ISO 27001 Certification Journey
Dr. Abeer Alshammari · Published 7/29/2026
| Stage | What happens |
|---|---|
| Gap analysis | Assess current state against ISO 27001 requirements to scope the project |
| ISMS design and implementation | Build the policy suite, risk assessment, Statement of Applicability, and evidence base -- typically the longest phase |
| Internal audit + management review | Required before external certification audit -- confirms the ISMS is actually operating, not just documented |
| Stage 1 audit | Certification body reviews documentation and readiness; identifies gaps before Stage 2 |
| Stage 2 audit | Certification body verifies the ISMS is implemented and effective in practice, not just on paper |
| Certificate issued | Valid for 3 years, subject to ongoing surveillance |
| Surveillance audits | Typically annual, checking continued conformance |
| Recertification audit | Full re-audit at the end of the 3-year cycle |
Realistic timeline
For an organization starting from limited existing documentation, 6-12 months from gap analysis to certificate is a realistic range, heavily dependent on organizational size and how mature existing security practices already are. Organizations that already run informal but genuine security practices (regular risk discussions, access reviews, incident handling) move faster, since the work is largely formalizing and documenting existing behavior rather than building from zero.
The most common project failure I see is not a lack of security controls -- it is a lack of evidence. Organizations often do the right things but do not document that they did them consistently, and an ISMS lives or dies on demonstrable evidence, not on what actually happened informally.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon