top of page
bg_3.png
bg_3.png

ISO 27001 Certification Audit: Stage 1 vs Stage 2 Explained

Sep 22
8 min read

ISO 27001 certification does not start with a certificate. It starts with proof. An auditor must see that information security is planned, controlled, measured, and improved in a consistent way.



The certification audit happens in two main parts: Stage 1 and Stage 2. Each stage has a different purpose. Stage 1 checks whether the organization is ready for the full audit. Stage 2 checks whether the system works in practice.


Wide-angle view of a secure server aisle with locked cabinets and cool blue lighting
Certification is based on evidence, not assumptions.

What the ISO 27001 certification audit is designed to prove


ISO 27001 is an international standard for managing information security. It focuses on protecting confidential information, keeping systems available, and preserving data accuracy.


The standard requires an organization to create and maintain an information security management system. This is the set of policies, risk decisions, controls, records, reviews, and improvement steps used to manage security.


The audit checks whether that system meets the requirements of ISO 27001 and whether the organization follows it.


A certification audit usually includes:


  • A review of required documents

  • Interviews with staff

  • Sampling of records

  • Checks on security controls

  • Evidence that risks are assessed and treated

  • Evidence that leadership reviews the system

  • Checks that internal audits and corrective actions happen


The auditor does not test every file, system, or employee. The audit uses sampling. That means the auditor selects examples and checks whether they support the same conclusion: the system is defined, followed, and improving.


The ISO 27001 Certification Audit Stage 1 & Stage 2 process reduces the risk of certifying a system that only exists on paper. Stage 1 tests readiness. Stage 2 tests real operation.


ISO 27001 Certification Audit Stage 1 checks whether the organization is ready


Stage 1 is often called the readiness review. It is not a full pass-or-fail test of every process. Its main goal is to confirm that the organization has built the required foundation before the detailed audit begins.


Key objectives of Stage 1


During Stage 1, the auditor checks whether the organization has:


  • Defined the scope of certification

  • Identified information security risks

  • Created a plan to treat those risks

  • Selected relevant security controls

  • Written key policies and procedures

  • Completed internal audits

  • Held management reviews

  • Prepared records that show the system is active


The auditor also checks whether the organization understands ISO 27001 requirements. A file full of templates is not enough. The documents must reflect how the business actually works.


For example, a startup that stores customer data in cloud systems needs a scope that covers those systems, the people who manage them, and the processes used to control access. A generic scope such as “all business operations” may be too vague to audit well.


What to expect during Stage 1


Stage 1 usually includes document review and discussion with key staff. The auditor may ask for information such as:


  • The certification scope

  • The risk assessment method

  • The risk treatment plan

  • The statement of selected controls

  • Information security policies

  • Internal audit results

  • Management review records

  • Legal, regulatory, and contract requirements

  • A list of sites, systems, and teams included in scope


The auditor looks for gaps that could stop Stage 2 from succeeding. These gaps may include missing records, unclear scope, internal audits that were not completed, or policies that do not match actual work.


Stage 1 may be remote, on-site, or a mix of both. The format depends on the certification body, audit scope, and organization size.


At the end, the auditor issues findings. These may include concerns to fix before Stage 2. If the gaps are serious, Stage 2 may need to be delayed.


Close-up view of a printed security checklist beside a locked metal file box
Stage 1 confirms that the basic structure is ready.

ISO 27001 Certification Audit Stage 2 checks whether the system works


Stage 2 is the certification audit. This is where the auditor checks whether the information security management system is in place and operating as required.


Stage 2 goes deeper than Stage 1. The auditor does not only ask, “Do you have a policy?” The auditor asks, “Do people follow it, and can the organization prove it?”


Key objectives of Stage 2


The Stage 2 audit checks whether:


  • Security risks are managed as planned

  • Controls are working

  • Staff understand their security duties

  • Required records are maintained

  • Incidents are handled and reviewed

  • Access to information is controlled

  • Suppliers are managed where relevant

  • Internal audits lead to real correction

  • Leadership reviews security performance

  • The organization improves the system over time


The auditor compares written requirements with actual behavior.


For example, if the access control policy says user access must be reviewed every quarter, the auditor may ask for recent access review records. If the policy says employees must complete security awareness training, the auditor may sample training records and ask staff basic questions.


What to expect during Stage 2


Stage 2 is more active and evidence-based. It often includes:


  • Interviews with process owners

  • Interviews with employees

  • Review of records and logs

  • Checks on physical security

  • Review of risk treatment progress

  • Review of incident records

  • Review of supplier controls

  • Testing whether procedures are followed


The auditor may follow a process from start to finish. For example, they may review how a new employee gets system access. That can include the access request, approval, setup, training, and later access review.


The auditor may also check how a security incident is reported and handled. If no incidents occurred, the auditor may review the process, test records, and any practice exercises.


Findings from Stage 2 usually fall into categories. The exact terms can vary, but the common types include:


  • Major issue

    A serious failure that shows a requirement is missing or not working.


  • Minor issue

    A limited gap that needs correction but does not break the whole system.


  • Opportunity for improvement

    A suggestion that can improve the system but is not a formal failure.


A major issue can block certification until corrected. Minor issues usually require a corrective action plan and follow-up.


Eye-level view of a keypad access panel on a heavy secure door
Stage 2 tests whether controls work in daily operations.

Stage 1 and Stage 2 have different roles


Stage 1 and Stage 2 are connected, but they are not the same audit repeated twice.


Area

Stage 1

Stage 2

Main purpose

Confirm readiness

Confirm effective operation

Main focus

Documents, scope, planning, required records

Evidence, interviews, control performance

Typical result

Readiness findings and concerns

Certification recommendation or corrective actions

Audit depth

Broad review

Detailed testing

Common question

Is the system ready to audit?

