Zum Inhalt springen
Grundlagen
12 Min. Lesezeit

12 Week or 6–10 Month ISO 27001 Project Milestones: Book Stage 2 First

support@ismscalculator.com|

Auditor reviewing ISO certification evidence

Fast implementations run 3 to 4 months, typical first-timers take 6 to 10 months, and complex or multi-site rollouts often run 9 to 18 months. Whatever band you land in, the schedule hinges on one rule: fix your Stage 2 audit date first, then work backward, booking Stage 1 four to six weeks earlier and finishing your internal audit and management review before that. Everything else, gap analysis, risk assessment, control rollout, gets scheduled around those two anchor points.


TL;DR:

  • Keeping the Stage 2 audit date fixed first allows scheduling Stage 1 four to six weeks earlier and ensures internal audits are completed beforehand.
  • Completing risk assessments and signing off the Statement of Applicability must occur before documenting controls and evidence collection.
  • Larger or multi-site projects extend timelines up to 9 to 18 months, mainly due to scope size, control maturity, and owner availability.
  • Fast implementations with a dedicated full-time owner and tight scope can be completed in 3 to 4 months; first-time efforts typically take 6 to 10 months.
  • Building an organized evidence folder for each control and scheduling evidence collection early reduces last-minute scrambling and accelerates certification.

Ismscalculator
Estimate Your ISO 27001 Timeline
Get a tailored implementation estimate based on your company size, industry, and security maturity before committing to project milestones.
Calculate your estimate

Table of Contents

What Are the Key ISO 27001 Project Milestones and Phases?

Every ISO 27001 certification process moves through the same sequence, whether you finish in 12 weeks or 18 months. The order doesn’t change; only the time spent inside each phase does.

1. Project setup and scoping. You need a charter, a written scope statement, and a named project owner before anything else starts. Skip this and you’ll spend month three arguing about whether the sales team’s laptops are in scope.

2. Gap analysis. This establishes your baseline against ISO/IEC 27001:2022’s clauses 4 through 10, which cover context, leadership, planning, support, operation, evaluation, and improvement. The output is a gap report with prioritized actions, not a vague sense of “we’re mostly okay.”

3. Risk assessment and Statement of Applicability (SoA). You build an asset register, run a risk assessment against your chosen methodology, then produce the SoA justifying which Annex A controls apply and which don’t. This is a gating deliverable: you cannot finalize your SoA until the risk register is complete, and you cannot finalize control implementation until the SoA is signed off.

4. Documentation and control implementation. Policies, procedures, and technical controls get built and mapped directly to SoA entries. This is usually the longest phase because it involves actual operational change, not paperwork.

5. Operate and collect evidence. Controls need to run long enough to produce real records: access reviews, incident logs, change logs, training completions. Certification bodies expect to sample this evidence, and it’s the one phase you cannot compress by adding people.

6. Internal audit and management review. A formal internal audit under Clause 9.2 and a documented management review under Clause 9.3 are mandatory milestones. Auditors want to see the ISMS functioning as an improvement loop, not just a binder of policies, before certification proceeds.

7. Stage 1 and Stage 2 audits. Stage 1 is largely a documentation review checking that your ISMS is designed correctly and ready for assessment. Stage 2 tests whether it actually operates as documented, and auditors generally expect Stage 2 within six months of Stage 1.

What Are the Key ISO 27001 Project Milestones and Phases? — overview diagram

ISO 27001 Milestones Checklist: What Evidence Do Auditors Expect?

Auditors don’t grade intentions. They grade evidence, and each milestone above needs a specific artifact behind it before you book an audit date.

  • Scope and charter: signed scope statement naming systems, locations, and exclusions
  • Asset inventory: a maintained register of information assets with owners assigned
  • Risk register: documented risks, treatment decisions, and residual risk ratings
  • Statement of Applicability: every Annex A control marked applicable or excluded, with justification
  • Policy sign-off: dated approval records for information security policy and supporting policies
  • Implemented control evidence: configuration screenshots, access logs, firewall rules, encryption settings tied to specific SoA entries
  • Training records: completion logs showing staff awareness training happened, not just that it was planned
  • Internal audit report: findings, nonconformities, and corrective actions from the Clause 9.2 audit
  • Management review minutes: dated meeting records showing leadership reviewed ISMS performance under Clause 9.3

Sequencing matters as much as the list itself. Risk assessment has to finish before the SoA, the SoA has to exist before you can point to “implemented” controls, and the internal audit plus management review both need to happen before Stage 1, not squeezed in between Stage 1 and Stage 2. Auditors have seen every shortcut attempt, and a management review dated three days before Stage 1 reads as exactly what it is.

