I think, most notably, compared to other certs we've looked at, the crossover isn't there with ISO 27001 resulting on more time needed end to end than we originally planned. The documentation requirements are quite significant and getting that right is load bearing (sorry, AI, I was using this term before you existed). Aside from the work it takes to do the documentation, I've found that many of my policies and procedures need updates to go along with them (e.g. my incident response plan, data handling, acceptable use...)