Information Security

ISO 27001 Stage 1 and Stage 2 Audit Explained

Standarity Editorial Team·ISO/IEC 27001 Lead Auditors and ISMS Practitioners
··5 min read

The ISO 27001 certification audit is a two-stage assessment carried out by an accredited certification body. Stage 1 is a documentation and readiness review that confirms the information security management system is designed correctly, while Stage 2 tests whether the controls actually operate in practice through evidence sampling and staff interviews.

Why the audit has two stages

A useful shorthand is that Stage 1 asks "do you have what you need?" and Stage 2 asks "are you doing what you say?" Splitting the assessment this way protects everyone. It gives the auditor a chance to check that the foundations are sound before committing to a full operational audit, and it gives the organisation a formal, documented list of gaps to close before the decisive visit. Certification is never awarded at Stage 1; it is a checkpoint, not a verdict.

The two-stage structure is not an invention of individual certification bodies; it reflects the requirements of ISO/IEC 17021, the standard that governs how bodies audit management systems. That is why the pattern is consistent whether you are certified in London, Sydney, or New York. Understanding this helps set expectations internally: the audit is a defined, repeatable process with clear entry and exit criteria, not an open-ended inspection that can move the goalposts at will.

What Stage 1 covers

Stage 1 focuses on your documentation and management-system readiness. The auditor reviews the scope of the ISMS, the information security policy, the risk assessment and risk treatment plan, and the Statement of Applicability to confirm it justifies every control decision. They check that mandatory records exist, that internal audits and a management review have been performed, and that the system has been running long enough to generate evidence. If any of these building blocks is missing, the auditor raises it as a finding for you to close before Stage 2. Our Statement of Applicability guide explains the document auditors scrutinise most closely at this stage.

  • Scope statement that clearly defines boundaries and interfaces
  • Information security policy approved by top management
  • Risk assessment methodology and documented results
  • Risk treatment plan aligned to the assessed risks
  • Statement of Applicability justifying each included and excluded control
  • Evidence of internal audit and management review having taken place

What Stage 2 covers

Stage 2 is the main operational audit. Rather than reading documents, the auditor gathers evidence that the ISMS is genuinely operating. They sample records, observe processes, and interview staff across the business to confirm that the controls described on paper are the controls people actually follow. Expect the auditor to trace a risk from the assessment through to the treatment plan, the Statement of Applicability, and the working control, then ask a front-line employee to demonstrate it. This is where a healthy internal audit programme pays off, because it proves you already find and fix your own gaps. Our internal audit guide covers how to build that programme.

Per Cybernion and Bridewell, most certification bodies schedule Stage 2 four to six weeks after Stage 1, and Stage 2 generally must occur within six months of Stage 1 with the ISMS having operated for at least three months beforehand.

The gap between the stages

The interval between Stage 1 and Stage 2 is typically four to six weeks, though some bodies allow anywhere from two to eight weeks. This gap is deliberate preparation time, not waiting time. Use it to close every observation raised in the Stage 1 report and to collect the evidence the auditor will sample at Stage 2. Major findings from Stage 1 must be resolved before Stage 2 can begin; minor findings can sometimes be carried forward with a documented corrective-action plan, depending on the certification body.

It is worth resisting the temptation to make this gap as short as possible. A rushed two-week turnaround leaves little room to remediate anything substantial the auditor flagged, and if new evidence is thin the Stage 2 auditor has less to sample. On the other hand, an excessively long gap risks the environment drifting from what was reviewed at Stage 1. Four to six weeks tends to be the sweet spot because it is long enough to fix documentation gaps and gather fresh records, yet short enough that the ISMS the auditor saw is still recognisably the one they will audit.

Major versus minor nonconformities

Nonconformities fall into two categories, and the difference matters enormously. A major nonconformity is a requirement that is absent or has broken down entirely, for example no risk treatment process or a Statement of Applicability that does not match what the organisation actually does. A major finding stops certification until it is corrected and the auditor verifies the fix, sometimes with a follow-up visit. A minor nonconformity is a single lapse against a requirement that is otherwise met. You submit a root-cause analysis and corrective-action plan, and it is checked at the next surveillance audit. Minor findings usually need correcting within roughly 30 to 90 days and rarely delay the certificate.

How to prepare

Run your own internal audit and management review well before the certification body arrives, then treat the Stage 1 report as a gift: every observation is a defect you can fix before it becomes a nonconformity. Make sure staff can explain the controls they operate in their own words, because auditors trust demonstrated practice over polished documents. Keep evidence organised and traceable, from risk to treatment to control to record. Do this, and the two-stage audit becomes a confirmation of work already done rather than a test you cram for.

One preparation detail is frequently underestimated: the three-month operating requirement. Because the ISMS must have run for roughly three months before Stage 2, you cannot compress certification into a few frantic weeks. The controls need to have generated real records, the internal audit needs to have happened, and management review minutes need to exist. Teams that leave documentation until the last moment often clear Stage 1 but stumble at Stage 2, because there is simply not enough operational history for the auditor to sample. Plan backwards from your target certificate date and give the system time to breathe.

What auditors check most closely

Across both stages, a handful of areas attract disproportionate auditor attention. Knowing them lets you rehearse the answers before the auditor asks.

  • Whether the Statement of Applicability matches the controls actually in operation
  • Traceability from each identified risk to its treatment and working control
  • Evidence that internal audits genuinely find and report issues, not rubber-stamp
  • Management review minutes showing leadership engagement with security
  • Access control records, joiner-mover-leaver processes, and privileged access reviews
  • Incident and corrective-action records that demonstrate the ISMS improving over time

None of these can be faked convincingly in a single audit day. They are the residue of a management system that has been running honestly for months. That is the deeper point of the two-stage design: it rewards organisations that have built real security habits and gently exposes those that have only built paperwork.

Frequently Asked Questions

What is the difference between ISO 27001 Stage 1 and Stage 2 audits?

Stage 1 is a documentation and readiness review confirming the ISMS is designed correctly. Stage 2 is the operational audit that tests whether the controls actually work, using evidence sampling and staff interviews.

How long is the gap between Stage 1 and Stage 2?

The gap is typically four to six weeks, though some certification bodies allow two to eight weeks. Stage 2 generally must take place within six months of Stage 1.

Can you fail a Stage 1 audit?

Stage 1 does not pass or fail in the certification sense. It produces findings you must address. Major gaps must be closed before Stage 2 can proceed, but they do not deny certification outright.

What is the difference between a major and minor nonconformity?

A major nonconformity is an absent or broken-down requirement that blocks certification until fixed and verified. A minor nonconformity is a single lapse that is addressed through a corrective-action plan, usually without delaying the certificate.

How long must an ISMS run before Stage 2?

Certification bodies generally expect the ISMS to have operated for at least three months before Stage 2, so there is enough evidence of internal audits, management reviews, and working controls to sample.

Explore Courses on Udemy

Intermediate

ISO 27001 Certification Process — A Step-by-Step Guide

Intermediate

ISO 27001:2022 Internal Audit Step by Step

Advanced

ISO 27001:2022 Lead Auditor