iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 Stage 1 vs Stage 2: what each audit checks

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 11 min read
5 primary sources cited on this page. How we check what is on this site
The short version Stage 1 reads it. Stage 2 checks it happens.

Both are defined in ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1, the standard every accredited certification body is assessed against. Stage 1 has seven objectives and Stage 2 has six things it must audit. Everything below is quoted from those two lists.

The certification audit is the one event in this whole process that you book, pay for and cannot redo cheaply. It comes in two parts, and most descriptions of it stop at “Stage 1 is documents, Stage 2 is evidence”. That is roughly right and it leaves out the parts that actually catch people.

Stage 1 and Stage 2, side by side

The two stages of the initial certification audit
Stage 1Stage 2
Its purpose, in the standard's wordsDetermine preparedness for Stage 2 and gather what is needed to plan it“The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.”
What it mostly looks atDocuments, scope, and whether the machinery existsEvidence that the system actually operates as documented
WhereCan be partly off-site; the standard notes that on-site work helps“shall take place at the site(s) of the client” — which can include remote access to electronic sites
Internal audit and management reviewChecks they are being planned and performed — objective (g)Audits them directly as part of the system — item (e)
Formal audit planNot required for Stage 1Yes
What it producesDocumented conclusions on readiness, including areas that could become nonconformitiesAudit findings and conclusions that feed the certification decision
What can go wrongStage 2 postponed or cancelledNonconformities that must be closed before certification
Counts towards the audit-day totalYesYes

The row most readers miss is the fourth. Your internal audit and your management review are examined twice: once at Stage 1 to check they exist, and again at Stage 2 as part of the system itself. They are the two activities people most often leave until the last month, and they sit on the critical path of both visits.

What Stage 1 is required to achieve

BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text sets out the objectives of Stage 1. They are not a checklist the auditor may choose from — they are what Stage 1 is for.

The objectives of Stage 1 (ISO/IEC 17021-1:2015 clause 9.3.1.2.2), verbatim
Stage 1 is to
areview the client’s management system documented information
bevaluate the client’s site-specific conditions and to undertake discussions with the client’s personnel to determine the preparedness for stage 2
creview the client’s status and understanding regarding requirements of the standard, in particular with respect to the identification of key performance or significant aspects, processes, objectives and operation of the management system
dobtain necessary information regarding the scope of the management system, including: the client’s site(s); processes and equipment used; levels of controls established (particularly in case of multisite clients); applicable statutory and regulatory requirements
ereview the allocation of resources for stage 2 and agree the details of stage 2 with the client
fprovide a focus for planning stage 2 by gaining a sufficient understanding of the client’s management system and site operations in the context of the management system standard or other normative document
gevaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2

Objective (a): your documented information

This is the part everyone expects. The auditor reads what you have written — scope, policy, risk assessment, risk treatment, the Statement of Applicability — and forms a view on whether it describes a management system or a set of documents.

The auditor must obtain information about your scope including your sites, processes and equipment, the level of controls, and “applicable statutory and regulatory requirements”. That last item is easy to overlook: if you are in a regulated sector, expect to be asked what those requirements are and how your management system knows about them.

Scope is also the input that set your audit fee. The day count comes from the persons doing work in scope — in the words of the ISMS rules, “The total number of persons doing work under the organization’s control for all shifts within the scope of the certification is the starting point for determination of audit time.” If Stage 1 finds the scope is not what you described when you were quoted, the numbers move.

Objective (g): the one that decides whether Stage 2 happens

Stage 1 must “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2.”

Read that as two tests. The first is mechanical: has an internal audit happened, and has a management review happened? The second is judgement: does the system look implemented enough to be worth auditing? A management system stood up in the previous six weeks tends to pass the first and fail the second, because there has not been time for it to produce the evidence Stage 2 will look for.

What comes out of Stage 1

ISO/IEC 17021-1:2015 clause 9.3.1.2.3 requires that “Documented conclusions with regard to fulfilment of the stage 1 objectives and the readiness for stage 2 shall be communicated to the client, including identification of any areas of concern that could be classified as a nonconformity during stage 2.”

