Features Pricing Our AI AI Project Plan Generator
Industries Internal projects Use Cases Case Studies
Blog Knowledge library Comparisons PM Templates Free Tools Integrations AI Project Management API & Developers
Login Get started free
Example project plan

Project plan for an ISO 27001 certification

ISO 27001 certification is not an IT project but a management system: scope, risk assessment, Annex A controls, internal audit and management review have to fit together. This plan shows the path to the certification audit.

No sign-up · opens instantly · 34 Weeks · 10 Phases · 67 Tasks · Budget approx. €216,350

This is how the plan looks in PathHub — click through the tabs or tick off tasks.

app.pathhub.ai/try?example=iso-enOpen live
Example plan

ISO/IEC 27001:2022 ISMS Implementation and Certification

This project will establish and operationalize an organization-wide Information Security Management System for a 120-person software company. It will define the ISMS scope, governance, risk treatment, documentation, and operational controls needed to meet ISO/IEC 27001:2022 requirements. The work also includes training, evidence collection, internal audit, management review, and support through certification audits. The goal is to achieve certification readiness within the nine-month delivery window while embedding sustainable business-as-usual ownership.

Total Progress0%
34Weeks
0/10Phases
0/67Tasks
€216,350Budget
AI Recommendations KIAI Chat KIAI Tools KI

Phases

1

Phase 1: Mobilization and Certification Planning

Pending · 2W · 0/4
ISMS Manager or CISO
0

Establish executive sponsorship, project governance, certification assumptions, and delivery capacity. This phase creates the decision-making structure needed to meet the nine-month certification deadline.

Timeline

Timeline 10 PhasesStart: Oct 1, 2026
Phase / Task
Oct 2026
Nov 2026
Dec 2026
Jan 2027
Feb 2027
Mar 2027
Apr 2027
May 2027
W 1Oct 1
W 4Oct 22
W 7Nov 12
W 10Dec 3
W 13Dec 24
W 16Jan 14
W 19Feb 4
W 22Feb 25
W 25Mar 18
W 28Apr 8
W 31Apr 29
W 34May 20
Mobilization and Certification PlanningOct 1 – Oct 14 · 2 wk · 0/4
Mobilization and Certification Planning
ISMS Scope, Context and GovernanceOct 15 – Nov 4 · 3 wk · 0/5
ISMS Scope, Context and Governance
Asset, Information and Dependency InventoryOct 29 – Nov 25 · 4 wk · 0/7
Asset, Information and Dependency Inventory
Gap Assessment and Remediation RoadmapNov 26 – Dec 16 · 3 wk · 0/5
Gap Assessment and Remediation Roadmap
Risk Assessment, Treatment Plan and Statement of ApplicabilityDec 17 – Jan 13 · 4 wk · 0/7
Risk Assessment, Treatment Plan and Statement of Applicability
ISMS Documentation and Process DesignJan 14 – Feb 10 · 4 wk · 0/7
ISMS Documentation and Process Design
Technical and Operational Control ImplementationJan 21 – Mar 10 · 7 wk · 0/12
Technical and Operational Control Implementation
Training, Awareness and Evidence OperationMar 4 – Apr 7 · 5 wk · 0/8
Training, Awareness and Evidence Operation
Internal Audit and Management ReviewApr 8 – Apr 28 · 3 wk · 0/5
Internal Audit and Management Review
Certification Audit, Corrective Actions and HandoverApr 29 – May 26 · 4 wk · 0/7
Certification Audit, Corrective Actions and Handover
PlannedIn progressCompletedBlockedMilestones

Budget

Budget: €216,350
External Advisory and Certification · €70,400Technical Remediation and Independent Testing · €63,500Software and Security Tooling · €30,150Training, Legal and Supplier Assurance · €27,300Internal Personnel and Backfill · €25,000
External Advisory and Certification€70,400
ItemQtyUnit priceTotal
External ISO 27001 implementation consultant32 Person days€1,200€38,400
Independent internal audit specialist10 Person days€1,000€10,000
ISO 27001 certification body Stage 1 and Stage 2 audits1 Flat rate€22,000€22,000
Technical Remediation and Independent Testing€63,500
ItemQtyUnit priceTotal
Cloud and identity security remediation engineer25 Person days€900€22,500
DevSecOps and secure-development remediation engineer20 Person days€850€17,000
Backup, logging and secure-configuration implementation1 Flat rate€8,000€8,000
External penetration test of applications and cloud infrastructure1 Flat rate€12,000€12,000
Penetration-test remediation validation and retesting1 Flat rate€4,000€4,000
Software and Security Tooling€30,150
ItemQtyUnit priceTotal
GRC and evidence-management platform9 Person days€1,200€10,800
Security awareness and training platform9 Person days€500€4,500
Vulnerability scanning and dependency-monitoring subscription6 Person days€900€5,400
Cloud logging and SIEM service uplift9 Person days€700€6,300
Access governance and access-review tooling9 Person days€350€3,150
Training, Legal and Supplier Assurance€27,300
ItemQtyUnit priceTotal
Organization-wide security awareness workshops16 Person days€250€4,000
Control-owner and evidence-operation workshops12 Person days€250€3,000
GDPR, privacy and contractual alignment review8 Person days€1,100€8,800
Supplier security assessment and contractual assurance support10 Person days€850€8,500
Training materials, communications and completion tracking setup1 Flat rate€3,000€3,000
Internal Personnel and Backfill€25,000
ItemQtyUnit priceTotal
Internal ISMS Manager / CISO allocation20 Person days€700€14,000
Control owners and business process leads backfill20 Person days€550€11,000

