How long does ISO 27001 certification take in the UK?
Last verified 2026-08-19 · UK focus
Short answer
In the UK, ISO 27001 certification typically takes three to nine months from project start to Stage 2 audit. A 10-50 person technology or professional-services firm with reasonable existing controls usually completes it in four to six months. The binding constraints are evidence history (most auditors expect the ISMS to have been operating for a few months) and UKAS-accredited certification body availability, not documentation effort.
Key facts
- Typical UK range: 3-9 months; common SME case: 4-6 months.
- Most certification bodies expect at least 1-3 months of operating evidence before Stage 2.
- Stage 1 and Stage 2 audits are usually 2-6 weeks apart.
- Certificates run for a three-year cycle with annual surveillance audits.
Typical ISO 27001 certification timeline for a UK SME (10-100 staff)
| Phase | Typical duration | What happens |
|---|---|---|
| Scoping and gap analysis | 2-4 weeks | Define ISMS scope, assess against clauses 4-10 and Annex A |
| Risk assessment and treatment | 3-6 weeks | Risk register, risk treatment plan, Statement of Applicability |
| Documentation and control build | 4-10 weeks | Policies, procedures, technical control changes |
| Operating period (evidence) | 4-12 weeks | Controls run and generate records; awareness training |
| Internal audit and management review | 2-3 weeks | Mandatory before Stage 2 |
| Stage 1 audit | 1-2 days on site/remote | Documentation readiness review |
| Stage 2 audit | 2-5 days | Effectiveness audit; nonconformities raised |
| Nonconformity closure and certificate | 2-6 weeks | Corrective actions accepted, certificate issued |
Elapsed time, not effort. Phases overlap in practice.
Caveats
- Organisations above ~250 staff, or with multiple sites or regulated data, routinely take 9-18 months.
- Certification body lead times of 4-8 weeks are common and are not always factored into vendor timelines.
- A certificate is only meaningful when issued by a body accredited by UKAS (or an equivalent IAF signatory).
Sources
- ISO/IEC 27001:2022 Information security management systems — Requirements. International Organization for Standardization, 2022-10-25.
- UKAS accredited certification body directory. United Kingdom Accreditation Service, 2026-08-19.
Check your own position
Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.
