Skip to main content
RiskZeroCertifiers

Audit insight

ISO 27001 Stage 1 vs Stage 2 audits: what the auditor is actually looking for

The difference between the Stage 1 readiness review and the Stage 2 certification audit, what is examined at each, and how to prepare, explained by the auditors.

By RiskZero Certifiers5 min read

Every accredited ISO 27001 certification audit is split into two stages. The split is not arbitrary. It exists because it is wasteful to send an auditor to test whether controls work before anyone has checked that the system they belong to is designed properly. Here is what each stage is for and what happens in the room.

Stage 1: is the ISMS designed correctly and ready?

Stage 1 is a review of the design of your information security management system and of your readiness for Stage 2. It is mostly a documentation and interview exercise, and for most organizations it can be done remotely in one or two days.

What the auditor examines

  • Scope. Is it defined clearly enough to audit? Does it make sense given what the organization does? Are exclusions justified? An ISMS scope that covers the product but excludes the engineers who build it will be questioned.
  • Policy and leadership. Is there an information security policy approved by top management, with objectives that can be measured?
  • Risk assessment. Is there a documented method? Has it been applied? Do the results lead to a treatment plan? Are risk owners identified?
  • Statement of Applicability. Are all 93 Annex A controls listed with a decision on applicability and a justification? Does the list of applicable controls match the risk treatment plan?
  • Mandatory processes. Has at least one internal audit been done? Has at least one management review taken place with the required inputs and outputs?
  • Logistics. Sites, people to be interviewed, and any constraints for Stage 2.

What Stage 1 produces

A report that identifies areas of concern: things that, if left unchanged, would probably be raised as nonconformities at Stage 2. It is not a pass or fail; it is a readiness assessment with a recommendation on whether to proceed and when.

Common Stage 1 concerns

  • A risk assessment that is a list of threats with no link to assets or controls
  • A Statement of Applicability with no justification for excluded controls, or with controls marked applicable that are not actually in place
  • An internal audit that only covered a few clauses, or was done by the person who built the ISMS
  • A management review with no record of decisions or actions

Stage 2: does the ISMS actually work?

Stage 2 is the certification audit. Its purpose is to test whether the ISMS is implemented and effective, not just documented. The auditor spends most of the time talking to people and looking at records.

How it is structured

The audit plan lists sessions, each covering clauses of the standard or groups of Annex A controls, with the people the auditor wants to meet. A typical Stage 2 for a 100-person software company runs three to four days and includes:

  • Opening meeting with leadership
  • Interviews with the ISMS owner on planning, performance evaluation, and improvement
  • Sessions with engineering on secure development, change, and vulnerability management
  • Sessions with IT or platform on access control, logging, backup, and cloud configuration
  • Sessions with HR on screening, onboarding, training, and leavers
  • Sessions with procurement or whoever owns suppliers
  • Sample checks of physical security if sites are in scope
  • Closing meeting where findings are presented

What the auditor is looking for

Evidence. Not policies that say a thing should happen, but records showing it did. For each control sampled the auditor wants to see three things: a defined approach, evidence it is followed, and evidence someone checks. For access control, that means the policy, a sample of access requests and approvals, and the most recent access review with the actions it produced.

Auditors also look for coherence. If the risk assessment says supplier compromise is your top risk and the supplier controls are thin, that inconsistency is a finding even if each part is individually acceptable.

Findings

  • Major nonconformity. A requirement is absent or has systemically failed. Certification cannot be granted until it is corrected and verified.
  • Minor nonconformity. A lapse or isolated failure that does not undermine the system. A corrective action plan is needed before certification.
  • Opportunity for improvement. An observation, not a nonconformity. No action required, though good organizations act on them anyway.

How to prepare for each stage

Before Stage 1, read your own documents as an outsider. Does the scope make sense? Can you trace a line from a risk to a control to the Statement of Applicability? Have the internal audit and management review actually happened, with records?

Before Stage 2, gather evidence. For every applicable control, know where the records live and who owns them. Brief the people who will be interviewed: they should answer honestly and describe what they actually do. Rehearsed answers that do not match the records are worse than an honest “we do not do that yet”.

Who decides

Neither stage ends with the auditor issuing a certificate. The audit file goes to an independent reviewer at the certification body, who checks that the audit covered everything and that the evidence supports the conclusion. That separation between the person who audits and the person who decides is a requirement of accreditation, and it is one of the reasons an accredited certificate carries weight.

  • stage 1
  • stage 2
  • audit preparation

Read next

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.