Stage 1 vs Stage 2: What Happens in an ISO 27001 Audit
The certification audit comes in two stages with very different purposes. Knowing what each one tests helps you prepare for the right things at the right time.
By Kellwick Team · July 26, 2026 · 5 min read
Most teams treat the ISO 27001 certification audit as a single event. It is not. It runs in two distinct stages, weeks or months apart, and each stage tests something different. Understanding that split is the difference between walking in prepared and scrambling to explain gaps you could have closed earlier.
Why the Audit Is Split in Two
ISO 27001 certification is carried out by an accredited certification body, not by an advisor and not by you. The two-stage model exists because an information security management system (ISMS) is not just documentation. It is a set of controls and habits that have to be running over time. A single visit cannot fairly judge both whether your system is well designed and whether it actually works in practice.
So the certification body separates the two questions. Stage 1 asks whether your ISMS is designed and documented well enough to be auditable. Stage 2 asks whether it is genuinely operating. The gap between them is deliberate. It gives you time to fix design issues before anyone tests operation.
This matters commercially. If you go into Stage 1 expecting a full controls audit, you will over-prepare in some areas and under-prepare in others. If you treat Stage 2 as a formality, you will fail it.
What Stage 1 Actually Checks
Stage 1 is often called the documentation review or readiness review. The assessor is looking for evidence that your ISMS exists on paper and is coherent. Expect them to focus on:
- Your scope statement and whether it is defensible. What is in, what is out, and why.
- The Statement of Applicability (SoA), checking that each Annex A control is marked applicable or not, with justification.
- Core mandatory documents: the information security policy, risk assessment methodology, risk treatment plan, and objectives.
- Evidence that a risk assessment has been carried out at least once.
- Whether you have planned internal audits and a management review.
Stage 1 is not where they test whether controls work. It is where they test whether the system is ready to be tested. The assessor will usually produce a short report listing areas of concern. These are not always formal nonconformities, but they are a map of where you are exposed.
Treat that report as a gift. It tells you exactly what a trained assessor thinks is weak, before the stage that carries the pass or fail weight.
The Gap Between Stage 1 and Stage 2
Between the two stages you typically have a few weeks to a couple of months. This window is where good teams pull ahead. Use it to:
- Close every issue raised in the Stage 1 report, with evidence, not intentions.
- Make sure your controls have been running long enough to produce records. Access reviews, backups, vulnerability scans, and incident logs all need history behind them.
- Run at least one full internal audit cycle if you have not already.
- Hold a real management review with real decisions recorded.
The most common mistake here is assuming Stage 2 is imminent enough that nothing new needs to happen. In reality, Stage 2 evidence often has to span weeks or months of operation. If you only turned on quarterly access reviews last week, you cannot show a quarter of history. That timing problem is the single most avoidable Stage 2 failure.
What Stage 2 Actually Checks
Stage 2 is the operational audit. The assessor is now sampling evidence to confirm your ISMS runs the way your documents claim. This is where the depth increases sharply. Expect:
- Sampling of records across controls. They will pick specific joiners and leavers and ask to see access granted and revoked on time.
- Interviews with staff outside the security team, to check that policies are known and followed, not just written.
- Review of your risk treatment in action, including whether identified risks actually got treated.
- Evidence of internal audit findings and how you closed them.
- Evidence that management review happened and drove decisions.
- Handling of any security incidents, including whether your process was followed.
Findings at Stage 2 are graded. A minor nonconformity is a lapse that does not undermine the whole system, and you usually get time to correct it with a plan. A major nonconformity means a control or requirement is fundamentally absent or broken, and it blocks certification until resolved. Several minors can be raised together and still allow certification to proceed once you commit to fixing them.
The assessor is not trying to trap you. They are trying to confirm the system is real. The teams that pass cleanly are the ones whose evidence is boringly consistent.
How to Prepare for Both Without Wasting Effort
The two stages reward different preparation, so sequence your work.
For Stage 1, prioritise clarity and completeness of documentation. Make your scope tight and honest. Make your SoA justifications specific. Do not pad. An assessor reads a lot of these and can tell copied text from considered decisions.
For Stage 2, prioritise operational evidence and habit. The best signal you can give an assessor is that controls run on a schedule and leave a trail without anyone having to reconstruct it. That means:
- Turning on recurring controls early, so history accumulates before the audit.
- Keeping evidence in one place your team can produce on request.
- Rehearsing the interview element. People freeze when asked where the policy lives. A quick internal walkthrough prevents that.
One more thing. Do not over-scope to look impressive. A smaller, honest scope that you can fully evidence beats a broad scope full of gaps. Scope is one of the few decisions that is genuinely hard to reverse cleanly once certified, so get it right before Stage 1.
Bottom Line
Stage 1 tests whether your ISMS is designed to be auditable. Stage 2 tests whether it actually runs. The gap between them is your best opportunity to fix what a professional has already flagged, but only if your recurring controls have been running long enough to leave evidence. Most avoidable failures come down to timing and thin operational history, not weak intent.
If you want an honest read on whether your documentation would survive Stage 1 and whether your controls have enough operating history for Stage 2, a Kellwick readiness review will show you where you actually stand before a certification body does.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.