Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Stage 1 vs stage 2 audit comparison chart for ISO 27001 certification

Stage 1 vs Stage 2 Audit: The Complete 2026 ISO 27001 Guide

The stage 1 vs stage 2 audit split is not something your certification body invented to bill you twice. It is a requirement of ISO/IEC 17021-1:2015, clause 9.3.1.1, which says the initial certification audit of a management system shall be conducted in two stages. Most companies going for ISO 27001 prepare for both as if they were one long inspection, and that is exactly how good programs fail. The two audits ask different questions. Stage 1 asks whether your information security management system exists and is ready to be tested. Stage 2 asks whether it actually runs.

Here is the stage 1 vs stage 2 audit comparison in full: what each stage examines, where the clause requirements come from, how many days to budget, and what an auditor is realistically looking for at each visit.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

Stage 1 vs Stage 2 Audit: The Short Comparison

 Stage 1Stage 2
ClauseISO/IEC 17021-1 9.3.1.2ISO/IEC 17021-1 9.3.1.3
Question askedIs the ISMS designed, documented and ready?Is the ISMS implemented and effective?
LocationClient must be told of any “on site” activities; commonly run remotelyTakes place at site
Primary evidenceDocumented information, scope, SoA, risk assessment, internal audit and management review plansRecords, logs, tickets, interviews, observed practice, performance data
OutputDocumented conclusions on stage 1 objectives and readiness for stage 2, plus areas of concernAudit findings feeding the certification decision
Worst realistic outcomeStage 2 is postponed, or stage 1 is repeated in whole or in partMajor nonconformity; no certificate until it is closed
Can it be failed?Not formally — but it can stop stage 2 from happeningYes, in the practical sense that certification is withheld

What a Stage 1 Audit Actually Checks

Most of the confusion in a stage 1 vs stage 2 audit comes from treating stage 1 as a formality. Clause 9.3.1.2.2 lists seven objectives for it, and they are worth reading as a checklist rather than a description:

  • review the client’s management system documented information;
  • evaluate the client’s preparedness for stage 2;
  • review the client’s status and understanding regarding requirements of the standard;
  • obtain necessary information regarding the scope, including sites, processes and equipment used, levels of controls established, and applicable statutory and regulatory requirements;
  • review the allocation of stage 2 details with the client;
  • provide a focus for planning stage 2;
  • evaluate if the internal audits and management reviews are being planned and performed.

Two of those catch people out. The fourth means your scope statement is examined, not just accepted — an auditor who cannot work out which sites, systems and legal obligations sit inside the boundary will say so. The seventh means internal audit and management review are in scope at stage 1, not deferred. A company with 40 written policies and no completed internal audit is not ready, and stage 1 is where that surfaces.

For ISO 27001 specifically, stage 1 is where the Statement of Applicability earns its keep. The SoA is mandatory under clause 6.1.3 and has to account for all 93 Annex A controls across the four themes — 37 organizational, 8 people, 14 physical and 34 technological. An SoA that marks controls applicable without a justification traceable to the risk assessment is the single most common stage 1 area of concern. Our guide to the ISO 27001 Statement of Applicability covers how to build that traceability.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

What a Stage 2 Audit Actually Checks

Clause 9.3.1.3 is blunt about the purpose of stage 2: to evaluate the implementation, including effectiveness, of the client’s management system. It also states that stage 2 takes place at site, and sets out six areas the audit includes:

  • information and evidence of conformity to all requirements of the standard;
  • performance monitoring, measuring, reporting and reviewing against key performance objectives and targets;
  • performance regarding meeting applicable statutory, regulatory and contractual requirements;
  • operational control of the client’s processes;
  • internal auditing and management review;
  • management responsibility for the client’s policies.

Notice that internal audit and management review appear in both halves of the stage 1 vs stage 2 audit. At stage 1 the auditor checks they are planned and being performed. At stage 2 they check the output — whether findings were raised, actioned and closed, and whether top management actually reviewed anything. That double exposure is why a rushed internal audit programme is the most expensive shortcut in the whole project. Our walkthrough of the ISO 27001 internal audit explains what evidence each pass needs to leave behind.

The word “effectiveness” is the real difference between the two stages. At stage 1 an access control policy that says reviews happen quarterly is conforming documentation. At stage 2 the same policy with no completed review records is a nonconformity.

Stage 1 vs Stage 2 Audit Duration: How Many Days to Budget

For ISO 27001, audit time is not set by your certification body’s commercial judgement. It is governed by ISO/IEC 27006-1:2024, Annex C, which is the renumbered and expanded successor to Annex B of the 2015 edition. The table is keyed on the number of persons doing work under the organization’s control within the ISMS scope — not company headcount, which is the biggest lever most buyers have and never use.

Persons in ISMS scopeInitial audit days (stage 1 + stage 2 combined)
1–105
11–156
16–257
26–458.5
46–6510

Those are auditor days for both stages together, not per stage. In practice a certification body allocates roughly a quarter to a third of the total to stage 1, so a 25-person company on seven days typically sees one and a half to two days of stage 1 and five to five and a half days of stage 2. Treat that split as typical rather than mandated — ISO/IEC 17021-1 does not prescribe it, and the allocation is agreed with you under objective (e) of clause 9.3.1.2.2.

Annex C also introduces the concept of persons performing certain identical activities (section C.2.1) and sets out how to determine the initial number of persons in section C.3.4. Where a large group performs the same activity, the square root of that head count, rounded up, can be used instead of the full number. For a 200-seat support centre with one job role, that is the difference between a two-week audit and a one-week audit. Separate sections now cover multi-site calculations (C.6) and scope extensions (C.7). For the money side of this, see our breakdown of ISO 27001 certification cost.

How Long Is the Gap Between Stage 1 and Stage 2?

