Tool · Certification

ISO Audit Duration Calculator

Get an indicative estimate of the audit time (mandays) for your ISO certification — initial, surveillance and recertification — based on IAF MD 5, ISO/IEC 27006, ISO/IEC 27706 and ISO/IEC 42006.

Estimated audit time

Initial certification
Stage 1 + Stage 2
Stage 1 (readiness)
Stage 2 (certification)
Surveillance (per year)
Recertification

Indicative only. Final audit time is determined by Cianaa under IAF MD 5, ISO/IEC 27006, ISO/IEC 27706 (privacy) and ISO/IEC 42006 (AI) and applicable accreditation rules, allowing for scope, multiple sites, integrated systems and shift patterns.

Get a formal quote →

How audit time is calculated

Certification bodies determine audit duration using internationally agreed rules — primarily the number of people doing work within the scope, adjusted for the risk and complexity of your activities.

Effective employees

The main driver — all personnel (including shifts, part-time and contractors) whose work is covered by the management system.

Standard & risk

ISO 27001 audits use ISO/IEC 27006; ISO 27701 privacy audits use ISO/IEC 27706:2025 — audit time depends on your PII role (controller / processor); ISO 42001 (AI) uses ISO/IEC 42006 — role-based too; QMS/OH&S (9001, 45001) use IAF MD 5.

Audit cycle

Initial certification covers Stage 1 + Stage 2. Surveillance is roughly one-third, and recertification about two-thirds, of the initial time.

Please note: this calculator gives a guide figure to help you plan and budget. It is not a quote. Multi-site operations use site sampling, and integrated audits (two or more standards together) reduce the combined time. Contact us and we’ll confirm your exact audit programme and a fixed-fee proposal. Looking for SOC 2? Try our SOC 2 audit duration calculator.
Initial audit · two stages

What each stage of the initial audit includes

Initial certification is carried out in two stages — together they make up the initial audit time shown above.

Stage 1

Readiness review

  • Review of your management-system documentation — scope, policy, risk assessment, Statement of Applicability and key procedures
  • Confirmation that internal audits and a management review have been completed
  • Evaluation of your site, processes and understanding of the requirements
  • Identification of any areas of concern that could become nonconformities at Stage 2
  • Confirmation that you are ready, and planning of the Stage 2 audit
Stage 2

Certification audit

  • Assessment of how effectively your management system is implemented in practice
  • Audit against all applicable clauses and your selected controls
  • Objective evidence gathered through interviews, observation and records
  • Review of monitoring, measurement, internal-audit and management-review results
  • Findings reported, with an independent recommendation on certification