{"id":727,"date":"2026-08-16T13:57:43","date_gmt":"2026-08-16T13:57:43","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=727"},"modified":"2026-08-16T13:57:43","modified_gmt":"2026-08-16T13:57:43","slug":"stage-1-and-stage-2-audit","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/stage-1-and-stage-2-audit\/","title":{"rendered":"Stage 1 and Stage 2 Audit"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: STAGE 1 AND STAGE 2 AUDIT\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">ISO 27001 certification is awarded after a two-part audit. Stage 1 checks whether you are ready to be audited. Stage 2 checks whether the system actually works.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">ISO 27001<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Stage 1 is a documentation review. The auditor reads your scope, policies, risk assessment and Statement of Applicability, and confirms the management system exists on paper. Stage 2 is the certification audit proper: the auditor tests whether the controls you described are actually operating, by sampling evidence and interviewing people. Certification is decided after Stage 2.<\/p>\n<\/div>\n\n<p>Failing Stage 1 is not a failure in the usual sense. It produces a list of things to fix before Stage 2 is scheduled, which is exactly what it is designed to do.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#compare\">What each stage covers<\/a><\/li>\n    <li><a href=\"#stage1\">Inside Stage 1<\/a><\/li>\n    <li><a href=\"#stage2\">Inside Stage 2<\/a><\/li>\n    <li><a href=\"#findings\">Nonconformities and what they mean<\/a><\/li>\n    <li><a href=\"#osto\">How Osto prepares you<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"compare\">What each stage covers<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Stage 1 reviews documentation, a gap period follows, then Stage 2 tests the controls and certification is decided.\">\n  <defs><marker id=\"stA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"40\" width=\"228\" height=\"112\" rx=\"16\" fill=\"#e9ecfa\"\/>\n  <text x=\"126\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#4a52a8\">Stage 1<\/text>\n  <text x=\"126\" y=\"95\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Documentation review<\/text>\n  <text x=\"126\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Are you ready to be audited?<\/text>\n  <text x=\"126\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#4a52a8\">Output: readiness findings<\/text>\n\n  <line x1=\"248\" y1=\"96\" x2=\"288\" y2=\"96\" stroke=\"#b9c0d4\" stroke-width=\"2.5\" marker-end=\"url(#stA)\"\/>\n  <text x=\"268\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">weeks<\/text>\n\n  <rect x=\"296\" y=\"40\" width=\"228\" height=\"112\" rx=\"16\" fill=\"#e3f0e9\"\/>\n  <text x=\"410\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#3a6f5d\">Stage 2<\/text>\n  <text x=\"410\" y=\"95\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Certification audit<\/text>\n  <text x=\"410\" y=\"115\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Do the controls actually operate?<\/text>\n  <text x=\"410\" y=\"136\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">Output: nonconformities<\/text>\n\n  <line x1=\"532\" y1=\"96\" x2=\"572\" y2=\"96\" stroke=\"#b9c0d4\" stroke-width=\"2.5\" marker-end=\"url(#stA)\"\/>\n\n  <rect x=\"580\" y=\"40\" width=\"168\" height=\"112\" rx=\"16\" fill=\"#1c267a\"\/>\n  <text x=\"664\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#ffffff\">Certificate<\/text>\n  <text x=\"664\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Valid three years,<\/text>\n  <text x=\"664\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">audited annually<\/text>\n\n  <rect x=\"12\" y=\"176\" width=\"736\" height=\"52\" rx=\"12\" fill=\"#f4f5fd\"\/>\n  <text x=\"380\" y=\"198\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Before Stage 1 you must already have run an internal audit and a management review<\/text>\n  <text x=\"380\" y=\"218\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Both are clause requirements. Arriving without them is the most common reason Stage 1 goes badly.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The two stages are usually weeks apart, long enough to close whatever Stage 1 surfaced.<\/figcaption>\n<\/figure>\n\n<h2 id=\"stage1\" class=\"c-sage\">Inside Stage 1<\/h2>\n\n<p>Mostly a desk exercise, often remote, typically a day or less for a small organisation. The auditor is confirming that the pieces exist and are coherent with each other.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>The auditor looks at<\/th><th>And checks<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Scope statement<\/td><td>It is defined, defensible and matches what you actually do<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/information-security-risk-assessment\/\">Risk assessment<\/a> and treatment plan<\/td><td>A method exists, has been applied, and produced a register<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a><\/td><td>Every control has a decision and every exclusion has a justification<\/td><\/tr>\n    <tr><td>Policies and mandatory documents<\/td><td>They are approved, current and reference each other correctly<\/td><\/tr>\n    <tr><td>Internal audit and management review<\/td><td>Both have happened at least once, with records<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"stage2\" class=\"c-apri\">Inside Stage 2<\/h2>\n\n<p>Longer, more forensic, and evidence-driven. The auditor now samples: pick a joiner, show me the access request, the approval and the accounts created. Pick a change, show me the review. Pick a risk, show me the treatment and who accepted the residual.