ISO 27001 certification involves two distinct audits, separated by a gap of two to six weeks. Both are mandatory. They have different purposes, different evidence expectations, and different consequences when findings emerge. Understanding the difference is essential to passing both efficiently and to avoiding the late-stage surprise that costs organisations time, money, and certification timeline.
This article sets out what each stage covers, what auditors actually look for, the common nonconformities that emerge, and how senior practitioners avoid them.
What Stage 1 actually is
Stage 1 is the documentation audit. It is sometimes called the readiness review or desktop audit. The auditor examines the design of your Information Security Management System on paper. They are checking whether your ISMS, as documented, conforms to the requirements of ISO 27001:2022. They are not yet checking whether it operates in practice.
The auditor will review your information security policy and approval evidence. They will read your scope statement against Clause 4.3 requirements. They will examine your context analysis covering Clauses 4.1 and 4.2. They will look at your risk methodology, your risk register, and your risk treatment plan. They will read your Statement of Applicability and check that exclusions are justified. They will examine your roles and responsibilities documentation, your competence and awareness records, and your internal audit programme. They will confirm that you have evidence of at least one internal audit and one management review.
For most small to mid-sized organisations, Stage 1 takes one day. Larger or more complex organisations may take two days. The audit can be conducted on-site, remotely, or in hybrid form depending on the certification body's approach.
At the end of Stage 1, the auditor produces a report. The report identifies areas of concern, opportunities for improvement, and any gaps that would need to be closed before Stage 2. Different certification bodies handle Stage 1 findings differently. Some classify them as observations only and reserve formal nonconformity classification for Stage 2. Others issue minor or major nonconformities at Stage 1 itself.
Either way, the practical implication is the same. If material gaps are identified in Stage 1, you have to close them before Stage 2 can proceed. The gap between Stage 1 and Stage 2 is usually four to six weeks for this reason. Some certification bodies move faster, two to three weeks, but Stage 2 must occur within six months of Stage 1 or the Stage 1 audit may need to be repeated.
What Stage 2 actually is
Stage 2 is the implementation audit. It is sometimes called the certification audit or main audit. This is where certification is decided. The auditor examines whether your ISMS operates in practice as it is documented to operate.
The auditor will conduct staff interviews across roles. They will sample evidence of control operation, not just documentation of control existence. They will review audit trails, system logs, incident reports, training records, supplier security evidence, and management review minutes. They will test whether the ISMS produces evidence of ongoing effectiveness, not just evidence of one-time setup.
For small to mid-sized organisations, Stage 2 takes two to three days. Larger organisations can take a week or longer. The audit is usually on-site, although remote and hybrid approaches are increasingly common.
The ISMS must have been operating for at least three months before Stage 2, with documented evidence showing controls have been in use over time. This is non-negotiable. An ISMS that was implemented two weeks before Stage 2 has not produced operational evidence and will not pass.
At the end of Stage 2, the auditor produces a final audit report classifying findings as major nonconformities, minor nonconformities, or opportunities for improvement. Certification depends on resolution of nonconformities according to their classification.
Major versus minor nonconformities
The classification matters and is worth understanding precisely.
A major nonconformity indicates the absence or total breakdown of a required element of the management system. It signals systemic failure that affects the ability of the ISMS to achieve its intended results. Examples include the absence of a documented risk methodology, an incomplete Statement of Applicability with unjustified exclusions, no evidence of internal audit having been conducted, or no evidence of management review. Major nonconformities must be closed with corrective action and verified evidence before certification can be granted. Most certification bodies allow 30 to 90 days for major nonconformity closure, after which a follow-up audit or evidence review verifies remediation. Failure to close in the agreed timeframe means certification cannot be granted.
A minor nonconformity indicates a single instance of non-compliance that does not indicate systemic failure. The ISMS, as a whole, still works. Examples include a policy that has not been reviewed within its stated review period, an internal audit report missing one signature, or a single supplier without documented security evidence. Minor nonconformities require a corrective action plan and evidence of correction, but the certificate can be issued before remediation is fully verified. Closure typically follows at the next surveillance audit.
An opportunity for improvement is not a nonconformity. It is an observation that the auditor thinks the ISMS could be enhanced. There is no requirement to act on opportunities for improvement, although they are usually worth tracking.
A note on scoring. Some certification bodies treat groups of minor nonconformities against the same requirement as a major nonconformity. Three minors against Clause 9.2 internal audit, for instance, can collectively constitute a major nonconformity for systemic internal audit failure. This is at the auditor's discretion and worth being aware of.
The most common nonconformities
Drawing on a wide pattern of UK ISO 27001 audits, the recurring nonconformities cluster into five themes.
Statement of Applicability gaps. Failing to justify excluded controls, missing controls from the 2022 revision (particularly the 11 new controls), or treating the SoA as a list rather than a justified position document. Auditors specifically test SoA quality because it is one of the most common implementation shortcuts.
Risk assessment methodology issues. No documented methodology, methodology not consistently applied, missing evidence that risks have been reviewed and approved by management, or risk treatment plan that does not link to risk register entries.
Internal audit programme weakness. No documented audit programme, audits conducted but evidence not preserved, audit reports not addressing all clauses or controls, or auditor competence not documented.
Management review thin evidence. Management review held but minutes not retained, inputs not covering all required topics, outputs not driving documented action items, or no evidence of follow-up between reviews.
Supplier security evidence. Supplier register exists but per-supplier security assessments not documented, contracts not including security requirements, or no evidence of ongoing supplier security monitoring.
These five clusters account for the substantial majority of nonconformities surfaced in Stage 2 audits. An organisation that addresses all five thoroughly during implementation rarely surfaces major nonconformities at Stage 2.
How senior practitioners prepare
Three preparation approaches separate efficient certification from rushed certification.
A practice run before Stage 2. An internal audit conducted as if it were the certification audit, by someone other than the implementer, against the same evidence the auditor will see. This surfaces issues at the cheapest moment to fix them.
An evidence pack rather than scattered evidence. ISO 27001 auditors do not have time to assemble your evidence for you. An organised evidence pack indexed by clause and control reduces audit time and reduces the risk of evidence being missed.
A closing the loop discipline. Every internal audit finding tracked through to corrective action and verification. Every management review action tracked through to completion. Auditors specifically test loop closure because it is the strongest evidence that the ISMS is alive rather than performing for the audit.
Closing thought
Stage 1 and Stage 2 are not pass-or-fail exams. They are calibration points. Organisations that treat them as performance moments rather than as evidence of an ongoing ISMS produce certificates that survive surveillance audits but do not improve security. Organisations that build a substantive ISMS pass both stages cleanly because the audit is then incidental to work that was already happening.
Goldline Consultancy is led by an ISO 27001 Lead Implementer (PECB) and ISO 42001 Lead Implementer and Lead Auditor (PECB), SC-cleared, and delivers ISO 27001 implementation as a fixed-scope engagement that includes Stage 1 and Stage 2 readiness preparation. Take our free ISMS maturity self-assessment or book an ISO 27001 diagnostic call.
