ISO 27001 Stage 1 vs Stage 2: what each audit checks
Both are defined in ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1, the standard every accredited certification body is assessed against. Stage 1 has seven objectives and Stage 2 has six things it must audit. Everything below is quoted from those two lists.
The certification audit is the one event in this whole process that you book, pay for and cannot redo cheaply. It comes in two parts, and most descriptions of it stop at “Stage 1 is documents, Stage 2 is evidence”. That is roughly right and it leaves out the parts that actually catch people.
Stage 1 and Stage 2, side by side
| Stage 1 | Stage 2 | |
|---|---|---|
| Its purpose, in the standard's words | Determine preparedness for Stage 2 and gather what is needed to plan it | “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” |
| What it mostly looks at | Documents, scope, and whether the machinery exists | Evidence that the system actually operates as documented |
| Where | Can be partly off-site; the standard notes that on-site work helps | “shall take place at the site(s) of the client” — which can include remote access to electronic sites |
| Internal audit and management review | Checks they are being planned and performed — objective (g) | Audits them directly as part of the system — item (e) |
| Formal audit plan | Not required for Stage 1 | Yes |
| What it produces | Documented conclusions on readiness, including areas that could become nonconformities | Audit findings and conclusions that feed the certification decision |
| What can go wrong | Stage 2 postponed or cancelled | Nonconformities that must be closed before certification |
| Counts towards the audit-day total | Yes | Yes |
The row most readers miss is the fourth. Your internal audit and your management review are examined twice: once at Stage 1 to check they exist, and again at Stage 2 as part of the system itself. They are the two activities people most often leave until the last month, and they sit on the critical path of both visits.
What Stage 1 is required to achieve
BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text sets out the objectives of Stage 1. They are not a checklist the auditor may choose from — they are what Stage 1 is for.
| Stage 1 is to | |
|---|---|
| a | review the client’s management system documented information |
| b | evaluate the client’s site-specific conditions and to undertake discussions with the client’s personnel to determine the preparedness for stage 2 |
| c | review the client’s status and understanding regarding requirements of the standard, in particular with respect to the identification of key performance or significant aspects, processes, objectives and operation of the management system |
| d | obtain necessary information regarding the scope of the management system, including: the client’s site(s); processes and equipment used; levels of controls established (particularly in case of multisite clients); applicable statutory and regulatory requirements |
| e | review the allocation of resources for stage 2 and agree the details of stage 2 with the client |
| f | provide a focus for planning stage 2 by gaining a sufficient understanding of the client’s management system and site operations in the context of the management system standard or other normative document |
| g | evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2 |
Objective (a): your documented information
This is the part everyone expects. The auditor reads what you have written — scope, policy, risk assessment, risk treatment, the Statement of Applicability — and forms a view on whether it describes a management system or a set of documents.
Objective (d): scope, including the legal requirements
The auditor must obtain information about your scope including your sites, processes and equipment, the level of controls, and “applicable statutory and regulatory requirements”. That last item is easy to overlook: if you are in a regulated sector, expect to be asked what those requirements are and how your management system knows about them.
Scope is also the input that set your audit fee. The day count comes from the persons doing work in scope — in the words of the ISMS rules, “The total number of persons doing work under the organization’s control for all shifts within the scope of the certification is the starting point for determination of audit time.” If Stage 1 finds the scope is not what you described when you were quoted, the numbers move.
Objective (g): the one that decides whether Stage 2 happens
Stage 1 must “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2.”
Read that as two tests. The first is mechanical: has an internal audit happened, and has a management review happened? The second is judgement: does the system look implemented enough to be worth auditing? A management system stood up in the previous six weeks tends to pass the first and fail the second, because there has not been time for it to produce the evidence Stage 2 will look for.
What comes out of Stage 1
ISO/IEC 17021-1:2015 clause 9.3.1.2.3 requires that “Documented conclusions with regard to fulfilment of the stage 1 objectives and the readiness for stage 2 shall be communicated to the client, including identification of any areas of concern that could be classified as a nonconformity during stage 2.”
