward requires starting the operational controls early, so they are producing evidence while the documentation catches up.
Most tools hand you a to-do list; we do the list and run the security behind it. On a timeline that ordering matters: we stand up the operational controls first, so logging, monitoring and vulnerability management accumulate evidence while the governance and ISMS build runs alongside, and we hold you to a Stage 1 date booked early. The certification audit itself is performed by an accredited certification body; our work is getting you in front of it ready. Book a readiness call for a timeline scoped to your gap.
What's the longest phase of ISO 27001 certification?
Implementation. Gap assessment, internal audit and the two audit stages are each short by comparison. Implementation runs as long as it takes to close your gap against the 93 Annex A controls, and for the new controls to operate long enough to produce evidence an auditor can sample.
Can policy templates make certification faster?
They shorten the writing, which is not the long phase. Stage 2 covers interviews and evidence: the auditor checks that controls operate rather than that documents exist. A template pack without operating controls behind it moves the certificate date very little.
What's the difference between Stage 1 and Stage 2?
Stage 1 is a documentation review — the certification body checks your ISMS paperwork and confirms readiness. Stage 2 covers interviews and evidence — the auditor talks to your people and samples records to confirm the controls operate.
When should we book the certification body?
During implementation. Certification bodies schedule ahead, and a fixed Stage 1 date converts the implementation plan into a deadline.
Does the timeline end at certification?
No. Surveillance audits run annually, and full recertification comes every three years. The system has to keep producing evidence between audits, so ownership of it needs to extend past the certificate date.
Does company size change the timeline?
Yes, mostly through scope. More people produces more interviews at Stage 2, more systems in scope, more access to review and more evidence to produce. A small single-cloud company has structurally less to implement and less to audit.