ISO 27001 Stage 1 vs Stage 2: What Auditors Actually Check
ISO 27001 certification is a two-stage audit because ISO/IEC 17021-1, the standard certification bodies are accredited against, requires it to be. Stage 1 is a readiness and documentation review: the auditor confirms your ISMS scope, risk assessment, Statement of Applicability and mandatory documented information exist and hang together, and decides whether you are ready to be audited properly. Stage 2 is the certification audit: the auditor tests whether the system described in those documents is actually operating, by sampling records, tracing controls end to end and interviewing the people who run them. The one-line version: Stage 1 asks whether you have what you need, Stage 2 asks whether you are doing what you say.
This article covers what each auditor pulls, what a finding at each stage actually costs you, and the Stage 1 outcome people fear that is not really the risk.
Key takeaways
- Two stages are a requirement on your certification body under ISO/IEC 17021-1, not an upsell.
- Stage 1 is largely documentary and shorter; Stage 2 is evidence sampling and interviews and carries most of the audit days your certification body derives under ISO/IEC 27006-1.
- You do not "fail" Stage 1. You get findings and a readiness judgment, and the realistic bad outcome is Stage 2 being deferred, which costs weeks.
- The most common Stage 1 findings are structural: a scope that does not match reality, and a Statement of Applicability whose justifications do not trace to the risk assessment.
- A major nonconformity at Stage 2 blocks the certification decision until correction is verified, so the fix is to rehearse with a real internal audit first.
What Stage 1 is actually for
The mental model most teams arrive with is that Stage 1 is a soft opening act. It is better understood as the auditor deciding whether Stage 2 is worth booking.
The auditor reads your ISMS scope statement under clause 4.3 and checks whether it is coherent and defensible against what your organization actually does. They read the risk assessment and risk treatment process under clauses 6.1.2 and 6.1.3 and check that a process exists, was followed, and produced results. They read the Statement of Applicability and check it covers the Annex A controls with justifications. They confirm the documented information the standard names is present: the policy under 5.2, objectives under 6.2, competence records under 7.2, the operational planning evidence under clause 8, monitoring results under 9.1, the internal audit program and results under 9.2, and the management review output under 9.3.
They also do something less obvious and more useful: they evaluate whether you understand your own system. Stage 1 usually includes conversations, and a scope document nobody in the room can explain is itself a finding.
Stage 1 is typically conducted at least partly on site or in a live session rather than as a document drop, because ISO/IEC 17021-1 expects the auditor to evaluate your site-specific conditions and your readiness for Stage 2, which is hard to do from a folder.
What Stage 2 is actually for
Stage 2 is where the auditor stops reading and starts sampling.
Expect the auditor to pick specific instances and follow them all the way through. A joiner from four months ago: was access provisioned per the documented process, approved by the right person, and does the record exist. A leaver: was access removed, how fast, and can you show it. A change to production: was it reviewed, tested and approved per your change process. A supplier onboarded this year: was it assessed against your supplier control before it got data. An incident: was it logged, classified, resolved, and did anything feed back into the ISMS.
They will also test the management-system layer, which is the part that catches teams coming from a SOC 2 background off guard. Did the internal audit under clause 9.2 actually happen, was the auditor independent of what they audited, and did it produce findings. Did top management hold a management review under 9.3, with the inputs the clause names, and did it produce decisions. Were nonconformities recorded and corrected under clause 10. A control environment can be genuinely strong and still fail here, because ISO certifies a management system, not a control list.
Interviews matter more at Stage 2 than most first-timers expect. The auditor will ask the engineer who runs the access review to describe it, and compare the answer to the policy. Divergence between the written process and the practiced one is the single most productive thing an auditor can look for, and they know it.
Can you fail Stage 1?
Not in the way the question implies. There is no pass mark and no certificate at stake yet.
What happens instead is that the auditor raises findings and makes a readiness determination. If the gaps are documentary and small, you correct them and proceed to Stage 2 as planned. If they are structural, the auditor concludes you are not ready, and Stage 2 gets pushed. That is the real cost: not a failure, but a delay, plus the rescheduling friction of a certification body's calendar.
One more cost to plan around. Certification bodies limit how long a Stage 1 stays valid, because its conclusions describe a system that may have moved on, so a long deferral can mean repeating Stage 1 and paying for those days twice. If Stage 1 goes badly, ask immediately how long you have before it expires, and plan remediation against that date.
The findings that show up over and over
Scope that does not match reality. The scope statement excludes a team, an environment or a product that everyone in the room knows handles the data. Scope is the first thing the auditor reads and the easiest thing to test against your own org chart.
A Statement of Applicability that does not trace. The justifications say "not applicable, no such systems" for controls whose risk-assessment entries say otherwise, or every control is marked applicable with identical boilerplate. Both patterns say the same thing to an auditor: the SoA was written as a deliverable rather than derived from the risk assessment.
Documented information that describes an aspiration. Policies that specify quarterly reviews when the organization does them annually, or name a role nobody holds. This is a Stage 1 finding on paper and a Stage 2 nonconformity in practice, because at Stage 2 the auditor tests you against your own document.
