ISO 27001 audit timeline: How long does certification really take?

This guide walks through the full ISO 27001 timeline, from preparation to certification, explaining audits, delays, planning and post-certification requirements clearly.

Key takeaways

  1. ISO 27001 certification is a structured journey, not a quick audit. While audit days are measured in days, the full certification process usually takes several months.
  2. The biggest delays rarely come from the audit itself. They usually happen when organisations rush preparation, leave Stage 1 findings unresolved, or struggle to produce clear, organised evidence at Stage 2.
  3. A clear scope, genuine control implementation, and realistic scheduling lead to predictable timelines and a smoother path to certification.

Understanding the ISO 27001 audit timeline

Understanding the schedule and timeline of an ISO 27001 audit is key to a smooth certification. Whether you are planning your first audit or estimating the full journey, it is important to separate the two timelines.

  • The audit duration refers to the number of days the auditor formally assesses your ISMS.
  • The certification journey covers the wider process, which usually takes several months and includes preparation, internal audits, and corrective actions.

When organisations ask how long ISO 27001 certification takes, the honest answer is this: timelines depend on readiness, not shortcuts or speed-first claims.

What does a typical ISO 27001 audit day look like?

One of the biggest concerns organisations have is what an audit day actually feels like. In a conventional on-site audit, you would typically sit with the auditor from 9 am to 5 pm while documents are reviewed in real time.

That model works, but it can feel disruptive - particularly for senior leaders wearing multiple hats. Remote audits at Tempo work differently from the traditional on-site model.

Most of our clients gather their evidence in advance. This might sit inside GRC platforms (such as Vanta,  Drata, Secfix, Kertos, Adoptech or Probo), or within well-organised Notion workspaces, Google Drive folders, or SharePoint sites.

The Tempo Audits remote audit flow

Instead of requesting documents one by one while you sit in a meeting room, we flip the process:

  • You share access to your organised evidence repository.
  • The auditor reviews policies, procedures, risk assessments, logs, and records independently.
  • Focused live sessions are scheduled to clarify points or discuss findings.
  • You continue running your business while the auditor works through the documentation.

This approach aligns with guidance for remote auditing under UKAS and the requirements set out in ISO/IEC 27006, ensuring rigour is never compromised.

What this looks like in practice

A typical remote audit day often runs within a 9 am–5 pm UK window, but your active involvement is usually limited to focused sessions:

  • 9:00 am – Opening meeting (30 mins): Introductions, confirm scope, and evidence access.
  • 9:30 am-12:30 pm – Asynchronous review: Auditor independently reviews documentation while you work.
  • 12:30 pm – Midday sync (30 mins): Clarifications and additional evidence requests.
  • 1:00 pm-4:00 pm – Continued asynchronous review: Quick questions handled via Slack or Teams.
  • 4:00 pm – Closing sync (30 mins): Discussion of preliminary findings, requests for more evidence.

The one caveat we always give is that we need clients to remain available throughout the day to support our auditors in case they need additional support or have questions.

Why remote?

  • Designed for busy tech teams - In many growing companies, ISO 27001 sits with senior leaders rather than a dedicated compliance team. Remote auditing respects limited time and competing priorities.
  • Asynchronous review - Evidence is shared in advance, allowing auditors to review policies, logs, and records independently before focused discussions.
  • Less disruption - You attend short, structured sessions instead of being tied up in meetings all day.
  • Flexible format - Choose fully asynchronous, fully synchronous, or a hybrid model based on how your team works best.
  • Supports distributed teams - Team members can join from different cities or countries without travel logistics.
  • Lower overall cost - No additional expenses for auditor travel, accommodation or on-site arrangements.
  • Reduced environmental impact - Eliminating travel cuts carbon emissions while maintaining full audit rigour.

How audit length is calculated

Audit duration is not guessed or shortened for convenience. For a UKAS-accredited certification body, it is always calculated using the framework set out in ISO/IEC 27006.

This standard sets minimum audit time requirements to ensure assessments are thorough and consistent. Without a mandated minimum time, audits could be rushed, reducing confidence in the certificate issued.

The calculation considers:

  • Organisation size - primarily the number of employees within scope.
  • Number of sites - including remote or multi-location operations.
  • Scope boundaries - what parts of the business are included.
  • Complexity of the ISMS - technical environments, cloud infrastructure, outsourced processes and regulatory exposure.

The result is a defined number of audit days split across Stage 1 and Stage 2.

How long does it take to get ISO 27001 certification?

