Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 Stage 1 vs Stage 2 audit comparison infographic

ISO 27001 Stage 1 vs Stage 2: The Complete 2026 Audit Guide

The ISO 27001 Stage 1 vs Stage 2 question comes down to one distinction: Stage 1 asks whether your ISMS is designed, Stage 2 asks whether it is working. Both belong to a single initial certification audit, and ISO/IEC 17021-1 — the standard your certification body is itself accredited against — requires that audit to be conducted in two stages. Neither one is optional.

Most confusion comes from treating Stage 1 as a formality and Stage 2 as the “real” audit. That framing costs money. Stage 1 is where the scope of Stage 2 gets set, where the auditor decides how many days to spend and where to look, and where “areas of concern” get logged to be re-tested against you weeks later. Handle Stage 1 badly and you have bought a harder Stage 2.

This ISO 27001 Stage 1 vs Stage 2 guide covers what each stage examines, how long each takes, the gap between them, what happens when you fail, and the deadline that catches people out.

ISO 27001 Stage 1 vs Stage 2 at a Glance

Stage 1Stage 2
Core questionIs the ISMS designed and are you ready?Is the ISMS implemented and effective?
Primary evidenceDocumented information — scope, policies, risk method, Statement of ApplicabilityRecords, interviews, observation of processes actually running
Typical durationRoughly a fifth to a quarter of total audit time; often 1–2 days for a small organizationThe remaining bulk of audit time; often 2–5 days for a small organization
LocationFrequently remote or off-siteAt your site(s), with remote techniques used where the certification body permits
Findings raised“Areas of concern” and conclusions on readinessMajor and minor nonconformities
Can you fail?Not formally — but Stage 2 can be postponed or Stage 1 repeatedYes — unresolved major nonconformities block certification
OutcomeA readiness verdict and a plan for Stage 2A recommendation to the certification decision-maker

What Stage 1 Actually Examines

ISO/IEC 17021-1 sets out the objectives your Stage 1 auditor has to meet, and they are broader than “read the policies.” The auditor reviews your documented management system; evaluates your preparedness for Stage 2; checks your understanding of the standard’s requirements; gathers information about the scope, sites, processes and applicable legal requirements; agrees how Stage 2 time will be allocated; and — this is the one people forget — evaluates whether internal audits and management reviews are being planned and performed.

That last objective is where thinly prepared organizations come unstuck. You can write every policy in a fortnight. You cannot retroactively produce an internal audit and a management review. If those two records do not exist, the auditor has a documented reason to say you are not ready — which is the first place the ISO 27001 Stage 1 vs Stage 2 sequence bites.

Expect close attention to the ISMS scope statement, the information security policy, the risk assessment methodology, and the Statement of Applicability. The SoA is mandatory under clause 6.1.3 and must account for all 93 Annex A controls in ISO 27001:2022 — 37 organizational, 8 people, 14 physical and 34 technological — justifying every inclusion and exclusion. An SoA with blank justification columns is the most common Stage 1 finding I see.

“Areas of concern” are not free passes

Stage 1 does not usually raise formal nonconformities. It produces documented conclusions on your readiness and identifies areas of concern — and ISO/IEC 17021-1 is explicit that those can be raised as nonconformities during Stage 2. Treat the Stage 1 report as the list of things the auditor intends to test hardest.

What Stage 2 Actually Examines

Stage 2 evaluates implementation, including effectiveness, and takes place at your site(s). The auditor works through performance monitoring and review against your security objectives, how you meet statutory, regulatory and contractual requirements, operational control of your processes, internal audit and management review, and management responsibility for the policies you published.

In practice this means sampling. The auditor will not read your access control policy again — they will ask for the last three access reviews, pick a leaver, and trace whether the accounts were actually disabled. Expect the same treatment for incident records, change approvals, supplier security assessments, backup restore tests and training completion.

The evidential gap is the heart of the ISO 27001 Stage 1 vs Stage 2 difference: documents satisfy the first stage, dated records satisfy the second. This is why organizations are usually asked to have the ISMS running for a period before Stage 2 — commonly around three months, though this is certification body practice rather than a requirement written into ISO 27001 itself. Without an operating history there is simply nothing to sample. A well-run ISO 27001 gap analysis months earlier is what makes this window survivable.

How Long Each Stage Takes, and Who Decides

Audit duration is not negotiable in the way clients expect. Your certification body must have a documented procedure for determining audit time, and for ISMS certification the governing document is ISO/IEC 27006-1:2024, published in March 2024, whose normative Annex C sets the audit time table and whose informative Annex D explains the calculation methods.

A point worth correcting, because it circulates constantly: IAF MD 5 does not apply here. Its title limits it to quality, environmental, and occupational health and safety management systems. ISMS audit time comes from ISO/IEC 27006-1, not MD 5.

The starting point is the effective number of personnel doing work under your organization’s control within the ISMS scope. The 2024 edition tightened this: people count whether or not they are members of your organization, so contractors inside the scope are included. Auditors then adjust for complexity, sites, technology and outsourcing. In the ISO 27001 Stage 1 vs Stage 2 split of those days, Stage 1 typically absorbs a fifth to a quarter of the total.

Two consequences follow. Shrinking your scope genuinely reduces audit days and therefore cost — see our breakdown of the ISO 27001 certification timeline. And a quote that looks suspiciously cheap usually means the certification body was given a headcount that will not survive Stage 1.

ISO 27001 Stage 1 vs Stage 2: How Long Is the Gap?

