ISO27K

ISO 27001 implementation, step by step

An implementation is eleven phases in a fixed order. The order is not a preference: doing the Statement of Applicability before the risk assessment produces a control set you cannot defend, and it is the single most common way a project loses a quarter.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

A first ISO 27001 implementation takes a Canadian company nine to fifteen months and runs through eleven phases in a sequence that is largely fixed. The sequence below is the one that works, with the reason each phase depends on the one before it, because the reason is what tells you when you can safely compress and when you cannot.

What decides the schedule is not effort. It is that clause 9 requires an internal audit and a management review before certification, and both need a system that has been running long enough to have something to review. That is the floor under every timeline on this page.

Phase 1: confirm what was asked for

Get the wording in writing before spending anything. A large share of requests that arrive as "we need you ISO certified" turn out to be a security questionnaire, a SOC 2 report request, or a clause pasted from another contract. This is a five to six figure decision in Canadian dollars and it deserves an email asking the customer to confirm. If the answer names a report rather than a certificate and the buyer is North American, read the comparison with SOC 2 before continuing.

Phase 2: define the scope

Clause 4.3 asks for a documented scope, and the wording ends up printed on the certificate that your customer will read. Write it in terms of services, systems, locations and legal entities, not departments. Two rules save money here: narrow is better than broad for a first certification, because you can widen at recertification and you cannot easily narrow without looking like you retreated; and the scope must be defensible to a customer, because a certificate covering a subsidiary nobody has heard of answers nothing.

Scope also prices the audit. Audit days are derived from effective headcount adjusted for sites, environments and complexity, so every system you pull in costs money for three years, not once.

Phase 3: leadership accountability

Clause 5 wants an accountable executive, a policy signed at the top, and resources committed. In practice you need two named people: someone accountable, who is senior enough to make a spending decision, and someone who runs the management system in the working week. Companies without a security executive commonly fill the first with a fractional CISO. Projects that skip this phase fail at management review, because there is nobody with standing to hold it.

Phase 4: the inventory

Systems, the data in them, where that data physically sits, who has access, and which suppliers touch it. This is the phase most worth doing yourself. A consultant builds it by interviewing your people, which is the slowest and most expensive way to obtain information your people already have. It also decides whether personal information governed by PIPEDA or a provincial statute is in scope, which shapes the boundary and the privacy work that sits beside the certification rather than inside it.

Phase 5: the risk assessment

Clause 6.1.2 requires a documented method, applied consistently, producing risks with owners and assessed levels. The method matters less than applying the same one twice and getting comparable answers. What auditors reject is a risk register that arrived as a template, has no owner names and no dates, and bears no relationship to the inventory from phase 4. The risk assessment methodology page sets out a workable method and the register structure.

Phase 6: treatment and the Statement of Applicability

Decide what to do about each risk, then record a decision on every one of the 93 Annex A controls: applicable or not, why, and how it is implemented. The Statement of Applicability is the first document a stage 1 auditor reads and the one that reveals whether the project was done in the right order. A Statement of Applicability written before the risk assessment reads as a shopping list, because the justification column can only say "good practice", which is not a justification the standard accepts.

Phase 7: implementation

The longest phase, three to six months for most companies, and the one where budget goes. Two workstreams run in parallel: closing control gaps, which is technical and procurement work, and putting the 25 clause requirements into operation, which is process work and includes documented information control, competence and awareness, communication, and the nonconformity process.

Teams underestimate the second workstream because it produces nothing visible. It is also where a project quietly goes wrong: a company can close every technical gap and still fail stage 2 because there is no evidence that anyone was trained, that documents are controlled, or that a nonconformity has ever been raised and closed.

Phase 8: run it

Three months minimum, and a full cycle of the periodic activities is better. An access review completed and signed. A supplier review. A restore actually tested rather than a backup job reported as successful. An incident logged and closed, even a trivial one, because an incident register with no entries tells an auditor the process is theoretical. This phase cannot be shortened by spending money, which is why it should be started earlier than most plans assume. What ready looks like covers the checkpoints in detail.

