+31 (0)73 220 2000 | info@brandcompliance.com
English EN
  • Dutch NL
  • English EN
  • French FR
  • Dutch NL
  • English EN
  • French FR
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Discuss your situation
  • Information security
    • ISO 27001
    • NEN 7510
    • CyFun
      • CyFun verification
      • Request CyFun verification
    • ISO 27799
    • ISO 27017 and ISO 27018
    • BIO2
    • ISO 19770-1
  • Privacy
    • BC 5701
    • ISO 27701
    • GDPR standard BC 5701:2024 EN
  • IT assurance
    • SOC 2
    • ISAE 3402
    • ISAE 3000
  • Quality & continuity
    • ISO 9001
    • ISO 14001
    • ISO 22301
    • Gap analysis
  • Knowledge & news
    • Knowledge articles
    • News
  • Academy
    • All training courses
    • NIS2 & CyFun
    • ISO 27001
  • About us
    • Accreditations
    • Careers
    • Compliment, complaint or tip
    • Locations
    • Privacy Statement
    • Contact

Preparing for certification

6
  • Certification checklist: how to prepare for certification
  • Do you have your first certification audit soon?
  • The certification process step by step
  • How long does ISO certification take?
  • How to conduct an internal audit
  • Describing the scope of certification: tips and examples

Audit process & certification cycle

7
  • Initial audit Stage 1
  • Initial audit Stage 2
  • What is a certification cycle?
  • Nonconformities within the management system
  • What should you know about certificate suspension or revocation?
  • Transfer of certification
  • The use of certification logos

Management systems & key concepts

6
  • Whitepaper management system audits
  • Quality Management: best practices for success
  • Certification glossary
  • What is a management system?
  • Internal or external audit?
  • Accreditation versus certification

Information security

3
  • Excelling in information security: best practices
  • Operational Capabilities: The Backbone of Information Security
  • The Traffic Light Protocol (TLP): what does it mean for you?

NEN 7510 & healthcare

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 & CyberFundamentals

5
  • ISO 27001 in a NIS2 context in Belgium
  • CyberFundamentals 2025: transition from CyFun 2023 to 2025
  • Self-assessment & CyFun verification: best chance of success
  • NIS2 liability for board members
  • CyberFundamentals Framework in Belgium: what is the relationship with NIS2?

Privacy & data protection

8
  • ISO 27701:2025 transition
  • GDPR compliance best practices
  • Data breach: What is it and how do you prevent it?
  • Your Data Protection Officer and the GDPR
  • Your record of processing activities and the GDPR
  • Checklist for your BC 5701 certification
  • BC 5701 certification: where do you start?

Assurance audits

1
  • ISAE 3402 vs SOC 2: what is the difference?
View Categories

How long does ISO certification take?

How long does ISO certification take?Many organizations interested in ISO certification want to know how much time the certification process will take. How long does the process with a certification body take before an ISO certificate can be issued? There is no fixed timeframe. The total lead time depends on factors such as the organization’s preparation, audit planning and any required follow-up of audit findings. The audit time itself is determined using a fixed method. In this article, we explain how the required audit time is established.

Initial audit #

To obtain ISO certification, an organization goes through an initial audit. An initial audit usually consists of a stage 1 audit and a stage 2 audit. During the stage 1 audit, the auditor assesses whether the organization is ready for stage 2. This is done, among other things, by reviewing documented information within the management system and the organization’s understanding of the requirements of the standard. During the stage 2 audit, the implementation and effectiveness of the management system are assessed. Are processes carried out as described? Is the policy followed? Are employees aware of their contribution to the management system?

Determining audit time #

The audit time for an initial audit is determined on the basis of applicable accreditation and scheme requirements. These requirements specify the principles that certification bodies, such as Brand Compliance, must apply when determining audit time. For management system certification, ISO/IEC 17021-1 is an important accreditation standard. For ISO 27001 certification, additional requirements from ISO/IEC 27006-1 apply. These standards specify requirements for bodies providing audit and certification of management systems and, in the case of ISO/IEC 27006-1, information security management systems.

Example #

As an example, consider ISO 27001 certification. For ISO 27001, audit time is determined on the basis of the applicable requirements for information security management systems. For a small organization, this results in a minimum audit time for the initial audit. Part of this time is spent on audit activities with the organization, either on site or by using remote audit techniques. Another part is spent on audit-related activities, such as preparing the audit, drawing up the audit plan and writing the audit report.

Factors that affect audit time #

In addition to the number of FTEs, other factors may affect the audit time. Examples include:

  • the extent to which processes or services have been outsourced;
  • the number of locations within the scope of certification;
  • the complexity of the management system;
  • the nature of the organization’s activities, processes and risks;
  • any changes within the organization or management system.

These factors may lead to an increase or reduction in audit time. The relevant time factors are discussed during the application process.

Surveillance audits and recertification #

Once the certificate has been issued, periodic surveillance audits take place within the certification cycle. During these audits, the auditor assesses whether the management system continues to meet the requirements of the standard and remains effective. For surveillance audits and recertification, it is also assessed whether any factors affect the audit time. For example, if many nonconformities were identified during previous audits, or if significant changes have been made to the management system, the auditor may need more time to perform the audit.

Would you like to know more about what happens after certification? Read the article What is a certification cycle?.

Conclusion #

There is no standard answer to the question of how long ISO certification takes. The total lead time depends on your organization’s preparation, audit planning, the size and complexity of the organization and any follow-up of audit findings.

The audit time itself is determined using a fixed method. This ensures that the required time is established in a consistent and substantiated way.

Share This Article :

  • Facebook
  • X
  • LinkedIn
Updated on 15 July 2026
The certification process step by stepHow to conduct an internal audit
Contents
  • Initial audit
  • Determining audit time
    • Example
    • Factors that affect audit time
  • Surveillance audits and recertification
  • Conclusion

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 technical area 33 information technology and 35 other services.

View our accreditations

Contact

Have a question about certification, verification or assurance?

info@brandcompliance.com
+31 (0)73 220 2000

Prefer local contact details?
View our locations

Our locations

‘s-Hertogenbosch, The Netherlands

Antwerp, Belgium

Ottignies-Louvain-la-Neuve, Belgium

Stockholm, Sweden

Dublin, Ireland

Luxembourg, coming soon

Practical information

Privacy statement

Terms and conditions

Company details

Feedback and complaints

 

© Copyright 2026 Brand Compliance
Thank you for your rating!
Thank you for your rating and comment!
This page was translated from: Dutch
Please rate this translation:
Your rating:
Change
Please give some examples of errors and how would you improve them: