Home
Resources

Can You Still Get ISO 27001 Certified This Year? A Backward-Planned Timeline

Can You Still Get ISO 27001 Certified This Year? A Backward-Planned Timeline

Every year, around late August or early September, once everyone is back from the holiday season, the same conversation starts. A CEO or CTO at a SaaS company gets in touch with a version of the same question: we told a customer we would have ISO 27001 by the end of the year, we are partway through, is that still realistic?

It is a fair question and a hard one to answer from the inside, because the ISO 27001 certification timeline is not driven by how much work you have left. It is driven by other people's calendars. The certification body's availability, their auditor's holiday schedule, and the review queue at the certification body after your audit finishes all sit outside your control, and all of them tighten in the fourth quarter.

This article is a backward-planned calendar. It works from a December target back to the decisions you need to make now, and it tells you where the hard stops are. The audience is the founder, CTO, or compliance owner at a SaaS company of roughly 20 to 100 people that is already in flight: you have your asset register, you have done your risk assessment, you might already be using a GRC tool that shows 30-50% completeness, and you are somewhere in the middle of risk treatment. Nothing here assumes you are starting from zero, though there is a section at the end for companies that are. These timings assume a single production environment and a scope of manageable complexity. Multi-entity groups, significant on-premises infrastructure, or several production environments in scope will not compress this way.

Quick answer

The binding constraint is booking your certification body, and the practical deadline for that is early September, because audit days go fast. If your audit is booked, a Stage 2 in late November is achievable. If it is not booked by the end of September, you are almost certainly looking at Q1. Also, you probably do not need the certificate in hand by 31 December. You need evidence that you passed, and that is a different and much more achievable thing.

First, work out what "certified by December" actually means

This is where most of these conversations should start, and almost never do.

There are two distinct milestones, and people conflate them constantly:

  • Passing the Stage 2 audit. The auditor completes the assessment and recommends you for certification.
  • Holding the certificate. The certification body completes its internal technical review and issues the document.

The gap between those two is entirely outside your control. Smaller certification bodies can turn a certificate around in two days to a week. Larger ones routinely take two to eight weeks. You cannot accelerate it, you cannot escalate it, and it does not care about your customer's deadline.

Here is the part that matters: once you have passed Stage 2, you can ask your certification body to issue a confirmation letter. It states that you have successfully completed the certification audit and that your certificate is pending issuance. Different certification bodies word this differently, worth asking during the initial engagement what they provide and what it says.

In our experience, that letter satisfies the large majority of customer and partner requirements. The person on the other side of the procurement conversation wants assurance that you have been independently assessed and passed. A letter from the certification body confirming exactly that, on their letterhead, does the job.

So the real target is not a certificate on 31 December. The target is passing Stage 2 by the end of November, with the certificate arriving whenever it arrives.

That single reframe is often the difference between a plan that works and a plan that does not.

The real deadline is a booking date, not an audit date

Here is the thing nobody factors in: certification bodies run out of Q4 capacity before Q4 starts.

The fourth quarter is the busiest period in the audit calendar. Companies with December deadlines, companies on annual surveillance cycles, and companies whose certification anniversary falls in Q4 are all competing for the same finite pool of auditor days. By mid-October, the slots are largely gone.

If you want a Stage 2 in the second half of November, you need to book your certification body in early September. Don't waste time on discovery or scoping calls or comparing quotes. Booked, with dates confirmed.

This is why, when we run a kickoff call, one of the non-negotiable questions is the scheduled external audit date. Alongside two others that matter just as much, are there major product releases coming that will occupy your engineering team, and what holidays are your key people taking? Those three questions decide whether a target date is a plan or a wish, and they get asked at the start of an engagement, not in October.

The other hard stop is the end of the calendar year itself. From roughly 10 to 15 December onward, the audit industry effectively stops. Auditors take leave, certification body reviewers take leave, and your file sits in a queue until January.

Can you audit later than that? Technically, yes. We have run a Stage 2 on 15 December. We have run one on 24 December, which in most of Europe is Christmas Day in everything but name. Nobody enjoyed it. It works, but you are asking your team and your auditor to spend the holidays on your certification, and you have no margin at all if anything goes wrong. Do not build a plan around it.

