As a Security Officer or as the CEO or owner of a small or midsize business, sooner or later you will face the same question: “How quickly can we become ISO certified?” The answer no one wants to hear, but the one that is true, is this: plan for at least nine months.
Yes, there are firms and consultants who claim they can get it done in six or eight weeks, or even less time. Technically, that may be possible. You get a certificate on the wall. But in practice, what you often end up with is a quality management system or information security management system that no one in the organization recognizes, let alone uses. The result is a thick report sitting in a drawer, followed by a lot of stress a year later during the surveillance audit because nothing has been done with it in the meantime.
ISO Is Not a Sticker, but a System
An ISO-standard, whether it is ISO 27001, ISO 9001, or another standard, is not simply a label you buy. At its core, it is a management system: a way of working in which risks are structurally identified, measures are implemented, results are measured, and improvements are made on an ongoing basis. The Plan Do Check Act cycle is not a side note in the standard. It is the standard.
That means certification only has real value when the organization owns the system. Not just the Security Officer, not an external consulting firm, but the people who work with it every day, from the front office to senior management.
Why This Takes Time, Especially in Small and Midsize Businesses
Large organizations often already have a compliance department, standardized processes, and people who work full time on risk management. In small and midsize businesses, that is rarely the case. That is one of the reasons why a crash course toward certification is a bad idea.
It is often new material
Risk assessments, incident registration, supplier reviews, internal audits. For many employees, this is unfamiliar territory. New knowledge needs time to land, not just to be explained.
It is an additional role on top of the regular job
An information security coordinator, a quality manager, an internal auditor. In small and midsize businesses, these roles are rarely full time positions. They are added to an existing role.
Other priorities easily take over
A proposal that needs to go out, a customer calling, a production issue. The “real work” easily wins over the “ISO project” if certification is not given clear priority and if time is not deliberately made available for it.
All these factors mean that processes need time to settle: testing, adjusting, explaining again, and allowing habits to form. That process cannot be accelerated without weakening the quality of the embedding.
It Can Be Done Faster, but the Bill Comes Later
Organizations that become “certification ready” within a few weeks or months usually have one thing in common: the system has been built by an external firm, with documents that neatly align with the standard, but that never truly became the property of the people within the organization itself.
The problem usually does not show up during the first audit. That often goes reasonably well, because everything is still fresh. The problem arises a year later, during the surveillance audit or recertification. That is when it becomes clear that the risk register has not been updated, that internal audits have not been performed, and that no one really remembers why certain controls were introduced in the first place. The system has not grown with the organization, because the organization never truly carried the system.
At that point, the certificate is no more than a paper reminder of money and time invested without lasting results.
The Value Is in the Embedding, Not in the Certificate
That is unfortunate, because when properly implemented, an ISO management system is one of the most powerful tools an organization can have to make continual improvement structural. Not ad hoc improvement initiatives that fade away after a few months, but a steady rhythm of measuring, evaluating, and adjusting that becomes part of the organization’s daily operations.
To achieve that, time is needed:
• time to bring employees along and allow them to get used to new ways of working;
• time to run through processes several times, so they become logical and workable rather than theoretical;
• time to conduct the first internal audit and actually implement improvements;
• time for the management review to become a steering moment rather than a hurdle.
Nine months is not a random number. It is roughly the time needed to complete at least one full PDCA cycle before an external auditor can rightfully determine that the system is actually functioning and does not only exist on paper.
What This Means for Your Organization
For the Security Officer, this means: dare to plan realistically and explain this clearly to senior management. Promising a faster timeline because it sounds better does not serve the organization. It only postpones the problem.
For the CEO or owner, this means: do not see the certification journey as a project with an end date, but as an investment in the way the organization works. The nine months are not a delay. They are the time needed to make sure the money invested and the time spent by your people do not disappear into a drawer, but continue to work in daily practice.
In short: an ISO certificate is not the goal. It is proof that something fundamental has changed along the way in how the organization deals with risks and improvement. That deserves the time it needs.
Want to know more? Schedule a no obligation introductory meeting and together we will explore how we can support you.
