Most organizations starting from zero need 6 to 12 months to reach ISO 27001 certification, with a lean, well-resourced team sometimes closing it in 4 to 5 months and a larger or more scattered organization taking 14 months or more. The exact number depends less on company size than on how much of your Information Security Management System (ISMS) already exists in some form before you start.
We get this question constantly from Canadian SaaS and fintech founders who have a US enterprise deal sitting on the table waiting for a certificate. The honest answer is that ISO 27001 is not a document you buy, it is an operating system for security that has to run for a while before an auditor will certify it. Below is the realistic phase-by-phase breakdown, and what actually moves the timeline in either direction.
The Six Phases of an ISO 27001 Timeline
Every certification path runs through the same six phases, whether you use a consultant, a compliance automation platform, or build it entirely in-house.
1. Gap Assessment and Scoping (2 to 4 weeks)
You map your current controls against Annex A of the standard, decide what is in scope (which products, which offices, which cloud environments), and identify the gaps. Companies that skip this step and jump straight into policy writing almost always redo work later.
2. ISMS Design and Documentation (4 to 8 weeks)
This is where you build the risk assessment methodology, the Statement of Applicability, and the required policy set (access control, incident response, vendor management, and roughly 15 to 20 others depending on scope). For a deeper walkthrough of exactly which documents you need and in what order, see our ISO 27001 implementation guide.
3. Control Implementation (6 to 12 weeks)
Documentation on paper is not a control. This phase is where MFA gets enforced everywhere, logging gets centralized, vendor contracts get reviewed, and access reviews actually get run. For most first-time companies, this is the longest phase because it touches engineering, HR, and vendor management all at once.
4. Operating Period (Minimum 4 to 8 weeks, Often Longer)
ISO 27001 requires evidence that controls have been running, not just written. Auditors want to see completed access reviews, closed incident tickets, training records, and at least one internal audit cycle before they will issue a certificate. There is no way to shortcut this by throwing more budget at it. Calendar time has to pass.
5. Internal Audit and Management Review (1 to 3 weeks)
A qualified internal auditor (can be a trained employee outside the ISMS team, or an outsourced resource) walks through every control and flags nonconformities. Leadership then reviews the findings in a formal management review meeting, which the standard requires as a discrete, minuted step.
6. Stage 1 and Stage 2 Certification Audits (4 to 10 weeks, Including Scheduling)
Stage 1 is a documentation review by your accredited certification body. Stage 2 is the operational audit, where the auditor tests whether controls actually work as designed. Booking slots with a reputable, accredited body can itself take 4 to 8 weeks of lead time in busy quarters, so this should be scheduled well before you think you are ready.
What Actually Compresses the Timeline
A handful of factors reliably shave months off the process, and they are almost all about maturity going in, not about spending more money.
- Existing SOC 2 controls. If you have already been through a SOC 2 Type II audit, a large share of your access control, logging, and vendor management evidence transfers directly. Overlap can compress the control implementation phase by 4 to 6 weeks.
- A single, well-defined scope. Certifying one SaaS product on one cloud provider is dramatically faster than certifying a multi-product, multi-entity organization with legacy on-prem systems.
- Executive sponsorship from day one. ISMS work stalls when it is treated as a side project for one security hire. When a founder or CTO blocks calendar time and enforces deadlines across engineering and HR, phases 2 through 4 move noticeably faster.
- Starting the internal audit early. Companies that run a mock internal audit at the halfway point catch nonconformities while there is still time to fix them, instead of discovering gaps the week before Stage 1.
- Working with a firm that has done this before. A readiness partner who has run the process dozens of times avoids the two most common time sinks: over-scoping the ISMS, and writing policies that do not match how the company actually operates.
What Extends the Timeline
On the other side, a few patterns reliably push companies past the 12-month mark.
- Trying to certify multiple business units or acquired entities in the same cycle.
- Building the ISMS with no dedicated owner, so it competes with engineering sprints for attention.
- Waiting until the risk assessment is "perfect" instead of iterating on it, which is a normal and expected part of year one.
- Discovering during Stage 2 that a control described on paper is not actually followed in practice, forcing a remediation cycle and a second visit from the certification body.