The backward-planned calendar

Working back from a Stage 2 in the last week of November, for the profile described above:

  • Book certification body — Early September. Owner: you.
  • Management review #1 — Mid to late October, 30 to 45 minutes. Owner: your leadership team.
  • Internal audit — Late October to early November, 5 to 10 business days. Owner: internal or outsourced auditor.
  • Stage 1 audit — Second or third week of November, 1 to 2 days. Owner: certification body.
  • Management review #2 — Between Stage 1 and Stage 2, 30 minutes. Owner: your leadership team.
  • Stage 2 audit — Last week of November, 2 to 4 days. Owner: certification body.
  • Certificate issued — December to February, 2 days to 8 weeks. Owner: certification body.

The assumption most likely to break this plan is the gap between Stage 1 and Stage 2. Most certification bodies working with companies of this size run a short gap, often around a week. Some require considerably longer, particularly if Stage 1 surfaces anything they want addressed before proceeding. Confirm the gap with your certification body before you build a calendar around it, because a four-week gap instead of a one-week gap moves your Stage 2 into the dead zone.

ISO 27001 backward-planned certification timeline from September booking to a late-November Stage 2 audit
Backward planned milestones for hitting the end of year deadline

The management review sequencing most companies get wrong

You should do two management reviews, not one. This trips up more companies than any other scheduling detail, and it is entirely avoidable. Here is why.

Management review #1 comes before the internal audit. Clause 9.3 requires management review, and your internal auditor will look for evidence that it has happened. If you tell the internal auditor that the management review is scheduled for later, they will raise it as a major nonconformity on the internal audit report. That report goes to your certification body. You have then created a documented major nonconformity in your own ISMS, before the external auditor has even arrived, for no reason other than sequencing. You have to do all the formal legwork of the corrective action plan on the internal auditor's finding, identifying root cause, remediation plan, and so on. You can avoid all these by doing a quick management review session before the internal audit.

Management review #2 comes after the internal audit, and the natural slot is the gap between Stage 1 and Stage 2. Clause 9.3.2 lists audit results as a required management review input, so the first review cannot cover them. That second review covers the internal audit results, the Stage 1 findings, and any corrective actions in progress. It demonstrates the management review process actually operating as a cycle rather than as a one-off box tick, which is what the external auditor is looking for.

It also puts the gap week to work. Otherwise, it is dead time in a calendar that has none to spare.

Are you actually ready? Five checks

Before going further, run this against your own ISMS. It takes about ten minutes, and it is the same bar we use for a certification readiness assessment:

  • All mandatory documents exist and are current
  • Statement of Applicability is complete and approved, with proper justification for inclusions and exclusions
  • No critical risks sitting at "not started"
  • Management review has occurred
  • Internal audit is planned or conducted

If you fail two or more of these in late September, the December date is in serious trouble. If your internal audit is not yet scheduled, book it this week. It is the one item on this list that has a hard dependency on someone else's availability. See our ISO 27001 internal audit service if you need it run independently.

What actually kills the date

Across the engagements we have run under a compressed year-end timeline, four things cause the damage. Ranked by how often we actually see them:

1. The risk assessment is not finished. Everything downstream depends on it. Your Statement of Applicability, your risk treatment plan, your control implementation priorities, all of it flows from the risk assessment. An incomplete risk assessment in October is not a delay; it is a blocker, and it is a clause-level failure under Clause 6.1.2. See our risk assessment service.

2. Risk treatment actions are not complete. This is the most common state for a company that is genuinely mid-implementation. You know what your risks are, you know what you agreed to do about them, and a meaningful number of those actions are still open. Every open action on a high or critical risk is something the auditor will ask about.

3. Technical debt in the production environment. The controls you need to implement collide with the environment you actually have. Logging that was never centralized. Access that was granted three years ago and has never been reviewed. An EC2 instance nobody wants to touch. None of this is unusual, and none of it gets fixed quickly when your engineering team is also shipping product.

4. Endpoint and device management is not deployed. This one is consistently underestimated, and it is worse in distributed teams. A.8.1 requires user endpoint devices to be protected, and across a distributed workforce on personal machines, MDM is the only practical way to evidence it. Rolling that out is a change management problem rather than a technical one. It touches every employee, it generates pushback, and it cannot be done in a week. If you do not have MDM deployed and you are targeting a November Stage 2, start now. And no, a GRC platform's agent monitoring manual device configuration and returning a green checkbox is not equivalent to a properly implemented MDM enforcing security settings and enabling remote wipe and lock. That is the professional opinion of someone who has seen too many incidents caused by weak device security.

