For most small businesses, getting ISO 27001 certified takes between three and twelve months. The wide range comes down to your company’s size, how mature your existing security practices are, and which certification path you choose. Digital companies with fewer than 50 employees can often move significantly faster than that, especially when they use a streamlined online process. Below, we answer the most common questions about the ISO 27001 certification timeline so you know exactly what to expect.
What factors determine how long ISO 27001 certification takes?
The biggest factors are company size, the maturity of your existing information security practices, the complexity of your IT environment, and how much internal time your team can dedicate to the process. A small digital company with basic security measures already in place will move much faster than a larger organisation starting from scratch.
More specifically, the following elements shape your timeline:
- Scope of the Information Security Management System (ISMS): A narrower scope, covering fewer systems or departments, means less documentation and fewer controls to implement.
- Existing documentation: If you already have written policies, access controls, and incident response procedures, you are not starting from zero.
- Team availability: Certification work competes with daily operations. Companies that assign a dedicated owner to the project move faster.
- Certification body scheduling: Audit slots are not always immediately available, which can add weeks to your timeline even after you are fully prepared.
- Tooling and support: Using a digital platform with AI-assisted documentation can compress preparation from months to days.
What are the stages of the ISO 27001 certification process?
ISO 27001 certification follows a structured sequence of stages: gap analysis, ISMS design and implementation, internal audit, management review, and then the two-stage external certification audit. Each stage builds on the previous one, and skipping steps will typically cause delays later.
- Gap analysis: You assess what security controls and documentation you already have versus what ISO 27001 requires. This reveals exactly where work is needed.
- ISMS design and implementation: You build or update your information security management system, including risk assessments, a Statement of Applicability, and the relevant policies and controls.
- Internal audit: Before the external auditor arrives, you conduct an internal review to catch gaps and verify that the ISMS is working as intended.
- Management review: Senior leadership formally reviews the ISMS’s performance, confirms resources, and signs off on the system.
- Stage 1 audit (documentation review): An accredited auditor reviews your ISMS documentation to confirm you are ready for the full audit.
- Stage 2 audit (implementation audit): The auditor verifies that your controls are actually in place and operating effectively. If no major non-conformities are found, certification is issued.
How long does ISO 27001 certification take for a small business?
A small business with up to 50 employees can realistically achieve ISO 27001 certification in four to twelve weeks when using a focused, digital approach. Traditional consulting-led projects at this scale typically take three to six months, largely because of manual documentation work and slower feedback cycles.
The most time-consuming phase for small businesses is usually the ISMS build, specifically writing policies, completing the risk assessment, and producing the Statement of Applicability. With the right tools, this work can be done in a matter of days rather than weeks. The ISO 27001 online certification process is designed specifically to compress this stage for smaller organisations.
Once documentation is complete and an internal audit has been passed, scheduling the external audit is usually the remaining variable. Some certification bodies can schedule within a week or two; others have longer queues.
Can ISO 27001 certification be completed entirely online?
Yes, ISO 27001 certification can be completed entirely online. For digital companies without physical production facilities or complex on-site infrastructure, there is no practical reason the process needs to involve in-person visits. Documentation, gap analysis, internal audits, and the Stage 1 and Stage 2 external audits can all be conducted remotely via video conferencing and shared digital platforms.
This is particularly relevant for software companies, digital agencies, SaaS providers, and other technology-focused businesses whose assets and processes are inherently online. An online audit allows the auditor to review your systems, interview staff, and verify controls without anyone needing to travel. The result is a faster, more flexible process that does not require coordinating physical meetings across locations.
It is worth noting that the ISO 27001 standard itself does not require on-site audits. The decision is made by the certification body, and many now offer fully remote options as standard.
What slows down ISO 27001 certification most often?
The most common cause of delays is incomplete or poorly structured documentation. Specifically, risk assessments that lack clear asset inventories, Statements of Applicability that are not aligned with actual controls, and missing records of management reviews. These gaps are almost always flagged at Stage 1 and require rework before the Stage 2 audit can proceed.
Other frequent slowdowns include:
- Unclear scope definition: If the boundary of your ISMS is not precisely defined, the audit process becomes harder to manage and often expands unexpectedly.
- Lack of internal ownership: When no one person is responsible for driving the certification forward, tasks sit unfinished and deadlines slip.
- Underestimating the internal audit: Treating the internal audit as a formality rather than a genuine review means non-conformities surface during the external audit instead, which is more costly and time-consuming to resolve.
- Certification body scheduling: Waiting for an available audit slot is a factor outside your control, but choosing a certification body early in the process reduces this risk.
If you are also considering other management systems, note that many of the documentation practices required for ISO 27001 overlap with those for other standards. Building a solid foundation here makes it easier to pursue related certifications such as ISO 9001 quality management later on.
How long does ISO 27001 certification remain valid?
An ISO 27001 certificate is valid for three years. During that period, you are required to undergo annual surveillance audits to confirm that your ISMS is still operating effectively. At the end of the three-year cycle, a full recertification audit is conducted to renew the certificate.
Surveillance audits are typically shorter and less intensive than the initial certification audit. They focus on whether your controls remain in place, whether you have addressed any non-conformities from previous audits, and whether your management system has kept pace with changes in your business or threat landscape.
The three-year structure means that certification is not a one-time project but an ongoing commitment. Companies that maintain their documentation and run regular internal reviews between audits find the surveillance process straightforward. Those who let the ISMS go dormant after initial certification often face significant remediation work before each surveillance visit.
For businesses exploring how AI-driven management systems can help with other compliance needs, the ISO 42001 AI management certification follows a similar three-year validity structure and may be relevant alongside ISO 27001 for technology companies.
How DICIS AG helps you get ISO 27001 certified
We built our platform specifically for small digital companies that want a real ISO 27001 certificate without the months of consulting fees and paperwork that traditionally come with it. Here is what working with us looks like in practice:
- AI-assisted documentation: Our platform generates the policies, risk assessments, and Statement of Applicability you need, tailored to your business, in hours rather than weeks.
- Fully online audits: We conduct Stage 1 and Stage 2 audits entirely remotely, which means no travel, no scheduling headaches, and a faster path to your certificate.
- Built for companies up to 50 employees: Our process is scoped and priced for small businesses, not adapted from enterprise frameworks.
- BVUZ membership: We are a member of the Bundesverband unabhängiger Zertifizierungsstellen, which means our certifications meet recognised quality standards.
- Fast turnaround: For many clients, the entire process from onboarding to certification takes a matter of weeks, not months.
If you are ready to get your ISO 27001 certification online, start your application today and see how quickly your business can be certified.

