All insights
ISO 27001 July 14, 2026 7 min read

ISO 27001 Stage 1 vs Stage 2 Audits: What to Expect

ISO/IEC 27001:2022 certification is awarded through a two-stage audit conducted by an accredited certification body. Understanding what each stage tests, and why they are separated, removes most of the anxiety from the process and helps you prepare the right evidence at the right time.

This article explains what happens at Stage 1 and Stage 2, the kinds of findings auditors raise, and the practical steps that separate organisations who sail through from those who stumble.

Why certification is split into two stages

The two-stage model exists to protect both you and the certification body. Stage 1 is a relatively light-touch check that your information security management system is designed correctly and that you are genuinely ready for the deeper audit. Stage 2 is the substantive examination of whether the system actually works.

Separating them means you are not paying for a full implementation audit only to discover on day one that fundamental documents are missing. It gives you a checkpoint, a defined gap-closure period, and a much higher chance of a clean Stage 2.

Stage 1: the readiness and documentation review

Stage 1 focuses on the design of your ISMS rather than day-to-day operation. The auditor wants to confirm that the foundations are in place and that proceeding to Stage 2 is worthwhile. Expect them to examine:

  • Scope of the ISMS. Is the boundary clearly defined and defensible? Does it cover the products, services, locations and information assets you claim?
  • The risk assessment and risk treatment plan. Is there a documented, repeatable methodology, and have risks been identified, evaluated and treated?
  • The Statement of Applicability. Are the Annex A controls justified as included or excluded, and does the SoA align with your risk treatment decisions?
  • Mandatory documented information. The information security policy, objectives, roles and responsibilities, and evidence that you have begun internal audits and management review.

Stage 1 also confirms practical readiness. The auditor will check that internal audits and at least one management review have started, because Stage 2 cannot meaningfully assess effectiveness if these core management processes have never run. They will provide a report identifying any areas of concern that must be addressed before Stage 2. These are not always formal nonconformities, but they signal where you are exposed.

The gap between the stages

After Stage 1 you receive findings and recommendations. The interval before Stage 2, usually a few weeks to a couple of months, is your window to fix readiness gaps. If Stage 1 exposes serious immaturity, a reputable certification body will tell you to delay Stage 2 rather than walk into a likely failure. Take that advice seriously. Pushing ahead unprepared typically results in major nonconformities, a delayed certificate, and the cost of a follow-up audit.

Use this period deliberately. Close the documented gaps, run any outstanding internal audits, complete a management review if you have not, and rehearse how you will retrieve evidence quickly during Stage 2.

Stage 2: the implementation audit

Stage 2 is where certification is genuinely earned. The auditor moves from “does the system exist” to “does the system work.” They gather objective evidence that your controls are implemented and effective across the full scope. Typical activities include:

  • Sampling records. Access reviews, change management tickets, incident logs, backup and restore tests, vulnerability scans, supplier assessments and training completion records.
  • Tracing controls end to end. Selecting a control from the Statement of Applicability and following it from policy through procedure to actual operational evidence.
  • Interviewing staff. Confirming that people understand their responsibilities and that the documented process matches what actually happens.
  • Reviewing management system evidence. Internal audit reports, management review minutes, corrective actions, and progress against security objectives.

The auditor is testing for consistency between what your documents claim and what your people and systems actually do. The most common failures are not missing policies but policies that nobody follows: an access review procedure with no completed reviews, or an incident process that was never used during a real incident.

Understanding nonconformities

Almost every organisation receives findings at Stage 2, and that is normal. They fall into categories:

  • Major nonconformity. A significant failure, such as a required process being absent or systematically not working. Majors must be resolved and verified before the certificate is issued.
  • Minor nonconformity. An isolated lapse or partial implementation. These generally allow certification to proceed provided you submit a corrective action plan, with verification at a later visit.
  • Observations and opportunities for improvement. Not breaches, but areas worth strengthening. Acting on them shows maturity and reduces future findings.

When a finding is raised, respond with the same discipline Clause 10.2 expects: correction, root cause analysis, corrective action and verification. A clear, credible corrective action plan reassures the auditor that your management system actually learns and improves.

