77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
ISO 27001 certification: duration, preparation, effort
IT Security & NIS-2

ISO 27001 certification: duration, preparation, effort

29 June 202614 min readBy Lena Vogt
CIVAC

An ISO/IEC 27001:2022 certification takes 9 to 18 months from the start of the project to the certificate in medium-sized companies. This guide breaks down the phases, names the effort and shows where audits typically fail.

The international standard ISO/IEC 27001:2022 was published on October 25, 2022 and replaces the previous version 2013/2017. Existing certificates according to ISO/IEC 27001:2013 will no longer be valid on October 31, 2025, with an extended transition period depending on the accreditation body until October 31, 2026 for on-site audits. Companies that are building an information security management system (ISMS) today certify directly according to the 2022 version with 93 controls in four subject groups (Appendix A: Organizational, People, Physical, Technological). The transition periods are bindingly regulated in IAF-MD 26 (International Accreditation Forum) and converted into national accreditation law by the German Accreditation Body (DAkkS).

This article is aimed at management, IT management and information security officers (ISB) who need realistic scheduling and effort estimates. You will find out which five phases the ISMS implementation includes, which costs per phase are realistic for medium-sized companies, what a Stage 1 and Stage 2 audit specifically checks, which stumbling blocks lead to failure and how the preparation can be shortened with a compliance platform and officer-as-a-service model. CIVAC provides a workspace with all 93 controls, 490 audit templates and reporting lines. The appointment certificate, signed, filed, verifiable. Licence the workspace for your internal representatives, or have our representatives order it. The content is based on the specifications of ISO/IEC 27001:2022, ISO/IEC 27002:2022 and the auditing specifications according to ISO/IEC 27006.

Key Takeaways

  • Realistic project duration for medium-sized companies: 9 to 18 months from kickoff to certificate, depending on the level of maturity and scope.
  • The certification takes place in two stages: Stage 1 checks the documentation, Stage 2 checks the operational effectiveness over at least 3 months of operation.
  • The most common audit findings relate to risk management, supplier management and proof of effectiveness of controls, not technical hardening.

Phase 1: Preparation and Scope (1 to 3 months)

The preparation phase lays the foundations without which no ISMS works. First: Determine the scope according to clause 4.3 of the standard. The scope defines which locations, business processes, products and services are covered by the ISMS. A scope that is too broad creates effort without added value; a scope that is too narrow excludes business-critical areas and reduces the market value of the certificate to customers. The choice must be strategic and coordinated with the management.

Secondly: stakeholder analysis according to clause 4.2. Internal and external interested parties must be identified and their requirements and expectations must be collected. Typically: customers with audit requests, supervisory authorities (BSI, BaFin, state data protection authorities), parent company, insurers, suppliers, and if necessary auditors. Third: Appointment of the information security officer with an appointment document, reporting line to management, exempt time quota.

Fourth: GAP analysis against the 93 controls from Appendix A. The analysis answers per control: implemented, partially implemented, not implemented, not applicable. The result is the Statement of Applicability (SoA), the mandatory document of the standard according to clause 6.1.3 d. The SoA is checked centrally in the Stage 1 audit and is the basis of every follow-up conversation with the auditor.

Fifth: Project planning with milestones, resources and budget. What is realistic in medium-sized companies is 1.0 to 2.5 full-time equivalents for 9 to 12 months plus external consultants or officer-as-a-service. The external information security officer takes over the methodology, the operational steps remain with the company. This phase lasts 1 to 3 months if it is managed in a disciplined manner, otherwise phase 1 quickly drags on to 6 months and blocks all subsequent phases. A typical kickoff agenda includes scope workshop, stakeholder mapping, appointment of the ISB, GAP analysis workshop and determination of the risk appetite by management with a documented decision.