Does the system work in real life?

Risk if weak

Stage 2 delays

Certification delays or refusal


Stage 1 protects the organization from entering the final audit too early. Stage 2 protects the value of the certificate.


Both stages matter. A strong Stage 1 reduces surprises. A strong Stage 2 proves that security is part of daily work, not a binder on a shelf.


Why compliance matters beyond the certificate


ISO 27001 Certification can help organizations meet customer, partner, and regulatory expectations. Many buyers ask for certification before sharing sensitive data or signing contracts. For software firms, service providers, and companies that handle customer records, certification can reduce repeated security questionnaires.


The compliance value also goes beyond sales.


A well-run ISO 27001 program helps an organization:


  • Know what information it needs to protect

  • Assign owners for security risks

  • Make security decisions based on risk

  • Track whether controls are working

  • Respond to incidents with a clear process

  • Improve security over time


Compliance does not mean zero risk. No audit can promise that. It means the organization has a controlled and repeatable way to manage risk.


That matters when something goes wrong. If a data issue occurs, records from risk reviews, training, access checks, incident handling, and management reviews can show that the organization took security seriously.


Common challenges during certification audits


Many audit problems come from weak preparation, not weak technology. The following issues appear often.


The scope is unclear


A vague scope creates confusion. The auditor needs to know what teams, systems, locations, and services are included.


A narrow scope can also cause issues if it leaves out key systems that support the service being certified. The scope must match the real flow of sensitive information.


Documents do not match daily work


A policy may say one thing while staff do another. Auditors notice this quickly during interviews and record sampling.


For example, if a policy says every supplier is reviewed before approval, but no supplier review records exist, the control is not working as written.


Risk assessments are too generic


Risk assessment is central to ISO 27001. A weak risk record lists broad issues without clear owners, decisions, or treatment plans.


Good risk records connect threats to real business processes. They also show why controls were selected.


Internal audits happen too late


An internal audit is required before certification. It gives the organization a chance to find and fix gaps before the external auditor arrives.


Waiting until the last week creates avoidable pressure. It also leaves little time to correct findings.


Evidence is scattered


Policies may live in one place, logs in another, and approvals in email. If the audit team cannot find evidence quickly, interviews become slower and more stressful.


Auditors do not need perfect formatting. They need clear, reliable records.


Staff are not ready for interviews


Staff do not need to memorize the standard. They do need to understand their role in protecting information.


Common interview questions include:


  • What security training have you completed?

  • How do you report a security concern?

  • How do you handle sensitive information?

  • What do you do when access is no longer needed?

  • Where do you find security policies?


Short, honest answers are better than scripted ones.


Overhead view of labeled folders and printed risk records arranged on a plain table
Good audit preparation makes evidence easy to find.

Tips for successful preparation


Start with the audit dates and work backward. Stage 2 needs real operating evidence, so the system must run before the auditor arrives.


Use these practical steps.


Define the scope with care


Write a scope that is clear and auditable. Include the services, locations, systems, and business units that handle or support sensitive information.


Ask one simple question: could an auditor understand what is included without a long explanation?


Build evidence as work happens


Do not create records after the fact. Keep evidence during normal operations.


Useful records include:


  • Risk assessment results

  • Risk treatment decisions

  • Security training logs

  • Access review records

  • Supplier review records

  • Incident reports

  • Internal audit reports

  • Corrective action records

  • Management review minutes


The best evidence is current, dated, and tied to a clear owner.


Test the system before Stage 1


Before Stage 1, check the required items. Confirm that risk work is complete, policies are approved, internal audits occurred, and management reviews are recorded.


This reduces the chance of a delay between Stage 1 and Stage 2.


Prepare people, not scripts


Tell staff what the audit is for and how interviews work. They should answer based on what they do.


A good preparation session covers:


  • Where policies are stored

  • How to report an incident

  • How access is requested and removed

  • What information needs protection

  • What to do if something looks suspicious


Fix issues with clear corrective actions


When gaps appear, document the cause and the fix. A weak response says, “We updated the policy.” A stronger response explains why the gap happened, what changed, who owns the fix, and how the team will prevent repeat issues.


Keep leadership involved


ISO 27001 requires leadership involvement. Senior leaders should review risks, resources, audit results, and improvement actions. If leadership treats certification as an IT-only project, the system will be weaker.


Security affects contracts, hiring, suppliers, operations, and customer trust. Leadership must stay close enough to make decisions.


FAQ


How long does the ISO 27001 certification audit take?


The length depends on organization size, scope, locations, and complexity. A small company with one main service may need less time than a larger organization with many sites and systems. The certification body sets the audit duration based on recognized audit planning rules.


Can an organization fail Stage 1?


Stage 1 can identify gaps serious enough to delay Stage 2. The usual result is not “failure” in the final sense. The organization receives findings and must fix readiness issues before moving forward.


What happens if Stage 2 finds a major issue?


A major issue must be corrected before certification can be recommended. The auditor will usually require evidence of correction and may need a follow-up review.


Do auditors check every control?


No. Auditors use sampling. They review selected records, people, systems, and processes to decide whether the management system meets the standard and works in practice.


Is certification the end of the process?


No. Certification requires ongoing audits. The organization must keep the system active, fix issues, review risks, and improve controls over time.


Low-angle view of a locked server cabinet with a visible security seal
Certification is easier to maintain when controls stay active.

Final takeaway


Stage 1 asks whether the information security management system is ready for full review. Stage 2 asks whether it works in real operations. Both stages protect the value of certification.


The best preparation is practical. Define the scope. Run the system before the audit. Keep records. Train staff on their real duties. Fix gaps before the auditor finds them.


For help preparing clear audit documents, policies, and certification-ready evidence, get ISO 27001 audit support.



Comments


bottom of page