After duration, this is the most common stage 1 vs stage 2 audit planning question, and there is no prescribed interval. Clause 9.3.1.2.4 requires the certification body to determine the gap between stage 1 and stage 2 taking account of your need to resolve areas of concern identified during stage 1, and its own need to revise the stage 2 arrangements. Typical practice is two to eight weeks.

The same clause carries the sanction that surprises people: where stage 1 conclusions are poor, the certification body may need to repeat all or part of stage 1, which cancels the planned stage 2. That is the closest thing to failing stage 1 that exists. It is also why “areas of concern” is not a soft phrase — clause 9.3.1.2.3 allows them to be raised as nonconformities during stage 2 if you have not dealt with them.

Long gaps also age your evidence. A stage 1 held against a risk assessment you then revise means the stage 2 auditor is testing a different system from the one they were briefed on. Keep the gap short and the change log clean.

Remote or On Site? What Changed by 2026

This is the part of most competitors’ stage 1 vs stage 2 audit guidance that is now out of date. The 2015 edition of ISO/IEC 27006 required a certification body to get accreditation body approval when remote auditing exceeded 30% of planned on-site audit time. ISO/IEC 27006-1:2024, published on 31 March 2024, removed that requirement. Remote audit requirements moved to section 9.1.3.3, and section 9.4.3.2 now requires the extent and effectiveness of remote auditing to be stated in the audit report. Where a client has few or no physical relevant sites, the audit report and the certification document itself must say that the client’s activities are conducted remotely.

This matters on a date. Under the transition arrangements published by accreditation bodies, including Standards Council of Canada bulletin 2024-18, 31 March 2026 was the deadline for every accredited certification body to complete the move to ISO/IEC 27006-1:2024 and use it for all clients. If you are scoping an audit now, the 2024 rules are the rules.

The practical effect: stage 1 is routinely remote, and a cloud-native company with no server room can often run much of stage 2 remotely too. What has not changed is clause 9.3.1.3’s wording that stage 2 takes place at site, so get your certification body’s methodology in writing before you sign.

After Stage 2: What the Certificate Actually Starts

A stage 1 vs stage 2 audit is assessed as one exercise, not two. Clause 9.3.1.4 requires the audit team to analyse all information and evidence gathered during stage 1 and stage 2 together, review the findings and agree the conclusions. A separate competent person or panel then makes the certification decision. The certificate is dated from that decision, not from the last day of stage 2.

From there the clock in ISO/IEC 17021-1 takes over. The first surveillance audit following initial certification shall not be more than 12 months from the certification decision date, and surveillance audits run at least once each calendar year except in recertification years. Surveillance audits are on-site audits but are not necessarily full system audits. Our posts on the ISO 27001 surveillance audit and the ISO 27001 recertification audit cover what each one samples.

How to Prepare for a Stage 1 vs Stage 2 Audit Without Rework

Stage 1 vs stage 2 audit preparation is genuinely different work, and conflating the two is what creates the last-minute scramble.

For stage 1, have a defensible scope statement, a completed risk assessment, an SoA that justifies every one of the 93 controls, the mandatory clause 4 to 10 documented information, and at least one completed internal audit and management review. Documents that exist but are unapproved are the commonest finding.

For stage 2, work backwards from records. Every policy that promises a frequency needs that many completed records. Access reviews, supplier reviews, backup restore tests, incident records, awareness training completion, risk treatment plan progress — these are what stage 2 samples, and they cannot be manufactured on the day.

One note on edition: the 2013 to 2022 transition closed on 31 October 2025, so every audit now runs against ISO/IEC 27001:2022, including the free Amendment 1:2024 climate action change to clauses 4.1 and 4.2. If any of your documentation still references the 2013 Annex A numbering, fix it before stage 1.

If you are building the documentation set from scratch, the ISO 27001 Toolkit ships 165 templates mapped to the 2022 clause structure and all 93 Annex A controls, including the SoA, risk assessment, internal audit programme and management review pack that stage 1 asks for. It is $99, which is less than an hour of most auditors’ time.

Stage 1 vs Stage 2 Audit FAQ

The five questions buyers ask most often before booking a stage 1 vs stage 2 audit.

Can you fail a stage 1 audit?

Not in the formal sense — stage 1 produces conclusions on readiness, not a pass or fail. But clause 9.3.1.2.4 lets the certification body repeat all or part of stage 1 and cancel the planned stage 2, which has the same effect on your timeline.

How long between stage 1 and stage 2?

ISO/IEC 17021-1 sets no fixed interval. The certification body decides it based on how long you need to resolve areas of concern. Two to eight weeks is typical; longer gaps risk your stage 1 evidence going stale.

Is stage 1 included in the audit price?

Yes. A stage 1 vs stage 2 audit is quoted as one initial certification audit — the ISO/IEC 27006-1 Annex C day figures are for both stages combined, so a quote covering “the initial certification audit” should already include both. Ask for the day split in writing so you can plan internal availability.

Do we need a full year of records before stage 2?

No, but you need at least one full cycle of every activity your own documentation commits to, plus one internal audit and one management review. A control that claims quarterly reviews needs completed evidence of a review, not a calendar invite.

Can stage 2 be done remotely?

Partly, and more than before. ISO/IEC 27006-1:2024 removed the 30% remote-audit approval threshold, but clause 9.3.1.3 of ISO/IEC 17021-1 still says stage 2 takes place at site. Expect a hybrid, and get your certification body’s position documented up front.

The short version of the stage 1 vs stage 2 audit question: stage 1 tests your design, stage 2 tests your discipline. If you are still reading your own policies for the first time a week before the auditor arrives, you are preparing for the wrong stage. Start with our complete guide to ISO 27001 certification for the whole path from scope to certificate.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.