That document is the most useful thing you will receive from the whole audit, and it is often treated as a formality. It tells you, in advance, what the auditor expects to raise at Stage 2. Anything on it that you close before Stage 2 is a nonconformity you do not receive.
Stage 1 can stop the audit
“The client shall be informed that the results of stage 1 may lead to postponement or cancellation of stage 2.” This is the sentence behind most missed certification dates. If a contract has a date on it, plan backwards from Stage 2, and leave room for Stage 1 to find something.
The gap between the two visits
There is no fixed interval. The standard says: “In determining the interval between stage 1 and stage 2, consideration shall be given to the needs of the client to resolve areas of concern identified during stage 1.”
What decides how long it is
Two things, and only one of them is yours. How much Stage 1 found, and how long you need to close it, is yours. The certification body's availability is not, and it is frequently the binding constraint — the second visit is scheduled around their auditors, not your deadline.
What happens if something changes in between
“If any significant changes which would impact the management system occur, the certification body shall consider the need to repeat all or part of stage 1.” A restructure, an acquisition, a new site, or a change to what the scope covers can reopen part of Stage 1. Telling the certification body early costs less than discovering it at Stage 2.
What Stage 2 is required to audit
BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text: “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” It must include the auditing of at least the following:
| Stage 2 shall include the auditing of | |
|---|---|
| a | information and evidence about conformity to all requirements of the applicable management system standard or other normative documents |
| b | performance monitoring, measuring, reporting and reviewing against key performance objectives and targets |
| c | the client’s management system ability and its performance regarding meeting of applicable statutory, regulatory and contractual requirements |
| d | operational control of the client’s processes |
| e | internal auditing and management review |
| f | management responsibility for the client’s policies |
Item (a): all requirements, not a sample of them
Conformity to all requirements of the standard. The auditor samples evidence, but the coverage is the whole of clauses 4 to 10. This is why a management system that is strong on technical controls and thin on governance still produces findings.
Item (c): the legal, regulatory and contractual requirements
Objective (d) at Stage 1 gathered what they are; item (c) at Stage 2 audits whether the system actually meets them. For a supplier in a regulated sector this is where the second framework above ISO 27001 — the sector requirement — meets the audit.
Item (e): the internal audit and the management review, again
At Stage 1 the question was whether they were happening. At Stage 2 they are audited as part of the system: whether the internal audit was competent and independent enough to find things, and whether the management review actually considered what it is meant to consider and decided anything. An internal audit that found nothing and a review whose minutes record no decisions are both findings waiting to happen.
Item (f): management responsibility
The auditor will want to talk to management, not only to whoever runs the ISMS. If the leadership team cannot describe the information security policy or its objectives, that is evidence against item (f) however good the documents are.
Can the audit be remote?
Partly. Stage 1 does not require a formal plan and can be partly off-site. Stage 2 must take place at your site(s), but the standard notes that ““On-site” audits can include remote access to electronic site(s) that contain(s) information that is relevant to the audit of the management system.” and that where any part is done by electronic means the certification body must ensure the evidence is sufficient for an informed decision.
For a fully cloud-hosted company this matters: much of the evidence genuinely lives in electronic systems. What it does not remove is the physical controls, which still have to be reasoned about for wherever people actually work.
How many days, and what is not in the number
Stage 1 and Stage 2 come out of a single figure — the initial certification audit time in the published audit-day table. At 25 people in scope that is 7 days across both stages, before adjustment. The split between the two stages is the certification body's decision.
Two rules from the ISMS audit requirements are worth knowing when you read the quote. On-site time is protected: planning and report writing should not typically reduce on-site audit time to less than 70% of the calculated time. And “Auditor travel time is not included in this calculation and is additional to the audit time referenced in the chart.” A quote that folds travel into the day count, or a plan with very little time on site, is worth a question. Both come from ISO/IEC 27006:2015/Amd 1:2020; the current edition is ISO/IEC 27006-1:2024, which we have not been able to read, so we cite the text we opened.