Phase 9: internal audit

Clause 9.2, and it has to cover the entire management system, not a sample of favourite controls. Independence is the constraint: whoever built the system cannot audit it, which means small teams either buy this from a firm, at $6,000 to $15,000 CAD, or find someone genuinely uninvolved internally. Log real findings. An internal audit report with no nonconformities is a finding in itself at stage 2, because it tells the auditor the internal audit was not real.

Phase 10: management review

Clause 9.3 lists the inputs the meeting must consider, including the status of previous actions, changes in risk, audit results, objective performance and opportunities for improvement. Hold it as a real meeting with the accountable executive present, and minute the decisions rather than the discussion. Auditors check the inputs against the clause line by line, so structure the agenda the same way.

Phase 11: stage 1 and stage 2

Stage 1 is a documentation and readiness review, usually one to two days and often remote. Expect a list of what will fail at stage 2, and take four to twelve weeks to close it. Stage 2 is three to eight days of interviews, sampling and evidence, on site or remote depending on the body and the scope. Major nonconformities must be closed before a certificate issues; minor ones get a corrective action plan. The certificate then runs three years with surveillance audits in between, described on the certification page.

Where the months go

Typical implementation timeline, Canadian company under 100 staff
PhaseElapsedConstraint
Confirm, scope, leadership2 to 4 weeksExecutive availability
Inventory3 to 6 weeksHow scattered your systems are
Risk assessment and treatment4 to 8 weeksGetting risk owners in a room
Implementation3 to 6 monthsProcurement and engineering capacity
Operating period3 months minimumCalendar time. Cannot be bought.
Internal audit and management review3 to 5 weeksIndependent auditor availability
Stage 1, gap closure, stage 23 to 5 monthsCertification body scheduling

Those overlap, which is how the total lands at nine to fifteen months rather than the sum. The two things that genuinely compress are running implementation and the operating period together, by turning controls on as they are built rather than at the end, and booking the certification body early because scheduling a stage 2 can take two months on its own.

Three ordering mistakes that cost a quarter each

Writing the Statement of Applicability before the risk assessment, which leaves the justification column unanswerable. Leaving the internal audit until after stage 1, which pushes stage 2 by six weeks because the findings have to be closed first. And turning controls on at the end of implementation instead of as you go, which means the three month operating clock starts on the last day of the project rather than in the middle of it.

Get the implementation quoted

Tell us your scope, headcount and deadline and we will match you with Canadian firms that run these projects.

Get matched

Common questions

How long does it take to implement ISO 27001?

Nine to fifteen months for a Canadian company starting without a management system. Six months is achievable if security controls are already documented and operating, because the binding constraint is having enough records for a stage 2 auditor to sample rather than the amount of work. Under four months from a standing start is not realistic.

Do we have to implement all 93 Annex A controls?

No. You have to make and record a decision on all 93, which is different. Controls you exclude need a justification tied to your risk assessment, and the usual valid exclusions are ones where the activity does not exist in your organization, such as controls about physical facilities for a company with no premises. Excluding a control because it is inconvenient is not a justification an auditor accepts.

Can we implement ISO 27001 without a consultant?

Yes, and companies do. It takes someone internal with time, the two standards to hand, and a tolerance for reading. The first pass done internally teaches you the management system in a way no deliverable will. Buy help if a signed deal is holding on a date, because then the cost of delay exceeds the fee.

What should we do first?

Confirm what the customer actually asked for, then write the scope statement. Both are cheap, both are fast, and both determine what everything afterward costs. Buying a policy template pack before either is done is the most common way to spend money that has to be rewritten later.

Does a compliance platform change the timeline?

It shortens evidence collection and does not shorten the operating period, which is the part that sets the date. Platforms help most from about thirty people upward, or when you are running ISO 27001 and SOC 2 together and the same evidence serves both.