How long it really takes: it depends on the standard.
No vague '~3 months'. We give real per-standard timelines, and we quantify them for your case in the gap analysis.
ISO/IEC 27001
1
Preparation : typically 3-6 months
given adequate readiness
2
Exam / issuance : Stage 1 + Stage 2 audit by an accredited body
3
Cycle / maintenance : certificate valid 3 years
annual surveillance, recertification in year 3
SOC 2 Type I
1
Preparation : after readiness (control design, point-in-time)
2
Exam / issuance : CPA report
3
Cycle / maintenance : cyclical refresh
SOC 2 Type II
1
Readiness + observation period : typically 3-12 months
the observation period is what sets Type II apart
2
Exam / issuance : CPA report after the period
3
Cycle / maintenance : cyclical refresh
ISO/IEC 42001 (AIMS)
1
Preparation : similar to ISO 27001
AI Management System
2
Exam / issuance : audit by an accredited body
3
Cycle / maintenance : cycle similar to 27001
These are honest orders of magnitude, not promises. Real timing depends on how ready you already are: we tell you upfront in the gap analysis.