A 16-week ISO 27001 program runs through four phases: foundation (weeks 1-4), build (weeks 5-10), operate and evidence (weeks 11-14), and certify (weeks 15-16). The full week-by-week breakdown is below.
Quick answer: Weeks 1-4 set the scope, gap assessment, risk assessment, and Statement of Applicability. Weeks 5-10 build the policies and technical controls. Weeks 11-14 run training, evidence collection, the internal audit, and a management review. Weeks 15-16 are the certification body's Stage 1 (documentation review) and Stage 2 (certification audit).
Sixteen weeks is the number most Australian SMBs hear before they have any real sense of what fills those sixteen weeks. Knowing the total is useful for budgeting. Knowing what happens week by week is what actually lets a founder or ops lead plan around it - which weeks need engineering time, which weeks are mostly paperwork, and which week the certification body actually shows up.
This article is that breakdown. If you want the drivers behind why a timeline lands at 16 weeks rather than 12 or 24, read how long ISO 27001 certification takes in Australia first. This article assumes you already know the destination and want the week-by-week route.
What Are the Four Phases of a 16-Week ISO 27001 Program?
Before the week-by-week detail, here is the shape of the program. A well-run 16-week engagement moves through four phases: build the foundation, implement the controls, operate the system and gather evidence, then certify.
| Phase | Weeks | Focus |
|---|---|---|
| 1. Foundation | 1-4 | Scope, gap assessment, risk assessment, Statement of Applicability |
| 2. Build | 5-10 | Policies, technical control implementation, vendor and third-party risk reviews |
| 3. Operate & Evidence | 11-14 | Training, evidence collection, internal audit, remediation, management review |
| 4. Certify | 15-16 | Stage 1 documentation review, Stage 2 certification audit |
What Happens in Each Week of a 16-Week ISO 27001 Program?
The table below is the level of detail we work to internally when running a program. Real engagements shift by a week here or there depending on scope and resourcing, but this is a representative run.
| Week | Focus | Key Deliverable |
|---|---|---|
| 1 | Kickoff and scope definition | Approved ISMS scope statement |
| 2 | Gap assessment against Annex A | Prioritised gap and remediation list |
| 3 | Risk assessment | Risk register and draft risk treatment plan |
| 4 | Statement of Applicability | Draft SoA identifying which controls apply |
| 5 | Core policy suite drafted | ISMS policy, access control, acceptable use and related policies |
| 6 | Policy approval and rollout | Management sign-off and staff acknowledgement |
| 7 | Technical control implementation begins | MFA, logging, backup testing and endpoint controls underway |
| 8 | Technical control implementation continues | Remaining Annex A control gaps closed |
| 9 | Vendor and third-party risk reviews | Vendor risk register for key suppliers and cloud providers |
| 10 | Evidence collection begins | Evidence repository mapped to each control |
| 11 | Security awareness training and phishing simulation | Training completion records |
| 12 | Internal audit | Internal audit report and findings |
| 13 | Remediation of internal audit findings | Corrective actions closed |
| 14 | Management review | Formal leadership review of ISMS performance |
| 15 | Stage 1 audit | Documentation review by the certification body |
| 16 | Stage 2 audit | Certification issued (subject to any minor findings being closed) |
Why Does the Internal Audit Matter More Than the Stage 2 Audit?
Week 12 gets less attention than the Stage 2 audit, but it is the week that determines whether Stage 2 is straightforward or stressful. Every control your Statement of Applicability declares in scope needs to be implemented and operating, with evidence to show it, by the time the certification body arrives for Stage 2 - not most of them, all of them. The internal audit is scheduled with real runway before that, typically about a month, precisely so it can catch gaps early enough to close them internally rather than have them surface for the first time in front of the certification body.
A nonconformity raised internally in week 12 costs you a remediation task. The same gap surfacing for the first time in week 16, in front of the certification body, costs you a delayed certificate. That is the entire argument for treating the internal audit as a real audit rather than a formality.
What Causes an ISO 27001 Timeline to Slip Past 16 Weeks?
Two things account for most of the delays we see in the build phase (weeks 5-10):
- Cloud infrastructure that has not been segregated. A single AWS or GCP account running production, staging and development side by side is a common finding, and it is not a quick fix - it turns "implement access control" into an infrastructure re-architecture project. Segregating environments early, ideally before the program starts, keeps weeks 7 and 8 on schedule.
- One person carrying evidence collection alongside their existing job. Evidence collection in weeks 10-11 needs dedicated hours, not the leftover time of whoever is already the busiest technical person in the business. Programs that assign this properly stay on the 16-week track; programs that do not tend to slip a phase at a time.
What Happens After You Get ISO 27001 Certified?
Certification is valid for three years, not sixteen weeks. Certification bodies run an annual surveillance audit at the end of year one and year two, reviewing a subset of controls to confirm the ISMS is still operating as designed - including whether internal audits and management reviews happened on schedule. Before the three-year certificate expires, a more thorough recertification audit takes place, similar in scope to the original Stage 2 audit, and it resets the three-year cycle. The 16-week program gets you certified; ongoing governance is what keeps you certified.
The honest version: The 16 weeks are demanding but predictable if the phases above are resourced properly. Most of what extends a timeline past 16 weeks is not the standard being difficult - it is infrastructure debt or resourcing gaps that were already there before the program started.
At Logic Weave, we run 16-week ISO 27001 certification end to end - gap assessment, policy and control implementation guidance, internal audit, and representation through Stage 1 and Stage 2 with your chosen certification body. If you want a realistic week-by-week plan for your specific starting point, book a call and we will walk through it.
Frequently Asked Questions
What happens in a 16-week ISO 27001 certification program?
A 16-week ISO 27001 program typically runs through four phases: foundation (weeks 1-4 - scope, gap assessment, risk assessment, Statement of Applicability), build (weeks 5-10 - policies, technical controls, vendor reviews), operate and evidence (weeks 11-14 - training, evidence collection, internal audit, remediation, management review), and certify (weeks 15-16 - Stage 1 documentation review and Stage 2 certification audit).
What is the difference between an ISO 27001 Stage 1 and Stage 2 audit?
Stage 1 is a documentation review where the certification body checks that your Information Security Management System (ISMS) is adequately designed and ready for assessment. Stage 2 is the full certification audit, where auditors test whether your controls are actually operating as documented. Certification is issued after Stage 2 is successfully completed.
How much control evidence do you need before the external audit?
Every control your Statement of Applicability declares applicable needs to be implemented and operating, with evidence to show it, by the time the Stage 2 audit begins. The internal audit is scheduled with enough runway before Stage 2 - typically about a month - so that any gap it finds can be fixed internally rather than surfacing for the first time in front of the certification body.
What happens after your ISO 27001 certificate is issued?
Certification is valid for three years. Certification bodies conduct annual surveillance audits at the end of year one and year two, reviewing a subset of controls to confirm the ISMS is still operating as designed. Before the three-year certificate expires, a more thorough recertification audit takes place, similar in scope to the original Stage 2 audit, which resets the three-year cycle.
Can the 16-week ISO 27001 timeline slip?
Yes. The two most common causes are cloud infrastructure that has not been segregated into separate environments (production, staging, development), which turns control implementation into an architecture project, and reliance on a single technical resource who cannot dedicate time to evidence collection alongside their existing workload.