ISO 27001 Stage 1 vs Stage 2 audit: what to expect
5 min read · Certifyi research team · Updated July 2026
Stage 1 is a documentation and readiness review; the auditor checks whether your ISMS exists on paper and whether you are ready to be tested. Stage 2 tests whether it actually operates, through evidence sampling and staff interviews. Findings at Stage 1 are expected and useful.
What Stage 1 examines
Stage 1 is deliberately a paper exercise. Treat it as a paid rehearsal rather than a hurdle.
- ISMS scope definition and boundaries
- Information security policy and supporting policies
- Risk assessment methodology and the risk register
- Statement of Applicability with justifications
- Evidence that internal audit and management review are planned
- Whether mandatory clause documentation exists
What Stage 2 examines
Stage 2 tests operation. The auditor samples evidence and interviews people who are supposed to be performing the controls.
- Evidence that controls in the SoA actually operate
- Records of completed internal audits and management reviews
- Corrective actions raised and closed
- Staff awareness: can people describe their responsibilities?
- Consistency between what the documentation claims and what happens
Findings and what they mean
| Finding | Meaning | Effect |
|---|---|---|
| Observation | A weakness that is not a breach of requirement | No block; address at your discretion |
| Minor nonconformity | An isolated lapse against a requirement | Corrective action plan needed; usually not blocking |
| Major nonconformity | Systemic failure or absent required process | Blocks certification until remediated and verified |
How to prepare for each
- Before Stage 1: complete the mandatory documentation and make sure the SoA justifies exclusions
- Between stages: close Stage 1 findings and generate operating evidence
- Before Stage 2: run your own internal audit and management review, and rehearse with control owners
- During Stage 2: give the auditor one coordinator and prompt access to evidence
The most common Stage 1 finding
A Statement of Applicability that lists controls but does not justify exclusions. The second most common is a management review that has been scheduled but never held, because both are mandatory clauses that teams treat as optional formalities.
Key takeaways
- Stage 1 tests documentation, Stage 2 tests operation.
- Stage 1 findings are expected and useful, not failures.
- Major nonconformities block certification; minors usually do not.
- Internal audit and management review are mandatory, not optional.
Frequently asked questions
How long between Stage 1 and Stage 2?
Commonly four to eight weeks, enough to close findings and accumulate operating evidence.
Can we fail Stage 1?
Not in a pass/fail sense. The auditor may conclude you are not ready for Stage 2 and recommend delaying.
Who should attend?
The ISMS owner, control owners for sampled areas, and a coordinator. Senior management should attend the management review discussion.
How long is the certificate valid?
Three years, subject to annual surveillance audits.
Related reading
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call