What the certification body checks in each stage, what you have to show, and what happens if the auditor raises a nonconformity.
An ISO 27001 stage 1 audit checks whether your information security management system is documented well enough to be audited. An ISO 27001 stage 2 audit checks whether that system is actually operating, by sampling real records against ISO/IEC 27001:2022 clauses 4 to 10 and every Annex A control you declared applicable. Stage 1 cannot certify you. The certification decision follows stage 2. Both are performed by an accredited certification body, and both are required for initial certification.
An ISO 27001 stage 1 audit is a readiness review. The certification body reads your documented information and decides whether a stage 2 audit can usefully be planned. Under ISO/IEC 17021-1 clause 9.3, the stage 1 auditor reviews your documented information, evaluates your scope, checks that you understand the requirements of the standard, and confirms that internal audits and management reviews have been planned and performed.
An ISO 27001 stage 1 audit is usually delivered remotely as a desk review and needs only one or two people from your side. It ends in a stage 1 report listing areas of concern: things that are missing, thin or contradictory, and that would be raised as nonconformities if they were still like that at stage 2. That report is the most useful document you will get in the whole process, because it tells you what the auditor intends to look at next.
An ISO 27001 stage 2 audit is the certification audit proper. Where stage 1 asks whether the ISMS is designed, stage 2 asks whether it is running. The auditor samples evidence that your controls operated: access review records with dates and approvers, joiner and leaver tickets, change records, supplier reviews, incident records and training records. The auditor also interviews the people who own those controls, because a policy nobody can describe is a finding.
An ISO 27001 stage 2 audit covers the management system clauses 4 to 10 of ISO/IEC 27001:2022 and every Annex A control your Statement of Applicability marks as applicable. ISO/IEC 27001:2022 has 93 Annex A controls across four themes: organisational, people, physical and technological. Stage 2 ends with a report of any nonconformities and a recommendation. The certification decision itself is made by someone at the certification body who was not on the audit team, which is an impartiality requirement of ISO/IEC 17021-1.
The ISO 27001 stage 1 audit is a document exercise, so the checklist is short and specific. Have these ready and complete before the day:
The two items that most often derail an ISO 27001 stage 1 audit are the internal audit and the management review. Both are mandatory clauses, both have to have happened before certification and neither can be faked after the fact.
An ISO 27001 stage 2 auditor asks for proof that a control ran on a real date, for a real system, approved by a real person. Expect sampling rather than a complete file review: the auditor picks a quarter, a system or a handful of employees and follows the trail. Typical requests include a user access review for a named system, the offboarding record for a named leaver, a change record for a named production change, the last supplier security review, and a restore test that proves the backup worked.
Screenshots without dates, policies without approval records and spreadsheets that cannot be tied to a source system are the usual causes of findings. Our guide to what auditors look for in evidence covers what separates evidence that passes first time from evidence that gets sent back.
ISO/IEC 17021-1 does not fix a number. The certification body sets the interval between the ISO 27001 stage 1 and stage 2 audits based on what stage 1 found, and it has to leave you enough time to resolve the areas of concern that stage 1 raised. In practice that is commonly a few weeks to a few months, and it is longer when stage 1 exposes something structural such as an unclear scope or a missing internal audit.
The interval also has an upper end. If enough time passes that your ISMS has materially changed since stage 1, the certification body can require the stage 1 audit to be repeated. Ask your certification body for its rule in writing before you book, and treat the stage 1 report as a fixed to-do list with dates rather than a set of suggestions.
Almost every first ISO 27001 stage 2 audit raises something. A nonconformity is not a failure, it is a classification, and the classification determines whether your certificate is delayed.
| Major nonconformity | Minor nonconformity | |
|---|---|---|
| What it means | A requirement of ISO/IEC 27001 is not met at all, or a failure raises significant doubt that the ISMS delivers its intended results. | An isolated lapse in an otherwise working control, which does not undermine the ISMS as a whole. |
| Effect on certification | The certificate is not issued until the correction is made and the certification body has verified it. | Certification can normally proceed once the certification body accepts your corrective action plan. |
| What you have to do | Correct the issue, do a root cause analysis, take corrective action, and submit evidence to the certification body. | Do a root cause analysis and submit a corrective action plan with named owners and dates. |
| When it is verified | Before the certification decision, sometimes at a follow up visit. | Usually at the next surveillance audit. |
An ISO 27001 certificate is valid for three years, and the audits do not stop when it is issued. The first surveillance audit has to happen no later than 12 months after the certification decision date, the second within 12 months of the first, and a full recertification audit before the three year certificate expires. Surveillance audits are shorter than stage 2 and sample part of the ISMS rather than all of it, but they always revisit your internal audit, your management review and any findings from last time.