That document is the most useful thing you will receive from the whole audit, and it is often treated as a formality. It tells you, in advance, what the auditor expects to raise at Stage 2. Anything on it that you close before Stage 2 is a nonconformity you do not receive.

Stage 1 can stop the audit

“The client shall be informed that the results of stage 1 may lead to postponement or cancellation of stage 2.” This is the sentence behind most missed certification dates. If a contract has a date on it, plan backwards from Stage 2, and leave room for Stage 1 to find something.

The gap between the two visits

There is no fixed interval. The standard says: “In determining the interval between stage 1 and stage 2, consideration shall be given to the needs of the client to resolve areas of concern identified during stage 1.”

What decides how long it is

Two things, and only one of them is yours. How much Stage 1 found, and how long you need to close it, is yours. The certification body's availability is not, and it is frequently the binding constraint — the second visit is scheduled around their auditors, not your deadline.

What happens if something changes in between

“If any significant changes which would impact the management system occur, the certification body shall consider the need to repeat all or part of stage 1.” A restructure, an acquisition, a new site, or a change to what the scope covers can reopen part of Stage 1. Telling the certification body early costs less than discovering it at Stage 2.

What Stage 2 is required to audit

BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text: “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” It must include the auditing of at least the following:

What Stage 2 must include (ISO/IEC 17021-1:2015 clause 9.3.1.3), verbatim
Stage 2 shall include the auditing of
ainformation and evidence about conformity to all requirements of the applicable management system standard or other normative documents
bperformance monitoring, measuring, reporting and reviewing against key performance objectives and targets
cthe client’s management system ability and its performance regarding meeting of applicable statutory, regulatory and contractual requirements
doperational control of the client’s processes
einternal auditing and management review
fmanagement responsibility for the client’s policies

Item (a): all requirements, not a sample of them

Conformity to all requirements of the standard. The auditor samples evidence, but the coverage is the whole of clauses 4 to 10. This is why a management system that is strong on technical controls and thin on governance still produces findings.

Objective (d) at Stage 1 gathered what they are; item (c) at Stage 2 audits whether the system actually meets them. For a supplier in a regulated sector this is where the second framework above ISO 27001 — the sector requirement — meets the audit.

Item (e): the internal audit and the management review, again

At Stage 1 the question was whether they were happening. At Stage 2 they are audited as part of the system: whether the internal audit was competent and independent enough to find things, and whether the management review actually considered what it is meant to consider and decided anything. An internal audit that found nothing and a review whose minutes record no decisions are both findings waiting to happen.

Item (f): management responsibility

The auditor will want to talk to management, not only to whoever runs the ISMS. If the leadership team cannot describe the information security policy or its objectives, that is evidence against item (f) however good the documents are.

Can the audit be remote?

Partly. Stage 1 does not require a formal plan and can be partly off-site. Stage 2 must take place at your site(s), but the standard notes that ““On-site” audits can include remote access to electronic site(s) that contain(s) information that is relevant to the audit of the management system.” and that where any part is done by electronic means the certification body must ensure the evidence is sufficient for an informed decision.

For a fully cloud-hosted company this matters: much of the evidence genuinely lives in electronic systems. What it does not remove is the physical controls, which still have to be reasoned about for wherever people actually work.

How many days, and what is not in the number

Stage 1 and Stage 2 come out of a single figure — the initial certification audit time in the published audit-day table. At 25 people in scope that is 7 days across both stages, before adjustment. The split between the two stages is the certification body's decision.

Two rules from the ISMS audit requirements are worth knowing when you read the quote. On-site time is protected: planning and report writing should not typically reduce on-site audit time to less than 70% of the calculated time. And “Auditor travel time is not included in this calculation and is additional to the audit time referenced in the chart.” A quote that folds travel into the day count, or a plan with very little time on site, is worth a question. Both come from ISO/IEC 27006:2015/Amd 1:2020; the current edition is ISO/IEC 27006-1:2024, which we have not been able to read, so we cite the text we opened.