Pro Tip: Build one evidence folder per SoA control, named after the control number, and drop every artifact for that control into it as you go. When Stage 1 arrives, you hand the auditor a mapped folder structure instead of scrambling through email threads at 11pm the night before. For a fuller breakdown of every deliverable, the ISO 27001 certification checklist walks through all 80 steps in sequence.

ISO controls mapped to evidence artifacts

How Should You Schedule Stage 1 and Stage 2 Audits?

Work backward from your certification target, not forward from your kickoff date. Planning forward from day one is how teams end up with a Stage 2 date that quietly slides three times.

  1. Pick your Stage 2 date first. This is the date you actually need the certificate by, driven by a client contract, a tender deadline, or a board commitment.
  2. Schedule Stage 1 four to six weeks earlier. This gap gives you room to close any observations Stage 1 raises before Stage 2 arrives.
  3. Place your internal audit and management review before Stage 1, not squeezed against it. Both need to be genuinely complete, with signed minutes and a closed-out audit report, before the certification body walks in.
  4. Set your evidence/operating period as a fixed input, not a variable. You can accelerate writing policies. You cannot accelerate three months of access-review logs that don’t exist yet.
  5. Build a remediation buffer after Stage 1. Stage 1 usually surfaces observations rather than major nonconformities, and projects that schedule a 4 to 6 week window to close them almost always clear Stage 2 on the first attempt.

This backward-planning method has a useful side effect: it exposes bad assumptions immediately. If working backward from your Stage 2 date puts your kickoff in the past, your target date is wrong, not your plan. That’s a cheap thing to learn in week one instead of month eight. It’s also worth confirming certification body availability early. Booking slots fill up, and a body that can’t schedule Stage 1 for ten weeks will wreck a tight timeline regardless of how disciplined your internal work is.

How Long Does ISO 27001 Certification Actually Take?

Three bands cover almost every real-world project, and the difference between them isn’t luck. It’s scope discipline and resourcing.

  • Fast (3 to 4 months): Small organization, tightly bounded scope, an existing security baseline, and a dedicated owner working on this full time.
  • Typical (6 to 10 months): First-time implementation, moderate scope, an owner splitting time with other duties, and documentation built mostly from scratch.
  • Slow (9 to 18 months): Multi-site or multi-entity scope, low starting security maturity, shared ownership across several people, or a highly regulated environment requiring extra control depth.

Organizations that scope tightly at the start, assign realistic dedicated time, and resist scope creep during build correlate with 30 to 50% faster implementations than teams that let scope drift.

The variables that move you between bands are predictable. Scope size is the biggest one: certifying one product line is a different project than certifying five subsidiaries. Existing control maturity matters almost as much. A company already running decent access management and logging is halfway there before the project even starts. Owner FTE allocation is the quiet killer. An ISMS owner juggling this alongside a full IT workload will stretch a 6 month project into 12 without anyone noticing until the calendar says so.

If you want to shorten your timeline, the levers are concrete. Tighten scope before you start rather than mid-project. Use documentation templates instead of drafting every policy from a blank page. Dedicate real hours, not “when I get to it” hours, to the ISMS owner role. And start operating your controls early, since the evidence window is the one phase that punishes procrastination without mercy.

Sample ISO 27001 Project Timelines You Can Copy

Two schedules cover most planning needs: an aggressive 12-week sprint for small, well-prepared scopes, and a realistic 6 to 10 month plan for typical first-time implementations.

