The first phase is building the ISMS: scope, risk assessment, the Statement of Applicability, the Annex A controls that apply, and the policy set. With an operated program this is weeks of concentrated work; solo, it is the phase that swallows quarters. The wrinkle ISO adds is that the system must then demonstrably run — certification auditors expect a completed internal audit and management review before they arrive, which bakes a short operating runway into every honest timeline.
Certification itself is two visits. Stage 1 reviews your documentation and readiness; Stage 2 tests that the ISMS operates as written. Nonconformities raised at Stage 2 must be addressed before the certificate issues. And the certification body’s schedule is a real constraint — reputable ones book out — so the visits get reserved while the ISMS is still under construction, not after.
Scope. Certifying one product line and the teams behind it is a different project from certifying the whole company. Narrow first certificates are normal; they expand at recertification.
Certification-body lead time. Auditors plan visits well ahead. Booking Stage 1 and Stage 2 early converts their queue from a delay into a deadline that keeps everyone honest.
Findings. A major nonconformity at Stage 2 means remediation and follow-up before issuance. The startup-specific pitfalls — and how to route around them — are covered in ISO 27001 for startups.
Three years, with annual surveillance audits in between and full recertification at the end of the cycle. Skipping a surveillance visit puts the certificate itself at risk.
Not a fixed evidence window, no. But Stage 2 tests operation, and auditors expect the internal audit and management review to be done — so the ISMS still needs real operating history before certification.