Risks

High

Insufficient Executive Sponsorship and Control-Owner Capacity

If the CEO, CTO, and functional leaders have not approved the ISMS RACI, allocated named control owners, and reserved engineering, IT, HR, legal, and operations capacity by the end of Week 2, critical decisions and remediation work may be delayed throughout Phases 2–8.

Countermeasure: The Executive Sponsor must approve the ISMS charter, decision rights, resource commitments, and escalation route by Week 2; the ISMS Manager must report capacity and overdue decisions weekly from Week 3.
High

Uncontrolled Expansion of the Certification Scope

If products, cloud environments, customer services, regions, or suppliers are added after the scope is approved in Week 5, the company may need to repeat inventory, risk assessment, control design, and evidence work, threatening the nine-month certification deadline.

Countermeasure: The CEO, CTO, and ISMS Manager must approve a fixed scope statement by Week 5 and enforce formal change control, with any proposed scope change requiring impact, cost, and schedule approval before implementation.
High

Incomplete Asset, Information, and Dependency Inventory

If critical systems, repositories, SaaS platforms, data stores, shadow IT, cloud accounts, or information owners remain unidentified by the end of Week 8, material risks may be omitted from the risk assessment and exposed during the certification audit.

Countermeasure: The ISMS Manager, IT/Cloud Lead, Engineering Lead, and process owners must reconcile CMDB, cloud, identity, code-repository, SaaS, supplier, and data inventories by Week 8 and obtain owner sign-off for all critical assets.
High

Delayed Risk Assessment or Statement of Applicability

If the risk register, treatment plan, residual-risk acceptances, or Statement of Applicability are not approved by Week 15, documentation and technical implementation may proceed without an agreed control basis, causing rework and audit objections.

Countermeasure: The ISMS Manager must run structured risk workshops during Weeks 12–14, and the CEO, CTO, and relevant risk owners must approve treatment decisions and residual-risk acceptances by Week 15.
High

Cloud, Identity, and Secure-Development Control Gaps

If critical findings involving excessive cloud privileges, weak joiner-mover-leaver controls, unmanaged secrets, insufficient logging, vulnerable dependencies, insecure CI/CD pipelines, or inadequate backup protection remain open at the end of Week 23, certification-critical controls may not be demonstrably effective.

Countermeasure: The CTO must prioritize remediation of all high-risk findings; the IT/Cloud Lead and DevSecOps Lead must complete control implementation and produce test evidence by Week 23, with exceptions formally accepted by the CTO and ISMS Manager.
High

Controls Documented but Not Operating Consistently

If access reviews, vulnerability remediation, incident records, backup tests, supplier reviews, change approvals, or security monitoring activities have not operated for sufficient cycles by Week 27, the company may be unable to demonstrate control effectiveness even where procedures exist.

Countermeasure: Control owners, coordinated by the ISMS Manager, must operate each priority control from its defined start date, retain evidence in the approved repository, and complete weekly evidence-quality checks during Weeks 23–27.
High

Certification-Body Availability or Significant Audit Findings

If a certification body is not provisionally booked by Week 2, Stage 1 identifies major scope or documentation deficiencies, or Stage 2 findings remain open after Week 32, there may be insufficient time to achieve certification within the nine-month deadline.

Countermeasure: The ISMS Manager must confirm auditor availability and Stage 1/Stage 2 dates by Week 2, conduct a readiness review before Week 28, and maintain a daily corrective-action plan during Weeks 31–34 with the certification body and control owners.
Medium

Supplier, Customer-Contract, and Privacy Gaps

If critical cloud, SaaS, hosting, development, or support suppliers have not been assessed or lack appropriate security commitments by Week 19, or if customer data-processing and breach obligations conflict with ISMS procedures, legal and audit findings may remain unresolved.

