Skip to main content
ISO 27001

How long does ISO 27001 implementation actually take?

By Goldline Consultancy

9 min read

Contents

    The honest answer is between 12 and 24 weeks for most UK organisations. The wider answer, and the one that matters when you are scoping a real implementation, is that the timeline depends on five factors that anyone proposing a "90-day ISO 27001" engagement is not being straight with you about.

    This article sets out the factors honestly, calibrated against ISO 27001:2022 and against the engagements Goldline Consultancy delivers as fixed-scope work for UK defence supply chain and regulated organisations.

    The 12-week claim and why it is misleading

    Search for ISO 27001 implementation timelines and you will find a lot of vendors promising certification in 90 days. The claim is technically defensible in narrow circumstances. It is misleading as general guidance.

    A 90-day implementation is achievable when four conditions hold simultaneously. The organisation is small, typically under 50 staff. The scope is narrow, often a single SaaS product or service line. Existing technical controls are mature, usually a Cyber Essentials Plus baseline already in place. And internal capacity is dedicated, with at least 0.5 to 1 full-time equivalent committed to the implementation alongside management sponsorship.

    Outside those four conditions, 90 days is fiction. Most defence supply chain organisations facing ISO 27001 requirements through prime contractor pressure do not meet them. Most regulated mid-market organisations with mixed legacy and cloud estates do not meet them. The honest baseline for UK organisations in these positions is 12 to 24 weeks, with the variation driven by factors set out below.

    The five factors that drive timeline variation

    Organisation size and scope complexity. The single biggest determinant. A 30-person professional services firm with a defined SaaS scope can be ready for Stage 1 in 12 to 14 weeks. A 250-person engineering firm with manufacturing sites, supplier relationships, and physical asset estate routinely takes 20 to 24 weeks. The work is not proportionally larger; it is structurally more complex. More interested parties to engage, more asset categories to inventory, more risk treatments to document.

    Existing baseline maturity. A Cyber Essentials Plus holder is meaningfully ahead. The technical controls overlap substantially with ISO 27001 Annex A.8 (Technological controls). What CE Plus does not cover is the management system layer, governance, risk management, supplier security, internal audit, management review. Most CE Plus holders score in the 30 to 50 range on an honest ISMS maturity self-assessment, which is a realistic baseline for the work ahead. Organisations with no existing baseline take meaningfully longer, often 24 to 36 weeks.

    Internal capacity allocation. This is where many implementations slip. ISO 27001 cannot be delivered as a side-of-desk project for the operations manager. Even with external implementation support, internal stakeholders need to participate in policy approval, risk treatment decisions, and evidence gathering. An organisation with a named ISMS owner allocating one to two days a week to the implementation will move noticeably faster than one trying to fit it around existing workloads.

    Decision-making cadence. ISO 27001 implementation requires dozens of small decisions that compound. Risk acceptance thresholds. Statement of Applicability inclusion or exclusion calls. Supplier classification choices. Policy approval. Organisations with clear executive sponsorship and weekly steering rhythms move through these decisions in days. Organisations without that structure can lose two or three weeks per significant decision, and the delays compound.

    Documentation discipline. ISO 27001 produces a meaningful body of documentation. Information security policy and topic-specific policies. Statement of Applicability covering 93 Annex A controls. Risk register and risk treatment plan. Asset register. Internal audit reports. Management review minutes. Organisations that already operate with documentation discipline absorb this naturally. Organisations that do not are doing two implementations at once, the ISMS itself plus a documentation operating model.

    A realistic phased breakdown

    Goldline Consultancy delivers ISO 27001 implementation as a three-phase fixed-scope engagement. The phases reflect the work pattern that sustains certification rather than performs for one audit.

    The Gap Assessment phase typically runs two days of intensive work followed by a one-week analysis and report period. Output is a calibrated maturity profile across the five ISMS domains, prioritised remediation areas, and a sequenced implementation plan.

    The Implementation phase typically runs 8 to 16 weeks depending on scope. This is where the substantive work happens. Policy suite generation and approval. Risk register build with risk treatment plan. Asset inventory and classification. Statement of Applicability against Annex A. Supplier inventory and supplier security baseline. Internal audit programme establishment. Initial internal audit. Management review.

    The audit readiness phase typically runs two to four weeks before Stage 1. This is internal audit completion, evidence packaging, and Stage 1 dry-run rehearsal. Organisations that skip this phase are the ones who get surprised in Stage 1.

    The audit timeline you do not control

    Even an organisation that completes its implementation work in 12 weeks does not certify in 12 weeks. The certification body audit process adds its own timeline.

    Stage 1 audit is usually scheduled four to eight weeks after the certification body engagement is signed. Stage 2 follows two to six weeks after Stage 1, with most certification bodies preferring four to six weeks to allow corrective action on Stage 1 observations. Certificate issuance typically follows two to four weeks after Stage 2 completion, longer if major nonconformities require corrective action and verification.

    In practice, an organisation with a clean implementation can be holding their certificate within 16 to 28 weeks of starting the work, depending on certification body availability and organisation responsiveness to audit findings.

    What this means for procurement decisions

    If you are procuring ISO 27001 implementation services, the timeline a vendor promises tells you something about the rest of their methodology. A 90-day commitment from a generic vendor without sight of your scope, baseline, or internal capacity is sales language. A 12 to 24 week range with explicit scoping criteria is calibrated estimation.

    Goldline's fixed-scope engagement model commits to a defined scope, a defined deliverable set, a defined timeline range, and a defined price. The price does not change if the work runs longer than expected within scope. The scope is set against the maturity profile from the Gap Assessment, so the implementation plan is calibrated against your organisation's actual starting position rather than an idealised average.

    Closing thought

    Implementation timelines that sound too short usually are. Twelve weeks is real for some organisations. Twenty-four weeks is real for others. The difference matters because rushed implementations fail at Stage 2 or sustain certification only by performing for the surveillance audits, which is more expensive in the long run than doing the work properly the first time.

    If you want to understand where your organisation actually sits before committing to a vendor or a timeline, the ISMS Maturity Self-Assessment below is calibrated against ISO 27001:2022 and produces a 5-domain maturity profile in five minutes.

    Goldline Consultancy is led by an ISO 27001 Lead Implementer (PECB) and ISO 42001 Lead Implementer and Lead Auditor (PECB), SC-cleared, and delivers ISO 27001 implementation as a fixed-scope engagement for UK defence supply chain and regulated organisations. Take our free ISMS maturity self-assessment or book an ISO 27001 diagnostic call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.