Updated: 5 July 2026
What is an ISO 27001 implementation? Implementing ISO 27001 is the project of building an Information Security Management System (ISMS) conformant with ISO/IEC 27001:2022. It covers: defining the ISMS scope, conducting a risk assessment, implementing appropriate security controls (from Annex A), creating the required documentation, and submitting the system to an external certification audit. The typical time from project start to certificate is 9 to 18 months, depending on organisational size and the maturity of existing security controls.
ISO 27001 implementation – at a glance:
- The ISMS scope must be precisely defined before the project begins – it covers a chosen part or the whole organisation, specific locations and processes
- A gap analysis conducted at the outset allows you to assess how many controls are already in place and how much work remains – this is the basis for the timeline and budget
- ISO/IEC 27001:2022 references 93 controls in Annex A – but not all need to be applied if exclusions are justified in the Statement of Applicability
- The certification audit has two stages: Stage 1 (documentation review) and Stage 2 (technical verification and interviews) – each may identify nonconformities
- An ISO 27001 certificate is issued for 3 years with an annual surveillance audit – maintaining the certificate requires continuous ISMS management
- Patronusec guides organisations through the full ISO 27001 implementation cycle – from gap analysis to the annual surveillance audit – in a project model or vCISO retainer
Table of Contents
How do you define the ISMS scope – and why is this a strategic decision?
The ISMS scope is the first and most consequential decision of the entire project. It determines which processes, organisational units, locations, and IT systems are covered by the information security management system.
Scope options:
- The whole organisation – all processes, all locations, all employees. The most expensive and time-consuming option, but one that delivers the broadest certificate.
- A selected business unit or division – for example, the IT department or a data centre. A faster and less expensive starting point, but the certificate is limited to that scope.
- A specific product or service – scope defined around a particular SaaS product or system. Popular among technology firms when clients require a certificate for a specific service.
What the documented ISMS scope must contain:
- A description of the organisation and its context (ISO 27001 Clauses 4.1 and 4.2)
- A list of processes, units, and locations covered by the ISMS
- A list of ISMS boundaries (what is internal, what is external – suppliers, cloud providers)
- Justification for any exclusions
The most common scoping mistake:
Setting too wide a scope at the outset – the organisation takes everything in order to get a “proper” certificate, and the project takes 24 months and costs three times more than planned. It is better to start with a narrower, well-managed scope and expand it over time.
Patronusec Insight: “What scope should we define for the ISMS?” is always the first question at the kick-off of a new ISO 27001 project. Firms with clients requiring a certificate for a specific service (for example, SaaS for a bank) should define the scope around that service – it is the fastest path to a certificate acceptable to the client. Firms implementing ISO 27001 for internal reasons can afford to expand scope progressively. We help clients choose the optimal scope as part of the initial consultation preceding the ISO 27001 implementation project.
How do you conduct a gap analysis before ISO 27001 implementation?
A gap analysis is the assessment of the difference between the organisation’s current security posture and the requirements of ISO/IEC 27001:2022. It is the step immediately following scope definition and preceding the implementation project itself.
What an ISO 27001 gap analysis covers:
- Organisational and contextual requirements (Clauses 4 to 6)
- Information security policies and procedures
- The status of all 93 Annex A controls – implemented, partially implemented, or absent
- Risk management – does a risk register exist? Is there a methodology and named risk owners?
- Incident management and business continuity
- Employee security training and awareness
- Supplier and third-party management
Output of the gap analysis:
The gap analysis should deliver:
- A compliance assessment for each requirement (met / partially met / not met)
- A prioritised remediation action list with estimated effort
- A realistic implementation project timeline
- A preliminary project budget
Without a gap analysis, an organisation enters the project blind – not knowing whether 20% or 70% of requirements are already met, and unable to plan a realistic schedule.
Planning to implement ISO 27001 but not sure where to start or how long it will take?
Patronusec conducts a gap analysis as the first service before any implementation project. Within 2 to 3 weeks: a complete gap assessment, project timeline, and a board-ready quotation.
Book an ISO 27001 gap analysis
What does an ISO 27001 implementation timeline look like – and what causes delays?
A typical ISO 27001 implementation project for an organisation of 50 to 500 employees takes 9 to 15 months. Below is a typical phased timeline.
ISO 27001 implementation timeline:
| Phase | Duration | Key activities |
|---|---|---|
| Preparation | 1 to 2 months | ISMS scope, gap analysis, assembling project resources |
| Documentation | 2 to 4 months | Policies, procedures, SoA, risk treatment plan |
| Control implementation | 3 to 6 months | Technical and organisational security controls |
| Training and awareness | Concurrent | Training programme, phishing simulations, internal communications |
| Internal pre-audit | 1 month | Internal audit or external readiness assessment |
| Stage 1 audit | 1 to 2 weeks | Documentation review by the certification body |
| Stage 1 remediation | 2 to 4 weeks | Addressing documentation gaps |
| Stage 2 audit | 2 to 4 weeks | Testing, interviews, verification of implementation |
| Certification | After findings closure | Certificate issued (valid 3 years) |
Factors that extend the project:
- Wide ISMS scope (whole organisation, multiple locations)
- Lack of board engagement in approving documentation
- Key personnel turnover during the project
- Technical environment complexity (legacy systems, multi-vendor cloud)
- Absence of a dedicated internal resource to work alongside the consultant
Patronusec Insight: ISO 27001 projects most commonly stall not at the technical stage but at the document approval stage. The information security policy, the Statement of Applicability, and the risk treatment plan all require board approval – and they frequently reach the board unprepared for what the board actually needs to decide. In our vCISO model, we prepare decision-ready materials for the board – concise, with a recommendation and rationale – rather than technical documents to be read. This reduces approval time from weeks to days.
