Ninety days are tight, but they are enough. What matters is not the pace of individual steps, but their order. ISO 27001 projects rarely fail because of technical hurdles. They fail because documents are created before the risks have been assessed, because the internal audit is forgotten, or because someone notices the management review only two days before the external audit.
This guide is aimed at small and medium-sized enterprises without an existing certification. Anyone starting today, at the end of October, will have an auditable management system by the end of January. Each phase builds on the previous one; skipping one produces gaps that become visible in the audit.
“The companies that get through quickly are not the ones with the best IT. They are the ones that decided early what belongs in the scope – and what does not.” – Nadeesh Lötscher, Sales Partner Switzerland and ECA auditor ISO 9001/27001
First of all: the scope determines the effort
Before day 1 begins, one decision is needed: which sites, systems and information fall under the management system? A scope defined too broadly is the most expensive mistake at the start, because it enlarges every subsequent task – every risk assessment, every document, every audit day.
The boundary has to be professionally defensible, not convenient. Anyone who cuts out the area where the customer data worth protecting resides produces a certificate that the customer will reject the moment they read the scope. The criteria for this are set out on our page on ISO 27001.
Phase 1, days 1 to 30: know what you are protecting
The first phase answers one question: what is at stake? Start with an overview of your information assets. Which data do you process, where is it held, who has access? The overview has to cover more than servers: cloud services, laptops and mobile devices, external service providers, paper records, access rights of employees who have left.
Next comes the risk assessment. It is the core of every information security management system – the BSI, too, describes general requirements for an ISMS in its Standard 200-1 and takes a structured approach in doing so. ISO 27001 does not prescribe a particular method, but it does require a systematic and repeatable approach: for each asset or group of assets you identify threats, estimate the likelihood of occurrence and the impact, and derive the need for action. Repeatable means: another person using the same method would arrive at comparable results.
Two practical notes. First: work with groups rather than individual devices, otherwise a small company drowns in rows. Second: base your threats on the real situation. The BSI report on the state of IT security in Germany 2025 cites an average of 119 new vulnerabilities per day for the period from 1 July 2024 to 30 June 2025, around 24 percent more than in the same period the year before, and attributes around 80 percent of the reported attacks to small and medium-sized enterprises. Unpatched systems reachable from the internet therefore belong in every SME risk assessment.
At the end of phase 1 you have: the overview of information assets, the documented risk assessment and a risk treatment plan.
Phase 2, days 31 to 60: choose controls and write down the rules
Now risks turn into controls. Annex A of ISO 27001 contains 93 controls in four themes: organisational, people, physical and technological. They do not all have to be implemented – but every control needs a justified decision, including the decision against it. The result is the Statement of Applicability, the central document of the certification: which control is applied, which is not, and why.
In parallel, the other required documents are created. For an SME these are essentially:
- Information security policy and objectives
- Description of the scope
- Method and results of the risk assessment, risk treatment plan
- Statement of Applicability
- Rules on access, storage media and passwords
- Procedure for security incidents, including reporting channels
- Requirements for backup and restoration
- Rules for suppliers and service providers
- Records of training and awareness-raising
The most important rule of this phase: quality before quantity. A concise document that reflects actual day-to-day work holds up in the audit. Twenty detailed policies that nobody knows are an invitation to a nonconformity – because what is examined is not the text, but what happens in the business.
Training also starts in this phase and is documented. Anyone who only trains in week twelve cannot demonstrate effectiveness.
Phase 3, days 61 to 90: check yourself before others check you
The final phase is the one most often underestimated. It consists of two mandatory parts.
The internal audit checks whether the management system meets the requirements of the standard and is effective. It has to be carried out independently: whoever is responsible for an area does not audit it themselves. In small organisations this can often only be solved with an external person, and that is expressly permitted. This is exactly the role our partners in the partner network take on as internal auditors.
The management review is the documented assessment of the system by top management, with defined inputs and outputs: status of the controls, results of the audits, incidents, feedback, changes in the environment, resource requirements, improvement decisions. It is not a form, but the point at which management visibly takes responsibility – and auditors recognise very quickly whether this meeting actually took place or was written up after the fact.
Both records are a prerequisite for the external audit. This runs in two stages: in stage 1, documentation and readiness for certification are assessed; in stage 2, the actual implementation and effectiveness are examined. How this process works with us, who carries out the audits and under which rules, is described on the page Independently certified. After the certification decision, the certificate is valid for three years from the audit date, with surveillance between the audits.
The five stumbling blocks that turn 90 days into 180
- The scope is changed again during the project. Then the risk assessment starts from scratch.
- Documents are written before risks have been assessed. They then do not match the controls and have to be reworked.
- The internal audit is treated as a formality and takes place too late. Gaps found can then no longer be corrected.
- Management delegates the management review. That is noticed in the audit.
- Suppliers and service providers are left out of consideration, even though the relevant data often sits with them.
Where tools help and where they do not
The time saved in preparation lies in organising and mapping. In the Eucerta platform you upload existing documents – including as an export from Notion, Confluence or Google Docs – the mapping to the clauses of the standard and the open items become visible, reminders run automatically. What the platform does not take over is responsibility for the content: which risks you accept and which rules apply in your business is your decision.
Anyone combining ISO 27001 with ISO 9001 saves on top of that: context, leadership, internal audit programme and management review then arise only once, as described on the page on the integrated management system. The second standard costs €149 instead of €179 per month; the bundle price is shown by the cost calculator.
Conclusion
Ninety days are feasible if you work in the right order: scope first, then risks, then controls and documents, then internal audit and management review. Anyone who starts by writing policies instead does more work and takes longer.
The most honest test of your preparation is simple: can you say, for every rule, who applies it in day-to-day work and how you would recognise that? If yes, the audit is a confirmation. If no, you know where the next few days should go.
Your next step: If your ISMS is already running and only the evidence is missing, take a look at express certification – otherwise work out your route with the cost calculator.
Further reading:




