isms.coach
← All guides

Timeline

How many hours does ISO 27001 actually take?

A realistic breakdown by company size, not the vague "a few months" every vendor page gives you.

Vendor pages tend to answer this with "as fast as a few weeks," because they're selling automated evidence collection to companies that already have most controls in place. That number is close to useless if you're starting from nothing at a 5-to-15-person company.

The honest range

For a self-led implementation at a small company, 4 to 6 months to be audit-ready is a realistic target if one person is dedicating meaningful time to it every week, and 12 to 18 months is common if it's genuinely a side-of-desk project competing with everything else that person does.

Where the hours actually go

  • Context, scope, and policy (10–20 hours): faster than people expect, especially with a structured starting point rather than a blank page.
  • Risk assessment (15–30 hours): the first pass is slow; it gets much faster once you have a repeatable method.
  • Statement of Applicability (20–40 hours): going through all 93 Annex A controls with real justification, not rubber-stamping. This is usually the single biggest time sink.
  • Closing implementation gaps (highly variable): if you're missing backups, MFA, or basic access reviews, implementing those controls — not documenting them — is where months disappear.
  • Internal audit and management review (10–15 hours): quick once everything above exists, because you're reviewing your own work rather than creating it.

The variable that changes everything

Companies that already have basic security hygiene (MFA everywhere, real backups, some access control discipline) move through this dramatically faster than companies documenting from zero. The paperwork is rarely the bottleneck — closing genuine implementation gaps is.

Ready to actually start? Your Statement of Applicability comes pre-populated with all 93 Annex A controls — no blank page.

Start your ISMS