ISO 27001 Stage 1 vs Stage 2 Audit Explained
ISO 27001

ISO 27001 Stage 1 vs Stage 2 audit: what to expect

5 min read · Certifyi research team · Updated July 2026

Short answer

Stage 1 is a documentation and readiness review; the auditor checks whether your ISMS exists on paper and whether you are ready to be tested. Stage 2 tests whether it actually operates, through evidence sampling and staff interviews. Findings at Stage 1 are expected and useful.

What Stage 1 examines

Stage 1 is deliberately a paper exercise. Treat it as a paid rehearsal rather than a hurdle.

  • ISMS scope definition and boundaries
  • Information security policy and supporting policies
  • Risk assessment methodology and the risk register
  • Statement of Applicability with justifications
  • Evidence that internal audit and management review are planned
  • Whether mandatory clause documentation exists

What Stage 2 examines

Stage 2 tests operation. The auditor samples evidence and interviews people who are supposed to be performing the controls.

  • Evidence that controls in the SoA actually operate
  • Records of completed internal audits and management reviews
  • Corrective actions raised and closed
  • Staff awareness: can people describe their responsibilities?
  • Consistency between what the documentation claims and what happens

Findings and what they mean

FindingMeaningEffect
ObservationA weakness that is not a breach of requirementNo block; address at your discretion
Minor nonconformityAn isolated lapse against a requirementCorrective action plan needed; usually not blocking
Major nonconformitySystemic failure or absent required processBlocks certification until remediated and verified

How to prepare for each

  1. Before Stage 1: complete the mandatory documentation and make sure the SoA justifies exclusions
  2. Between stages: close Stage 1 findings and generate operating evidence
  3. Before Stage 2: run your own internal audit and management review, and rehearse with control owners
  4. During Stage 2: give the auditor one coordinator and prompt access to evidence

The most common Stage 1 finding

A Statement of Applicability that lists controls but does not justify exclusions. The second most common is a management review that has been scheduled but never held, because both are mandatory clauses that teams treat as optional formalities.

Key takeaways

  • Stage 1 tests documentation, Stage 2 tests operation.
  • Stage 1 findings are expected and useful, not failures.
  • Major nonconformities block certification; minors usually do not.
  • Internal audit and management review are mandatory, not optional.

Frequently asked questions

How long between Stage 1 and Stage 2?

Commonly four to eight weeks, enough to close findings and accumulate operating evidence.

Can we fail Stage 1?

Not in a pass/fail sense. The auditor may conclude you are not ready for Stage 2 and recommend delaying.

Who should attend?

The ISMS owner, control owners for sampled areas, and a coordinator. Senior management should attend the management review discussion.

How long is the certificate valid?

Three years, subject to annual surveillance audits.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.

Book a 20-min deal readiness call

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top