From initial implementation to certificate issue, ISO 27001 typically takes 3 to 12 months. This includes building your ISMS, completing risk assessment and treatment, implementing controls, running an internal audit and holding management review - not just the external audit.

Note: Audit days are measured in days. Certification is measured in months.

Typical timelines:

  • SMEs: 3-6 months
  • Larger organisations: 6-12+ months due to broader scope

With Tempo Audits, the formal audit phase for an SME lasts around 3-4 weeks: Stage 1, a 3-week gap, Stage 2, and then certification issued about one week later.

Typical ISO 27001 certification timeline (End-to-end)

Area UKAS-accredited Other IAF-accredited Unaccredited
Oversight Government-recognised national body Recognised national body (IAF member) No recognised external oversight
Audit duration Strictly policed following ISO 27006 Same ISO 27006 framework, enforcement may vary depending on accreditation body No enforced minimum
Technical review Mandatory technical review Mandatory technical review Not externally enforced
Public verification UKAS CertCheck & IAF database IAF CertSearch and may be specific database for accreditation body Usually not publicly verifiable
Tender acceptance Often explicitly required in the UK Generally accepted internationally Frequently challenged
Transfer to UKAS N/A Always possible Requires full re-certification

1. Preparation & readiness (1-3+ months)

This is the foundation stage.

You will:

  • Define the scope of your ISMS
  • Conduct risk assessment and risk treatment
  • Implement Annex A controls
  • Produce policies and procedures
  • Generate evidence that controls are operating
  • Hold a management review

Good preparation means controls have been working for weeks or months, not days.

2. Internal audit (Dry run - around month 4)

A complete internal audit is mandatory under ISO 27001 (Clause 9.2).

It must:

  • Cover the full ISMS scope
  • Be documented properly
  • Identify and track findings

Best practice is to complete the internal audit before Stage 1. When internal audits are skipped, rushed, or incomplete, Stage 2 often results in major non-conformities and delays.

3. Stage 1 audit (Document review – around month 5)

Stage 1 assesses readiness.

The auditor reviews:

  • ISMS documentation
  • Risk assessment and treatment plan
  • Statement of Applicability alignment
  • Internal audit and management review records

Stage 1 may raise gaps or opportunities for improvement. These must be genuinely resolved before Stage 2. If not, they frequently become formal non-conformities later, extending your timeline.

4. Stage 2 audit (Implementation & effectiveness – around month 5.5)

Stage 2 is where certification is earned. It tests whether your controls operate effectively in practice.

The auditor will:

  • Interview control owners
  • Sample logs and system configurations
  • Review monitoring activities
  • Verify evidence of control operation

This is also where timelines most commonly extend - and almost always due to preparation gaps.

Common causes include:

  • Policies exist, but controls have not been implemented (for example, no access reviews have been performed or an incident log maintained).
  • Risk assessments created once and not reviewed
  • Training documented but not completed
  • Evidence scattered across tools and difficult to access
  • Stage 1 findings left unresolved
  • Internal audit incomplete or poorly executed
  • Key personnel unavailable during audit

When this happens, organisations must implement fixes, allow controls to operate, gather evidence, and undergo verification. This can add months in a traditional certification body, although Tempo works efficiently with clients to review and verify corrective actions, typically completing follow-up within about a week where evidence is ready.

Certification decision (Around month 6)

After Stage 2:

  • Findings are reviewed
  • Corrective actions (if any) are verified
  • An independent reviewer confirms the certification decision
  • The certificate is issued (valid for 3 years, subject to surveillance audits)

Factors that affect your ISO 27001 timeline

Several practical factors influence how long the ISO 27001 process takes. Most delays are predictable - and preventable.

  • Scope of your ISMS - The more teams, systems, and locations included, the longer the implementation and audit will take.
  • Security maturity - If core controls already operate effectively, timelines shorten significantly.
  • Statement of Applicability quality - A clear, accurate SoA aligned to implemented controls avoids confusion and rework at Stage 1 and Stage 2.
  • Management involvement - Active leadership engagement keeps risk reviews, approvals, and corrective actions moving. Passive oversight slows everything down.
  • Team availability - Key control owners must be available during preparation and audit. Holidays, product launches, and operational firefighting often extend timelines.
  • Evidence organisation - Disorganised logs, training records, or access reviews are one of the biggest causes of extended audit days. A structured central repository makes a measurable difference.
  • Tooling and automation - Platforms such as Vanta or Drata can accelerate preparation, but only if controls are genuinely implemented.
  • Remediation buffer planning - Build a realistic time between Stage 1 and Stage 2 to resolve findings properly. Optimistic scheduling is one of the most common pre-audit delays.

