How long does ISO 27001 certification take in the UK?

Last verified 2026-08-19 · UK focus

Short answer

In the UK, ISO 27001 certification typically takes three to nine months from project start to Stage 2 audit. A 10-50 person technology or professional-services firm with reasonable existing controls usually completes it in four to six months. The binding constraints are evidence history (most auditors expect the ISMS to have been operating for a few months) and UKAS-accredited certification body availability, not documentation effort.

Key facts

  • Typical UK range: 3-9 months; common SME case: 4-6 months.
  • Most certification bodies expect at least 1-3 months of operating evidence before Stage 2.
  • Stage 1 and Stage 2 audits are usually 2-6 weeks apart.
  • Certificates run for a three-year cycle with annual surveillance audits.

Typical ISO 27001 certification timeline for a UK SME (10-100 staff)

Typical ISO 27001 certification timeline for a UK SME (10-100 staff)
PhaseTypical durationWhat happens
Scoping and gap analysis2-4 weeksDefine ISMS scope, assess against clauses 4-10 and Annex A
Risk assessment and treatment3-6 weeksRisk register, risk treatment plan, Statement of Applicability
Documentation and control build4-10 weeksPolicies, procedures, technical control changes
Operating period (evidence)4-12 weeksControls run and generate records; awareness training
Internal audit and management review2-3 weeksMandatory before Stage 2
Stage 1 audit1-2 days on site/remoteDocumentation readiness review
Stage 2 audit2-5 daysEffectiveness audit; nonconformities raised
Nonconformity closure and certificate2-6 weeksCorrective actions accepted, certificate issued

Elapsed time, not effort. Phases overlap in practice.

Caveats

  • Organisations above ~250 staff, or with multiple sites or regulated data, routinely take 9-18 months.
  • Certification body lead times of 4-8 weeks are common and are not always factored into vendor timelines.
  • A certificate is only meaningful when issued by a body accredited by UKAS (or an equivalent IAF signatory).

Sources

  1. ISO/IEC 27001:2022 Information security management systems — Requirements. International Organization for Standardization, 2022-10-25.
  2. UKAS accredited certification body directory. United Kingdom Accreditation Service, 2026-08-19.

Check your own position

Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.

Related