ISMS

Planning an ISMS Project: Roadmap, Milestones, and Resources

TL;DR
  • An ISMS project is not an IT project but an organizational project. The biggest risks lie not in technology but in lacking leadership support and unclear responsibilities.
  • Plan three phases: foundations and quick wins (months 1 to 3), core build (months 4 to 8), and consolidation with audit preparation (months 9 to 12). Each phase needs its own milestones.
  • For a company with 100 to 300 employees, the resource requirement is half to one FTE for the CISO/ISM, plus proportional capacity from IT, HR, legal, and business departments.
  • The first-year budget ranges between 40,000 and 120,000 euros, depending on the starting position, external consulting, and chosen tooling.
  • Milestones must be measurable. Not 'conduct risk assessment,' but 'all 25 identified assets assessed for protection requirements and risk owners assigned.'

Why ISMS Projects Fail Before They Really Begin

Roughly half of all ISMS projects in mid-market companies take significantly longer than planned. Not because the standard requirements are so complex, but because the project itself is poorly planned. The typical symptoms: a motivated IT manager gets the assignment to "set up an ISMS." They read up on the topic, create an information security policy, begin the risk assessment, and after three months realize they cannot move forward alone. The business departments have no time, management asks about the status but not about the obstacles, and the initial enthusiasm gives way to disillusionment.

The problem is almost never a lack of expertise. It is a lack of project planning. Building an ISMS is not a technical undertaking that one person in the IT department handles on the side. It is an organizational project that simultaneously changes processes, people, technology, and culture. And like any organizational project, it needs a structured plan, clear milestones, and realistically allocated resources.

This article gives you the tools to put your ISMS project on a solid footing from the start. Not as an abstract framework, but as a concrete roadmap that you can adapt to your organization.

Before You Plan: Clarifying the Prerequisites

Before you set the first milestone, you must answer three questions. If you do not have a clear answer to any of these questions, that is your first work item — even before the actual project planning.

Question 1: Why Are We Doing This?

The motivation determines the scope, the time pressure, and the organization's willingness to allocate resources. The most common drivers for an ISMS project are:

  • Customer requirement: A key customer demands ISO 27001 certification or an equivalent security level. This gives you external time pressure and a concrete goal.
  • Regulatory obligation: NIS2, DORA, or industry-specific regulations make an ISMS mandatory. The time pressure comes from the legislator.
  • Strategic decision: Management recognizes that information security is a competitive advantage and should be built proactively. Here you have more flexibility on timing but often less urgency within the organization.
  • Reaction to an incident: A security incident has shown that existing measures are insufficient. The willingness to act is high, but emotions run high too.

Each of these drivers requires a different communication strategy and a different prioritization. If a customer expects certification by end of year, you plan differently than if you strategically want a mature ISMS in three years.

Question 2: Where Do We Stand Today?

An honest assessment of the current state saves months. Many organizations have already implemented more security measures than they think — just not documented or systematically managed. At the same time, some organizations overestimate their maturity because they confuse technical measures (firewall, antivirus) with a management system.

Conduct a gap analysis before creating the project plan. This does not have to be a formal audit. Go through the ISO 27001 requirements and assess for each area: Is something in place? Is it documented? Is it practiced? Is there evidence?

The results of this analysis determine how much effort is required in which areas. A company with already well-structured IT operations, documented processes, and an established backup concept has different priorities than one that has not yet written a single policy.

Question 3: Who Owns the Project?

An ISMS project needs a project owner with sufficient time, competence, and organizational backing. Whether this is the future ISM (Information Security Manager), an internal project manager, or an external consultant depends on the company size and available competencies.

What is critical is that this person is not only technically competent but also has the authority to schedule meetings with department heads, demand decisions, and trigger escalations when milestones are at risk. Without this authority, the project becomes a supplicant's existence.

The Three Phases of the ISMS Roadmap

A proven structure for ISMS projects in SMEs consists of three phases. The timeframes refer to a company with 100 to 300 employees that does not yet have a formal ISMS but has basic IT security measures in place.

Phase 1: Foundations and Quick Wins (Months 1 to 3)

In the first three months, you lay the groundwork. This phase is critical because it sets the tone for the entire project. If you deliver visible results here while simultaneously building the organizational foundations, you win the trust of management and the acceptance of the business departments.

