Est.

ISO 27001 Certification Audit Stage 1 vs Stage 2 Differences

Stage 1 confirms your security system exists on paper; Stage 2 verifies it actually works.

Features Editor · · 11 min read
Cover illustration for “ISO 27001 Certification Audit Stage 1 vs Stage 2 Differences”
ISO 27001 and Multi-Framework Programs · September 21, 2026 · 11 min read · 2,541 words

ISO 27001 certification runs through two separate audits, not one, and the split exists because a certification body cannot test whether an information security management system works until it first confirms the system exists on paper in a form worth testing. That sequencing isn't a bureaucratic flourish tacked onto ISO 27001 itself. It comes from ISO/IEC 17021-1, the standard that governs how certification bodies operate and get accredited in the first place, and The two-stage requirement sits in that standard rather than in ISO 27001 itself. Understanding why the split exists, and what each stage is actually built to catch, is the fastest way to know what to prepare and when.

The timing matters more than it used to. ISO 27001 is now the fastest-growing certification type tracked in the Wise Guy Reports market study, with a forecast compound annual growth rate of 14.2% for 2025 through 2032, and certifications grew 15% between 2022 and 2025 alone. A lot of organizations going through Stage 1 and Stage 2 right now are doing it for the first time. All new certifications reference the 2022 edition of the standard; the transition window for organizations still holding 2013 certificates closed on October 31, 2025. Everything below assumes the 2022 edition governs the audit.

What Stage 1 examines and what "documentation review" means in practice

Stage 1 has a formal name that gets dropped in casual conversation more than it should: the Documentation Review, sometimes called the Readiness Audit. The auditor's job at this stage is narrow on purpose. They are confirming the management system has been properly designed, not that it functions day to day. That distinction sounds small until you watch how much it changes what gets checked.

The auditor wants a defined ISMS scope with clear boundaries, an information security policy that leadership has actually signed off on with roles assigned, a documented risk assessment methodology paired with a completed risk register, and a risk treatment plan that follows from that register logically. They also want the Statement of Applicability, or SoA, and this document does more work than its name suggests. Cybernion's analysis holds that the SoA has to exist before Stage 1 even starts, because the entire audit hangs off it: every control marked included or excluded needs justification that traces back to the risk assessment and lines up with Annex A. An SoA that excludes a control with no stated reason, or includes one with justification that doesn't match the risk register, creates exactly the kind of gap Stage 1 exists to catch.

Beyond the paperwork, Stage 1 also checks for evidence that at least one internal audit and one management review have already happened, along with plans for how those will continue. That requirement does double duty. The auditor uses that requirement to confirm the ISMS has been running long enough to generate something worth sampling later. A system stood up the week before Stage 1 has nothing behind it yet, and no amount of well-written policy will substitute for that.

Bridewell's research and Elevate's guidance both describe Stage 1 as an investigation or exploration audit: high-level, structural, not the deep evidence-sampling exercise Stage 2 becomes. It typically runs one to two days depending on the organization's size and how complex the scope is, and per IAF MD 4 guidance it can happen on-site, remotely, or as a hybrid of both.

The research identifies the most common findings at this stage as incomplete risk assessments, an SoA that's missing pieces or poorly justified, no internal audit evidence yet, and a management review that hasn't happened. Those four items form a checklist to work through before anyone schedules Stage 1 at all. Cybernion's view holds that a Stage 1 audit that comes back completely clean usually means the auditor didn't look hard enough. The findings list is the actual deliverable. It's the actual deliverable.

Stage 1 outputs are called Improvement Requests, not nonconformities, and that wording is deliberate. They don't fail the organization. But they need addressing before Stage 2, because an Improvement Request left alone has a way of turning into a formal nonconformity once the auditor comes back looking for evidence that it operates. Stage 1 ends with one of three verdicts: proceed to Stage 2, proceed with observations, or delay Stage 2 until remediation happens.

What Stage 2 examines, and why operational evidence is harder to fake than documentation

Stage 2 is the Main Audit, sometimes called the Certification Audit, and it flips the whole exercise. Where Stage 1 asked whether the ISMS was designed properly, Stage 2 asks whether the controls documented in Stage 1 actually run, get monitored, and improve over time. This is the shift the two-stage model was built around from the start: you don't sample operational evidence for a system that might not exist yet, so Stage 1 clears that question first.

The auditor's evidence base widens considerably. Access reviews and the actual configuration of access controls. Risk assessment records matched against evidence that treatment plans were carried out as written. Incident records and corrective action logs. System logs, change tickets, vulnerability scan results. Training records showing staff went through security awareness training, not just that a training module exists somewhere. Internal audit reports and management review minutes. And running through all of it, audit trails that show controls operated consistently over a real stretch of time, because a single instance of a control working right rarely satisfies an auditor at this stage.