| Audit | When it has to happen | What it covers |
|---|---|---|
| Stage 1 | Interval to stage 2 set by the certification body | Documented information and readiness |
| Stage 2 | Once the stage 1 areas of concern are addressed | Clauses 4 to 10 and every applicable Annex A control |
| Certification decision | After nonconformities are cleared | Certificate issued, valid for 3 years |
| Surveillance audit 1 | No later than 12 months after the certification decision date | A sample of the ISMS, always including clauses 9.2 and 9.3 |
| Surveillance audit 2 | Within 12 months of surveillance audit 1 | A different sample, plus previous findings |
| Recertification | Before the 3 year certificate expires | The whole ISMS again, in the manner of a stage 2 audit |
Preparation for an ISO 27001 stage 1 audit is document work, and preparation for an ISO 27001 stage 2 audit is evidence work. Treat them as two different jobs. Get the scope, policy, risk assessment, Statement of Applicability, internal audit and management review finished and dated for stage 1. For stage 2, work control by control and record which evidence proves each one and where it lives, so the auditor is never waiting on you.
CertAssist is built for exactly that second job. CertAssist lays out every ISO 27001 control on one board, gives you editable policy and evidence templates instead of a blank page, tracks the evidence each control needs, handles the Statement of Applicability, and gives your auditor read only access to review it all in place. CertAssist does not connect to your systems, which means there is nothing to integrate and nothing to breach. As of September 2026, CertAssist costs US$225 per month on a limited-time launch offer, normally US$375 per month, or US$3,999 per year.
CertAssist is not the right choice for everyone. CertAssist is not a certification body and cannot audit or certify you: only an accredited certification body, listed by a member of the International Accreditation Forum, can do that. Nor does CertAssist collect evidence automatically, so if you run a large estate and want continuous monitoring pulled from your cloud and identity provider, an integrated platform will suit you better. And no tool of any kind reduces the number of audit days your certification body sets under ISO/IEC 27006-1.
How long does an ISO 27001 audit take?
The certification body calculates audit days under ISO/IEC 27006-1, based on the effective number of people doing work within your scope, then splits those days between stage 1 and stage 2, with stage 2 taking the larger share. A small organisation is measured in days rather than weeks. The elapsed calendar time is longer, because it includes the interval between the two stages and the time to clear nonconformities.
Who can perform an ISO 27001 audit?
Only a certification body accredited for ISO/IEC 27001 can perform a certification audit and issue a certificate, and its accreditation comes from a national accreditation body that belongs to the International Accreditation Forum. A consultant can help you prepare and can run your clause 9.2 internal audit, but the same organisation is not permitted to consult on your ISMS and then certify it, because ISO/IEC 17021-1 requires the certification body to be impartial.
How much does an ISO 27001 audit cost?
The certification body quotes a fee based on the audit days it calculates for your scope and headcount, so the number comes from a quote rather than a price list. Ask two or three accredited certification bodies for written quotes covering stage 1, stage 2, both surveillance audits and recertification, so you are comparing the full three year cycle. Our ISO 27001 certification cost guide breaks down the other components.
What is a surveillance audit in ISO 27001?
A surveillance audit is a shorter audit that happens between certification and recertification to confirm your ISMS is still working. The first one has to happen no later than 12 months after the certification decision date, and the second within 12 months of that. A surveillance audit samples part of the ISMS rather than all of it, but it reliably revisits your internal audit, your management review, and the corrective actions from any previous findings.
What is in an ISO 27001 stage 1 audit report?
An ISO 27001 stage 1 audit report records the auditor's view of your scope, your documented information, and your readiness for stage 2. It lists areas of concern, which are gaps that would be raised as nonconformities if they were still open at stage 2, and it usually confirms the proposed stage 2 dates and the audit plan. It does not grant certification and it does not contain nonconformities, because nonconformities are raised at stage 2.
CertAssist lays out every ISO 27001 control, gives you editable policy and evidence templates, handles the Statement of Applicability, and lets your auditor review it all in one place, for US$225 a month on the launch offer.
See pricing FrameworksFlat $375 a month, or $3,999 a year (12 months for the price of 11). All prices in USD.