Can you speed up the ISO 27001 certification? (Without cutting corners)

Yes, you can move faster - but the biggest variation in speed happens during implementation, not the audit itself.

Some organisations complete the implementation journey in as little as 1 to 2 months. Others take a year or more. The difference usually comes down to how structured and realistic the preparation phase is.

You can accelerate implementation by:

  • Leveraging experienced consultants who understand common pitfalls
  • Using in-house knowledge effectively rather than reinventing processes
  • Adopting platforms that streamline documentation and evidence gathering
  • Allocating more internal time and resources to implementation

Although tools support preparation, they do not make certification easier or bypass audit rigour.

Real acceleration comes from defining a clear scope, producing a clean and accurate Statement of Applicability, properly implementing controls, and ensuring stakeholders are available.

Tempo Audits supports efficiency by booking audits quickly, shortening the gap between Stage 1 and Stage 2, and reviewing corrective actions promptly - often issuing certificates within a week of Stage 2 completion.

What happens after certification?

  • Annual surveillance audits - Each year, auditors review key parts of your ISMS to confirm controls are still operating effectively. These are shorter than the initial audit but remain thorough.
  • Ongoing ISMS monitoring - You must continue internal audits, risk reviews, management reviews, and corrective actions. ISO 27001 requires continuous improvement, not a one-time setup.
  • Full recertification every 3 years - A complete reassessment of your ISMS is required to renew certification for the next cycle.

Why planning matters more than speed in ISO 27001 certification

When people focus only on “how fast can we get certified?”, they often forget the real driver of a smooth timeline: quality of planning and readiness. Rushing into audits without a clear scope, accurate documentation, and real control implementation almost always leads to delays, not faster certification.

Tempo Audit’s approach focuses on predictable, human-centred audit planning rather than speed for speed’s sake. That means:

  • Predictable timelines - We plan your audit based on your ISMS maturity, not wishful dates.
  • No “surprise days” - You’ll know exactly what will be reviewed and when.
  • UKAS credibility maintained - We follow accredited standards, so your certificate stands up to scrutiny.
  • Remote-first, human-led auditing - Efficient but flexible, respecting your team’s time and availability.

Related read - Everything you need to know ahead of your ISO 27001 audit

Take the next step towards certification!

If you’re mapping out your ISO 27001 journey, the next step is simple: get clarity on your scope, audit duration, and realistic timeline.

At Tempo Audits, we keep the process transparent, structured, and predictable from the outset. Request a quote today and take the next practical step towards ISO 27001 certification with confidence.

Reviews

Trusted by fast-moving tech teams across the world who value a more human audit experience.

We transferred to Tempo from one of the established certification bodies — and we are delighted with the choice. Our audit was one of the smoothest we’ve had in terms of collaboration and engagement.
Laurence, Director of IT & Client Services @ RDT
If Carlsberg did auditors… We use Tempo for our ISO 27001 auditing and I'm thrilled that we were introduced. They ensured that the process dovetailed so smoothly with our ongoing operational activities that the impact was barely noticeable.
Jason, Director of Operations @ The Risk Factor
The Tempo team moved really fast to help us meet our timeframes — it’s rare to have an audit firm move at the speed of a start-up.
Ellie, COO @ Everblue Technology
Alfonso was nothing short of brilliant. Having worked with many auditors over the years, he stood out for his clarity, professionalism, and kindness. He completely changed my view of auditors.
Amardeep, Director @ Blue Edge
Tempo lives up to its name. No other company we contacted was faster or more straightforward during the process.
Lukas, CEO @ Noreja Intelligence
Is it weird to say I had a good time? We had worked with a more traditional auditor, but they didn't understand the needs/tech of our start-up. Tempo knew how to use our ISMS software and understood our business.
Jonny, Head of Engineering @ Nomio

Resources

Audit Timeline

How long does ISO 27001 certification take? Explore audit timelines, preparation requirements, common delays, and certification expectations.

Stage 1 Audit

Understand ISO 27001 Stage 1 audit requirements, checklists, costs, and preparation steps. Learn how to assess ISMS readiness and progress confidently to Stage 2.

Stage 2 Audit

Learn how the ISO 27001 Stage 2 audit works, what evidence is required, common mistakes to avoid, and how to achieve certification.

Internal Audit

ISO 27001 internal audit guide covering Clause 9.2 requirements, audit planning, Annex A controls, checklists, evidence collection, and compliance.

Statement of Applicability

Learn what an ISO 27001 Statement of Applicability (SoA) is, what it must include, common audit expectations, and how to avoid certification delays.