Phase 2: Risk management and statement of applicability (2 to 4 months)

Clause 6.1 of ISO/IEC 27001:2022 requires a documented process for information security risk assessment and management. The methodology can be freely chosen; in practice, an asset-based or scenario-based approach according to ISO/IEC 27005 has proven to be effective. The method must be consistent and deliver reproducible results. A changing methodology between iterations leads to audit complaints.

Steps: Inventory of information assets (data, systems, applications, people, locations), evaluation according to protection goals confidentiality, integrity, availability. Identification of threats and vulnerabilities, risk assessment with probability of occurrence and amount of damage, determination of risk acceptance criteria by management. Risk treatment with the four options avoidance, reduction, transfer, acceptance, each with documented justification.

The result is a risk register with typically 80 to 250 risks in medium-sized companies. Each risk is linked to measures from Appendix A or your own measures. The Statement of Applicability documents per control: status (applicable or not applicable with justification), implementation description, reference to guidelines or technical measures. The SoA must be formally approved by management.

Common mistakes: Asset-level risks assessed too granularly, with hundreds of individual assessments that cannot be controlled. Or vice versa: too general with ten collective risks that do not specify anything. Supervisory authorities and auditors expect a level at which concrete measures can be derived. The transition periods for the 2022 version must be adhered to. The CIVAC platform provides a risk register template with ISO/IEC 27005 logic and automatically maps to the 93 controls including references to specific guidelines. Phase 2 lasts 2 to 4 months depending on asset size and maturity level. The risk acceptance criteria are recorded in a formal decision by the management and form the objective standard against which each treatment is assessed in the further course.

Phase 3: Implementation of the 93 controls from Appendix A (3 to 9 months)

The implementation of the controls is the largest phase and largely determines the overall duration of the project. Annex A of ISO/IEC 27001:2022 contains 93 controls in four groups: 37 Organizational Controls (A.5), 8 People Controls (A.6), 14 Physical Controls (A.7), 34 Technological Controls (A.8). The reduction from 114 controls in the 2013 version to 93 in 2022 was achieved through consolidation. New controls concern, among other things, threat intelligence (A.5.7), information security for use of cloud services (A.5.23), data masking (A.8.11) and web filtering (A.8.23).

Organizational controls include guidelines, roles, responsibilities, supplier control, incident response, business continuity. People controls concern background checks, disciplinary procedures, training, post-contract responsibilities. Physical controls regulate access, safe areas, cabling and device disposal. Technological controls address access control, cryptography, backup, logging, vulnerability management, secure development.

Operationally, a policy landscape is created with typically 15 to 30 main policies plus associated work instructions. Key policies: information security policy (top level), access control, cryptography, backup and restore, vulnerability management, incident response, supplier security, data classification, mobile device management, emergency management, awareness training, key management, secure software development.

Most common gaps: lack of evidence of effectiveness. A guideline is not enough, the auditor expects evidence that the guideline is being lived – log files, tickets, training certificates, inspection logs. The deadline expires when we become aware of it: an incident without an entry in the incident register is exposed by the ISMS. The CIVAC workspace links the guideline with the proof of effectiveness for each control and automatically reports missing documents to the reporting line, with audit-proof storage and EU data residency. Phase 3 lasts 3 to 9 months, with several workstreams running in parallel. A steering committee meeting every four weeks with management, ISB and department heads is standard, supplemented by weekly operational reviews with workstream leads and a transparent list of measures.

Phase 4: Internal Audit and Management Review (1 to 2 months)

Clause 9.2 requires at least one internal audit of all clauses and controls of the ISMS before the external auditor comes. The internal audit must be carried out independently, i.e. not by the person responsible for the areas to be audited. In smaller companies, an external auditor for the internal audit is often pragmatic and reduces the risk of complaints of bias.

Methodology: Audit program with topics, dates and auditors, audit checklist for each control, samples from practice (tickets, log files, training certificates, inspections, interviews with key roles), written audit report with main deviations, minor deviations, observations and recommendations. The deviations are tracked in the action plan, each measure with the person responsible and the deadline.

