
Most organizations need 6 to 12 months and roughly 288 to 481 person-days to reach ISO/IEC 27001 certification, though a lean, cloud-native team can finish in 3 to 4 months while a multi-site enterprise can run past 18. Scope is the single biggest lever on that number: the tighter you draw the boundary around what’s actually certified, the less work everything downstream requires. Before you commit to a budget or a board date, run a gap analysis or a free readiness check to see where your organization actually sits.
TL;DR:
- Smaller, cloud-native companies with a narrow scope can achieve ISO 27001 certification in three to four months with around 150 to 250 person-days.
- Most mid-size organizations need six to twelve months and approximately 288 to 481 person-days, depending on complexity and existing controls.
- Extended timelines beyond twelve months often result from regulatory requirements, multi-site operations, or broad scope involving numerous stakeholders.
- Investing in early scope narrowing, parallel work streams, and proactive evidence collection can significantly reduce project duration.
- Budgeting should consider internal labor costs, external consulting fees, certification fees, and ongoing tooling expenses, with internal effort typically totaling over 300 person-days.
Table of Contents
- How Long Does ISO 27001 Implementation Really Take?
- What Does Each Phase of Implementation Actually Cost in Effort?
- Who Does the Work: Roles and Time Allocation
- What Makes ISO 27001 Implementation Take Longer or Shorter?
- Sample Schedules by Organization Size
- What Does ISO 27001 Implementation Cost in Budget Terms?
- Why Do ISO 27001 Projects Get Delayed?
- How Do You Turn a Ballpark Estimate Into an Actual Plan?
- What I’d Prioritize First on Any ISO 27001 Project
- Get an Estimate Built Around Your Organization, Not a Generic Range
- Where to Verify These Numbers Yourself
- Sources
- FAQ
How Long Does ISO 27001 Implementation Really Take?
Timelines cluster into three bands, and the gap between them comes down to organizational complexity, not effort or willpower.
Fast track (3 to 4 months). Small, cloud native companies with modern tooling and no legacy infrastructure to untangle can move quickly. Expect somewhere around 150 to 250 person-days total, concentrated in a small core team working near full-time on the project.

Typical range (6 to 12 months). This is where most mid-size organizations land, and it lines up with what industry surveys report as the standard window. Person-day totals in this band generally fall between 288 and 481, based on activity-level estimates from implementation guides, spread across a project team rather than one or two people.
Extended timeline (12 to 18+ months). Regulated industries, multi-site operations, or organizations bolting ISO 27001 onto other frameworks (SOC 2, HIPAA, PCI DSS) routinely take longer. The person-day count climbs too, often exceeding 500, because every control needs sign-off from more stakeholders and evidence has to be collected across more environments.
Quick reference: A 2 person startup and a 2,000 employee logistics company are not solving the same problem, even though they’re both chasing the same certificate. The standard doesn’t scale effort linearly with headcount. It scales with how many systems, data flows, and third parties fall inside your scope.
A few things shrink the calendar without shrinking the internal work:
- Running risk assessment and documentation drafting in parallel instead of sequentially
- Using pre-built policy templates instead of writing every document from scratch
- Bringing in a consultant to handle project management and gap closure planning
- Choosing a narrower initial scope and expanding certification later
That last point matters more than people expect. Parallel work and templates cut calendar time, but they rarely cut the internal person-days much. Someone still has to review every policy, approve every control, and sit for every interview. Compressing the schedule mostly means compressing when the work happens, not how much of it exists.
What Does Each Phase of Implementation Actually Cost in Effort?
Breaking the project into phases turns a vague “6 to 12 months” into something you can actually staff and budget. The activity-based estimates from Messemer’s implementation guide put initial implementation at roughly 288 to 481 person-days total, with ongoing annual maintenance running another 173 to 282. Here’s how that splits across the four phases most projects move through.
Planning and preparation. This is where scope gets defined, gap analysis happens, and the Statement of Applicability takes its first draft form. Skipping or rushing this phase is the single most common reason projects run over budget later, because every downstream estimate depends on what you decide here.
