+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Beglië
  • Dutch
  • English
  • Beglië
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Contact
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • AVG standard BC 5701:2023 NL
    • GDPR standard BC 5701:2023 EN
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • Checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • Applying for a certification process
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities management system
  • Certificate suspended or revoked? This is how you solve it!
  • Transfer of certification

BC 5701

5
  • BC 5701 certification: where do you start?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
  • Checklist for your BC 5701 certification
  • Data breach: What is it and how do you prevent it?

General

9
  • SOC 2 or ISAE 3402: which standard suits your organization?
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

ISO 27001:2022

3
  • Operational Capabilities: The Backbone of Information Security
  • ISO 27001:2022 – FAQ transition
  • ISO 27001:2022 – Transition process

Whitepapers

2
  • Whitepaper management system audits
  • Whitepaper GDPR Certification Standard and Criteria BC 5701

Best practices

3
  • Mastering GDPR compliance: best practices
  • Excelling in information security: best practices
  • Quality Management: best practices for success

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

2
  • NIS2 liability
  • NIS2 & the Belgian CyberFundamentals
View Categories

How long does ISO certification take?

1 min read

ISO-certificeringMany people interested in obtaining an ISO certification wonder how much time such certification takes. How long does the process with a certifying body take to obtain an ISO certificate? In this article we explain how the required time is determined. There is no fixed time frame, but there is a fixed method! Read all about it below. 

Initial audit

In order to achieve ISO certification, a so-called initial audit is completed. An initial audit consists of stage 1 and stage 2. 

During stage 1, it is assessed whether the organization is ready for stage 2 on the basis of documented information in your management system and the understanding of the requirements of the standard. 

During stage 2, the implementation and effectiveness of the management system are assessed. Are all processes executed as described? Is the policy adhered to? Are employees aware of their contribution to the management system? 

Man-day table 

How much time is needed for the initial audit is determined in the ‘man-day table’ from the accreditation standard. An accreditation standard contains requirements that certification bodies, such as Brand Compliance, must adhere to. For example, ISO 17021 for certification of ISO 9001 and ISO 27006 for certification of ISO 27001. 

Example 

Let’s sketch an example for the ISO 27001 certification. In accordance with accreditation standard ISO 27006 for an organization with 1 to 10 FTE, a total of 5 days of audit time is calculated for an initial audit. Of this time, 70% is spent on the audit at your location or by means of remote audit techniques. The remaining 30% is used for administrative tasks related to the audit, such as drawing up the audit plan and writing the audit report. 

Factors 

In addition to the factor of the number of FTEs, there are more factors that must be taken into account in arriving at a time calculation. 

Some examples: 

  • the degree of outsourcing of services;
  • the number of locations;
  • the complexity of the management system. 

The factors can lead to an increase or reduction of the audit time. All time factors are discussed in detail during the application process. 

Follow-up audits 

When ISO certification is achieved, smaller audits will take place after the initial audit, the so-called surveillance audits. For follow-up audits it is also determined whether there are factors that lead to time reduction or increase. For example, many nonconformities found during the initial or surveillance audits or significant changes within the management system. In such cases, the auditor usually needs more time to perform the audit. 

In conclusion 

Now you know how the time spent on a certification is determined. As you have read, there is no ready-made answer to the question of how long ISO certification takes. It depends on several factors. A conversation with one of our account managers can provide you with more insight. 

Share This Article :
  • Facebook
  • X
  • LinkedIn
Updated on 6 June 2024
Do you have your first audit soon?What is a certification cycle?

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 scope 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2025 Brand Compliance