Clause 9.3 requires the management review at least annually. The management evaluates the ISMS effectiveness based on defined inputs: audit results, corrective action status, key figures, risk situation, incidents, customer feedback, status of the goals from clause 6.2. Output is a documented decision on improvements, resources and strategy. The management review is one of the three mandatory artifacts that an auditor always sees in Stage 1 and Stage 2. A blanket protocol note without content is objected to.

Phase 4 lasts 1 to 2 months. The most common mistake is confusing internal audit with self-assessment: the internal audit must be carried out methodically according to ISO/IEC 19011 with traceable audit traces, otherwise it will be criticized in the Stage 1 audit. Others run compliance like a filing cabinet. We run it like software. The CIVAC platform provides an audit program, checklists, report templates and management review templates, all versioned and with an audit trail, so that the mandatory artifacts are signed, filed and verifiable. The internal audit is typically completed six to eight weeks before Stage 1 to allow sufficient time for corrections.

Phase 5: Stage 1 and Stage 2 with accreditation body (2 to 4 months)

The external certification takes place in two stages by an accredited certification body (in Germany, including TÜV companies, DEKRA, DQS, BSI Group). The choice of certification body depends on the industry, language and company requirements. Accreditations can be verified via the German Accreditation Body (DAkkS). Anyone who certifies for international customers chooses a body with IAF accreditation.

Stage 1 is the document audit. The auditor reviews ISMS policy, risk management methodology, SoA, guidelines, procedures, internal audit, management review. Stage 1 takes 1 to 3 audit days depending on the size of the company and can partly be done remotely. The result is an audit report with major deviations, minor deviations or “ready for Stage 2”. Major deviations must be remedied before Stage 2, otherwise Stage 2 will be postponed.

Stage 2 is the effectiveness audit. The auditor checks the implementation in practice on site, with interviews, random samples, technical tests and inspections. Stage 2 takes 3 to 10 audit days, depending on the size of the company. Requirement: the ISMS has been running productively for at least 3 months so that proof of effectiveness is available. The result is the recommendation for certification or the finding of failure with a correction period.

Phase 5 lasts a total of 2 to 4 months, including corrective measures between Stage 1 and Stage 2. The certificate is valid for 3 years, with annual monitoring audits and re-certification after expiry. The costs of the certification body are typically between 15,000 and 60,000 euros over three years, depending on size and complexity. The auditor calls, the evidence is ready. - this is the operational requirement for every phase and every appointment in the cycle. The audit mandates contain confidentiality agreements so that security concerns when disclosing sensitive information such as configuration data or supplier contracts are legally protected.

Effort per phase: full-time equivalents and costs

Realistic effort estimates help with project planning and budget approval. The following values ​​apply to a medium-sized company with 50 to 250 employees and a scope of 1 to 3 locations plus cloud services. For group scopes or multi-site certifications, the values ​​scale disproportionately.

Phase 1 (1 to 3 months): 0.5 to 1.0 FTE internal ISB plus 5 to 15 consulting days. Phase 2 (2 to 4 months): 1.0 to 1.5 FTE plus 10 to 25 consultant days. Phase 3 (3 to 9 months): 1.5 to 2.5 FTE over the entire phase plus 15 to 40 consulting days plus investments in tools (SIEM, MDM, vulnerability scanners) typically 50,000 to 200,000 euros. Phase 4 (1 to 2 months): 1.0 FTE plus 5 to 15 auditor days. Phase 5 (2 to 4 months): 1.0 FTE plus the certification body.

In total, the personnel costs are 12 to 25 person-months internally plus 35 to 95 consultant days externally. Die Gesamtkosten inklusive Tooling, Beratung und Zertifizierungsstelle liegen im Mittelstand bei 150.000 bis 500.000 Euro über die ersten drei Jahre, mit jährlichen Folgekosten von 30.000 bis 90.000 Euro für Aufrechterhaltung und Überwachungsaudits.