- Scope definition and stakeholder alignment involves several person-days
- Gap analysis against the Annex A controls typically takes multiple person-days
- Initial SoA drafting and risk methodology setup requires sufficient time
- Project charter, budget approval materials, and kickoff require attention over multiple person-days
Implementation. This is the heaviest phase by far, because it covers both the technical controls (access management, encryption, logging, backup) and the organizational ones (policies, training, HR onboarding changes, vendor management).
- Technical control implementation and configuration requires substantial effort
- Policy and procedure documentation demands significant person-days
- Risk treatment plan execution entails focused effort
- Staff awareness training and role-specific training take dedicated time
- Internal audit program setup and first internal audit involve planned resources
Certification. Once documentation and controls are in place, the effort shifts toward proving it works. This includes selecting an accredited certification body, going through Stage 1 and Stage 2 audits, and closing out any findings.
- Auditor selection and Stage 1 preparation require several person-days
- Stage 1 audit (documentation review) usually lasts a few days on-site or remote
- Remediation of Stage 1 findings takes dedicated effort
- Stage 2 audit (operational verification) involves multiple days on-site
- Post-audit corrective actions and closure need planned resources
The ongoing effort surprises many first-time planners. ISO 27001 is not a one-time project; annual surveillance audits, management reviews, and control monitoring require continuous effort while certification is maintained.
Who Does the Work: Roles and Time Allocation
The person-day totals above don’t fall on one person’s desk. They spread across a mix of internal staff and, in most projects, at least one external party.
Internal roles typically break down like this:
- Project manager or ISO lead: Owns the timeline, chases evidence, runs status meetings. Often 30 to 50 person-days across the project, frequently the largest single internal allocation.
- Information security lead or CISO: Drives risk assessment, control design, and technical decisions. Usually 40 to 70 person-days.
- IT and systems engineers: Implement technical controls like access logging, backup verification, and endpoint management. Effort varies widely, from 30 to 80 person-days depending on how much existing tooling already meets the bar.
- HR: Handles onboarding/offboarding policy updates and training rollout, typically 5 to 10 person-days.
- Legal and compliance: Reviews vendor contracts and data processing agreements, usually 5 to 15 person-days.
A consultant can draft policies faster and flag gaps auditors will catch, but someone inside the organization still has to own execution, approve documents, and answer audit interview questions. Auditors themselves contribute fixed time. Stage 1 and Stage 2 combined usually run 4 to 8 days depending on organization size.
Fractional ownership is the most common reason “6-month” projects quietly become 14-month projects.*
Staffing patterns vary by size. Smaller organizations often run with one dedicated project owner wearing multiple hats and a part-time consultant. Mid-market companies increasingly use a fractional or virtual CISO model to get security leadership without a full-time hire, particularly for the first certification cycle. Larger organizations tend to build a small internal team supported by a consulting firm for gap analysis and audit prep, with a partner like 121 Group’s security and data guidance helping map internal capacity against what the project actually demands.

What Makes ISO 27001 Implementation Take Longer or Shorter?
A handful of variables explain almost all the spread between a 3-month project and an 18-month one.
- Scope boundaries. Certifying one product line or business unit instead of the entire company cuts effort dramatically. Every additional system, office, or data flow inside scope adds controls to implement and evidence to collect.
- Existing security posture. A company already running SSO, centralized logging, and encrypted backups is halfway there before the project starts. Legacy infrastructure with fragmented access controls adds weeks of remediation work.
- Third-party and supply-chain coverage. If your Statement of Applicability includes vendor risk management for dozens of suppliers, expect real time spent chasing security questionnaires and contract updates.
- Regulatory overlays. Running ISO 27001 alongside HIPAA, PCI DSS, or GDPR obligations means mapping overlapping controls, which some auditors expect documented explicitly.
- Governance bottlenecks. Board approval cycles and change-control processes that take weeks rather than days quietly add months to a project that otherwise looks fast on paper.
Test these five variables early. They matter more to your actual timeline than any generic benchmark.
Sample Schedules by Organization Size
These three schedules aren’t universal, but they map closely to how real projects unfold once scope and resourcing are set.
- Fast-track SMB (3 to 4 months). Weeks 1 to 2: scope definition and gap analysis. Weeks 3 to 6: parallel policy drafting and technical control implementation. Weeks 7 to 10: internal audit and remediation. Weeks 11 to 14: Stage 1 and Stage 2 audits back to back. This works only with a narrow scope and a team already using modern cloud tooling.
