Ga naar de inhoud
Basisprincipes
10 min leestijd

90–900+ Person Days for ISO 27001: Ranges and Workstreams

support@ismscalculator.com|

ISO 27001 implementation effort planning session

Budget 90 to 180 person-days for a small organization, 200 to 400 for a mid-size company, and 450 to 900 or more for a large or complex enterprise. These corridors assume moderate starting maturity and a single-site scope; low maturity or multi-site environments push you toward the top of each range. Run a tailored readiness check before you commit a budget number, then use the breakdown below to see where those days actually go.


TL;DR:

  • Scope and organizational maturity significantly influence total effort, with multi-site or regulated data environments requiring many more person-days.
  • Controls implementation and evidence gathering are the most time-consuming workstreams, often accounting for up to half of the total effort.
  • A typical first-time ISO 27001 project takes around nine months, but evidence collection and owner availability mostly determine the calendar duration.
  • Internal effort usually amounts to 0.3 to 0.6 full-time equivalents over the project, making dedicated ownership and internal scheduling critical for success.
  • Using tools like readiness checks and effort calculators can help produce more accurate, defendable budgets tailored to your company’s size and maturity.

Ismscalculator
Estimate Your ISO 27001 Effort
Get a tailored estimate based on your company size, industry, and security maturity before committing to an implementation budget.
Calculate your estimate

Table of Contents

How Many Person-Days Does ISO 27001 Take by Size and Maturity?

The honest answer depends on two variables that matter far more than headcount alone: how many employees touch information assets, and how mature your existing security controls already are. A 40-person software company with documented access controls and an existing SOC 2 report will burn through far fewer person-days than a 40-person manufacturer starting from a blank folder.

Three size bands cover most implementations:

  • Small organizations (up to 50 employees): 90 to 180 person-days total. Low maturity (no formal policies, ad hoc access management) sits near 180. High maturity (existing frameworks like SOC 2 or a documented security program) can land closer to 90.
  • Mid-size organizations (50 to 250 employees): 200 to 400 person-days. This band sees the widest swing because scope varies most here, one department versus the whole company, one office versus three.
  • Large organizations (250-plus employees): 450 to 900-plus person-days. Multi-site operations, multiple business units, or regulated data types (health records, payment card data) routinely push past 900.

Scope is the multiplier that catches people off guard. A single-site company certifying one product line stays near the low end of its band. Add a second office, a subsidiary, or a “certify everything” mandate from leadership, and the ISO 27001 project timeline stretches accordingly, because every additional site usually means separate risk assessments, separate evidence collection, and separate staff training.

Maturity is the second lever. Organizations with an existing quality management system, prior compliance work (HIPAA, PCI DSS, SOC 2), or a security-literate IT team routinely finish at the bottom of their band. Organizations building an information security management system (ISMS) from zero, with no risk register, no asset inventory, and no documented incident process, should plan for the top.

Pro Tip: Don’t average your organization against “typical company size.” A 90-person company with three international offices behaves like a large-org estimate, not a mid-size one. Scope, not headcount, decides which band you’re really in.

ISO 27001 person-day estimate drivers

Where Do the ISO 27001 Man Days Actually Go?

Total effort splits across eight workstreams, and the split rarely looks like people expect. Documentation gets the reputation, but risk assessment and evidence collection usually eat more calendar time.

  1. Planning and scoping (5 to 10% of total days). Defining ISMS boundaries, appointing an owner, and securing management commitment. Owned by the compliance lead or IT manager, front-loaded into month one.
  2. Risk assessment (15 to 20%). Identifying assets, threats, and vulnerabilities, then scoring and treating each risk. Owned jointly by IT and compliance; this is where under-resourced projects stall.
  3. Documentation (15 to 20%). Policies, procedures, the Statement of Applicability, and the risk treatment plan. Compliance-owned, but it requires input from every department that appears in a policy.
  4. Controls implementation (20 to 25%). Technical and organizational controls across the 93 controls in Annex A, from access management to vendor security reviews. This is the largest single workstream and the one most likely to involve IT, HR, and facilities simultaneously.
  5. Training and awareness (5 to 8%). Building ISO 27001 training hours into onboarding and running annual refreshers for existing staff.
  6. Evidence collection (10 to 15%). Gathering logs, screenshots, and records that prove controls actually operate, not just exist on paper.
  7. Internal audit (5 to 8%). A dry run against the standard before the certification body shows up, ideally performed by someone outside the implementation team.
  8. Management review and remediation (5 to 10%). Closing gaps the internal audit surfaces, plus the formal leadership review ISO 27001 requires.

The hidden time sinks live in workstreams four and six. Vendor security reviews multiply fast once you start counting every SaaS tool with access to customer data, and evidence formatting (turning raw logs into audit-ready documentation) consistently takes longer than teams budget. A well-defined project plan and a dedicated internal owner shortens nearly every workstream above, according to ISACA’s implementation guidance, because ambiguity about ownership is what stalls risk assessment and controls work in the middle of a project.

How Long Does an ISO 27001 Project Actually Take?