How ISO 27001 Timelines Differ for Canadian Companies
Canadian tech companies, particularly SaaS and fintech firms in Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal, often layer ISO 27001 on top of existing privacy obligations rather than starting from a blank page. If you already handle personal information under PIPEDA, and especially if you have customers or operations touching Quebec's Law 25, several of your existing privacy controls (data mapping, breach notification procedures, retention schedules) can be folded directly into the ISMS instead of built twice. Structuring the ISMS with that overlap in mind from the start, rather than retrofitting it later, is one of the more reliable ways to save a full quarter of rework.
Realistic Timeline by Company Profile
As a rough guide based on the patterns above:
- Early-stage SaaS (under 30 people, one product, cloud-native): 4 to 6 months with focused sponsorship.
- Growth-stage company (30 to 150 people, some legacy tooling): 7 to 10 months.
- Larger or multi-entity organization: 12 to 18 months, sometimes longer if scope keeps expanding mid-project.
These ranges assume the organization is doing genuine control implementation work, not just paying for a certificate mill. An accredited certification body will not issue ISO 27001 without evidence the ISMS has actually been operating, and there is no legitimate shortcut around that.
Building a Timeline That Holds Up Under Audit
The companies that hit their target date are the ones that treat readiness as a structured project with a named owner, not an open-ended compliance backlog. That is the model traztech runs with clients: a readiness engagement that maps your existing controls, builds the ISMS around your real Canadian privacy obligations, and keeps the internal audit and certification body bookings on a calendar from week one instead of an afterthought. It sits alongside our broader compliance advisory work, so the ISMS you build for ISO 27001 also strengthens whatever comes next, whether that is SOC 2 or a customer security questionnaire.
If you are trying to put a real date on your ISO 27001 certification, not a guess, contact traztech for a scoping call. We will tell you honestly whether 6 months is realistic for your organization or whether you should plan for 12.
The Certification Body Booking Is the Constraint Nobody Plans For
Teams plan the internal work in detail and then discover the calendar belongs to somebody else. Accredited certification bodies allocate auditor days months in advance, and the auditors qualified for your sector and scope are a smaller pool than the firm's website suggests. Start the selection conversation at the end of phase 2, not after phase 5. Ask three questions of every body you shortlist: which accreditation mark will appear on the certificate and who granted it, how many audit days they are proposing for your headcount and scope, and whether the same lead auditor will run Stage 1, Stage 2 and the surveillance visits. A body that quotes noticeably fewer audit days than its peers is not being efficient with your budget, it is producing a certificate that a sophisticated buyer's security team may look at twice. Contract early, get the Stage 1 date in writing, and treat that date as the fixed point the rest of the plan works back from.
Where the Money Goes, and Why the Quote Ranges So Widely
Certification cost splits into three buckets that behave differently. The certification body's fee is priced on audit days, which scale with headcount, number of sites and scope complexity, and it repeats every year as surveillance and again as recertification. Readiness work, whether internal salary or an outside firm, is the largest single line in year one and close to zero afterwards if the ISMS is built to run. Then there is remediation, which is the genuinely unpredictable bucket: the logging platform you did not have, the endpoint tooling you need to cover contractor laptops, the identity provider upgrade that turns MFA from a policy into an enforced control. Companies that under-budget almost always under-budget remediation, because the gap assessment tells you what is missing and people read that list as documentation work. Ask the gap assessment to price the fixes, not just name them. Our published fixed-scope pricing exists so the readiness half of that number stops being a mystery, and on one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which is written up in our auditor vetting case study.
Scope Wording Ends Up on the Certificate
The scope statement is a sentence that goes on the certificate your customers will read, and it is agreed with the certification body rather than written freely by you. A narrow scope certifies faster and defends cleanly, but a buyer who reads "the information security management system supporting the development and operation of the X platform, at the Toronto office" will ask what happened to the mobile app, the professional services team and the second cloud account. A scope drawn to win deals rather than to minimise work is usually slightly wider than the readiness team wants. Settle the wording in phase 1 and share the draft with whoever owns the sales relationship that triggered the project. Changing scope after Stage 1 is possible but it resets documentation review and often costs additional audit days, and mid-project scope creep is the single most common reason a nine-month plan becomes a fourteen-month one.