Nonconformities and the distinction that matters

There is a difference between major and minor nonconformities that is worth being precise about, because it determines what actually threatens your date.

Major nonconformities are usually clause failures. These are failures against the mandatory requirements in clauses 4 to 10. In practice, the ones that show up look like this:

  • No risk assessment (Clause 6.1.2)
  • No internal audit (Clause 9.2)
  • No management review (Clause 9.3)
  • No information security objectives or KPIs (Clause 6.2)
  • General failure to implement and operate the ISMS

There is an exception worth knowing. Individually, an Annex A gap is usually minor. But an auditor can group several related Annex A failures into a single major where the pattern shows a whole area of the control set is not implemented. No secure coding practices, no source code access restriction, and no security engineering principles will not be written up as three minors. It will be one major covering software development controls.

Minor nonconformities are mostly Annex A implementation gaps. The control exists but is not properly implemented. The classic example: you have device management deployed, but there is no EDR or antivirus on the endpoints. The control is there, the implementation is incomplete.

You should not have nonconformities at Stage 2. Minor ones can and do get raised, but the internal audit and the Stage 1 audit exist precisely to surface problems while there is still time to fix them. If a major nonconformity appears at Stage 2, something upstream failed. The internal audit missed it, Stage 1 missed it, or the implementation work was not done.

If a major does land at Stage 2, the process is a corrective action plan submitted to the certification body for review. Every certification body requires this. How they review it, and how long that review takes, varies significantly between them. In our experience, this is a desk review rather than a return visit, at least for the kinds of majors that surface at this stage.

The December problem is not the remediation work. You can usually close a corrective action plan reasonably quickly. The problem is that the person at the certification body who needs to review and accept it may already be on annual leave. Your file waits until January, and your date is gone for reasons that have nothing to do with your security posture.

The harder failure happens earlier. A certification body can complete Stage 1, find clause-level majors, conclude that the ISMS is not actually implemented, and decline to recommend proceeding to Stage 2 at all. We have seen this happen. It ends the year in mid-November with nothing recoverable, because there is no remaining capacity to rebook.

This is the argument for treating Stage 1 as a gate rather than a formality. It is also the argument for doing the internal audit properly, with enough time to act on what it finds.

What about starting from scratch in September?

Short answer: possible, with a caveat that most companies will not accept.

For a company at the smaller end of the range, with limited technical debt, a clean cloud environment, and a modern tech stack, a full implementation between early September and late November Stage 2 is achievable. We have done it. The work is compressible because the sequence is well understood, and most of the effort can run in parallel with the right support.

The caveat is the entire point: it requires the company to genuinely prioritize the ISO 27001 implementation over other work. Not fit it around other work. Prioritize it. That means the product roadmap slips, client delivery commitments get renegotiated, and the internal projects your team cares about wait until January.

Most companies are not willing to make that trade, and that is a reasonable business decision. But it is the honest reason from-scratch timelines fail. It is almost never that the timeline was impossible. It is that the organization was not prepared to give the implementation the priority it required, which is a different problem entirely.

If you are considering it, be honest with yourself about that question before you sign an engagement letter, not in week three.

When to stop and plan for Q1

There are two triggers where the right answer is to move the target.

Your risk assessment is still open in October. Everything downstream depends on it, and there is not enough runway left to complete the risk assessment, execute the treatment actions, run a meaningful internal audit, and hold two management reviews before a November Stage 1.

You have competing priorities and no dedicated owner. A compressed certification timeline is a resourcing decision, not a compliance decision. If nobody in your organization is driving this as a primary responsibility, and it is competing with a product release and client work, December is not a plan. It is a hope with a date attached.

Moving to Q1 is not a failure. A clean Stage 2 in February is a substantially better outcome than a rushed Stage 2 in November that produces a major nonconformity, a corrective action plan sitting in a holiday queue, and a certificate that arrives in March anyway. You get the same certificate either way, and one path involves considerably less damage to your team.

If you do move it, tell your customer early and tell them precisely. "Our Stage 2 audit is booked for 12 February and we will share the certification body's confirmation the same week" is a materially different conversation from missing a vague year-end commitment in silence.