Clause 9 done at the last minute. An internal audit report and management review minutes dated the week before Stage 2, covering a system with no operating history. That fails the substance of both clauses even when the documents exist.
Risk assessment with no owner or date. A one-off spreadsheet produced for the project rather than a process with a defined methodology, a cadence and named risk owners.
Nonconformities at Stage 2, and what they cost
Findings at Stage 2 are graded, and the grading is what determines your timeline.
A minor nonconformity is a single lapse in an otherwise working control. You submit a correction, a root-cause analysis and a corrective action plan, and the certification decision generally proceeds while the body verifies the fix, often at the next surveillance visit.
A major nonconformity is the absence of a required element, a total breakdown of a control, or a set of minors that together show a systemic failure. It blocks the certification decision until the certification body verifies the correction and corrective action, sometimes by returning for a follow-up visit at your expense. Certification bodies publish their own time limits for closing majors, commonly measured in weeks to a few months, after which the audit can be treated as unsuccessful.
An observation or opportunity for improvement is neither, and it carries no obligation. Do not spend remediation budget on observations while a minor sits open.
The pattern worth internalizing: minors cost you paperwork, majors cost you the certificate date. That asymmetry is the entire argument for a real internal audit before Stage 2, because an internal audit is the only place a major can surface without consequence.
When outside help is not the answer
We do this work, so read the following with that in mind. Two cases where hiring for the audit stages is a poor use of money.
You have a competent internal auditor and a working ISMS. If clause 9.2 is genuinely being run by someone independent and it is finding real problems, the Stage 1 and Stage 2 preparation is mostly logistics: evidence organization, scheduling, and making sure the right people are available for interviews. Paying a consultancy to sit in the room adds cost and, occasionally, confusion about who answers the auditor.
Your gaps are engineering, not audit. If your access reviews do not happen and your logging does not retain, no amount of audit preparation changes the Stage 2 outcome. Spend the money on the control and go to audit a quarter later. A consultancy that agrees to prepare you for an audit you are not ready for is selling you a deferral you could have taken for free.
Where Top Floor fits
The place we add the most value is between the stages, and before them: running an internal audit that behaves like a real Stage 2 rather than a formality, so majors surface where they are cheap. That is audit and assurance work, and it stays separate from build work for exactly the impartiality reasons clause 9.2 cares about. The build side, scope, risk assessment, Statement of Applicability and the evidence habit, sits in our ISO 27001 and compliance-as-a-service engagements. If you are still deciding whether ISO comes before or after an attestation, our ISO 27001 and SOC 2 comparison is the better starting point.
How to decide this week
1. Read your own scope statement aloud to someone outside the project. If they can name a system or team it should cover and does not, fix that before anything else.
2. Open the Statement of Applicability and pick three controls at random. For each, trace the justification back to a specific risk-assessment entry. If you cannot, the SoA is the Stage 1 finding waiting to happen.
3. Check the dates on your internal audit report and management review minutes against the date your controls started operating. If the gap is days, you are not ready for Stage 2.
4. Ask your certification body two questions in writing: how many audit days it derived for each stage and from which table row, and how long a completed Stage 1 remains valid.
5. Schedule the internal audit as an adversarial exercise, not a formality. The goal is to find a major now.
Frequently asked questions
How long does an ISO 27001 Stage 1 audit take?
Stage 1 is the shorter of the two stages and for a small organization it commonly runs a day or two, but the number is not arbitrary. Your certification body derives total audit time under ISO/IEC 27006-1 and ISO/IEC 17021-1, working from your effective number of personnel and adjusting for complexity and number of sites, then splits that total across the two stages. Ask for the derived day count, the split, and the basis for both in writing; a quote that cannot show its arithmetic is worth questioning.
What is the difference between a major and a minor nonconformity?
A minor nonconformity is an isolated lapse in a control that otherwise works, and it usually does not block certification: you supply a correction and corrective action plan and the certification body verifies it, often at the next surveillance audit. A major nonconformity is the absence of a required element, a complete breakdown of a control, or several minors that together indicate a systemic failure, and it blocks the certification decision until the body verifies the fix. Several minors against the same clause can be aggregated into a major, which is why repeated small findings in one area deserve attention rather than individual patches.
Do Stage 1 and Stage 2 have to be with the same certification body?
Yes in practice. The two stages are part of one initial certification audit under ISO/IEC 17021-1, and the certification decision rests with the body that performed them, so switching between stages means starting the initial certification over with the new body. The time to compare bodies is before Stage 1, on accreditation status, derived audit days, sector experience and calendar availability. Once Stage 1 is done you have effectively chosen.
Can you be certified if you have open nonconformities?
It depends on the grade. Open minor nonconformities generally do not stop a certification decision, provided you have submitted an accepted correction and corrective action plan that the certification body will verify later. Open major nonconformities do stop it: the body must verify that the correction and corrective action are effective before it can certify, which may require a follow-up audit. Observations and opportunities for improvement carry no obligation at all and should not be confused with either.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.