Work out your day count

We cannot audit anything and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. Which is why this page can tell you that the most expensive part of Stage 1 is usually the thing nobody prepared: the internal audit and the management review, not the documents.

Preparing, in the order the auditor will look

  1. Run the internal audit and hold the management review, and keep the records. Objective (g) at Stage 1, item (e) at Stage 2. Your certification body cannot do the internal audit for you — see why.
  2. Make the scope unambiguous, including sites and the legal and regulatory requirements that apply to it. Objective (d).
  3. Check the documented information describes what actually happens. Stage 2 will test it against practice.
  4. Brief management. Item (f) is audited by talking to them.
  5. Read the Stage 1 conclusions as a work list and close what you can before Stage 2.

Where this fits

Common questions

What is the difference between Stage 1 and Stage 2 in ISO 27001?

Stage 1 decides whether you are ready to be audited; Stage 2 is the audit. ISO/IEC 17021-1 gives Stage 1 seven objectives, most of which are about reviewing your documented information, understanding your scope and checking that your internal audits and management reviews are being planned and performed. It defines Stage 2's purpose as “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” Put simply: Stage 1 reads what you say you do, and Stage 2 checks that you do it.

How long is the gap between Stage 1 and Stage 2?

The standard does not set a number of days. It says that “In determining the interval between stage 1 and stage 2, consideration shall be given to the needs of the client to resolve areas of concern identified during stage 1.” So the interval is driven by how much Stage 1 found and by your certification body's availability. A Stage 1 with nothing of concern can be followed quickly; one with significant findings needs time for you to close them, and the body may revise its plans for Stage 2 as a result.

Can you fail Stage 1?

Not in the sense of receiving a failing grade, but it can stop the audit. The standard requires that “The client shall be informed that the results of stage 1 may lead to postponement or cancellation of stage 2.” Stage 1 produces documented conclusions on your readiness, including areas of concern that could be classified as nonconformities at Stage 2. Treat those as a to-do list, not as a verdict.

Is Stage 1 done on site?

It can be partly remote. The standard notes that carrying out at least part of Stage 1 at your premises can help achieve its objectives, which is a recommendation rather than a requirement, and Stage 1 does not need a formal audit plan. Stage 2, by contrast, is required to take place at your site(s) — though the standard also notes that on-site audits can include remote access to electronic sites that hold information relevant to the audit.

Do the internal audit and management review have to happen before Stage 1?

They have to be planned and performed before you will get through Stage 1. One of Stage 1's seven objectives is to “evaluate if the internal audits and management reviews are being planned and performed”, and Stage 2 then audits “internal auditing and management review” directly. A management system in which neither has yet happened is, by the standard's own definition, not ready for Stage 2.

Who carries out Stage 1 and Stage 2?

Your certification body, and nobody else. Your consultant cannot do either: under BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text the certification body is barred from providing consultancy, and the audit must be independent of whoever built the system. The auditor themselves must have prior ISMS audit experience of at least 10 on-site days within the last 5 years.

How many days do Stage 1 and Stage 2 take together?

They come out of one number: the initial certification audit time in the published audit-day table, which starts from the persons doing work in scope. At 25 people that is 7 days in total across both stages, before any adjustment for sites or complexity. How that total is split between the two stages is the certification body's decision and is not fixed by the table.

What happens if something changes between Stage 1 and Stage 2?

The standard anticipates it: “If any significant changes which would impact the management system occur, the certification body shall consider the need to repeat all or part of stage 1.” A reorganisation, an acquisition or a significant change of scope between the two visits can mean part of Stage 1 is done again. Tell the certification body early rather than at Stage 2.

Sources cited on this page

  1. BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
  2. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  3. ISO/IEC 27006:2015/Amd 1:2020, Requirements for bodies providing audit and certification of information security management systems — Amendment 1
  4. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
  5. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Stage 1 booked, and not sure you are ready?

Say where you are up to. The internal audit and the management review are the two things a consultancy can help you get done in time.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now