Skip to main content
Category: Audit Process

Audit Time Calculation

Also known as: Audit Time Determination, Audit Duration Calculation
Simply put

Audit time calculation is the process a certification body uses to estimate how many days an audit should take. The estimate depends on factors such as the size, complexity, risk profile, and nature of the organization being audited. Because these factors differ from one organization to another, the calculated time varies for each engagement.

Formal definition

Audit time calculation refers to the methodology by which an accredited certification body (or, in the ISO 27001 context, the body conducting the ISMS certification audit) determines the number of auditor-days required for an audit. In most engagements the calculation is driven by variables including organizational size (often measured by effective headcount), the complexity of processes and technology, the assessed risk, and the nature of the organization's activities. The result is not a fixed figure; it is derived per engagement and adjusted based on scope, and specific determination criteria may follow sector-specific procedures (for example, those defined for medical device schemes). Note that this concept as documented in the available evidence relates to management-system and quality-scheme audits rather than to a SOC 2 attestation examination, where the effort estimate is instead set by the CPA firm based on the defined scope and Trust Services Criteria selected.

Why it matters

Audit time calculation directly affects the cost, scheduling, and credibility of a certification engagement. In the ISO 27001 context, the number of auditor-days a certification body allocates determines how thoroughly an ISMS can be examined; too little time may undermine the depth of assurance, while an accurate estimate helps ensure the audit adequately samples the organization's processes, technology, and risk landscape. Because the calculation is driven by variables such as organizational size, complexity, risk, and the nature of activities, two organizations pursuing the same standard can receive materially different audit-day estimates.

For organizations planning a certification, understanding how audit time is derived helps set realistic budget and resourcing expectations and reduces surprises during scoping discussions with a certification body. It also underscores that the estimate is engagement-specific and adjusted based on scope rather than a fixed figure that can be assumed in advance. In certain sector-specific schemes, such as medical device programs, the determination of audit time may follow dedicated procedures, so the applicable methodology depends on the scheme under which the audit is conducted.

It is important to note the boundary of this concept. As documented in the available evidence, audit time calculation relates to management-system and quality-scheme audits (for example, ISO-family certifications and medical device schemes) rather than to a SOC 2 attestation examination. In a SOC 2 engagement, the effort estimate is instead set by the CPA firm based on the defined scope and the Trust Services Criteria selected, so the specific audit-time methodologies described here do not transfer directly to that attestation context.

Who it's relevant to

Compliance and GRC Managers
Those coordinating an ISO 27001 or other management-system certification use audit time estimates to plan budgets, schedules, and internal resourcing. Understanding that the estimate depends on size, complexity, risk, and the nature of the organization helps them anticipate how scoping decisions will affect audit-day counts.
Certification Bodies and Auditors
Accredited certification bodies apply audit time calculation methodologies to allocate auditor-days appropriately for each engagement. In sector-specific schemes such as medical device programs, they may follow dedicated determination procedures rather than a single generic formula.
Organizations Pursuing Certification
Companies seeking a management-system certificate benefit from knowing that audit duration is engagement-specific and adjusted based on scope. This helps them prepare realistic expectations during planning discussions with their chosen certification body.
Teams Comparing SOC 2 and ISO 27001 Paths
Professionals weighing both frameworks should note that audit time calculation, as described here, applies to management-system and quality-scheme audits rather than to a SOC 2 attestation examination. For SOC 2, the effort estimate is set by the CPA firm based on the defined scope and the Trust Services Criteria selected.

Inside Audit Time Calculation

Audit Duration (Audit Days)
The number of auditor days allocated to plan, conduct, and report on an assessment. For ISO 27001 certification, certification bodies typically estimate audit duration using guidance intended to promote consistency, adjusting for the specific engagement. The figure is an estimate rather than a fixed value and depends on the scope and characteristics of the organization being assessed.
Scope of the ISMS or Report
The defined boundary being assessed, which is a primary driver of audit time. For ISO 27001, the calculation reflects the scope of the ISMS; for a SOC 2 examination, the effort reflects the systems, Trust Services Criteria in scope, and controls covered. A narrower, well-defined scope typically reduces the time required.
Organizational Size and Complexity
Factors such as the number of personnel performing work relevant to the scope, the number of sites or locations, technological complexity, and the range of processes involved. These typically increase or decrease the estimated audit effort depending on the engagement.
Assessment Type and Stage
The nature of the engagement affects time. For ISO 27001, initial certification is commonly conducted in two stages (a documentation/readiness review followed by the main assessment), with subsequent surveillance and recertification activities scoped differently. For SOC 2, a Type I (suitability of design at a point in time) generally involves different effort than a Type II (design and operating effectiveness over a review period).
Review Period (SOC 2 Type II)
For a SOC 2 Type II examination, controls are evaluated over a defined review period whose length is set by scoping decisions and varies between engagements. The period covered influences the volume of evidence sampled and therefore the effort involved.
Adjustment and Justification Factors
Auditors and certification bodies may adjust baseline time estimates upward or downward based on documented factors such as maturity of the management system, use of automation, prior audit history, or risk considerations. Such adjustments are typically recorded to justify the final estimate.