- Typical SMB or mid-market (6 to 9 months). Month 1: scoping and gap analysis. Months 2 to 4: control implementation and documentation, run sequentially by domain to avoid overwhelming a small team. Month 5: internal audit and management review. Month 6: Stage 1 audit and remediation. Months 7 to 9: Stage 2 audit and certification issuance.
- Staged enterprise rollout (12 to 18 months). Months 1 to 3: pilot scope on one business unit, with lessons captured for the wider rollout. Months 4 to 9: expand controls and documentation across remaining scope. Months 10 to 12: internal audits across all units and evidence consolidation. Months 13 to 15: Stage 1 audit. Months 16 to 18: Stage 2 audit and certification.
Book your internal audit and your Stage 1 audit date early, regardless of which schedule you’re running. A fixed date on the calendar is what actually keeps documentation deadlines from sliding, according to preparation guidance for ISO 27001 certification. For technology and SaaS teams specifically, a practical implementation guide for tech companies can help translate these generic phases into your actual stack.
What Does ISO 27001 Implementation Cost in Budget Terms?
Person-days only become a budget number once you attach a labor rate to them. A fully loaded internal hourly rate for security or IT staff typically runs $75 to $150 depending on role and region, which means 300 person-days of internal effort can translate into $180,000 to $360,000 in absorbed labor cost, even before any external spend.
Budget in four buckets:
- Internal labor. The largest hidden cost, since salaried staff time rarely shows up as a separate line item until someone calculates it.
- Consultant fees. Engagements typically range from a few thousand dollars for light gap-analysis support to well over $50,000 for full-service project management on larger scopes, depending on how much of the implementation work the consultant actually performs versus advises on.
- Certification body fees. Initial certification audits (Stage 1 plus Stage 2) commonly run several thousand to tens of thousands of dollars depending on organization size, with annual surveillance audits adding recurring cost every year the certificate stays active.
- Tooling. GRC platforms, vulnerability scanners, and evidence-collection software add ongoing subscription cost, often modest compared to labor but easy to forget in early budget drafts.
Between organizations that self-implement with internal staff and those that lean on consultants, total internal effort tends to land in a similar range even when calendar time differs, so don’t assume a consultant engagement eliminates the need for internal hours in your budget.
Why Do ISO 27001 Projects Get Delayed?
Most schedule slippage traces back to a short list of repeat offenders, and each has a fairly direct fix.
- Board and approval delays. Waiting weeks for sign-off on policies or budget stalls everything downstream. Bring decision-ready materials to leadership, meaning a summary, a recommendation, and a deadline, rather than an open-ended request for input.
- “No evidence” nonconformities. Auditors flag controls that exist in policy but have no proof of operation. Build evidence collection into weekly routines from month one instead of scrambling to reconstruct six months of logs right before Stage 2.
- Scope creep. Adding “just one more system” mid-project resets gap analysis work and pushes the timeline. Consider certifying a narrower scope first and expanding in a later cycle instead of trying to cover everything at once.
- Staff turnover. Losing your ISO project lead midway through is one of the most damaging events a project can absorb. Document decisions and control ownership as you go, not just at handoff, so a replacement isn’t starting from zero.
Pro Tip: Treat evidence collection like a recurring calendar task, not a pre-audit sprint. Screenshots, access logs, and meeting minutes are worth ten times more when they’re dated across the actual review period than when they’re generated the week before Stage 2.
A checklist of frequent implementation mistakes covers several more failure patterns worth reviewing before you finalize a project plan.
How Do You Turn a Ballpark Estimate Into an Actual Plan?
A generic 6 to 12 month range is a starting point, not a plan. Converting it into something you can take to leadership requires organization-specific inputs, and that’s exactly what a tool like the ISO 27001 Cost Calculator is built to do.
The calculator adjusts its person-day and cost estimate based on three inputs that matter more than any generic benchmark: your company size, your industry, and your current security maturity across the four Annex A control themes. A financial services company with mature access controls gets a very different number than a healthcare startup with none of the groundwork laid, even at the same headcount.
A few ways to put this into practice:
- Run the free 2-minute readiness check first to get a directional sense of where gaps sit before committing to a full assessment.
