Understand the difference between the two certification audit stages and what to have ready for each.
Updated 4 Mar 2026
Two Stages Explained
ISO 27001 certification involves a two-stage audit process. Understanding the difference helps you prepare efficiently.
Stage 1: Documentation Review
Purpose
Assess whether your ISMS documentation is ready for a full audit.
What Auditors Review
•ISMS scope document
•Information Security Policy
•Risk assessment methodology and results
•Statement of Applicability
•Risk treatment plan
•Key procedures and policies
•Internal audit programme
•Management review records (if available)
Outcome
•Confirmation of readiness for Stage 2
•Identification of areas of concern
•Agreed Stage 2 audit plan
Timeline
Usually 1–2 days on-site or remote.
Stage 2: Implementation Audit
Purpose
Verify that your ISMS is implemented and effective — not just documented.
What Auditors Do
•Interview staff at all levels
•Review evidence of control implementation
•Observe actual security practices
•Test that processes match documentation
•Verify corrective actions from Stage 1 findings
Outcome
•Certification recommendation (or not)
•Nonconformities requiring correction
•Observations for improvement
Timeline
Usually 3–5 days depending on scope and size.
Gap Between Stages
Typically 2–8 weeks between Stage 1 and Stage 2. Use this time to:
•Address any Stage 1 findings
•Complete any remaining implementations
•Conduct final internal audit
•Run a management review
•Brief staff on what to expect
Key Advice
Stage 1 is about documentation; Stage 2 is about reality. Make sure they match.
Related Modules
Standard Controls
Documents
Corrective Actions
Calendar
Related Controls / Clauses
9.2
9.3
10.1
26 practitioner guides — included free with your workspace
27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.