Person-days and calendar months are not the same thing, and the gap between them trips up more budgets than the day count itself. A 9-month baseline is realistic for a first-time implementation at moderate maturity, according to Xiligent’s certification timeline research, and it maps loosely to three planning scenarios:

  • Fast track (5 to 6 months): Requires a nearly full-time internal owner and existing evidence to reuse from a prior framework like SOC 2. Matches the low end of each size band’s person-day range.
  • Typical (8 to 10 months): A part-time owner splitting attention across ISO 27001 and other duties, moderate starting maturity, single-site scope.
  • Conservative (12 to 18 months): Low maturity, multi-site scope, or an owner juggling the ISMS alongside a full existing job.

The gating factor most teams underestimate is the operating evidence period. Certification bodies typically want the ISMS running for about three months before the Stage 2 audit, per Konfirmity’s audit timeline research, so you cannot compress that window by adding more people. Stage 1 and Stage 2 audits themselves run just days, one to three for document review, three to seven for the implementation audit. Calendar duration is decided by evidence accumulation and owner availability, not auditor scheduling.

Self-Managed, Hybrid, or Fully Managed: Which Model Fits?

The delivery model you choose changes internal person-days more than almost any other decision in the project.

  • Self-managed (DIY): Highest internal burden, often 150 to 250 additional internal person-days beyond baseline, according to Reepa Solutions’ cost analysis, since your team absorbs every workstream with no outside expertise to shortcut risk assessment or documentation.
  • Hybrid (internal owner plus consultants): Roughly 80 to 150 internal days plus 20 to 40 consultant days. Consultants typically take over documentation templates and audit preparation, while your team still owns risk assessment and controls implementation, since that requires institutional knowledge no outsider has.
  • Fully managed: Lowest internal day count, but the highest external spend. Works best when internal security skills are thin and speed matters more than long-term cost.

Choose based on three factors: whether you have in-house security expertise, whether budget favors internal salaries over consultant invoices, and whether leadership needs certification by a fixed date. A tool like Segua can reduce the meeting overhead that eats into person-day budgets under any model, particularly when risk assessment and controls work span multiple departments.

Turn These Ranges Into a Number for Your Organization

Generic corridors get you in the right neighborhood. A tailored estimate gets you a number you can defend to a CFO. The ISO 27001 Cost Calculator generates real-time person-day and cost projections based on your actual company size, industry, and security maturity, rather than a generic band.

  • A maturity assessment covering multiple control areas to help indicate which areas may influence your effort.
  • Tools that offer customizable project timelines to help convert your person-day estimate into an implementation plan.
  • Features to save and compare multiple scenarios, useful for weighing different implementation approaches.
  • Options to export reports for board or budget presentations.
Starting point Best next step
Not sure where you stand on maturity Free 2-minute readiness check
Ready for a detailed budget number Full cost and effort calculator
Want to understand the model’s assumptions Cost model methodology

Run the readiness check first if you’re still scoping the project. Move to the full calculator once you know your size band and rough maturity level.

What Actually Sinks ISO 27001 Budgets

Most failed ISO 27001 timelines don’t fail because the estimate was wrong. They fail because the internal person-days were never protected as real work capacity. Teams treat the ISMS as something staff will “fit in around” their actual jobs, and then act surprised when risk assessment stalls for six weeks because nobody had two consecutive free days to finish it.

What Actually Sinks ISO 27001 Budgets — overview diagram

Two rules matter more than any spreadsheet. First, assign a dedicated ISMS owner as early as possible, even part-time, because projects with a nearly full-time owner who reuses existing compliance evidence finish in a fraction of the baseline timeline. Availability, not headcount, is the biggest accelerator anyone controls. Second, budget internal time as your largest line item, not an afterthought squeezed around vendor invoices. Internal effort routinely runs 0.3 to 0.6 FTE across the certification year in SME cases, a cost that never appears on an invoice but sinks more projects than any consulting fee.

For the next 30 days: confirm your scope, name an owner, run the readiness check, and do a quick gap scan against your existing policies.

— Martin

Sources

FAQ

How many person-days does ISO 27001 typically require?

Small organizations typically need 90 to 180 person-days, mid-size organizations 200 to 400, and large organizations 450 to 900 or more, depending on scope and starting maturity. Multi-site operations and regulated data types push toward the top of each range.

What is the biggest driver of ISO 27001 man-day estimates?

Scope and starting maturity matter more than company size. A single-site company with existing compliance frameworks (like SOC 2) can finish near the bottom of its band, while a low-maturity multi-site company can exceed the top of the next band up.

How do person-days convert into a project timeline?

A 9-month baseline is realistic for a typical first-time implementation, but the operating evidence period (commonly about three months before Stage 2 audit) often gates the calendar more than the day count itself.

Should I hire consultants or implement ISO 27001 internally?

Self-managed implementations require the most internal person-days, hybrid models balance roughly 80 to 150 internal days with 20 to 40 consultant days, and fully managed models cut internal days but raise external spend. The right choice depends on in-house expertise, budget, and deadline pressure.

Which workstream takes the most person-days?

Controls implementation typically consumes 20 to 25% of total effort, the largest single share, followed closely by documentation and risk assessment at 15 to 20% each.

Klaar om uw ISO 27001-kosten te schatten?

Gebruik onze gratis calculator voor een op maat gemaakte schatting van kosten, inspanning en planning op basis van uw bedrijfsprofiel.

Bereken uw raming — gratis
Terug naar alle artikelen