ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different
Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.
The one-paragraph difference
Stage 1 asks: is your ISMS designed and documented? — the auditor reviews scope, policies, risk assessment, Statement of Applicability, internal audit, and management review records. Stage 2 asks: does the ISMS actually operate? — interviews, sampling, and evidence that controls work in practice. Stage 1 finds paperwork gaps; Stage 2 finds reality gaps.
Side-by-side
| Stage 1 | Stage 2 | |
|---|---|---|
| Tests | Documentation and design readiness | Operating effectiveness of the ISMS |
| Duration | Typically 1–2 days | 2–10+ days by size and scope |
| Format | Often remote; document review + interviews | Usually on-site; interviews, sampling, site visits |
| Output | Findings to fix before Stage 2 — no certificate | Recommendation for certification (or not) |
| Gap between stages | Typically 2–8 weeks to remediate Stage 1 findings | |
What sinks companies at Stage 1
- No internal audit or management review. The standard requires them before certification — Stage 1 checks they happened.
- Sloppy Statement of Applicability. Unjustified control exclusions get flagged immediately.
- Scope that doesn't match reality. If the scope statement and the actual business don't line up, everything downstream wobbles.
What sinks companies at Stage 2
- Evidence that doesn't exist. "We do that" with no records is a finding. Every control needs evidence it operated.
- Staff who can't describe the process. Auditors interview operators, not just the security lead.
- Unclosed Stage 1 findings. Minor findings ignored after Stage 1 routinely become major ones at Stage 2.
The common mistake
Treating Stage 1 as a formality and rushing into Stage 2 with open findings. The fix window between stages exists for a reason — use it. A clean Stage 1 makes Stage 2 shorter, calmer, and cheaper.
Frequently asked
Can Stage 1 and Stage 2 happen back to back?
Sometimes, but it's risky: with no remediation window, any Stage 1 finding becomes a Stage 2 problem. Most CBs recommend 2–8 weeks between them.
Does Stage 1 have to be on-site?
Often not — many CBs run Stage 1 remotely. Stage 2 is usually on-site, especially for first certifications.
Related reading
Get quotes from accredited CBs
One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.
More guides
How to Choose an ISO 27001 Certification Body: 8 Questions to Ask
The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.
ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?
Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.
How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)
ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.