What is the Statement of Applicability (SoA) and why is it critical?
The Statement of Applicability (SoA) is a document required by ISO/IEC 27001:2022 (Clause 6.1.3 d) that lists all 93 Annex A controls with the following for each: whether it is applied, why (or why not), and in what form.
The SoA must contain for each of the 93 controls:
- Status: applied / not applied
- Justification for inclusion or exclusion
- Reference to the risk treatment plan (for included controls)
- Description of implementation (optional but recommended)
Why the SoA is the critical document:
The SoA is one of the first documents a certification body auditor requests at Stage 1. An incomplete SoA, or one not linked to the risk register, is the most common major nonconformity in a first ISO 27001 audit.
What may be excluded from the SoA:
An Annex A control may be excluded only if: the risk assessment identifies no risk that the control addresses, OR the risk is accepted by the board without implementing the control. A control cannot be excluded because “it is difficult to implement” – an auditor will reject that justification.
What do Stage 1 and Stage 2 certification audits involve?
The ISO 27001 certification audit is conducted by a certification body (Bureau Veritas, TUV, BSI, DNV, Lloyd’s Register, LRQA) – not by the consultant who supported the implementation.
Stage 1 – documentation review:
The auditor assesses whether the organisation has complete and consistent ISMS documentation: policies, procedures, SoA, risk register, risk treatment plan, internal audit results, and management review minutes. Stage 1 takes 1 to 3 days and concludes with a report listing observations and nonconformities to be addressed before Stage 2.
Stage 2 – verification of implementation:
The auditor verifies that the controls defined in the documentation are actually in place – through staff interviews, technical testing, and review of evidence (logs, screenshots, configurations). Stage 2 takes 2 to 5 days depending on scope. Following Stage 2, the auditor issues a findings report; the organisation must close all findings before the certificate is issued.
FAQ – ISO 27001 implementation
How much does ISO 27001 implementation cost?
The total cost is the sum of the consultant or adviser, the certification body audit, and internal organisational resources. For a firm of 50 to 200 employees: typically £65,000 to £200,000 for consulting services plus £12,000 to £35,000 for the certification audit. Scope, environment complexity, and organisational readiness determine where in that range a specific organisation falls.
Does ISO 27001 require hiring a dedicated CISO or ISMS manager?
The standard requires that accountability for the ISMS is assigned to a specific person or role – but does not require a full-time position. Many firms appoint a part-time ISMS manager (for example, 30% of an IT manager’s time) or use the vCISO model (an external CISO on a part-time retainer). The key is that this person has a board mandate and the time to genuinely manage the ISMS.
How long is an ISO 27001 certificate valid?
The certificate is issued for 3 years with an annual surveillance audit. After 3 years, a recertification audit is required. If a surveillance audit identifies critical nonconformities that are not closed within the required timeframe, the certification body may suspend or withdraw the certificate.
Can ISO 27001 and PCI DSS be implemented in parallel?
Yes – and it typically makes sense for organisations processing cardholder data. ISO 27001 and PCI DSS have significant control overlap: access management, risk management, incident management, security testing. An integrated project avoids documentation duplication and simultaneously satisfies the requirements of both standards.
How much does ISO 27001 implementation with Patronusec cost and how does the engagement work?
Patronusec prices ISO 27001 projects after a free initial call and gap analysis. The price is fixed with a guaranteed scope. Engagement model: the Patronusec consultant leads the implementation project (documentation, risk assessment, training) while the client provides system access and resources for implementing technical controls. Optionally, we manage the ISMS in the vCISO model after certification.
How do I choose a certification body for ISO 27001?
Key criteria: accreditation by UKAS (UK Accreditation Service) or another IAF-member accreditation body, experience in the client’s sector, pricing, geographic reach (if the firm has international offices), and audit availability. The certification body must be independent of the implementation consultant – Patronusec is not a certification body; we work with clients throughout the project and help select the right body.
ISO 27001 implementation – free consultation
Patronusec delivers ISO 27001 implementation projects for technology firms, fintechs, and professional services organisations – from gap analysis to certification audit support. In the vCISO model, we take responsibility for ISMS maintenance after certification.
In a free 30-minute consultation we will help you:
- Assess how much time and resource ISO 27001 implementation realistically requires in your organisation
- Choose the optimal ISMS scope for your business needs and client requirements
- Plan the project accounting for parallel regulatory requirements (PCI DSS, DORA, NIS2)
- Decide between a project model and an ongoing vCISO retainer for maintaining the certificate
Free consultation | ISO 27001 implementation | vCISO – ISMS management | DORA compliance | NIS2