Free, no sign-up to start: the plan opens as a live, editable Gantt chart. 17 tasks across 4 phases, about 23 weeks if every task runs in sequence.
What's in the template
| Phase | Task | Example duration |
|---|---|---|
| Plan | Agree ISMS scope | 5 days |
| Plan | Gap analysis | 10 days |
| Plan | Project plan and owners | 3 days |
| Risk | Asset inventory | 7 days |
| Risk | Risk assessment | 10 days |
| Risk | Risk treatment plan | 5 days |
| Risk | Statement of Applicability | 5 days |
| Implement | Write policies and procedures | 20 days |
| Implement | Implement controls | 30 days |
| Implement | Staff security awareness training | 5 days |
| Implement | Collect operating evidence | 30 days |
| Audit | Internal audit | 5 days |
| Audit | Management review | 2 days |
| Audit | Stage one audit | 2 days |
| Audit | Fix stage one findings | 10 days |
| Audit | Stage two audit | 3 days |
| Audit | Close nonconformities | 10 days |
Durations are examples to replace with your own estimates, not benchmarks.
About this iso 27001 certification plan
Getting ISO/IEC 27001 certified means building an information security management system (ISMS), running it for a while, and then passing a two-stage external audit. This plan puts the work in the usual order: agree the scope, assess risks, choose controls, write policies, operate the controls, then audit yourself before the certification body does.
Durations are a working example for a small to mid-sized organization. Your certification body and auditors set the actual audit dates.
Who it's for: Security leads, compliance managers and consultants running a first ISO 27001 project.
How to use it
- Open the plan. Click Open in the editor. The tasks load as a live Gantt chart without signing in.
- Set your scope. Rename the scope and asset rows to match the parts of the business you are certifying.
- Book the audits. Once the certification body gives you dates, adjust the audit rows; the rest of the plan moves with them.
- Share progress. Send a read-only link to leadership or your auditor; they can view the plan without an account.
Planning tips
- Keep the scope tight for a first certification; you can extend it later.
- Leave time to operate controls and gather evidence before the stage two audit.
- Hold the management review before the external audit, not after.
Frequently asked questions
- What are stage one and stage two audits?
- Stage one reviews your ISMS documentation and readiness. Stage two checks that the controls work in practice. The certificate is issued after stage two findings are closed.
- How long does ISO 27001 take?
- It depends on size and starting point. This example runs roughly six to eight months in sequence.
- Is it free?
- Yes. Opening and editing the template is free, and a free account saves one project. Downloading the chart as PDF or CSV needs Solo.
Related templates
The free plan saves one project. Downloads (PDF, CSV) and more projects are on Solo, $12/month.