Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

ISO 27001 Certification Timeline in India: Phases and Realistic Durations

11 min readBy , Director

Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX

Related Service:ISO 27001

Most organisations reach ISO 27001 certification in three to six months. That range is wide because the programme is six distinct phases, and two of them, implementation and the certification body's own audit scheduling, depend on things you do not fully control. This guide sets out each phase in order, what it produces, the duration we plan against, and the handful of decisions taken before day one that decide whether you land at the short end or the long end of the range.

The six phases at a glance

The ISO 27001 programme SecureRoot runs follows six phases, and the certification body's Stage 1 and Stage 2 audits sit inside the last one. The durations below are what we plan against for a typical scope; the gap assessment at the start is where the plan gets replaced by a real one for your organisation.

Phase What it produces Planned duration
1. Scoping and gap assessment Gap assessment report 2 to 3 weeks
2. Risk assessment and treatment Risk treatment plan and Statement of Applicability 2 to 3 weeks
3. Control design and documentation ISMS policy and procedure set 3 to 4 weeks
4. Implementation support Operating controls and an evidence trail 6 to 12 weeks
5. Internal audit and management review Internal audit report and management review record 2 to 3 weeks
6. Certification and surveillance ISO 27001 certificate, then annual surveillance Stage 1 and Stage 2, then ongoing

Added end to end, phases one to five come to roughly 15 to 25 weeks before the certification body arrives, which is where the three to six month figure comes from. In practice the phases overlap: control design starts while the risk register is being finished, and evidence collection begins the week the first policy is approved. A programme run strictly in sequence takes longer than it needs to.

Phase 1: Scoping and gap assessment (2 to 3 weeks)

Everything downstream is sized by this phase, so it is the one not to rush. We define what the ISMS covers and where its boundaries sit, interview the people who own controls across teams, assess maturity against clauses 4 to 10 of ISO/IEC 27001:2022, and test the current state against the 93 Annex A controls. Each gap is ranked by effort and by risk.

The output is a gap assessment report, and it does two jobs. It tells you what work remains, and it turns the generic timeline above into a dated plan for your organisation. This is the point at which we give you a realistic certification date rather than a range.

Scope is the largest single lever on the whole timeline. An ISMS covering one product and the team that runs it is assessed, documented and audited faster than one covering the whole organisation, at every subsequent phase.

Phase 2: Risk assessment and treatment (2 to 3 weeks)

ISO 27001 is a risk-driven standard, so the control set has to be justified by a risk assessment rather than copied from a template. We build the asset and risk inventory, score each risk by likelihood and impact, and agree how you will handle it: treat, tolerate, transfer or terminate. The Annex A controls that apply are selected from those decisions.

The phase closes with two documents auditors read closely. The risk treatment plan says what you will do about each risk. The Statement of Applicability lists every Annex A control, states whether you apply it, and explains why. A Statement of Applicability that cannot explain an exclusion is a common reason a Stage 1 review sends a team back to do more work, so it is worth the time here.

Phase 3: Control design and documentation (3 to 4 weeks)

This phase is shorter than most expect when the two before it were done properly. We draft the information security policy set and the procedures for access, change and incident management, define roles and the risk acceptance criteria, and map every document to a clause or an Annex A control so nothing is orphaned.

The point of the mapping is the audit. An auditor working through the Statement of Applicability wants to find the policy, the procedure and the evidence for each applicable control without being led to it.

Phase 4: Implementation support (6 to 12 weeks)

This is the longest phase and the one with the widest range, because it is where the organisation, not the consultant, does most of the work. Controls are rolled out across in-scope systems, a compliance platform is configured to collect evidence, security awareness training runs, and the recurring activities the standard expects, access reviews and log collection among them, start and keep running.

Two things set where you land in the six to twelve weeks. The first is how many controls already existed before the programme began: a team that already runs access reviews, backups and change control is documenting what it does rather than building it. The second is evidence automation. Pulling logs, access reviews and configuration state into a platform such as TrustGrid, Vanta, Drata, Sprinto or Scrut is faster than assembling them by hand, and it produces evidence the auditor can trust because it was not prepared for the audit.

The output is operating controls with an evidence trail behind them, which is what Stage 2 actually tests.

Phase 5: Internal audit and management review (2 to 3 weeks)

The standard requires both before certification, and they are worth treating as a dress rehearsal rather than a formality. We plan and run the internal audit programme, log nonconformities and corrective actions, prepare the inputs for the management review and verify that remediation is complete before the certification body is booked.

Finding a nonconformity here costs a corrective action. Finding the same nonconformity at Stage 2 costs a re-audit and the weeks it takes to schedule one, which is how a five month programme becomes an eight month one.

Phase 6: Certification and surveillance

The certification body runs two audits. Stage 1 is a documentation review: it checks that the ISMS is designed and documented in a way that can be audited. Stage 2 tests whether the controls actually operate, through interviews, sampled evidence and observation. You need to pass both, and findings raised at either stage have to be closed before the certificate is issued.

We prepare the evidence for the Stage 1 review, support the Stage 2 audit and close any findings raised. The certificate then runs on a three-year cycle with lighter annual surveillance audits, so the programme does not end at issue; it moves into a maintenance rhythm of access reviews, internal audits and management reviews that the surveillance visits check.

The scheduling of Stage 1 and Stage 2 is set by the certification body's calendar, not yours. Booking the body during phase 3, once the target date is credible, rather than after the internal audit is one of the easier ways to take weeks off the end of the programme.

What stretches the timeline, and what shortens it

Three things reliably stretch an ISO 27001 timeline. A scope that grows during the programme, because every new system or site re-opens phases one to four. A slow phase 4, usually because control owners were not given time for the work alongside their day jobs. And findings at Stage 2 that should have been caught by the internal audit.