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Sampling<\/p>\n    <p>Records pulled at random across the period, not a curated set you prepared in advance.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Interviews<\/p>\n    <p>Staff asked what they do. Answers that contradict the policy become a finding.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Control walkthroughs<\/p>\n    <p>Systems shown live: access lists, logs, alerts, patch status, offboarding records.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"findings\" class=\"c-plum\">Nonconformities and what they mean<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Finding<\/th><th>Meaning<\/th><th>Effect on the certificate<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Major nonconformity<\/strong><\/td><td>A requirement is absent, or a control has failed systemically<\/td><td>Blocks certification until corrected and verified<\/td><\/tr>\n    <tr><td><strong>Minor nonconformity<\/strong><\/td><td>A single lapse against a requirement that is otherwise met<\/td><td>Certification can proceed with a corrective action plan<\/td><\/tr>\n    <tr><td><strong>Observation<\/strong><\/td><td>Not a breach, but a weakness worth addressing<\/td><td>None, though it often becomes a finding next year<\/td><\/tr>\n    <tr><td><strong>Opportunity for improvement<\/strong><\/td><td>A suggestion from the auditor<\/td><td>None<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The most common major<\/p>\n  <p>An <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">SoA<\/a> that marks a control applicable when nothing has actually been implemented. It is visible on paper, easy for the auditor to test, and hard to argue away. The same discipline applies to a <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-gap-analysis\/\" target=\"_blank\" rel=\"noopener\">gap analysis<\/a> before any audit.<\/p>\n<\/div>\n\n<h2 id=\"osto\">How Osto prepares you<\/h2>\n\n<p>Stage 2 is an evidence exercise, and evidence is a byproduct of controls that genuinely run. Osto deploys the technical controls behind the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001-annex-a-controls\/\">Annex A<\/a> themes, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">access management<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">logging and monitoring<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">vulnerability testing<\/a>, endpoint and cloud posture, and collects the records continuously rather than in a scramble before the audit date. Policy generation, risk register and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> mapping sit in the same platform, so the documentation the Stage 1 auditor reads reflects the controls the Stage 2 auditor tests.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Walk into Stage 2 with the evidence already there<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto runs the controls and records the output continuously, so the audit is a review rather than a reconstruction.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Policies, controls and evidence &middot; ISO 27001 mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a Stage 1 and Stage 2 audit?<\/summary>\n  <p>They are the two parts of an initial ISO 27001 certification audit. Stage 1 reviews documentation to confirm readiness. Stage 2 tests whether controls are operating, by sampling evidence and interviewing staff. Certification is decided after Stage 2.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the gap between Stage 1 and Stage 2?<\/summary>\n  <p>Usually a few weeks to a couple of months, long enough to close whatever Stage 1 raised. Certification bodies generally require Stage 2 within six months of Stage 1, otherwise Stage 1 is repeated.<\/p>\n<\/details>\n\n<details>\n  <summary>Can you fail a Stage 1 audit?<\/summary>\n  <p>Stage 1 does not pass or fail in the usual sense. It produces findings that must be resolved before Stage 2 is scheduled. If the gaps are substantial the certification body will delay Stage 2 rather than proceed.<\/p>\n<\/details>\n\n<details>\n  <summary>How long does a Stage 2 audit take?<\/summary>\n  <p>For a small organisation with a narrow scope, typically two to four auditor days. Duration is set by accreditation rules based on headcount and scope complexity, not negotiated.<\/p>\n<\/details>\n\n<details>\n  <summary>What happens after Stage 2?<\/summary>\n  <p>Any nonconformities are closed with evidence, the certification body reviews the report independently, and the certificate is issued. It is valid for three years, with surveillance audits in years one and two.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> ISO 27001 &middot; ISMS &middot; Internal Audit &middot; Surveillance Audit &middot; Certification Body &middot; Statement of Applicability<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ISO 27001 certification is awarded after a two-part audit. Stage 1 checks whether you are ready to be audited. Stage\u2026<\/p>\n","protected":false},"author":8,"featured_media":728,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[280,279],"class_list":["post-727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-iso-27001-stage-1-audit","tag-stage-1-and-stage-2-audit"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=727"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/727\/revisions"}],"predecessor-version":[{"id":729,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/727\/revisions\/729"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/728"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}