The 12-week accelerated plan assumes a small scope, an existing security baseline, and a dedicated owner:

  1. Weeks 1 to 2: Scoping, charter, gap analysis complete
  2. Weeks 3 to 4: Risk assessment and draft SoA
  3. Weeks 5 to 7: Policy and control implementation against SoA entries
  4. Weeks 8 to 9: Operate controls, begin evidence collection, run staff training
  5. Week 10: Internal audit and management review, both fully documented
  6. Week 11: Stage 1 audit
  7. Week 12: Remediation of any observations, final evidence collection, Stage 2 booked for the following weeks

The 6 to 10 month realistic plan stretches the same phases with a longer evidence window: months 1 to 2 cover scoping and gap analysis, months 2 to 4 cover risk assessment, SoA, and control build, months 4 to 7 cover operating the controls and collecting genuine evidence, month 7 or 8 covers internal audit and management review, and Stage 1 lands in month 8 or 9 with Stage 2 four to six weeks later.

Adapt either plan to your reality. Part-time owners should roughly double the 12-week plan rather than try to compress a full-time schedule into fewer hours. Multi-site organizations need extra weeks in the risk assessment and evidence phases to account for site-by-site variation. For a deliverable-by-deliverable version of the fast plan, the 12-week ISO 27001 project plan breaks down each week’s outputs in more depth.

How Do You Validate Your Timeline Before You Commit to It?

A sample schedule is a starting point, not a guarantee your organization fits it. Ismscalculator’s ISO 27001 Cost Calculator gives you a real-time, organization-specific estimate based on your company size, industry, and current security maturity, so you can pressure-test whether “6 months” is realistic for your actual scope before you promise it to leadership.

  • Run the free 2-minute readiness check to get a quick maturity snapshot without signing up first.
  • Compare your assumptions against model reference comparisons across all four ISO/IEC 27001:2022 control themes to spot where your plan underestimates effort.
  • Export a customizable Gantt chart and lay it against one of the sample plans above to see where your timeline actually diverges.
  • Save and compare multiple estimates if you’re weighing a lean scope against a broader one before locking your charter.

Pairing project tooling with meeting discipline also helps here. Platforms like Segua are built around keeping project requirements and recurring meetings tied together, which matters when your milestone review cadence is the thing keeping a 10 month plan from drifting to 14.

What Most Teams Get Wrong About ISO 27001 Scheduling

The mistakes are predictable: vague scope statements nobody can defend to an auditor, ISMS ownership split across three people so nobody actually owns it, and evidence windows treated as flexible when they’re the one part of the schedule that isn’t. The mantra worth pinning above your desk is simple. Set Stage 2, work backward, protect the operating window. Everything else in the project bends around those three moves.

— Martin

FAQ

What Is the ISO 27001 Checklist?

An ISO 27001 checklist is the sequence of deliverables auditors expect to see: scoping documents, gap analysis, risk register, Statement of Applicability, implemented controls mapped to that SoA, training records, an internal audit report, and management review minutes. The certification checklist breaks this into a full step-by-step list.

What Are the 10 Clauses of ISO 27001?

ISO/IEC 27001:2022 has 10 clauses, but only clauses 4 through 10 carry mandatory requirements: context, leadership, planning, support, operation, performance evaluation, and improvement. Clauses 1 through 3 cover scope, references, and terms, and don’t impose obligations on their own, per the ISO 27001 standard.

What Is Stage 1 and Stage 2 Audit in ISO?

Stage 1 is a documentation review checking whether your ISMS is designed correctly and ready to be assessed. Stage 2 tests whether that ISMS actually operates as documented, using evidence like logs, records, and interviews, and is typically scheduled within six months of Stage 1.

What Are the Key Steps Involved in Implementing ISO 27001?

The core steps are scoping and gap analysis, risk assessment and Statement of Applicability, documentation and control implementation, operating those controls long enough to generate evidence, then completing an internal audit and management review before Stage 1 and Stage 2 audits. Each step feeds directly into the next, so skipping ahead usually means redoing work later.

How Long Does It Take to Get ISO 27001 Certified?

Fast, well-prepared implementations take 3 to 4 months, typical first-time projects take 6 to 10 months, and complex or multi-site rollouts often run 9 to 18 months. The 12-week project plan shows what the fast end of that range actually looks like week by week.

Bereit, Ihre ISO 27001-Kosten zu schätzen?

Nutzen Sie unseren kostenlosen Rechner für eine maßgeschneiderte Kosten-, Aufwands- und Zeitplanschätzung basierend auf Ihrem Unternehmensprofil.

Schätzung berechnen — kostenlos
Zurück zu allen Artikeln