Nonconformities: Minor, Major, and What Each One Costs in Weeks
A minor nonconformity is an isolated lapse against a requirement, for example one quarter's access review completed late. You submit a corrective action plan, usually within thirty days, and the auditor closes it at the next visit or on evidence. It does not stop the certificate. A major nonconformity is a systemic failure or a total absence of a required process, for example no internal audit having been performed, or risk treatment decisions that are not traceable to the risk assessment. A major blocks certification until it is closed, and closing it means implementing the process, running it long enough to produce evidence, and in most cases paying for a follow-up visit. Budget four to eight weeks for that loop and expect to lose whatever quarter you were selling against. The realistic way to avoid it is the mock audit at the halfway point, run by someone who has sat on the auditor's side, with a brief to look for missing processes rather than imperfect ones.
The Internal Audit Independence Trap
Clause 9.2 requires internal audits that are objective and impartial, and auditors read that as meaning the person auditing a control cannot be the person who built or operates it. In a company of forty people, the security lead has usually written the policies, implemented the controls and gathered the evidence, so their internal audit report is not independent by any reasonable reading. The workable arrangements are a trained employee from a different function auditing the ISMS with a documented competence record, a peer arrangement with a comparable company, or an outsourced internal auditor. Whichever you choose, do it early enough that the findings can be fixed. An internal audit that produces zero findings is itself a finding, because the certification body will conclude the audit was not performed with any depth, and that conversation costs you time at Stage 2.
Certification Is Year One of a Three-Year Cycle
The certificate runs three years, with surveillance audits in years two and three and a full recertification at the end. Surveillance is shorter, typically a third to a half of the Stage 2 days, and it samples a subset of controls plus the mandatory clauses: management review, internal audit, corrective actions, risk assessment updates and the objectives you set. The failure pattern is predictable. The team certifies, the project owner moves on to the next thing, and eleven months later somebody discovers no management review was minuted, no risk assessment was refreshed and half the access reviews were skipped. That is a major at surveillance, and it is harder to fix retrospectively than it was to do on schedule, because you cannot manufacture calendar time. Building the annual rhythm into the operating calendar before the certificate arrives is the cheapest thing on this page. Continuous operation is what our retainer work is designed around, and it is also perfectly achievable in-house with a named owner and a recurring diary entry.
Evidence Sampling: What "Operating" Actually Means to an Auditor
Auditors sample. For a quarterly control they will look at every occurrence in the period, which is why an ISMS that has run for two months cannot demonstrate a quarterly control at all. For a per-event control such as onboarding, offboarding or change approval, they will pull a sample of records from the population and test them, and they will pull the population themselves rather than accept your curated list. This is the mechanism behind the minimum operating period, and it explains why the honest answer to "can we compress this" is usually no. Two practical consequences: start generating evidence the day a control goes live rather than waiting for the process to feel polished, and make sure the system of record can produce a complete population on demand. Being unable to show the full list of leavers for the period is worse than showing a list with one imperfect record in it.
When You Should Not Be Doing ISO 27001 At All
If the only thing standing between you and a signed contract is a US enterprise buyer's vendor form, ISO 27001 may be the wrong certificate. North American buyers overwhelmingly ask for SOC 2, and a SOC 2 Type II report gives their reviewer control-level detail that an ISO certificate does not. If nobody has actually asked for ISO 27001 by name, ask your prospect which artefact their security team will accept before you commit two quarters and a six-figure programme to the wrong one. Equally, if you are pre-revenue, under fifteen people, and the request came from a single prospect who has not signed anything, the correct move is a documented security baseline and an honest questionnaire response, not a certification project that will consume your engineering capacity. ISO 27001 makes clear sense when you sell into Europe, the UK or Asia-Pacific, when a customer contract names it, when you already hold SOC 2 and want the international equivalent, or when the 93 Annex A controls and clauses 4 to 10 give you a governance structure your board is asking for. Outside those cases, tell the buyer what you actually have and spend the money on the controls. We would rather scope you into a smaller piece of work now than certify you against a standard nobody in your pipeline reads, and if you want that argued through against your real pipeline, our compliance advisory conversation starts there.
Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.
ISO 27001 readinessOr talk about a retainer