We cannot audit anything and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. Which is why this page can tell you that the most expensive part of Stage 1 is usually the thing nobody prepared: the internal audit and the management review, not the documents.
Preparing, in the order the auditor will look
- Run the internal audit and hold the management review, and keep the records. Objective (g) at Stage 1, item (e) at Stage 2. Your certification body cannot do the internal audit for you — see why.
- Make the scope unambiguous, including sites and the legal and regulatory requirements that apply to it. Objective (d).
- Check the documented information describes what actually happens. Stage 2 will test it against practice.
- Brief management. Item (f) is audited by talking to them.
- Read the Stage 1 conclusions as a work list and close what you can before Stage 2.
Where this fits
- The whole certification process
- The Statement of Applicability
- What the audit costs
- Choosing a certification body
- Consultants
Common questions
What is the difference between Stage 1 and Stage 2 in ISO 27001?
Stage 1 decides whether you are ready to be audited; Stage 2 is the audit. ISO/IEC 17021-1 gives Stage 1 seven objectives, most of which are about reviewing your documented information, understanding your scope and checking that your internal audits and management reviews are being planned and performed. It defines Stage 2's purpose as “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” Put simply: Stage 1 reads what you say you do, and Stage 2 checks that you do it.
How long is the gap between Stage 1 and Stage 2?
The standard does not set a number of days. It says that “In determining the interval between stage 1 and stage 2, consideration shall be given to the needs of the client to resolve areas of concern identified during stage 1.” So the interval is driven by how much Stage 1 found and by your certification body's availability. A Stage 1 with nothing of concern can be followed quickly; one with significant findings needs time for you to close them, and the body may revise its plans for Stage 2 as a result.
Can you fail Stage 1?
Not in the sense of receiving a failing grade, but it can stop the audit. The standard requires that “The client shall be informed that the results of stage 1 may lead to postponement or cancellation of stage 2.” Stage 1 produces documented conclusions on your readiness, including areas of concern that could be classified as nonconformities at Stage 2. Treat those as a to-do list, not as a verdict.
Is Stage 1 done on site?
It can be partly remote. The standard notes that carrying out at least part of Stage 1 at your premises can help achieve its objectives, which is a recommendation rather than a requirement, and Stage 1 does not need a formal audit plan. Stage 2, by contrast, is required to take place at your site(s) — though the standard also notes that on-site audits can include remote access to electronic sites that hold information relevant to the audit.
Do the internal audit and management review have to happen before Stage 1?
They have to be planned and performed before you will get through Stage 1. One of Stage 1's seven objectives is to “evaluate if the internal audits and management reviews are being planned and performed”, and Stage 2 then audits “internal auditing and management review” directly. A management system in which neither has yet happened is, by the standard's own definition, not ready for Stage 2.
Who carries out Stage 1 and Stage 2?
Your certification body, and nobody else. Your consultant cannot do either: under BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text the certification body is barred from providing consultancy, and the audit must be independent of whoever built the system. The auditor themselves must have prior ISMS audit experience of at least 10 on-site days within the last 5 years.
How many days do Stage 1 and Stage 2 take together?
They come out of one number: the initial certification audit time in the published audit-day table, which starts from the persons doing work in scope. At 25 people that is 7 days in total across both stages, before any adjustment for sites or complexity. How that total is split between the two stages is the certification body's decision and is not fixed by the table.
What happens if something changes between Stage 1 and Stage 2?
The standard anticipates it: “If any significant changes which would impact the management system occur, the certification body shall consider the need to repeat all or part of stage 1.” A reorganisation, an acquisition or a significant change of scope between the two visits can mean part of Stage 1 is done again. Tell the certification body early rather than at Stage 2.
Sources cited on this page
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27006:2015/Amd 1:2020, Requirements for bodies providing audit and certification of information security management systems — Amendment 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Stage 1 booked, and not sure you are ready?
Say where you are up to. The internal audit and the management review are the two things a consultancy can help you get done in time.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.