There is no fixed interval in the standard. ISO/IEC 17021-1 requires the certification body to determine the interval, taking into account your need to resolve the areas of concern raised at Stage 1 and its own need to revise the arrangements for Stage 2. In the extreme, it can require all or part of Stage 1 to be repeated, which effectively cancels the Stage 2 booking.

Four to eight weeks is the common range in practice, and some certification bodies will allow considerably longer when significant remediation is needed. Do not treat any published figure as a rule; it is your certification body’s call, agreed with you.

The interval has to serve two purposes at once: long enough to close the Stage 1 concerns, and long enough to accumulate the operational records Stage 2 will sample. If you close the concerns in a week but have no incident log and no management review minutes, a short gap does you no favours.

ISO 27001 Stage 1 vs Stage 2: What Failure Looks Like

Findings at Stage 2 are classified as major or minor nonconformities. Your certification body must require you to analyse the cause and describe the corrections and corrective actions taken or planned, within a defined time. It then reviews what you submit and decides whether it needs an additional full audit, an additional limited audit, or simply documented evidence to be confirmed at a future audit.

Before a certification decision can be made, majors must be closed and the plan for correcting minors must have been reviewed and accepted. Minors do not block the certificate; they follow you to your next audit.

Now the deadline nobody warns you about. If the certification body cannot verify that you have implemented the corrections and corrective actions for any major nonconformity within six months of the last day of Stage 2, it must conduct another Stage 2 before it can recommend certification. Not a follow-up visit — another Stage 2, priced accordingly. That clock is the strongest practical argument for over-preparing.

ISO 27001 Stage 1 vs Stage 2: How to Prepare for Each

The preparation differs sharply, which is the whole point of the ISO 27001 Stage 1 vs Stage 2 distinction.

Before Stage 1

  • Finalise and approve the ISMS scope statement, including interfaces and dependencies with outsourced services.
  • Complete the risk assessment and risk treatment plan using a documented, repeatable method.
  • Complete the Statement of Applicability with a justification against every one of the 93 Annex A controls.
  • Run at least one full internal audit cycle and hold a documented management review — these are objectives of Stage 1, not Stage 2.
  • Confirm your legal, regulatory and contractual requirements register is current.
  • Give the auditor an accurate headcount for the ISMS scope, contractors included.

Before Stage 2

  • Close every Stage 1 area of concern in writing, with evidence attached.
  • Build an evidence pack organised by clause and control, so nothing is hunted for during the audit.
  • Ensure three months of records exist for the processes most likely to be sampled: access reviews, incidents, change management, supplier reviews, backup testing, training.
  • Brief control owners. Auditors interview the people who run the process, not the person who wrote the policy.
  • Rehearse the awkward questions — the leaver whose access lingered, the risk you accepted and never revisited.

If building that documentation set from scratch is the bottleneck, our ISO 27001 Toolkit ships 175 editable ISO 27001:2022 templates — ISMS policies, risk assessment, Statement of Applicability, internal audit checklists and the records auditors ask for — so you spend your time tailoring and operating the ISMS rather than drafting it.

After Stage 2: The Decision and the Three-Year Cycle

The audit team recommends; it does not decide. A competent person who did not perform the audit makes the certification decision. Certification then runs on a three-year cycle beginning at that decision, with surveillance audits in years one and two and recertification in year three. The first surveillance audit must take place no more than twelve months from the certification decision.

Surveillance audits are on-site but not full system audits. They look at internal audit and management review, actions on previous nonconformities, complaints, effectiveness against your objectives, operational control, changes, and your use of certification marks. Nothing in the ISO 27001 Stage 1 vs Stage 2 process is a one-off — see our guide to the ISO 27001 audit process and the overview of ISO 27001 certification.

Frequently Asked Questions

Can I skip Stage 1 if I already hold another ISO certificate?

No. ISO/IEC 17021-1 requires the initial certification audit to be conducted in two stages. Holding ISO 9001 may make Stage 1 quicker, and combined audits are possible, but the stage itself is not waived.

Can Stage 1 and Stage 2 be done remotely?

Stage 1 is frequently conducted off-site. Stage 2 is expected to take place at your site(s), though certification bodies may use information and communication technology for parts of it under IAF MD 4, and must record in the report how extensively ICT was used and how effective it was.

What happens if Stage 1 says I am not ready?

Stage 2 gets postponed while you remediate, and the certification body may require all or part of Stage 1 to be repeated. That costs additional audit days, but it is considerably cheaper than failing Stage 2 with majors.

Is the ISO 27001 Stage 1 vs Stage 2 fee charged separately?

Certification bodies normally quote both stages together as a single initial certification audit, priced by audit days. Repeat work is what costs extra: a repeated Stage 1, an additional limited audit to verify corrective actions, or a second Stage 2 triggered by the six-month rule.

Does the certificate date run from Stage 2 or from the decision?

From the certification decision. The three-year certification cycle begins with that decision, not with the last day of your Stage 2 audit, and your first surveillance audit is timed from it.

The Practical Takeaway

Reduced to a sentence, the ISO 27001 Stage 1 vs Stage 2 difference is design versus evidence — and the costliest mistake is arriving at Stage 1 with a complete document set but no operating history behind it. Policies are easy to produce. Twelve weeks of access reviews, incident tickets, a completed internal audit and a real management review are not.

Build the documentation early, start operating the ISMS the day it is approved, and treat the Stage 1 report as your Stage 2 exam paper. That is the whole of the ISO 27001 Stage 1 vs Stage 2 discipline. For the underlying requirements, ISO/IEC 27001 is available from ISO directly.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.