Countermeasure: Procurement, Legal/DPO, and the ISMS Manager must complete risk-based supplier reviews, obtain security evidence, remediate contract gaps, and validate data-processing and breach obligations by Week 19, with unresolved exceptions escalated by Week 23.
Medium

Employee Adoption and Personnel-Control Failures

If mandatory security training completion is below the agreed threshold, onboarding/offboarding evidence is incomplete, or employees do not report incidents during the tabletop exercise by Week 27, personnel and incident-management controls may fail during audit testing.

Countermeasure: HR and the ISMS Manager must complete role-based training, test joiner-mover-leaver execution, and run the incident tabletop exercise by Week 27; overdue completion and failed tests must be escalated to functional leaders within five working days.
Medium

Remediation Budget and Internal-Resource Overrun

If technical remediation, tooling, penetration testing, or backfill forecasts exceed the approved budget by more than 10% by Week 19, the company may defer certification-critical controls or reduce evidence and testing quality.

Countermeasure: The Executive Sponsor and ISMS Manager must review cost and resource forecasts biweekly, protect the certification reserve for high-risk gaps, and approve or reject non-critical scope and tooling changes by Week 20.

Stakeholders

ES

Executive Sponsor / CEO

Provides funding, resolves cross-functional conflicts, and approves risk acceptance and ISMS direction

Involve: Phase 1
IM

ISMS Manager or CISO

Owns implementation, risk methodology, control coordination, evidence model, and certification interface

Involve: Phase 1
C

CTO

Decides on technology priorities, engineering capacity, architecture changes, and acceptance of technical risks

Involve: Phase 1
IC

IT, Cloud and Platform Operations Lead

Owns infrastructure, identity and access management, logging, backup, vulnerability management, and operational evidence

Involve: Phase 2
SE

Software Engineering and DevSecOps Lead

Implements secure development, code review, dependency management, release, and vulnerability remediation controls

Involve: Phase 3
DP

Data Protection Officer / Legal Counsel

Aligns the ISMS with GDPR, contracts, data-processing obligations, retention, and breach requirements

Involve: Phase 2
HP

HR / People Operations Lead

Owns onboarding, offboarding, role changes, security responsibilities, training records, and personnel controls

Involve: Phase 2
PA

Procurement and Vendor Management Lead

Establishes supplier due diligence, security clauses, monitoring, and third-party risk records

Involve: Phase 3
PC

Product, Customer Operations and Business Process Owners

Identify critical services and information, validate business risks, and own control execution within their areas

Involve: Phase 3
IA

Internal Audit or Quality Lead

Provides independence for the internal audit, tests control effectiveness, and verifies corrective actions

Involve: Phase 4
EI

External ISO 27001 Consultant

Supplies methodology, implementation guidance, readiness reviews, and remediation support without replacing internal control ownership

Involve: Phase 1
CB

Certification Body and Lead Auditor

Confirms audit requirements, performs Stage 1 and Stage 2 assessments, and determines certification readiness

Involve: Phase 1

Compliance

Mandatory

Establish and maintain the ISO/IEC 27001:2022 ISMS, including organizational context, interested parties, defined scope, leadership responsibilities, security objectives, documented information, and continual improvement under Clauses 4–10

ISMS Manager/CISO, CEO, CTO Weeks 1–34 and ongoing
Mandatory

Perform a documented information-security risk assessment, create and maintain a risk treatment plan, obtain residual-risk approvals, and approve the Statement of Applicability

ISMS Manager/CISO, risk owners, CEO/CTO Weeks 12–15 and at least annually or after material change
Mandatory

Implement and operate the controls selected in the Statement of Applicability, including access control, cloud security, secure software development, vulnerability management, logging, backup, incident management, physical/endpoint protection, and supplier security

CTO, IT/Cloud Lead, DevSecOps Lead, control owners Design Weeks 16–19; implementation Weeks 17–27; ongoing operation
Mandatory

Maintain reliable evidence of control operation, including access reviews, training, vulnerability remediation, changes, incidents, backup tests, supplier assessments, risk decisions, and corrective actions

ISMS Manager/CISO and all control owners Weeks 16–34 and ongoing
Mandatory

Conduct an independent internal audit, address nonconformities, complete management review, and verify corrective actions before certification

Internal Audit/Quality Lead, CEO, ISMS Manager/CISO Weeks 28–30
Mandatory

Fulfil binding customer, supplier, data-processing, confidentiality, security, breach-notification, audit-right, and data-location obligations relevant to the ISMS scope

Legal Counsel/DPO, Procurement, Vendor Management, Customer Operations Weeks 3–34 and ongoing
Optional

Maintain an approved security policy framework, role-based awareness and competence program, incident-response exercises, business-continuity and backup testing, and periodic control-performance reviews

