ISO/IEC 27001 audit duration: how ISO/IEC 27006-1 sets audit time
ISO/IEC 27001 audit duration explained: how ISO/IEC 27006-1:2024 counts persons, identical activities, multi-site and remote work, and what changed from 2015.
ISO/IEC 27001 audit duration is set by ISO/IEC 27006-1:2024, Annex C, not by IAF MD 5. The certification body counts all persons doing work under the organisation's control within scope, including contractors, may reduce the count for simple identical activities using a square root per category, reads the audit time from the Annex C table and adjusts it with documented factors. The transition deadline was 31 March 2026.
Key takeaways
- ISO/IEC 27001 audit duration comes from Annex C of ISO/IEC 27006-1:2024, which replaced ISO/IEC 27006:2015.
- The count covers everyone doing work under the organisation's control in scope, including contractors and freelancers.
- Simple, identical activities can be counted as the square root of each category, with documented criteria and risk analysis.
- For multi-site clients, total audit time is based on all persons irrespective of location.
Which document sets ISO/IEC 27001 audit duration?
ISO/IEC 27001 audit duration for accredited certification is set by ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems, Part 1. Audit time rules sit in Annex C (Annex B in the 2015 edition). IAF MD 5 does not apply to ISMS, although ISO/IEC 17021-1:2015 still governs the certification cycle and requires a documented, justified audit time for every client (clause 9.1.4).
The 2024 edition was published in March 2024. Under IAF MD 29:2024, accreditation bodies had to be ready to assess against it by 31 December 2024, use it for initial and extension assessments starting no later than 31 March 2025, and complete the transition, together with their certification bodies, by 31 March 2026. Check for later amendments before updating your procedure.
What changed in ISO/IEC 27006-1:2024 audit time?
The 2024 edition keeps the principle of a table of audit time by number of persons, adjusted by documented factors. What changed is mostly how the number is counted and how special cases are handled.
| Topic | ISO/IEC 27006-1:2024 |
|---|---|
| Location of rules | Annex C (Annex B in 2015) |
| Who is counted | All persons doing work under the organisation's control in scope, whether or not they are employees |
| Identical activities | Effective number of personnel for certain identical activities (C.3.4) |
| Multi-site | Total persons irrespective of location (C.6); the number of sites no longer drives the total |
| Scope extensions | A defined approach to calculating audit time for extensions |
| Remote auditing | The 2015 need for accreditation body approval above 30% remote activity is removed |
Who counts towards ISO/IEC 27001 audit duration?
Start with every person doing work under the organisation's control within the ISMS scope. That includes contractors, freelancers and outsourced staff working within the scope. For many technology clients this is the biggest source of error: headcount on the application form lists employees, while a large share of the development or operations work is done by contractors.
Ask for the number of persons in scope by role, site and employment type, and refresh it before each recertification. Part-time staff and shift patterns need the same attention as under MD 5, and your procedure should say how you convert them.
How does the identical activities reduction work?
Clause C.3.4 allows an effective number of personnel where persons perform certain identical activities. European co-operation for Accreditation (EA) guidance of September 2024 explains how it applies: the activities must be similar or repetitive, simple, and need limited skills, knowledge or education. The certification body must establish, justify and document the criteria and a risk analysis for each category, and still allocate enough time for a complete and effective audit.
The square root is applied to each category separately. EA's example has three categories of 49 persons (technicians, support staff and service desk). Each counts as √49 = 7, so the three categories count as 21 persons, and it is not acceptable to take the square root of all 147 together, which would give 12. EA puts the difference at about one audit day.
How is ISO/IEC 27001 audit duration set for multi-site clients?
Clause C.6 says total audit time for the on-site audit is calculated from the total number of persons doing work under the organisation's control, irrespective of their location. Summing separately calculated times for each site is an alternative only where that total is larger. When asked whether this conflicts with IAF MD 1, EA answered that ISO/IEC 27006-1 shall be applied, as stipulated in the scope of IAF MD 1.
The planning consequence: the number of sites no longer drives the total, but it still drives the booking. The total days have to be distributed across the sites that matter for information security risk, and every site day is a trip. For the sampling side, see IAF MD 1 multi-site sampling.
A worked example
- Count everyone in scopeA software company has 60 developers (20 of them contractors), 49 service desk staff and 30 in management and support functions: 139 persons.
- Test for identical activitiesThe service desk follows scripted, repetitive work needing limited skills. With documented criteria and risk analysis, it counts as √49 = 7. Development work is not simple or limited-skill, so all 60 count.
- Find the effective number60 + 7 + 30 = 97 persons for reading the Annex C table.
- Apply factors and recordAdjust for documented factors such as complexity and risk, record the justification and plan on-site and remote activities in the audit plan.
Leaving out the 20 contractors would have understated the count. That is the kind of error accreditation assessors find in client files.
How does ISO/IEC 27001 audit duration affect scheduling?
Once calculated, ISMS audit days behave like any other audit days. They sit inside the same ISO/IEC 17021-1 cycle, with surveillance at least once a calendar year and recertification before expiry. They need auditors competent in ISMS and in the client's technical area. Where ISO/IEC 27001 is audited together with ISO 9001 or others, each standard's time is calculated separately first under IAF MD 11 integrated audit time rules.
Remote work is more common in ISMS audits and the 2024 edition removed the separate approval step above 30% remote activity. Plan remote and on-site parts explicitly in the audit plan, since that decides which days need travel. See remote audits under IAF MD 4.
MythISO/IEC 27001 audit time follows the IAF MD 5 tables.
RealityISMS audit time comes from Annex C of ISO/IEC 27006-1:2024.
MythOnly employees count.
RealityEveryone doing work under the organisation's control in scope counts, including contractors.
MythMore sites always mean more ISMS audit days.
RealityClause C.6 bases total time on all persons irrespective of location; sites affect how the days are distributed.
- ✓Procedure updated to ISO/IEC 27006-1:2024 Annex C
- ✓Persons in scope include contractors and outsourced staff
- ✓Identical activity categories documented with criteria and risk analysis
- ✓Square root applied per category, not to the whole headcount
- ✓Multi-site time based on total persons irrespective of location
- ✓Remote activities identified in the audit plan
ScheduleAI is audit scheduling software built for testing, inspection and certification (TIC) organisations, with a planner approving every plan.
ScheduleAI books ISMS audit days against auditors with the right ISMS competence and technical area, and plans remote and on-site days separately so travel is only booked where the audit plan needs it.
Book a demo Estimate your savingsQuestions
Does IAF MD 5 apply to ISO/IEC 27001 audits?
No. ISMS audit time comes from ISO/IEC 27006-1. MD 5 covers quality, environmental and OH&S management systems; see IAF MD 5 audit time.
When did ISO/IEC 27006-1:2024 become mandatory?
IAF MD 29:2024 required accreditation bodies and certification bodies to complete the transition by 31 March 2026.
Do contractors count towards ISO/IEC 27001 audit duration?
Yes. The count covers persons doing work under the organisation's control within scope, whether or not they are employees.
Can the square root be applied to the whole workforce?
No. EA guidance says it applies to each category of simple, identical activities separately, with documented criteria and risk analysis.
Is there still a 30% limit on remote ISMS auditing?
The 2024 edition removed the requirement for accreditation body approval when remote activity exceeds 30%. Remote activities still need to be planned and justified.
How many days is an ISO/IEC 27001 audit?
It depends on the effective number of persons and adjustment factors, read from the table in Annex C of ISO/IEC 27006-1:2024. See audit man-days explained for how days turn into bookings.