Three things reliably shorten it. A tight scope agreed before the gap assessment starts. Evidence collected automatically from day one rather than assembled the month before the audit. And running ISO 27001 alongside SOC 2 where both are needed, so one control set and one evidence trail serve two assessments rather than the work being done twice. The ISO 27001 vs SOC 2 guide covers how the two frameworks overlap and how to sequence them, and the ISO 27001 certification cost guide covers how the same decisions move the budget.

Where SecureRoot fits

SecureRoot's ISO 27001 service runs the six phases above from first gap assessment to a certified ISMS, and stays through the Stage 1 and Stage 2 audits and the surveillance visits that follow. The programme is scoped and overseen by Sachin Shirish, an ISO 27001 Lead Auditor, and the firm holds its own ISO/IEC 27001:2022 certificate (IN60432E, issued by Staunchly Management & System Services Private Limited), so the process described here is one we have been through as the auditee as well as the consultant.

Frequently asked questions

How long does ISO 27001 certification take in India?

Most organisations reach certification in three to six months. The six phases of the programme add up to roughly 15 to 25 weeks before the certification body arrives, and the two audit stages follow that. Where you land in the range depends on three things more than anything else: how much of the organisation is in scope, how many controls already existed before the programme started, and how quickly your control owners can do the implementation work in phase 4 alongside their day jobs. A tightly scoped ISMS at an organisation that already runs access reviews, backups and change control can be certified towards the short end. A whole-organisation scope at a team building most controls from scratch sits at the long end. The gap assessment in the first two to three weeks is where the range becomes a date.

Which phase of ISO 27001 takes the longest?

Implementation support, phase 4, at six to twelve weeks, and it has the widest range of any phase. It is the point at which the organisation rather than the consultant does most of the work: controls are rolled out across in-scope systems, evidence collection is configured, awareness training runs, and recurring activities such as access reviews and log collection start and keep running. The duration is set by how many controls already existed, because a team that already does these things is documenting rather than building, and by how much of the evidence is collected automatically rather than by hand. Control owners who are given time for the work, rather than expected to fit it around everything else, are the difference between six weeks and twelve.

What is the difference between the Stage 1 and Stage 2 audits?

Stage 1 is a documentation review. The certification body checks that the ISMS is designed and documented in a way that can be audited: the scope is defined, the risk assessment and Statement of Applicability exist and make sense, and the policies and procedures cover the applicable controls. Stage 2 tests whether the controls actually operate. The auditor interviews control owners, samples evidence and observes the ISMS working, and raises findings where a documented control is not being followed in practice. You need to pass both, and findings at either stage have to be closed before the certificate is issued. The internal audit and management review in phase 5 exist to find those issues first, when they cost a corrective action rather than a re-audit.

Can the ISO 27001 timeline be shortened?

Yes, and the levers are decided before the programme starts rather than during it. Scope tightly: an ISMS covering one product and the team that runs it moves through every phase faster than a whole-organisation certificate. Automate evidence from day one, so logs, access reviews and configuration state accumulate in a platform rather than being assembled in the month before the audit. Book the certification body early, once the gap assessment has produced a credible date, because Stage 1 and Stage 2 are scheduled on the body's calendar rather than yours. Let the phases overlap: control design can begin while the risk register is being finished. And if SOC 2 is also on the roadmap, run the two together on one control set, so the evidence is collected once.

What happens after the ISO 27001 certificate is issued?

The certificate runs on a three-year cycle, with lighter annual surveillance audits in the years between full recertification. Surveillance visits check that the ISMS is still operating: that access reviews, internal audits and management reviews have continued at the frequency your documentation commits to, that risks have been reviewed, and that findings from the previous audit were closed. So the programme moves into a maintenance rhythm rather than ending. The evidence collection set up in phase 4 does most of the work here, because a platform that has been gathering evidence continuously means each surveillance audit is a review of what already exists rather than a fresh scramble. Our certification and surveillance phase includes planning that rhythm and the continual improvement the standard expects.

Next step

If you have a certification date in mind, or a customer asking for one, book a 30 minute scoping call. You will leave with a written scope, a phase-by-phase timeline for your organisation and a fixed price, and an honest answer if the date you have been given is not realistic.

Have a Question About This?

If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.

We reply within one business day.

All Articles
  • ISO 27001 Certification Cost in India: 2026 Pricing Guide

    8 min readBy Sachin Shirish, Director

    ISO 27001 Certification Cost in India: 2026 Pricing Guide

    Ask for an ISO 27001 quote and the range can be startling. iso 27001 certification cost in India depends on your size, scope, maturity and chosen certification body – so understanding the drivers helps you scope sensibly rather than overpay.

    Read Article
  • ISO 27001 vs SOC 2: Which Framework Do You Need?

    8 min readBy Sachin Shirish, Director

    ISO 27001 vs SOC 2: Which Framework Do You Need?

    If buyers are asking for security proof, you have probably hit the iso 27001 vs soc 2 question. Both show you protect data, but they differ in format, audience and how they are assessed – and the right choice depends on who is asking.

    Read Article
  • 11 min readBy Sachin Shirish, Director

    PCI DSS Scope Reduction: SAQ Types, Segmentation and What Auditors Check

    The fastest way to cut the effort of a PCI DSS assessment is to have less environment in it. This guide covers how cardholder data flow mapping sets the scope, how segmentation and tokenisation reduce it, which self-assessment questionnaire the result points to, and what an assessor checks before accepting a reduced scope.

    Read Article