ISO 27001 in 6 months is achievable for most small and mid-sized organisations that have management support, a dedicated project owner and a sensibly scoped information security management system. The 26 weeks break down into foundation, risk assessment, building the ISMS, implementation, operating it to gather evidence, and the certification audit. Book your certification body early.
Can You Really Get ISO 27001 in 6 Months?
Yes, for many organisations, but only with honesty about what the timeline assumes. Six months works when three things are true. Someone owns the project and can give it real time each week. Leadership genuinely backs it, because ISO 27001 touches every part of the business. And the scope is sensible rather than sprawling, covering the systems and information that matter without trying to include everything at once.
Where those conditions are missing, the timeline stretches. A part-time owner with no authority, a scope that keeps growing, or an organisation that treats certification as a paperwork exercise will all push six months into nine or twelve. The plan below is realistic, not optimistic, and it assumes you start booking your external certification body early, because audit slots often need weeks of lead time.
A quick note on the standard itself. This timeline is built for ISO/IEC 27001:2022, the current version, which sets out the requirements for an information security management system, or ISMS, and lists the controls you select from in Annex A. You can refer to the official ISO/IEC 27001 standard for the standard’s requirements.
Month 1: Foundation and Scope
Weeks 1 to 4
The first month is about direction, not documents. Getting this right saves months later.
Weeks 1 to 2: Leadership and Project Ownership
Secure leadership sponsorship and appoint a project owner with the authority to make decisions.
Define the scope of your ISMS, including the boundaries of what you are certifying, which locations, systems and information are in and out. Agree the business reasons for pursuing certification, since these shape every later decision.
The scope should be specific enough to manage. Trying to certify everything at once can make an already complex project unnecessarily difficult.
Weeks 3 to 4: Gap Analysis
Run a gap analysis against ISO 27001 to see where you already meet the requirements and where you do not. This becomes your project plan.
Start engaging certification bodies now to understand availability and lead times, so the audit at the end is not delayed by scheduling.
By the end of month one, you should know exactly what you are certifying, where the gaps are, and roughly who is auditing you.
Month 2: Risk Assessment and Treatment
Weeks 5 to 8
Risk is the engine of ISO 27001. The standard does not tell you which controls to apply. It tells you to assess your risks and treat them, and to justify your choices.
Weeks 5 to 6: Establish Your Risk Methodology
Agree a risk assessment methodology, so risks are scored consistently.
Build or confirm an inventory of your information assets, since you cannot assess what you have not identified.
This should cover the information, systems and processes that fall within your ISMS scope. Depending on the organisation, that could include customer information, employee records, intellectual property, cloud systems, business applications, infrastructure and third-party services.
A structured security risk assessment at this stage can provide the risk foundation for the wider ISMS.
Weeks 7 to 8: Assess and Treat the Risks
Carry out the risk assessment, identifying threats to your information and rating them.
Then create a risk treatment plan that decides how each significant risk is handled.
From this, produce your Statement of Applicability, or SoA. This document lists which Annex A controls you are applying and why, while also providing justification for controls that are excluded.
The Statement of Applicability is important because it connects the organisation’s risks with the controls selected to manage those risks.
Month 3: Build the ISMS
Weeks 9 to 13
With risks understood, month three is about writing the policies and procedures that define how you manage information security.
Weeks 9 to 10: Develop the Core Documentation
Draft the core mandatory documents, including your information security policy and the procedures required around the ISMS itself.
Depending on your scope and risk profile, this may include documentation covering:
- Information security
- Access control
- Asset management
- Incident management
- Supplier security
- Business continuity
- Risk management
- Security awareness
- Change management
- Vulnerability management
The objective should not be to create as many policies as possible. Documentation should reflect how the organisation actually operates.
Weeks 11 to 13: Implement the Applicable Controls
Work through the controls in your Statement of Applicability, documenting how each one is implemented.
The 2022 standard organises Annex A controls across four themes: organisational, people, physical and technological.
This is where the project needs to move beyond documentation.
If the risk assessment identifies weaknesses in access control, logging, supplier management or technical security, those gaps need to be addressed.
Resist the temptation to copy a generic policy pack. Auditors and security teams can quickly identify the difference between a documented process and one that is actually followed.
Month 4: Implement and Roll Out
Weeks 14 to 17
Documentation describes your controls. Month four is about making them real across the organisation.
Weeks 14 to 15: Close the Implementation Gaps
Put the controls into practice, closing the gaps identified during the earlier analysis.
Depending on your risks, this might mean:
- Tightening access control
- Improving logging
- Formalising supplier management
- Strengthening authentication
- Improving vulnerability management
- Reviewing privileged access
- Improving backup processes
- Updating incident response procedures
- Hardening systems and infrastructure
The exact work will depend on your organisation’s risk profile and ISMS scope.
Weeks 16 to 17: Security Awareness and Training
Roll out awareness training so staff understand their responsibilities.
ISO 27001 depends on people following the ISMS, and training is both a requirement and a genuine security control.
Employees should understand what is expected of them when handling information, using systems, reporting incidents and following security procedures.
This is the month where security stops being a document and becomes part of how the organisation operates.
Month 5: Operate the ISMS and Gather Evidence
Weeks 18 to 21
An auditor needs to see the ISMS working, not just written down. That means letting it run and collecting evidence.
Weeks 18 to 19: Operate and Record
Operate the ISMS and generate the records that demonstrate your controls are active.