Milestone 1: Management Commitment and Project Charter (Weeks 1 to 2)

The project charter is not just a formality. It defines the scope, budget, timeline, and management expectations. It gives the project owner the legitimacy to demand resources and make decisions. A good project charter answers: What should be achieved? By when? With what resources? Who decides in case of conflicts?

At the same time, management approves the information security policy. This document is the formal starting signal and shows the entire organization that information security is a leadership priority.

Milestone 2: ISMS Scope and Context (Weeks 2 to 4)

The scope defines which parts of the organization the ISMS covers. For most mid-market companies, the entire operation is recommended as scope, because partial scope definitions lead to demarcation problems. Simultaneously, you document the context: internal and external factors affecting information security, and the requirements of interested parties (customers, regulators, employees).

Milestone 3: Roles and Organization (Weeks 3 to 6)

Appoint the ISM, define the risk owners and asset owners, and create a RACI matrix for all ISMS processes. This sounds bureaucratic but is key to preventing responsibilities from disappearing into the fog. Every risk owner must know what is expected of them — before the risk assessment begins.

Milestone 4: Implement Quick Wins (Weeks 4 to 12)

In parallel with the organizational groundwork, you immediately implement visible improvements. These can be technical measures (MFA for all admin accounts, hardening email security with SPF/DKIM/DMARC) or organizational ones (publish a password policy, conduct the first awareness measure). Quick wins are important because they show that the project does not just produce paper but actually improves security.

Phase 2: Core Build (Months 4 to 8)

In this phase, you do the substantive heavy lifting. Risk assessment, policies, technical measures, and training are the focus. This is the part that requires the most time and resources.

Milestone 5: Risk Assessment Completed (Months 4 to 5)

The risk assessment is the heart of the ISMS. You identify the information assets, assess threats and vulnerabilities, and derive the treatment needs. For a company with 100 to 300 employees, expect 20 to 50 relevant assets and 40 to 100 risk scenarios. The risk assessment is not a solo exercise by the ISM but requires workshops with the risk owners from the business departments.

Measurable milestone: All identified assets assessed for protection requirements, risk owners assigned, risk treatment plan created and approved by management.

Milestone 6: Statement of Applicability (Months 5 to 6)

The SoA (Statement of Applicability) documents which controls from Annex A of ISO 27001 you apply and why, and which you do not apply and why not. This document is central to certification and forces you to consciously evaluate each control.

Milestone 7: Core Policies Approved (Months 5 to 7)

Create and approve the most important policies: access control, mobile device and remote work, cryptography, backup, incident response, supplier security, information classification. Each policy does not have to be perfect, but it must reflect actual processes and be understood by those responsible.

Milestone 8: Technical Measures Implemented (Months 5 to 8)

In parallel with the policies, you implement the technical measures that resulted from the risk assessment. These can include network segmentation, vulnerability scanning, improved logging, disk encryption, or the introduction of privileged access management. Prioritize by risk, not by complexity.

Milestone 9: Training and Awareness Program Running (Months 6 to 8)

All employees must receive basic training. The awareness program should not be a one-time mandatory exercise but an ongoing program with various formats: e-learning, short in-person sessions, phishing simulations, intranet information.

Phase 3: Consolidation and Audit Preparation (Months 9 to 12)

In the third phase, the focus is on testing the built system, collecting evidence, and reaching readiness for an audit.

Milestone 10: Business Continuity and Emergency Management (Months 9 to 10)

Business continuity is often the area that takes the longest because it requires a business impact analysis and coordination with many stakeholders. Create recovery plans for the most critical processes and test them in a tabletop exercise.

Milestone 11: Internal Audit Conducted (Months 10 to 11)

The internal audit is the litmus test for your ISMS. It shows you where gaps exist before an external auditor finds them. Plan enough time to address the findings from the internal audit before the certification audit takes place.

Milestone 12: Management Review Conducted (Months 11 to 12)

Management reviews the status of the ISMS, the results of the risk assessment, audit findings, and the effectiveness of measures. The management review is a mandatory requirement of ISO 27001 and must be documented.

Milestone 13: Audit Readiness (Month 12)

All evidence is collected, documentation is complete and current, open actions from the internal audit are resolved, and the organization is ready for the external certification audit.