Summary

  • Your real target is passing Stage 2, not holding the certificate. Certificate issuance takes two days to eight weeks, depending on the certification body and is outside your control. A confirmation letter from the certification body after a successful Stage 2 satisfies most customer requirements.
  • The binding deadline is the booking date. Book your certification body in early September. Q4 audit capacity is largely gone by October.
  • The industry stops around 10 to 15 December. Audits happen later than that. Do not plan for them.
  • You need two management reviews. One before the internal audit, or you will earn a major nonconformity on your own internal audit report. One after, ideally in the Stage 1 to Stage 2 gap.
  • Majors are clause failures, minors are Annex A implementation gaps. The former stop certificates. Both should be caught by the internal audit and Stage 1, not by Stage 2.
  • The four things that kill dates: incomplete risk assessment, incomplete risk treatment, technical debt in production, and undeployed device management.
  • Compressed timelines are a resourcing commitment. They work when the company genuinely prioritizes the implementation. They fail when it is fitted around everything else.

Frequently asked questions

How late can you book an ISO 27001 audit for a December deadline?

Early September, for a Stage 2 in the second half of November. Certification bodies allocate their Q4 auditor days before Q4 begins, and by mid-October the slots are largely gone. Booking means confirmed dates in a signed agreement, not a shortlist or a quote under review.

How long after the Stage 2 audit does the ISO 27001 certificate arrive?

Between two days and eight weeks. Smaller certification bodies often issue within a week. Larger ones run an internal technical review that routinely takes two to eight weeks. The timing sits entirely with the certification body and cannot be escalated or accelerated.

Can you tell a customer you are ISO 27001 certified before the certificate is issued?

Not certified, no, but you can evidence that you passed. After a successful Stage 2, most certification bodies will issue a confirmation letter stating that the audit is complete and the certificate is pending. In our experience that satisfies most procurement requirements. Check the contract language if the commitment is a dated condition precedent rather than a commercial expectation.

What is the difference between a major and a minor nonconformity in ISO 27001?

In practice, majors are failures against the mandatory requirements in clauses 4 to 10 — no risk assessment, no internal audit, no management review. Minors are usually Annex A implementation gaps, where the control exists but is incomplete. However, its easy to get a minor for issues with smaller points on the clasuses, for example you defined the risk assessment methodology, but not explicitly stated the risk acceptance criteria (aka, risk appetite). You have the majority of the clause implemented but you missed a subrequirement, often its managed as a Minor NC by the CBs. An auditor can also group several related Annex A failures into a single major where a whole area of the control set is missing.

Do you need two management reviews before ISO 27001 certification?

You need one before the internal audit and one after. Clause 9.3.2 lists audit results as a required management review input, so a review held before the internal audit cannot cover them. A review held only after leaves the internal auditor with no evidence that management review has happened. The gap between Stage 1 and Stage 2 is the natural slot for the second, where you can formally review the internal and stage 1 audit results and record it on the ISMS management review meeting to suffice the C9.3.2 requirement.

Can you implement ISO 27001 from scratch in three months?

Yes, for a smaller company with a clean cloud environment and limited technical debt. The constraint is not the timeline, it is priority. A compressed implementation requires the product roadmap to slip and internal projects to wait until the new year. Most companies are not willing to make that trade, which is the real reason from-scratch timelines fail.

Where to go from here

If you are mid-implementation and trying to work out whether your year-end date is still real, a short conversation is usually enough to tell you. We have taken over a hundred companies through this process and can generally give you a straight answer on where you stand, what is achievable, and where the hard stops are for your specific situation. If you want that answer before you commit to a date with a customer, book a scoping call with our experts. You can also talk to us about combining ISO 27001 with internal audit, risk assessment, or a complete vCISO program for ongoing program management. Also, for similar deep dives follow us on LinkedIn.

About the author:

Attila Horvath is the founder and CEO of Security Consultants OÜ, and has been working in the security space for 23+ years, including a decade and a half in the enterprise space at companies including Vodafone, AXA, Royal Bank of Scotland, and Bank of Tokyo. Since 2019, he and the Security Consultants team have helped 150+ SaaS companies address security, privacy, and compliance including ISO 27001, SOC 2, GDPR, ISO 42001 needs. Security Consultants is ISO/IEC 27001 certified and a member of the Cloud Security Alliance, ISACA, IAPP, and ISC2.

Share this post