Interviews carry real weight in Stage 2. Bridewell's research finds that auditors talk to managers and frontline staff, not only the compliance lead who wrote the policies. The point is to confirm the people actually running the controls understand them and can describe how they work day to day, which is a very different test than checking whether a document describing the control exists.

The SoA from Stage 1 becomes the map for this entire process. Every control an organization claimed as applicable now needs operating evidence behind it, and a system that's only been live for a short stretch simply can't produce that. Cybernion's 2026 guidance is direct on this point: Stage 2 needs at least one completed internal audit, one management review, and enough day-to-day records for the auditor to sample a real operating history, not a manufactured one from the week before the audit.

Stage 2 is traditionally conducted on-site, and while remote elements have become more workable in practice, physical visits are still generally required to verify physical security controls like server room access or badge systems. Duration scales with headcount: organizations with 1 to 10 employees typically see 2 to 3 days, scaling upward through intermediate bands, up to 10 to 12 days for organizations in the 426 to 625 employee range.

The outcome is categorical in a way Stage 1 never is. An organization either gets a certification recommendation, gets a recommendation contingent on resolving minor corrective actions, or doesn't get certified until major nonconformities are resolved and re-checked.

How nonconformity grades work for the path to certification

Nonconformity is the formal language of Stage 2, and it stays in use through every surveillance audit afterward. Stage 1 doesn't use this term at all: it issues Improvement Requests instead, which is a meaningful distinction to hold onto, because the two words carry very different weight with a certification body.

Nonconformities come in three grades. A major nonconformity means something required is either missing entirely or has broken down completely: no internal audit conducted, no management review, no SoA, a risk assessment that never happened, or a pattern of related issues that together indicate a systemic breakdown rather than isolated slips. A major nonconformity withholds the certificate until it's resolved and re-verified, usually through a follow-up audit within a few months.

A minor nonconformity is a single lapse against a requirement that's otherwise being met. The certificate can still be issued, on the condition the organization submits a corrective action plan the certification body accepts, typically corrected within roughly 30 to 90 days depending on the certification body's own policy and how serious the lapse is. Then there's the Observation, sometimes called an Opportunity for Improvement, which flags an area to strengthen without counting as a conformity failure at all. It doesn't block certification, but repeated OFIs in the same area are worth taking seriously even without immediate formal consequence.

GloCert International's data shows that a well-prepared organization going through initial certification should expect somewhere between two and five minor nonconformities as a normal outcome, zero major nonconformities, and a handful of OFIs. None of that should read as alarming. It's the expected shape of a healthy audit.

The practical takeaway is that Stage 1 Improvement Requests are a preview of where Stage 2 nonconformities are going to cluster. Closing them during the gap between the two audits is the cheapest preparation available, cheaper by far than discovering the same gap during Stage 2 when it carries formal weight. Konfirmity's research puts a number on what happens to organizations that skip this step: up to 40% of organizations entering Stage 1 without an already-managed security program end up rescheduling Stage 2 because their evidence simply isn't complete yet.

Using the gap between Stage 1 and Stage 2 productively

The interval between the two audits typically runs four to six weeks. ISO/IEC 17021-1 requires the certification body to agree on that interval with the client and to leave enough room to resolve whatever Stage 1 turned up. That window is not downtime, and treating it that way is one of the more expensive mistakes an organization can make in this whole process.

The gap is when Improvement Requests get closed out, missing operational evidence gets gathered, a supplementary internal audit gets run if the first one wasn't sufficient, and management review minutes get finalized if they were incomplete going into Stage 1.

There's also an upper boundary. There is also an upper boundary on the gap: push it too long and the certification body may need to recheck earlier findings or, in some cases, repeat Stage 1 entirely.

During the gap, the practical priorities are straightforward. Every Improvement Request the auditor raised needs a real answer, not an assumption that a minor item will slip past notice at Stage 2. Operational records, meaning logs, access reviews, incident tickets, need to cover a meaningful stretch of actual operation rather than the few days right before the audit date. Control owners and frontline staff should know roughly what a Stage 2 interview looks like, since anyone on the team could get pulled into one. And the SoA needs a second look to confirm it still matches reality: a discrepancy that appears in Stage 2 but wasn't flagged in Stage 1 reads as a red flag to the auditor, not as an oversight they'll wave through.