What auditors are really testing

It helps to understand the mindset behind the questions. A certification auditor is not trying to catch you out; they are trying to gather objective evidence that your management system does what it claims. Everything they sample is ultimately a test of one of three things: does the control exist, does it operate consistently, and does the organisation notice and respond when it fails.

That third element surprises many first-time candidates. Auditors are reassured by an organisation that has found its own problems, raised internal nonconformities, and fixed them. A self-correcting system is stronger than one that appears flawless, because no real system is flawless. If your internal audit log shows issues identified and resolved, you are demonstrating exactly the maturity the standard is designed to produce.

The role of the Statement of Applicability

The Statement of Applicability is central to both stages, and it pays to know it well. At Stage 1 the auditor checks that it is complete, that every Annex A control is marked as included or excluded, and that the justifications are coherent and tied to your risk treatment. At Stage 2 the SoA becomes the auditor’s map: they pick controls from it and trace each one through to operational evidence.

A weak SoA causes problems at both stages. Controls excluded without sound justification, or included but with no implementing process behind them, are an open invitation to findings. Treat the SoA as a living document that genuinely reflects your environment, not a form completed once and forgotten.

Roles during the audit

Knowing who does what during the audit reduces friction. A guide or sponsor from your team usually accompanies the auditor, helps locate evidence and clarifies context. Control owners are interviewed about the processes they run, so brief them in advance on what to expect. Someone should be designated to take notes on every finding and request, so nothing is lost and your corrective action work can begin immediately after the closing meeting.

The auditor will typically hold an opening meeting to confirm scope and logistics, conduct the audit through interviews and evidence review, and finish with a closing meeting summarising findings. Treat the closing meeting as the start of your remediation, not the end of the engagement.

How to prepare and pass cleanly

The organisations that pass smoothly do a few things consistently:

  • Run a thorough internal audit first. Your own audit should find the issues before the certification body does. A weak internal audit is a strong predictor of Stage 2 surprises.
  • Keep evidence retrievable. Auditors lose patience when teams cannot produce records during the audit window. Know where your access reviews, change logs and incident records live.
  • Brief your staff. Interviewees do not need to memorise the standard, but they should understand their own responsibilities and where to find the relevant procedure.
  • Be honest about scope. An over-ambitious scope is harder to evidence. A tightly defined, defensible scope is easier to certify and can be expanded later.

For a broader view of the certification journey and the wider control set, our ISO 27001 overview puts these stages in context, and Australian organisations balancing this with government baselines may find the Essential Eight explained guide useful.

Getting expert support

Preparing for a certification audit is far easier with someone who has sat on both sides of the table. CISO Advisory helps Australian organisations get ready for Stage 1 and Stage 2, conduct realistic mock audits, and remediate findings quickly. Engaging a virtual CISO gives you that experience without a permanent hire. To talk through your timeline, contact us or call 07 2112 8502.

Frequently asked questions

What is the difference between a Stage 1 and Stage 2 audit?

Stage 1 is a documentation and readiness review where the auditor checks your ISMS design, scope, risk assessment and key documents, and confirms you are ready to proceed. Stage 2 is the in-depth implementation audit where the auditor gathers evidence that your controls are operating effectively in practice across the defined scope.

How long is there between Stage 1 and Stage 2?

Typically a few weeks to a couple of months. The gap gives you time to close any findings or readiness gaps raised at Stage 1. If Stage 1 reveals significant immaturity, the certification body may recommend delaying Stage 2 rather than risk a failed audit, which is usually the cheaper outcome.

Can you fail a Stage 2 audit?

You will not be certified if major nonconformities remain unresolved, but a single audit is rarely a hard pass or fail. Most organisations receive some findings. Minor nonconformities can usually be addressed with a corrective action plan, while majors must be resolved and verified before the certificate is issued.

What does the auditor actually look at during Stage 2?

They sample evidence that controls operate as documented: access reviews, change records, incident logs, risk treatment, supplier assessments, training records, internal audit results and management review minutes. They interview staff to confirm awareness, and trace selected controls end to end against your Statement of Applicability.

How long does the whole certification audit take?

It depends on organisation size, scope and complexity, and the certification body calculates audit duration accordingly. A small SaaS business might see one to two days for Stage 1 and two to four for Stage 2; larger or multi-site organisations take longer. Your certification body will confirm the planned days in advance.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act