Depending on the scope, evidence could include:
- Access reviews
- Security logs
- Supplier checks
- Risk reviews
- Security awareness records
- Incident records
- Vulnerability management records
- Backup testing
- Management reporting
Certification requires evidence that the ISMS and its controls are being operated, so this operating period matters.
A policy approved immediately before an audit is not the same as evidence of an established process.
Weeks 20 to 21: Conduct the Internal Audit
Conduct an internal audit to check the ISMS against the standard and identify issues before the external auditor does.
Log any nonconformities and begin corrective action.
The internal audit is your dress rehearsal. Every problem you find here is one you have an opportunity to address before the certification auditor identifies it.
Month 6: Management Review and Certification Audit
Weeks 22 to 26
The final month brings everything together and takes you through certification.
Weeks 22 to 23: Management Review
Hold a management review where leadership formally reviews the ISMS, its performance and its risks.
This should consider areas such as:
- ISMS performance
- Security objectives
- Risk status
- Audit findings
- Corrective actions
- Changes affecting the organisation
- Opportunities for improvement
Management involvement demonstrates that information security is being managed as an organisational responsibility rather than simply an IT project.
Weeks 24 to 26: Certification Audit
The certification audit happens in two stages.
Stage 1 is a review of your documentation and readiness.
Stage 2 is the main audit, where the auditor assesses whether the ISMS is genuinely implemented and operating effectively.
You may receive findings that need to be addressed through the certification body’s process. On successful completion, the organisation achieves certification.
Because Stage 1 and Stage 2 are usually separated by a period of time, and because auditors book up in advance, the early engagement from month one is what makes finishing inside six months possible.
What Can Slow You Down?
Being honest about the risks to the timeline helps you protect it.
The common causes of delay include:
- A scope that keeps expanding
- A project owner without enough time or authority
- Weak management engagement
- Significant technical control gaps
- Poor understanding of the organisation’s information assets
- Controls that require substantial implementation work
- Insufficient evidence
- Certification body availability
None of these is unusual, and all of them are manageable if you plan for them from week one.
Scope creep is particularly dangerous. Every new system, business unit, location or information asset can introduce additional risks, controls, documentation and evidence requirements.
How to Keep to the Six-Month Timeline
Sustaining a six-month timeline comes down to momentum.
Keep the scope fixed once agreed. Protect the project owner’s time. Make decisions quickly rather than perfectly. Track responsibilities and deadlines throughout the programme.
Bring in experienced help where it saves weeks, particularly around the risk assessment, Statement of Applicability and audit preparation. These are areas where inexperienced teams can lose significant time.
Leadership should also receive regular progress updates. If a major risk or implementation blocker appears, it should be escalated rather than allowed to sit unresolved for several weeks.
The goal is not simply to complete a checklist. The ISMS needs to work in practice.
How Intrix Can Help
If you want experienced support throughout your ISO 27001 programme, Intrix can help establish, implement and improve your information security management system.
Our ISO 27001 services can support organisations through the implementation process, from understanding current gaps and assessing risks through to building the ISMS and preparing for certification.
A security risk assessment can provide the risk foundation the ISMS is built around, helping identify and prioritise the security issues that need to be addressed.
For organisations that need ongoing security leadership during the programme, virtual CISO services can also provide strategic direction and governance support.
The objective should not simply be to pass the certification audit. A well-designed ISMS gives your organisation an ongoing framework for managing information security risks and continually improving its security posture.
For the requirements of the standard itself, refer to the official ISO/IEC 27001:2022 standard.
Frequently Asked Questions
How long does ISO 27001 take?
For most small and mid-sized organisations, ISO 27001 takes around six months with a dedicated owner, management support and a sensible scope. Larger or more complex organisations often take nine to twelve months. The certification audit stages and internal audit evidence period create a practical timeline that needs to be planned from the beginning.
Can you get ISO 27001 in 6 months?
Yes, six months is realistic for many organisations that keep their scope focused, give the project genuine time and have leadership backing. It becomes difficult when the scope expands, the project owner lacks authority, significant technical remediation is needed or certification body availability creates scheduling delays.
What is the hardest part of ISO 27001?
The risk assessment and Statement of Applicability tend to be among the most challenging parts because they require you to assess your risks properly and justify your control decisions rather than simply copying a template. Internal auditing and evidence collection can also expose gaps in organisations that have focused too heavily on documentation.
Do you need a consultant for ISO 27001?
You can achieve ISO 27001 without a consultant, but experienced help can save time and reduce implementation risk, particularly around risk assessment, the Statement of Applicability and audit preparation. A virtual CISO or experienced advisor can help lead the programme, keep it on schedule and address common implementation gaps.
What is ISO/IEC 27001:2022?
ISO/IEC 27001:2022 is the current version of the international standard for information security management systems. It specifies requirements for establishing, implementing, maintaining and continually improving an ISMS. The standard uses a risk-based approach to help organisations manage information security risks according to their individual circumstances.
How much evidence is needed for ISO 27001?
There is no single fixed amount of evidence that applies to every organisation. The evidence required depends on the ISMS scope, risks, controls and how the organisation operates. Auditors will generally want to see evidence that relevant processes and controls are implemented and operating rather than simply documented.
What happens after ISO 27001 certification?
Certification does not mean the ISMS can be left unchanged. The organisation needs to continue operating the system, managing information security risks, monitoring controls, conducting internal audits, completing management reviews and addressing opportunities for improvement. ISO 27001 certification should therefore be treated as an ongoing management cycle rather than a one-off project.
