Anacruses Associates Ltd
← Back to ISO InsightsISO 27001

How Long Does ISO 27001 Certification Take for a UK SME?

2026-06-18

For a UK SME with no existing management system, realistic timelines run 4–9 months from kick-off to certification audit, depending on three factors.

Starting point. If you already have decent IT security practices but no formal ISMS documentation, you're closer to 4 months. If you're building security controls and a management system simultaneously, budget closer to 9.

Internal capacity. Someone needs to own this day-to-day — usually a CTO, Head of IT, or Compliance Manager carving out a few hours a week. Businesses that try to run certification entirely through an external consultant with no internal owner tend to stall at the evidence-gathering stage.

Audit scheduling. Stage 1 and Stage 2 audits with your certification body need booking in advance — popular UKAS-accredited bodies can have 4–6 week lead times during busy periods, typically Q1 and Q4.

A realistic phased breakdown:

  • **Weeks 1–4:** Gap analysis, scope definition, risk assessment methodology
  • **Weeks 5–12:** Control implementation (Annex A), policy and procedure documentation
  • **Weeks 13–16:** Internal audit, management review, corrective actions
  • **Weeks 17–20+:** Stage 1 audit, remediation, Stage 2 audit

The biggest timeline killer isn't the standard — it's evidence. Auditors certify against what you can demonstrate, not what you intend to do. Building evidence collection into business-as-usual from week one, rather than scrambling before the audit, is what separates a 4-month certification from a 9-month one.

Frequently asked questions

How long does ISO 27001 certification take for a UK SME?

For a UK SME with no existing information security management system, realistic timelines run 12 to 20 weeks from kick-off to certification audit. The main variables are your starting point (existing security controls and documentation), internal capacity, and certification body availability.

What is the biggest cause of delays in ISO 27001 implementation?

The biggest cause of delay is evidence. Auditors certify against what you can demonstrate, not what you intend to do. Organisations that treat evidence collection as a pre-audit scramble consistently take longer than those that build it into business-as-usual from week one.

How long in advance should I book the ISO 27001 certification audit?

UKAS-accredited certification bodies can have 4 to 6 week lead times for Stage 1 and Stage 2 audit slots, particularly in busy periods — typically Q1 and Q4. You should book your audit once your internal audit is complete and corrective actions are addressed, but keep scheduling in mind when planning your overall timeline.

What are the stages of ISO 27001 implementation?

ISO 27001 implementation follows five stages: gap analysis and scope definition (weeks 1–4), risk assessment and Statement of Applicability, Annex A control implementation and documentation (weeks 5–12), internal audit and management review (weeks 13–16), and the two-stage certification audit with your chosen UKAS-accredited body (weeks 17–20+).

Ready to talk about your business?

Book a free, no-obligation call. We will tell you exactly what certification would involve for your size, sector, and starting point.