Resource Planning: Who Is Needed When?

The biggest miscalculation in ISMS projects concerns the resource requirements. Many organizations only plan for the ISM and underestimate how much time other roles need to invest.

The ISM as Project Driver

The Information Security Manager is the central figure. During the build phase, plan for 60 to 100 percent of a full-time position. The ISM coordinates all activities, creates policies, moderates workshops, prepares decision papers, and maintains documentation.

If you only allocate 20 percent of the ISM's working time, the project will take at least twice as long. This is not because the work itself is so demanding, but because an ISM with little time cannot coordinate meetings, prepare workshops, or drive escalations. The project loses momentum.

Business Departments and IT

Business departments are heavily involved primarily in two phases: during the risk assessment (Phase 2) and during policy creation (Phase 2). Expect approximately 15 to 25 hours per risk owner across the entire project. With five to eight risk owners, that is 75 to 200 person-hours from the business departments.

The IT department bears the main burden in implementing technical measures. The effort varies widely depending on how much is already in place. Plan at least 100 to 300 hours of IT capacity for implementing technical measures.

Executive Management

Executive management is directly involved at three moments: for the project charter and information security policy (Phase 1), for approving the risk treatment plan (Phase 2), and for the management review (Phase 3). The direct time investment is 10 to 20 hours across the entire project, but indirect support (releasing resources, setting priorities, communicating within the organization) is priceless.

External Support

Many mid-market companies bring in external consultants for specific phases. This makes sense when internal experience is lacking but must not lead to the consultant building the ISMS while the company merely signs off. An ISMS built by an external party that internal staff do not understand will not survive the first surveillance audit.

Sensible uses for external support include the initial gap analysis, moderation of the risk assessment, conducting the internal audit, and preparation for the certification audit. The cost range for accompanying consulting is 15,000 to 40,000 euros, depending on intensity and duration.

Budget Planning: What Does an ISMS Project Cost?

The costs for an ISMS project consist of four categories. The figures refer to a company with 100 to 300 employees.

Internal Personnel Costs

The largest cost block. The ISM invests 800 to 1,600 hours in the first year. Expect internal personnel costs of 30,000 to 80,000 euros, depending on salary structure and position allocation. In addition, there are the capacities from IT and business departments, which are harder to quantify but must not be forgotten.

External Consulting

As described above: 15,000 to 40,000 euros for accompanying consulting. If you staff the ISM entirely externally, costs rise to 40,000 to 80,000 euros per year.

Tooling

An ISMS needs a tool for documentation, risk assessment, and measure tracking. The range goes from Excel (free but painful) to specialized ISMS tools (500 to 15,000 euros per year) to enterprise GRC platforms (30,000 euros and up). ISMS Lite, for example, costs ab 500 Euro pro Jahr oder als Einmalkauf für 2.500 Euro and covers risk assessment, measure tracking, and audit documentation. For SMEs, a specialized ISMS tool is the best compromise between functionality and effort.

Certification Costs

If you are pursuing ISO 27001 certification, the costs for the certification auditor are added. For a company with 100 to 300 employees, expect 8,000 to 20,000 euros for the initial certification audit (Stage 1 and Stage 2). Tools like ISMS Lite help you track project progress across all phases and maintain an overview of milestones, measures, and responsibilities.

Total Budget

Overall, you are looking at a first-year range of 40,000 to 120,000 euros, with internal personnel costs accounting for the largest share. From the second year onward, costs decrease significantly because the build effort is gone and only ongoing maintenance, surveillance audits, and further development remain.

Typical Planning Mistakes and How to Avoid Them

Trying to Do Too Much at Once

The most common mistake: you try to make everything perfect in Phase 1. The information security policy gets circulated for weeks because every paragraph is revised three times. The risk assessment methodology becomes an academic research project. The policies are supposed to cover every edge case.

The solution: work iteratively. The first version does not have to be perfect — it has to be good enough. An ISMS thrives on continuous improvement, which means you continue working on maturity even after certification. Start with the essentials and refine later.

Involving Business Departments Too Late

If you contact risk owners for the first time in month 5 and tell them they should now please assess their risks, you will receive bewilderment and resistance. Involve business departments from the start. Inform them about the project in Phase 1, explain what is coming, and schedule workshops in their calendars early.

