GuideCertification Preparation

Preparing for Stage 1 vs Stage 2 Audit

Understand the difference between the two certification audit stages and what to have ready for each.

Updated 4 Mar 2026

Two Stages Explained

ISO 27001 certification involves a two-stage audit process. Understanding the difference helps you prepare efficiently.

Stage 1: Documentation Review

Purpose

Assess whether your ISMS documentation is ready for a full audit.

What Auditors Review

ISMS scope document
Information Security Policy
Risk assessment methodology and results
Statement of Applicability
Risk treatment plan
Key procedures and policies
Internal audit programme
Management review records (if available)

Outcome

Confirmation of readiness for Stage 2
Identification of areas of concern
Agreed Stage 2 audit plan

Timeline

Usually 1–2 days on-site or remote.

Stage 2: Implementation Audit

Purpose

Verify that your ISMS is implemented and effective — not just documented.

What Auditors Do

Interview staff at all levels
Review evidence of control implementation
Observe actual security practices
Test that processes match documentation
Verify corrective actions from Stage 1 findings

Outcome

Certification recommendation (or not)
Nonconformities requiring correction
Observations for improvement

Timeline

Usually 3–5 days depending on scope and size.

Gap Between Stages

Typically 2–8 weeks between Stage 1 and Stage 2. Use this time to:

Address any Stage 1 findings
Complete any remaining implementations
Conduct final internal audit
Run a management review
Brief staff on what to expect

Key Advice

Stage 1 is about documentation; Stage 2 is about reality. Make sure they match.

Related Modules

Standard Controls
Documents
Corrective Actions
Calendar

Related Controls / Clauses

9.2
9.3
10.1

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.