Common questions

Answers to the questions practitioners most commonly ask about Audit Time Calculation.

Is there a fixed number of audit days required for a SOC 2 or ISO 27001 audit?
No. Neither framework prescribes a universal fixed duration. For a SOC 2 Type II, the review period is set by scoping decisions rather than a mandated length, and the auditor's effort depends on the number of Trust Services Criteria categories in scope, the complexity of the environment, and the volume of controls examined. For ISO 27001, certification body time is influenced by factors such as ISMS scope, organizational size, and complexity. In most engagements the time is calculated per engagement rather than drawn from a single standard figure, so any specific day count varies.
Does a longer or more expensive audit mean the resulting report or certificate is stronger or more valid?
Not necessarily. A SOC 2 report attests only to the controls and the period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS regardless of how much time was spent. More audit time generally reflects greater scope or complexity rather than a stronger outcome. The value of the result depends on the scope, the criteria or clauses assessed, and the rigor applied, not on the number of days alone. Additional time does not guarantee freedom from breaches or expand what the report or certificate actually covers.
What factors typically influence how audit time is calculated for a SOC 2 engagement?
In most SOC 2 engagements, the CPA firm considers the number of Trust Services Criteria categories selected (Security is required; Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on scope), the number of controls to be tested, whether the engagement is a Type I or Type II, and the length of the review period for a Type II. Environmental complexity, the number of systems and locations, and the maturity of evidence collection also affect the effort. Because these are scoping-driven, the calculation varies by engagement and by firm.
How does the choice between a SOC 2 Type I and Type II affect audit time planning?
A Type I assesses the suitability of the design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period. Because a Type II requires testing controls across a period, it typically involves more effort for evidence gathering and sampling than a Type I. The length of the Type II review period is set by scoping decisions rather than a fixed duration, so planning should account for the period selected and the volume of evidence spanning that period.
What drives audit duration for an ISO 27001 certification compared to a SOC 2 examination?
For ISO 27001, the certification body evaluates the ISMS requirements in clauses 4 through 10 and the reference controls selected through the Statement of Applicability and informed by risk assessment. Time is typically influenced by the defined scope of the ISMS, organizational size and complexity, and the number of applicable controls. This differs structurally from a SOC 2 examination, which is an attestation against the Trust Services Criteria. Because the frameworks assess different structures, their time calculations are not directly comparable and mapping between them is only partial.
How can an organization reduce or better estimate audit time before an engagement begins?
Organizations can support a more accurate estimate by clearly defining scope early, whether that is the Trust Services Criteria categories for SOC 2 or the ISMS boundary for ISO 27001, and by preparing organized evidence and control documentation in advance. Narrowing scope to what is relevant, maintaining consistent evidence throughout a Type II review period, and clarifying complexity factors with the CPA firm or certification body typically help produce a more reliable time estimate. Because the final calculation depends on the auditor, certification body, and scope, confirming assumptions with them during planning is advisable.

Common misconceptions

Audit time is a fixed number of days that is the same for every organization of a given size.
Estimated audit time varies by engagement. While guidance exists to promote consistency, the final figure depends on scope, complexity, number of sites and personnel, assessment stage, and, for SOC 2 Type II, the review period. It is an estimate adjusted for the specific organization rather than a universal fixed value.
The way audit time is calculated is identical for SOC 2 and ISO 27001.
The two frameworks are distinct. ISO 27001 is a certification against a management system standard, where certification bodies estimate audit duration for the ISMS scope. SOC 2 is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, where effort reflects the systems, Trust Services Criteria in scope, and the review period for a Type II. Satisfying the time expectations of one does not translate to the other.
More audit days always mean a more rigorous or better outcome.
Audit time reflects the scope and characteristics of the engagement, not a guarantee of quality or completeness. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS regardless of the number of days spent.

Best practices

Define and document the scope precisely before requesting a time estimate, since scope is a primary driver of audit effort for both the ISO 27001 ISMS and the SOC 2 examination.
For SOC 2 Type II engagements, confirm the review period as part of scoping, recognizing that its length is set by scoping decisions and varies rather than being fixed.
Provide the auditor or certification body with accurate information on the number of relevant personnel, sites, and technological complexity so the estimate reflects the real engagement.
Keep the two frameworks separate when planning: engage a licensed CPA firm for the SOC 2 attestation and an accredited certification body for ISO 27001, and do not assume one estimate applies to the other.
Retain documentation of any adjustment factors applied to the baseline estimate so the final audit time can be justified and revisited for surveillance or recertification.
Set expectations that estimated audit time is qualitative and engagement-specific; treat any figure as dependent on scope, criteria, and the assessing body rather than an absolute rule.