Planning guide · September 2026

How long compliance takes

Timelines vary widely by framework and readiness, but the phase structure is nearly universal. Understand the phases and you can plan the calendar honestly — and spot any provider promising an impossible shortcut.

The six phases

  1. Name the framework. Days to weeks. Get this wrong and every later phase is wasted. See the which-framework guide.
  2. Readiness and gap assessment. Weeks to a few months. A consultant or the audit firm maps your current state against the framework's requirements.
  3. Remediation and evidence building. The long pole for most first-timers. Controls get implemented, documented, and operated — evidence must accumulate over the review period the framework requires.
  4. Observation period (some frameworks). Attestation reports like SOC 2 Type 2 require months of operating evidence. Nothing about this phase can be rushed; it is calendar time, not effort.
  5. Fieldwork / assessment. The auditor or assessor tests your controls and evidence. Duration scales with scope — weeks for small, well-prepared engagements.
  6. Report and issuance. Drafting, review, and issuance. Then the maintenance cycle begins: most frameworks require annual reassessment or surveillance.
Plan backwards from your deadline. If a customer contract requires a report by June, the observation period and fieldwork must finish by May — which means readiness starts the previous year for frameworks with long evidence windows. Work the calendar backwards before you sign anything.

Framework-specific timelines

Each network directory publishes realistic timelines for its framework, with the observation periods and maintenance cycles spelled out. Two starting points: SOC 2 timelines on soc2type2.com and GLP timelines on glpcompliance.com.

Get a realistic timeline for your scope

Matched providers quote your situation and tell you the honest calendar. Free, no obligation.

Get a free quote