Die Spanne ist groß, weil der Reifegrad zu Projektbeginn entscheidet. Companies with existing IT security functions, documented guidelines and established patch management get off to a quicker start. Greenfield projects without preparatory work require 50 to 100 percent more time. Officer-as-a-Service models shorten Phase 1 to 4 weeks because methodology and templates are immediately available instead of having to be built. The CIVAC SLA: 2 working days instead of 2 to 6 weeks classic for ISB availability. For multi-location certifications, travel and site coverage costs are also added, which can amount to 10 to 25 percent of the consulting budget, depending on the geographical distribution.

Most common audit findings and how to avoid them

Evaluations by German certification bodies show recurring findings in the Stage 2 audit, which regularly lead to major deviations. Anyone who prepares these five points significantly reduces the risk of failure and shortens the time between Stage 1 and the final issuance of the certificate.

First: missing or unclear risk assessment. Auditors complain about unclear methodology, a lack of risk acceptance criteria or an SoA that does not fit the risk assessment. Second: supplier control (A.5.19 to A.5.22). Contracts without safety clauses, lack of categorization of critical suppliers, no periodic evaluation. Third: evidence of effectiveness. Guidelines exist, but no evidence of practical implementation. Log files are not evaluated, proof of training is missing, incident tickets are closed without lessons learned.

Fourth: Business continuity and emergency management (A.5.29, A.5.30). Plans exist on paper, exercises have not been carried out, restart times have not been tested. Fifth: vulnerability management and patch management (A.8.8). Scans exist, but the closure of the findings is not tracked, critical patches have waiting times for months without documented risk acceptance.

Four preparations help operationally: a central effectiveness dashboard with all 93 controls and statuses; a supplier register with criticality, contract, last rating; one documented BCP test per financial year; a maintained patch status with risk acceptance for outstanding findings. The CIVAC workspace displays these four dashboards in a standardised manner, with threshold alarms that automatically report missing documents to the ISB. The appointment certificate, signed, filed, verifiable – including annual effectiveness assessment for each control. In the Stage 2 audit, the auditor draws samples from exactly these dashboards. Audit-proof, documented, clause 9.1-proof. A complete collection of lessons learned after each internal audit and after each incident closes the improvement loop of clause 10. In practice, it has been shown that companies with medium maturity typically derive 40 to 80 corrective measures from the first audit cycle, which are structured and tracked with responsible persons and deadlines.

Accelerator: templates, platform, external function

Three levers shorten the project duration and reduce the risk of failure. First: pre-configured templates. Anyone who takes guidelines, SoA, risk registers and audit programs from the standard work and adapts them to their own context saves 30 to 50 percent preparation time. Creating your own greenfield creates additional effort without added value because the standard specifies the content structurally and only the adaptation to the industry and business model varies.

Secondly: integrated platform instead of a SharePoint collection. A compliance platform with an ISMS module bundles guidelines, controls, risk registers, measures, suppliers, incident tracking and proof of effectiveness in one place. Versioning, access rights, audit trail and reporting line are built in. The platform produces the stage 1 documents and audit reporting for the certification body at the push of a button.

Third: external ISB as officer-as-a-service. The function is transferred with an appointment certificate, the external ISB takes over the methodical leadership, trains internal multipliers, manages the projects and takes over the interface to the certification body. Advantages: cross-industry experience with other certifications, no learning curve, quick response to audit findings. CIVAC SLA: 2 working days instead of the classic 2 to 6 weeks.

Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data base, so that mixed forms are possible at any time: the function starts externally, the internal employees are empowered, the function moves internally in the second or third year. The certificate is retained, the platform continues to run, the reporting line remains audit-proof. Others run compliance like a filing cabinet. We run it like software. Audit proof, documented, ISO 27001 proof. The platform integrates NIS 2 reporting paths, GDPR information workflows and ISO 27001 proof of effectiveness in one file structure, so that parallel regulations are served with the same data basis. This eliminates the usual duplication of work with overlapping obligations from GDPR, NIS-2 and ISO/IEC 27001.