Zooming out, the full path from getting audit-ready to holding a certificate typically takes three to six months. Getting to audit-ready in the first place can take several months for many smaller organizations, with the certification audit itself adding time on top of that baseline.

Side-by-side comparison of Stage 1 and Stage 2 across every practical dimension

Diagram: Stage 1 vs. Stage 2: What Each Audit Actually Tests. Visualizes: Show a side-by-side comparison of the two audit stages across five concrete dimensions, making clear these are structurally different in kind, not degree.

Laid out next to each other, the differences are less about degree and more about kind. Stage 1's primary focus is documentation and design; Stage 2's is implementation and effectiveness. Where the Stage 1 auditor spends time reviewing documents and discussing scope at a high level, the Stage 2 auditor samples evidence, runs interviews, observes processes in motion, and in some cases runs technical tests.

The artifacts each stage pulls from differ accordingly. Stage 1 draws on the ISMS scope document, the policy set, the SoA, the risk register, and evidence that a management review and internal audit have occurred. Stage 2 draws on logs, access reviews, incident records, training records, and audit trails that stretch across time. Who gets interviewed shifts too: Stage 1 mostly talks to compliance leads and leadership, while Stage 2 can pull in any team member, including control owners and frontline staff who never touch the compliance function directly.

Location differs as well. Stage 1 can happen remotely, on-site, or as a hybrid without much friction. Stage 2 leans predominantly on-site, though remote elements are becoming more workable under IAF MD 4 guidance. Duration scales very differently between the two stages: Stage 1 is one to two days regardless of company size, while Stage 2 runs anywhere from two to three days for the smallest organizations up to ten to twelve days for larger ones.

The outputs reflect the difference in stakes directly. Stage 1 produces Improvement Requests and a readiness decision for Stage 2. Stage 2 produces a formal nonconformity report, graded major, minor, or observation, along with a certification recommendation. Both stages, worth restating, are governed by the same standard, ISO/IEC 17021-1, not by ISO 27001 itself.

The asymmetry between the two stages matters above all else. Stage 1 findings are advisory and can be deferred within reason. Stage 2 major nonconformities stop certification outright. These aren't two versions of the same test at different depths, they're structurally unequal in what they cost an organization if things go wrong.

The mistakes that blur this distinction tend to repeat across organizations. Treating Stage 1 like a pass-or-fail exam instead of a gap analysis is one. Piling on documentation volume while neglecting to build the operational records that back it up is another. Ignoring Stage 1 Improvement Requests and hoping they quietly disappear is a third, and entering Stage 2 with evidence that only covers a short operating window rounds out the list.

What happens after Stage 2: the three-year surveillance and recertification cycle

Diagram: The Three-Year Certification Cycle. Visualizes: Illustrate the repeating four-year audit cycle that begins once Stage 2 is passed: Year 1 = Initial Certification (Stage 1 + Stage 2); Year 2 = Surveillance Audit 1 (subset of controls…

Passing Stage 2 gets an organization a certificate valid for three years, and that number marks the start of an ongoing cycle rather than the finish line most people treat it as. Year one is the initial certification, covering both stages. Year two brings Surveillance Audit 1, a lighter review that samples a subset of controls and focuses on what's changed recently and whether continuous improvement is actually happening. Year three brings Surveillance Audit 2, in roughly the same format. Year four is the recertification audit, which runs at a depth close to the original Stage 2, and the whole cycle starts over from there.

Surveillance audits don't repeat the full Stage 1 and Stage 2 structure. They sample the ISMS to confirm it's still operating and has kept pace with new threats and regulatory changes since the last visit. Observations and OFIs that go unaddressed across multiple surveillance cycles have a way of hardening into nonconformities eventually, because the auditor's memory carries across visits. The period between audits isn't a reset button.

Organizations certified under the 2022 edition should expect the eleven new controls it introduced, covering areas like threat intelligence, cloud services, ICT readiness for business continuity, configuration management, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding, to appear directly in surveillance and recertification audits. Building operational evidence for those controls now, rather than scrambling for it before the next visit, is the difference between a routine surveillance audit and one that turns up findings nobody expected.

Sources

  1. ISO 27001 Stage 1 vs Stage 2 Audit: Key Differences Explained
  2. ISO 27001 Audit: Stage 1 vs Stage 2 Differences Explained - Elevate
  3. What to Expect From Stage 1 & 2 ISO 27001 Certification Audits | Bridewell
  4. ISO 27001 Stage 1 vs Stage 2 Audit Explained
  5. ISO 27001 Certification Process: Stage 1 vs Stage 2 Complete Guide
  6. konfirmity.com
  7. advisera.com

More in ISO 27001 and Multi-Framework Programs