ISO 27001 Stage 1 vs Stage 2 audit: the two-part external assessment explained, what each stage checks, and how to walk into both prepared.
TL;DR
ISO 27001 certification is a two-stage external audit. Stage 1 is a documentation review that checks your ISMS is designed correctly and you are ready. Stage 2 is the deeper audit where the certification body tests whether your controls actually operate in practice.
Stage 1 catches paperwork gaps; Stage 2 catches reality gaps. Passing both earns a certificate valid for three years, with annual surveillance audits in between.
On this page
ISO 27001 Stage 1 vs Stage 2: the two-stage structure
ISO 27001 certification is not a single event. An accredited certification body assesses you in two distinct stages, usually a few weeks to a couple of months apart. The split exists so that documentation problems are caught early, before the deeper, more expensive assessment of whether your controls truly work.
Stage 1: the documentation and readiness review
Stage 1 is a review of your ISMS on paper. The auditor examines your documentation, your scope, your Statement of Applicability, your risk assessment, and your core policies, to confirm the system is designed correctly and you are genuinely ready for Stage 2. It is diagnostic, not pass-or-fail in the final sense: the output is usually a set of observations to address before the next stage.
Stage 2: testing whether your controls actually work
Stage 2 is where certification is genuinely decided. The auditor moves beyond documents to test whether your controls actually operate. They interview people, sample evidence, and check that what your Statement of Applicability claims is true in practice. This is where a paperwork-only ISMS falls apart and a real one proves itself.
Stage 1 vs Stage 2: the key differences
| What differs | Stage 1 audit | Stage 2 audit |
|---|---|---|
| What the auditor examines | Your ISMS documentation and design | Your controls operating in day-to-day practice |
| The question it answers | Is the system designed correctly and ready? | Does the system actually work as documented? |
| How the auditor works | Reviews policies, scope, SoA, and risk assessment | Interviews staff, samples evidence, tests controls |
| What you walk away with | A list of observations to fix before Stage 2 | The pass-or-fail certification decision |
| Time and depth | Shorter, lighter, mostly desk-based | Longer and deeper, evidence-driven |
How to prepare for each stage
For Stage 1
- Complete, current documentation
- A finished Statement of Applicability
- A real risk assessment behind it
For Stage 2
- Controls genuinely operating
- Evidence ready to sample
- People who can speak to their areas
How lean teams clear both stages
Startups tend to pass Stage 1 and stumble at Stage 2, because Stage 2 is where claims meet reality. If your controls only exist on paper, the evidence sampling exposes it. If they genuinely run and produce evidence, Stage 2 becomes straightforward.
Walk into Stage 2 with controls that already run.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the controls and collect the evidence in one place, so what your documents claim is what the auditor finds. No security team required.
Frequently asked questions
What is the difference between Stage 1 and Stage 2 ISO 27001 audits?
Stage 1 is a documentation and readiness review that checks your ISMS is designed correctly. Stage 2 is the deeper audit where the certification body tests whether your controls actually operate, through interviews and evidence sampling. Stage 2 decides certification.
What happens in an ISO 27001 Stage 1 audit?
The auditor reviews your documentation: scope, Statement of Applicability, risk assessment, and policies, to confirm the ISMS is designed properly and you are ready for Stage 2. It usually produces observations to address rather than a final decision.
What happens in a Stage 2 audit?
The auditor tests whether your controls work in practice, interviewing staff, sampling evidence, and checking that your Statement of Applicability is accurate. Passing Stage 2 earns a certificate valid for three years.
How far apart are Stage 1 and Stage 2?
Typically a few weeks to a couple of months, enough time to address any Stage 1 observations before the deeper Stage 2 assessment. The exact gap depends on your readiness and the certification body’s schedule.
Why do startups pass Stage 1 but struggle at Stage 2?
Because Stage 1 checks documentation, which is easier to prepare, while Stage 2 checks whether controls genuinely operate. A paperwork-only ISMS clears Stage 1 but fails when Stage 2 samples evidence that does not exist.