Operational implementation with CIVAC: Platform or Officer-as-a-Service

An ISMS structure is a project with a defined end; the operation of the ISMS is a continuous process. CIVAC supports both phases as a compliance platform and officer-as-a-service, with identical data base between project and operation.

The first model: Licence the workspace for your internal representatives. The workspace contains the 93 controls of ISO/IEC 27001:2022, preconfigured risk register templates, 490 audit templates, policy library, supplier register, incident tracking, training modules, management review templates. EU data residency and client separation are built in. The platform covers 25 officer roles, so that the ISB works in an integrated manner with the data protection officer, the NIS-2 officer and the compliance officer.

The second model: Have our officers appointed. The external ISB takes over the function with an appointment certificate, reporting line to the management, methodical leadership, training of internal multipliers, audit preparation and support of the certification body. The SLA: 2 working days instead of 2 to 6 weeks classic. To ensure maintenance, the external ISB takes over annual audits and the management review.

The auditor calls, the evidence is ready. The platform sends reminders for annual audits, management reviews, training appointments and ongoing supplier reviews. When incidents occur, the incident workflow with defined escalation levels and reporting obligations runs parallel to NIS-2 reporting paths (24-hour early warning, 72-hour follow-up reporting).

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. The initial check of the maturity level against the 93 controls takes 90 minutes; the result is a concrete roadmap with phases, efforts and critical paths. The scope definition, appointment certificate and initial risk register will be available within 10 working days. The workspace is multi-client capable and allows multiple parallel certifications, for example for holding structures or when expanding the scope to include new locations or business areas.

FAQ

How long does ISO 27001 certification take for medium-sized businesses?

In medium-sized companies, realistically 9 to 18 months from the start of the project to the certificate. Phase 1 (preparation) 1 to 3 months, Phase 2 (risk management and SoA) 2 to 4 months, Phase 3 (implementation of the 93 controls) 3 to 9 months, Phase 4 (internal audit, management review) 1 to 2 months, Phase 5 (external certification with Stage 1 and Stage 2) 2 to 4 months. The level of maturity and scope determine the range.

What exactly does the Stage 1 audit check?

The Stage 1 audit is a document audit. The ISMS policy, scope, risk management methodology, statement of applicability, guidelines, procedures, result of the internal audit, protocol of the management review are examined. The audit takes 1 to 3 days. The result is the release for Stage 2 or the requirement to correct major deviations before Stage 2 can be scheduled.

How many controls does ISO/IEC 27001:2022 have in Annex A?

93 controls in four topic groups: 37 Organizational (A.5), 8 People (A.6), 14 Physical (A.7), 34 Technological (A.8). The previous version from 2013 had 114 controls; the reduction was achieved by merging them. New features include Threat Intelligence (A.5.7), Information Security for use of Cloud Services (A.5.23), Data Masking (A.8.11) and Web Filtering (A.8.23).

What are the costs for the certification body?

In medium-sized companies, typically 15,000 to 60,000 euros over three years, depending on size and complexity. The certificate is valid for 3 years, with annual surveillance audits and re-certification at the end of the cycle. In addition, there are internal costs and advice of 150,000 to 500,000 euros over the first three years in medium-sized companies.

Can the internal audit be carried out by your own employees?

Yes, provided the independence in accordance with clause 9.2 is maintained. The internal auditor is not allowed to audit his own area. In smaller companies, independence is often difficult to demonstrate, which is why an external auditor is often commissioned for the internal audit. The audit program must be managed in a comprehensible and versioned manner.

What happens after the certificate in the following years?

The certificate is valid for 3 years. In subsequent years, annual surveillance audits take place to check samples for effectiveness. After 3 years, a complete recertification takes place. In the event of serious violations, the certification authority can suspend or revoke the certificate. The internal ISMS program runs continuously with annual internal audit and management review.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles