Stage 1 and Stage 2 Audit

Stage 1 and Stage 2 audit process for ISO 27001 certification

ISO 27001 certification is awarded after a two-part audit. Stage 1 checks whether you are ready to be audited. Stage 2 checks whether the system actually works.

  • Glossary
  • ISO 27001

The short answer

Stage 1 is a documentation review. The auditor reads your scope, policies, risk assessment and Statement of Applicability, and confirms the management system exists on paper. Stage 2 is the certification audit proper: the auditor tests whether the controls you described are actually operating, by sampling evidence and interviewing people. Certification is decided after Stage 2.

Failing Stage 1 is not a failure in the usual sense. It produces a list of things to fix before Stage 2 is scheduled, which is exactly what it is designed to do.

What each stage covers

Stage 1 Documentation review Are you ready to be audited? Output: readiness findings weeks Stage 2 Certification audit Do the controls actually operate? Output: nonconformities Certificate Valid three years, audited annually Before Stage 1 you must already have run an internal audit and a management review Both are clause requirements. Arriving without them is the most common reason Stage 1 goes badly.
Swipe to see the full diagram. The two stages are usually weeks apart, long enough to close whatever Stage 1 surfaced.

Inside Stage 1

Mostly a desk exercise, often remote, typically a day or less for a small organisation. The auditor is confirming that the pieces exist and are coherent with each other.

The auditor looks atAnd checks
Scope statementIt is defined, defensible and matches what you actually do
Risk assessment and treatment planA method exists, has been applied, and produced a register
Statement of ApplicabilityEvery control has a decision and every exclusion has a justification
Policies and mandatory documentsThey are approved, current and reference each other correctly
Internal audit and management reviewBoth have happened at least once, with records

Inside Stage 2

Longer, more forensic, and evidence-driven. The auditor now samples: pick a joiner, show me the access request, the approval and the accounts created. Pick a change, show me the review. Pick a risk, show me the treatment and who accepted the residual.

Sampling

Records pulled at random across the period, not a curated set you prepared in advance.

Interviews

Staff asked what they do. Answers that contradict the policy become a finding.

Control walkthroughs

Systems shown live: access lists, logs, alerts, patch status, offboarding records.

Nonconformities and what they mean

FindingMeaningEffect on the certificate
Major nonconformityA requirement is absent, or a control has failed systemicallyBlocks certification until corrected and verified
Minor nonconformityA single lapse against a requirement that is otherwise metCertification can proceed with a corrective action plan
ObservationNot a breach, but a weakness worth addressingNone, though it often becomes a finding next year
Opportunity for improvementA suggestion from the auditorNone

The most common major

An SoA that marks a control applicable when nothing has actually been implemented. It is visible on paper, easy for the auditor to test, and hard to argue away. The same discipline applies to a gap analysis before any audit.

How Osto prepares you

Stage 2 is an evidence exercise, and evidence is a byproduct of controls that genuinely run. Osto deploys the technical controls behind the Annex A themes, access management, logging and monitoring, vulnerability testing, endpoint and cloud posture, and collects the records continuously rather than in a scramble before the audit date. Policy generation, risk register and ISO 27001 mapping sit in the same platform, so the documentation the Stage 1 auditor reads reflects the controls the Stage 2 auditor tests.

Free security assessment

Walk into Stage 2 with the evidence already there

Osto runs the controls and records the output continuously, so the audit is a review rather than a reconstruction.

Get a free security assessment Book a platform walkthrough

Policies, controls and evidence · ISO 27001 mapped · One platform, everything

Frequently asked questions

What is a Stage 1 and Stage 2 audit?

They are the two parts of an initial ISO 27001 certification audit. Stage 1 reviews documentation to confirm readiness. Stage 2 tests whether controls are operating, by sampling evidence and interviewing staff. Certification is decided after Stage 2.

What is the gap between Stage 1 and Stage 2?

Usually a few weeks to a couple of months, long enough to close whatever Stage 1 raised. Certification bodies generally require Stage 2 within six months of Stage 1, otherwise Stage 1 is repeated.

Can you fail a Stage 1 audit?

Stage 1 does not pass or fail in the usual sense. It produces findings that must be resolved before Stage 2 is scheduled. If the gaps are substantial the certification body will delay Stage 2 rather than proceed.

How long does a Stage 2 audit take?

For a small organisation with a narrow scope, typically two to four auditor days. Duration is set by accreditation rules based on headcount and scope complexity, not negotiated.

What happens after Stage 2?

Any nonconformities are closed with evidence, the certification body reviews the report independently, and the certificate is issued. It is valid for three years, with surveillance audits in years one and two.