Treating Documentation as an End in Itself

An ISMS needs documentation, but documentation alone is not an ISMS. If you produce 50 policies that nobody reads and that have no connection to practice, you have a paper tiger ISMS that will be exposed in the first audit. Every document must have a clear purpose, and the employees it concerns must know and understand it.

Not Planning Buffers

ISMS projects are always interrupted by unforeseen events. A security incident that absorbs all attention. A key stakeholder who is on vacation for three weeks. A technical measure that is more complicated than expected. Plan 20 to 30 percent buffer in each phase. If you do not need the buffer, you finish early. If you do, you are still on track.

Leaving the ISM Alone

The ISM cannot shoulder the project alone, no matter how competent they are. They need regular access to executive management, the support of the IT department, and the cooperation of business departments. If they feel like they are fighting windmills, they will either burn out or the project will stall. Ensure the ISM has a regular reporting channel to executive management and that there is an escalation path when stakeholders do not cooperate.

Project Steering: Making Status Visible

An ISMS project whose status nobody knows is a project nobody cares about. Make progress visible — not just to executive management but to all participants.

Monthly Status Reporting

Create a brief monthly status report (one page maximum) covering the following points: Which milestones were achieved? Which are upcoming? Where are there delays and why? Which decisions are pending? The report goes to executive management and the risk owners.

Milestone Reviews

After each phase, conduct a milestone review. This is a short meeting (60 to 90 minutes) where you present the phase results, discuss open items, and get approval to proceed to the next phase. Milestone reviews give the project structure and prevent problems from accumulating over months.

Traffic Light System for Measures

Each planned measure gets a status: green (on track), yellow (at risk), red (delayed). This overview enables executive management to see at a glance where the project stands and ask specifically where things are stuck.

The Roadmap as a Living Document

A roadmap that you create in month 1 and never touch again is worthless. Reality will deviate from your plan, and that is normal. What matters is that you recognize the deviations, adjust the roadmap, and inform the participants.

Update the roadmap at least monthly. If the scope changes (for instance, because a new location is added or a business area is removed), adjust the project plan accordingly. If a phase takes longer than planned, shift the subsequent milestones and communicate this openly.

The best roadmap is one the team uses for orientation and that is simultaneously flexible enough to respond to changes. It is not a rigid corset but a compass that points the direction.

Special Case: ISMS Project with Certification Goal

If you are pursuing ISO 27001 certification, additional requirements must be factored into your planning.

The certification audit consists of two stages. In the Stage 1 audit, the auditor reviews your documentation: Is the information security policy in place? Is the scope defined? Is there a risk assessment and a Statement of Applicability? The Stage 1 audit typically takes place two to three months before the Stage 2 audit and identifies gaps you can still close.

In the Stage 2 audit, the auditor checks on-site whether the documented ISMS is actually being practiced. They talk to employees, review evidence, and assess the effectiveness of measures. For this, they need evidence showing that the ISMS has been actively operated over a sufficient period (typically three to six months).

This means for your planning: between the point when the ISMS is operationally live and the Stage 2 audit, at least three months must pass during which you collect evidence. If you want to achieve certification within twelve months, the ISMS must be operational by month 9 at the latest.

Plan the certification auditor early. Good auditors are in demand and have lead times of two to four months. Clarify the audit scheduling no later than Phase 2.

From Project to Operations: The Transition

The ISMS project does not end with certification or the completion of the roadmap. It transitions into regular operations. This transition must be planned, or the ISMS will fall into a void after the project.

Before the end of the project, define what ongoing operations look like: Who maintains the documentation? Who conducts the annual risk assessment? Who organizes the internal audits? How are new employees trained? How are changes in the organization (new systems, new locations, reorganizations) reflected in the ISMS?

The ISM remains the central figure, but their effort decreases from 60 to 100 percent to 20 to 40 percent of a full-time position. The business departments take on more ownership because processes are established and roles are clearly defined.

The most important success factor for the transition: the ISMS must not be perceived as "a project that is now over." It must be understood as a permanent component of corporate governance — comparable to quality management or data protection.

Further Reading

Approach your ISMS project in a structured way

ISMS Lite gives you a ready-made project structure with all phases, milestones, and tasks. You don't start from zero but with a proven framework for SMEs.

Install now