- Use the maturity assessment across the four Annex A control themes to see which control families need the most work, rather than treating every domain as equally behind.
- Export the resulting estimate as a customizable Gantt chart to hand to a project sponsor, turning an abstract range into a dated schedule.
- Compare your estimate against model reference comparisons to sanity-check whether your projected timeline is realistic or optimistic.
- Save multiple scenarios (narrow scope versus full scope, self-implemented versus consultant-assisted) side by side before committing to one.
That last point matters most for budget conversations. Leadership rarely pushes back on a single number as much as they push back on a number with no visible alternative attached to it.
What I’d Prioritize First on Any ISO 27001 Project
If I had to compress everything above into three moves, they’d be these. First, narrow your scope aggressively, even to the point of a pilot business unit, before you touch a single policy template. Every hour spent implementing controls for systems that don’t need to be in scope is an hour you can’t get back. Second, build evidence collection into your team’s weekly routine from day one rather than treating it as a pre-audit scramble; auditors trust dated, incremental evidence far more than a folder assembled the week before Stage 2. Third, book your Stage 1 audit date the moment you have a rough implementation timeline, even if it feels premature. A date on the calendar does more to keep a project moving than any amount of internal pressure or good intentions. None of this is complicated advice. It’s just the difference between projects that hit their target month and the ones that quietly slip past it.
— Martin
Get an Estimate Built Around Your Organization, Not a Generic Range
Every range in this article is a starting point. Your actual number depends on your scope, your existing maturity, and your industry, which is exactly what the ISO 27001 Cost Calculator is built to calculate in real time.

Instead of guessing where your organization falls between “fast track” and “extended timeline,” run your numbers through a calculator that adjusts for company size, industry, and maturity across the four Annex A control themes, then compares your result against real model reference comparisons. If you want a structured starting point, the ISO 27001 Readiness Assessment walks through a full gap analysis. If you’d rather get a directional read first, the free 2-minute check takes almost no setup. These tools let you save and compare scenarios, and export a Gantt-style plan you can hand straight to a budget approver. Start with the free check, then decide how deep your project actually needs to go.
Where to Verify These Numbers Yourself
The ISO/IEC 27001 standard itself remains the authoritative reference for scope, required documentation, and the Statement of Applicability. For control selection and risk assessment techniques that map cleanly onto Annex A, the NIST Computer Security Resource Center offers practical guidance many implementers use alongside the standard. For the activity-level person-day breakdowns cited throughout this article, the detailed implementation and resource planning guide provides the underlying methodology.
Sources
- ISO/IEC 27001 information security standard
- NIST Computer Security Resource Center
- ISMS implementation guide according to ISO 27001 with effort and resource planning
FAQ
How Do You Implement ISO 27001 Step by Step?
The core sequence runs: scope definition, gap analysis, risk assessment, control implementation, documentation and the Statement of Applicability, internal audit, management review, then Stage 1 and Stage 2 certification audits. A step-by-step certification checklist breaks each stage into specific tasks you can assign to owners.
How Long Does It Take to Achieve ISO 27001 Certification?
Most organizations take 6 to 12 months, based on industry-reported timelines, though a small cloud-native team can finish in 3 to 4 months and a large regulated enterprise can take 18 months or more. Scope and existing security maturity drive most of that variation.
Is There an ISO 27001 Exam?
There is no exam for the organization itself. Certification comes from passing Stage 1 and Stage 2 audits conducted by an accredited certification body. Individuals can pursue separate personal certifications like Lead Auditor or Lead Implementer, but those are distinct from organizational certification.
What Is the ISO 27001 Implementation Certification Process?
It runs in two audit stages: Stage 1 reviews your documentation and readiness, and Stage 2 verifies that controls actually operate as documented, typically through interviews and evidence review. Passing both stages results in a certificate valid for three years, with annual surveillance audits required to maintain it.
How Many Person-Days Does ISO 27001 Implementation Typically Require?
Initial implementation commonly totals 288 to 481 person-days across planning, implementation, and certification phases, with ongoing annual maintenance adding another 173 to 282 person-days. Running your specifics through the ISO 27001 Cost Calculator narrows that range to your actual scope and maturity level.