Certification Scope

Learn how to define your ISO 27001 certification scope, what it should include, common mistakes to avoid, and what auditors expect during certification.

Controls

ISO 27001 controls explained: Annex A & the 93 controls (2026 guide)

Audit Preparation

Learn how to prepare for ISO 27001 certification with a practical guide to audit readiness, risk management, internal audits, and UKAS audits.

UKAS Accreditation

A practical guide to UKAS-accredited ISO 27001 certification, including audit stages, accreditation benefits, procurement requirements, and certification verification.

Requirements

Get audit-ready with our guide to ISO 27001 certification requirements, including mandatory clauses, controls, documentation, and certification steps.

Certification Cost

How much does ISO 27001 certification cost in the UK? Learn typical audit fees, pricing by company size, and the factors that influence certification costs.

Risk Assessment

ISO 27001 risk assessment explained. Learn the 5-step process, risk treatment methods, Statement of Applicability, and audit requirements.

ISO 27001 Resources

FAQs

ISO 27001 can feel complicated at first. Here are the answers to the questions we hear most from growing teams.

As standard, we schedule 8 hour audit days and share calendar invites to block out the dates in advance. The calendar invites typically start at 9am UK time and finishing at 5pm UK time.

Often the auditor schedules some time at the end of the day (from 3pm-ish) to gather evidence and review the notes, which means that your day might end a bit earlier.

If you have a preference to change the audit times (e.g. move the start time to 8am or 10am UK time - and finish one hour earlier or later accordingly), let us know and we will aim to update. A 1 hour or 30 minute earlier or later start time should rarely be a problem - but ultimately, it will be for the Auditor to confirm this works for their schedule, since they are responsible for managing the audit.

An ISO 27001 certificate is valid for 3 years, provided the company completes the required annual surveillance audits. In the third year, the company can extend certification for a further 3 years by successfully completing a recertification audit before the certificate expires.

If all goes smoothly, you can expect your certificate within 2 weeks after the Stage 2 audit closes.

However, Tempo can only issue your certificate once all these things have happened:

1. (If there are non-conformities) you've completed the Corrective Action Plan to close these non-conformities
2. Your auditor has approved your Corrective Action Plan (if the auditor has comments/questions on your Corrective Action Plan, they will send these to you - so you’ll need to respond to those before we can close them)
3. The auditor has finalised your report (typically within 1 week after audit)
4. Tempo has finalised its technical review of the report (typically within a few days of auditor submitting the report)

The biggest potential delay in the above scenario is the corrective action plan being finalised by yourselves, so if you’re in a hurry to get your certificate, please make sure you move through it quickly!

And if you have an urgent need for your certificate, make sure you relay this requirement to Tempo. We will always do our best to expedite requests to support your needs - although we note that we always need to follow the above steps.

The Audit Plan will set out a schedule which will include a lunch break and a shorter morning and afternoon break.

But don’t worry if you need to take additional breaks, or adapt the schedule - our auditors are flexible. If the audit needs to change based on how it's progressing or your circumstances, then it can do. Feel free to ask for breaks whenever needed. We understand that remote audits, , might come with occasional interruptions (whether you need to get the door for a delivery, or make another cup of tea) – that's no problem at all! Just let the auditor know and you can take 5/10 minutes!

Book a call

No forms, no faff – just a conversation and a quote. Prefer to skip straight to it? Fill out the application form and we'll get moving.

Alternatively, if you have all the details,
fill out this form here.

Latest Articles

July 15, 2026

Case Study: How The Risk Factor achieved ISO 27001 certification in 4 weeks

ISO 27001
July 8, 2026

ISO 27001 Audit: What to Expect and How to Prepare

ISO 27001
July 5, 2026

ISO 27001 Remote Auditing: The Future Of Information Security Audits

ISO 27001
June 22, 2026

ISO 27001 vs. SOC 2: Which Certification is Right for Your Business?

ISO 27001, SOC 2
June 10, 2026

ISO 27001 Benefits for SaaS: Win Clients Faster

ISO 27001
May 12, 2026

What Is ISO 27001? A Complete Guide to Information Security Standards

ISO 27001
April 30, 2026

How to Get ISO 27001 Certified: A Step-by-Step Guide for 2026

ISO 27001
April 28, 2026

Why ISO 27001 Certification is Important for Small Businesses

ISO 27001
April 7, 2026

ISO 27001 Accreditation Bodies: A Complete Guide for Tech Companies

ISO 27001
April 7, 2026

ISO 27001 Stage 1 vs Stage 2: What's the Difference?

ISO 27001