ISMS Manager/CISO, HR, IT/Cloud Lead, business process owners Weeks 16–34 and ongoing

Milestones

  1. Week 2

    Approved ISMS charter, named workstream owners, committed internal capacity, and provisionally booked certification audit dates

    Depends on: Executive sponsorship and project governance established
  2. Week 5

    Approved ISMS scope statement, context and interested-party register, security objectives, governance RACI, and obligations register

    Depends on: Scope and governance definition completed
  3. Week 8

    Signed-off information and asset inventory with owners, classifications, criticality ratings, dependencies, and identified inventory gaps

    Depends on: Asset and dependency discovery completed
  4. Week 11

    Approved gap assessment and funded remediation roadmap with named owners and deadlines for all certification-critical gaps

    Depends on: Current-state assessment completed
  5. Week 15

    Approved risk register, risk treatment plan, residual-risk acceptances, and Statement of Applicability

    Depends on: Risk assessment and control selection completed
  6. Week 19

    Approved ISMS policy and procedure set with control owners, operating frequencies, evidence requirements, and exception workflows

    Depends on: Documentation and process design completed
  7. Week 23

    Priority control implementations completed, high-risk technical findings remediated or formally accepted, and control test evidence available

    Depends on: Technical and operational implementation completed
  8. Week 27

    Required personnel training completed, priority controls operated with evidence, tabletop exercise completed, and evidence gaps closed or tracked

    Depends on: Training and evidence operation completed
  9. Week 30

    Completed independent internal-audit report, corrective-action plan, signed management-review minutes, and formal certification-readiness decision

    Depends on: Internal audit and management review completed
  10. Week 34

    Stage 1 and Stage 2 audits completed, certification findings addressed with submitted evidence, and ongoing ISMS ownership and improvement activities formally handed over

    Depends on: Certification audit and corrective actions completed

How this plan was created

This plan was created by PathHub AI from a single description: “Prepare a 120-person software company for ISO 27001 certification within 9 months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.

Obligations

Obligations with lead time: what many think of too late

These obligations are typically triggered by an ISO 27001 certification (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.

Engage a certification body and schedule the stage 1 and stage 2 audits (ISO 27001)
Required 2–4 months before the certification auditguide value
Rule & evidence

Why: Accredited certification bodies are often booked months ahead; stage 1 checks readiness, stage 2 effectiveness.

Rule from the compliance library
ISO 27001 (Information Security)
Criteria
  • Information security management system (ISMS) defined
  • Risk assessment and treatment documented
  • Statement of Applicability (SoA) with Annex A controls
  • Internal audit and management review annually

If breached: Voluntary standard but de facto mandatory for enterprise/government clients. Loss terminates business relationships.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Carry out an internal audit and management review before the certification audit (ISO 27001, cl. 9.2/9.3)
Required 4–8 weeks before the certification auditguide value
Rule & evidence

Why: Without a documented internal audit and management review the system is not ready for certification; findings need time to be corrected.

Rule from the compliance library
ISO 27001 (Information Security)
Criteria
  • Information security management system (ISMS) defined
  • Risk assessment and treatment documented
  • Statement of Applicability (SoA) with Annex A controls
  • Internal audit and management review annually

If breached: Voluntary standard but de facto mandatory for enterprise/government clients. Loss terminates business relationships.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
All typical initiatives and their obligations: planning internal projects

Frequently asked questions

How long does an ISO 27001 certification take?
In the example plan, an ISO 27001 certification takes 34 weeks in 10 phases, of which 3 phases partly run in parallel. The actual duration depends on company size, starting point and available resources — with your company context PathHub adjusts the schedule accordingly.
What does an ISO 27001 certification cost?
The example plan estimates about €216,350, split into 20 budget line items with quantity and unit price. The largest items are External Advisory and Certification, Technical Remediation and Independent Testing. This is an AI estimate as a starting point, not a quote.
What are the risks of an ISO 27001 certification?
The plan lists 10 risks with countermeasures. Rated highest: Insufficient Executive Sponsorship and Control-Owner Capacity; Uncontrolled Expansion of the Certification Scope; Incomplete Asset, Information, and Dependency Inventory.
Who needs to be involved in an ISO 27001 certification?
Among others, the plan includes these people: Executive Sponsor / CEO, ISMS Manager or CISO, CTO, IT, Cloud and Platform Operations Lead, Software Engineering and DevSecOps Lead, Data Protection Officer / Legal Counsel. For each role it states why and from when to involve them.
Can I adapt the plan to my company?
Yes. Open the plan in PathHub without signing up, adjust phases and tasks or describe your own initiative — with company context (departments, approval processes, works council, compliance requirements) every further plan gets more precise.

More project plan examples

Adapt this plan to your company

Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.

Open plan →