What's included
The certification audit is not one event. It is a documentation review, then a mandatory gap in which you fix what it found, then a full evidence audit — and the gap is the reason ISO 27001 plans cannot be squeezed at the end:
- Scope & gap analysis — ISMS boundaries, interested parties and legal obligations, a gap analysis against the Annex A controls, and certification body selection — which is also when the two audit dates get booked. Milestone: scope and gap baseline agreed.
- Risk assessment & SoA — Information asset inventory, the risk methodology, risk identification and evaluation, the risk treatment plan, and the Statement of Applicability that records which controls apply and why. Milestone: SoA and risk treatment approved.
- Control implementation — The policy set, access control and identity, supplier and cloud controls, secure development and change control, physical and people controls, and incident and continuity procedures. Milestone: controls implemented.
- Operate & accumulate records — The phase that cannot be shortened: running the controls long enough that access reviews, log monitoring, supplier reviews and an incident exercise have actually happened and left records behind. Milestone: three months of records available.
- Internal audit & management review — A full internal audit of the ISMS, the nonconformities it raises, corrective action, and the management review meeting. Both are mandatory inputs and both must be finished before Stage 2. Milestone: internal audit and management review complete.
- Stage 1 & Stage 2 audit — The Stage 1 documentation audit, its findings, the corrective action window, the evidence refresh, the Stage 2 audit, nonconformity closure and the certificate. Milestone: certificate issued.
How to customize it
- Book the certification body early and set the Stage 2 date first — everything before it is a countdown, not an estimate.
- Keep at least six weeks between Stage 1 and Stage 2 for corrective action; shortening it is the most common cause of a failed Stage 2.
- Expand the control implementation rows to one line per Annex A theme, or per control, once the Statement of Applicability is approved.
- Lengthen the operating phase if your risk treatment relies on controls with quarterly or annual cycles — you need at least one full cycle of evidence.
- Add rows for any scope exclusions you have to justify, since those are what Stage 1 will probe hardest.
- Add the year-one surveillance audit as a dated row so the ISMS is resourced past the certificate.
Scheduling tips
- The Statement of Applicability drives everything after it. Until it is approved you do not know which controls you are building, so implementation estimates before that point are guesses.
- Run the internal audit for real. A soft internal audit that finds nothing simply moves the findings to Stage 2, where they cost you the certificate date instead of a fortnight.
- Hold the management review as a minuted meeting. It is an explicit requirement with defined inputs, and auditors read the minutes rather than take your word for it.
- Do the incident and continuity exercise before Stage 2. It is one of the few pieces of evidence you can schedule rather than wait for.
- Do not blend this with SOC 2. They share controls but not mechanics: ISO 27001 is a certification with a three-year cycle and surveillance audits, SOC 2 is an AICPA attestation report against Trust Services Criteria.
Related templates
- ISO 9001 Certification Plan Template
- SOC 2 Compliance Timeline Template
- Internal Audit Plan Template
- Browse all Gantt chart templates
Frequently asked questions
How long does ISO 27001 certification take?
Commonly twelve to eighteen months from a standing start for an organisation with no existing ISMS. The template uses roughly fifteen months. The parts that resist compression are the operating period that generates records and the mandatory gap between Stage 1 and Stage 2.
What is the difference between Stage 1 and Stage 2?
Stage 1 is a documentation and readiness review — scope, policies, risk assessment, Statement of Applicability, internal audit and management review evidence. Stage 2 is the full audit of whether the ISMS actually operates. Stage 1 findings must be closed before Stage 2, which is why the template leaves a corrective action window between them.
Do I need an internal audit and management review before Stage 2?
Yes. Both are mandatory clauses of the standard and both are things the auditor will ask to see evidence of. The template puts them ahead of Stage 1 so the corrective actions they raise have time to be closed.
Is ISO 27001 the same as SOC 2?
No. ISO 27001 is an international standard you are certified against by an accredited body, on a three-year cycle with annual surveillance audits. SOC 2 is an AICPA attestation performed by a CPA firm against the Trust Services Criteria, and a Type II report covers a defined observation window rather than granting a certificate. Use the SOC 2 compliance timeline for that; the two plans overlap on controls but not on dates.
How does this differ from the ISO 9001 plan?
The audit mechanics are the same two-stage shape, but the content is different: ISO 9001 is a quality management system, this is an information security management system built on a risk assessment and a Statement of Applicability. See the ISO 9001 certification plan if you are certifying both.
Is the ISO 27001 template free?
Yes. Free Excel, PowerPoint and CSV downloads, and free online editing with no account and no watermark.