Stage 1 Versus Stage 2 Audit
In ISO/IEC 27001 certification, the initial certification audit is conducted in two stages, as required by ISO/IEC 17021-1 and ISO/IEC 27006. Stage 1 is mainly a documentation review and readiness assessment. The auditor checks whether the organization's information security management system (ISMS… In ISO/IEC 27001 certification, the initial certification audit is conducted in two stages, as required by ISO/IEC 17021-1 and ISO/IEC 27006. Stage 1 is mainly a documentation review and readiness assessment. The auditor checks whether the organization's information security management system (ISMS) has been designed in line with the standard. Key activities include reviewing the ISMS scope, information security policy, risk assessment and risk treatment methodology, Statement of Applicability, internal audit results, and management review records. The auditor also learns about the organization's context, sites, processes, and legal and regulatory requirements. They confirm that the ISMS has been operating long enough to generate evidence. Stage 1 is often performed partly on-site and identifies areas of concern that could become nonconformities in Stage 2. The output is a Stage 1 report that confirms readiness and informs Stage 2 planning, including resources, sampling, and timing. Stage 2 is the main evaluation of implementation and effectiveness. It is conducted on-site, or remotely where justified, and determines whether the organization actually operates its ISMS as documented and whether its controls are effective. Auditors interview personnel, observe activities, examine records, and sample evidence across clauses 4 to 10 and the Annex A controls selected in the Statement of Applicability. They verify that risks are treated, objectives are monitored, incidents are managed, and continual improvement is taking place. Findings are graded as major nonconformities, minor nonconformities, or opportunities for improvement. The key difference is focus. Stage 1 asks whether the system is designed correctly and ready for audit. Stage 2 asks whether it is implemented effectively and conforms in practice. Significant Stage 1 concerns should be resolved before Stage 2, and the interval between the stages should allow time for corrections. Stage 2 leads to a certification recommendation by the audit team leader once any major nonconformities have been closed and correction plans for minor nonconformities have been accepted.
Stage 1 Versus Stage 2 Audit: A Complete Guide for ISO/IEC 27001 Lead Auditors
Introduction
The initial certification audit of an Information Security Management System (ISMS) against ISO/IEC 27001 is carried out in two distinct parts: the Stage 1 audit and the Stage 2 audit. This two-stage structure is defined in ISO/IEC 17021-1 (requirements for bodies providing audit and certification of management systems), and ISO/IEC 27006 adds ISMS-specific requirements. Every ISO/IEC 27001 Lead Auditor candidate must understand the difference between the two stages, because exam questions frequently test the purpose, timing, outputs and boundaries of each.
Why It Is Important
1. Risk reduction for the certification body: Stage 1 confirms that the organisation is actually ready to be audited. This avoids wasting time and money on a full Stage 2 audit that would fail.
2. Proper planning: Stage 1 gives the audit team the information it needs to plan Stage 2 well. This includes the scope, sites, processes, risks, Statement of Applicability (SoA), staffing and logistics.
3. Fairness to the auditee: The organisation gets early warning of areas of concern. It can then correct them before the evaluation that decides certification.
4. Credibility of certification: The two-stage approach separates checking design and readiness from checking implementation and effectiveness. This makes the certification decision robust and defensible.
5. Exam relevance: Questions often present a scenario and ask whether an activity belongs in Stage 1 or Stage 2. They may also ask what happens when Stage 1 reveals problems, or whether Stage 1 may be done remotely or off-site.
What It Is
Stage 1 Audit is a readiness and documentation-focused audit. Its main objectives, per ISO/IEC 17021-1 clause 9.3.1.2, are to:
- Audit the client's management system documented information.
- Evaluate the client's site-specific conditions and hold discussions with personnel to determine readiness for Stage 2.
- Review the client's status and understanding of the standard's requirements, especially key performance indicators, significant aspects, processes, objectives and operation of the management system.
- Obtain information about the scope, processes, locations, and related statutory and regulatory requirements (for example, data protection law).
- Review the allocation of resources for Stage 2 and agree the details of Stage 2 with the client.
- Focus planning for Stage 2 by understanding the management system and site operations.
- Evaluate whether internal audits and management review are being planned and performed.
- Judge whether the level of implementation confirms the client is ready for Stage 2.
For ISO/IEC 27001 specifically, Stage 1 typically reviews these items:
- ISMS scope (clause 4.3)
- Information security policy (5.2)
- Risk assessment and risk treatment methodology and results (6.1.2, 6.1.3, 8.2, 8.3)
- Statement of Applicability (6.1.3 d)
- Information security objectives (6.2)
- Evidence that internal audit (9.2) and management review (9.3) are planned or performed
Stage 2 Audit is the implementation and effectiveness audit. Per ISO/IEC 17021-1 clause 9.3.1.3, its purpose is to evaluate the implementation, including effectiveness, of the client's management system. It normally takes place at the client's site(s) and includes at least:
- Information and evidence about conformity to all requirements of the standard.
- Performance monitoring, measuring, reporting and reviewing against key objectives and targets.
- The management system's ability and performance in meeting legal, regulatory and contractual requirements.
- Operational control of the client's processes, meaning the Annex A controls as implemented.
- Internal auditing and management review.
- Management responsibility for the client's policies.
How It Works
Step 1: Application and contract. The certification body reviews the application and determines audit time, often using ISO/IEC 27006 tables. It then appoints the audit team.
Step 2: Stage 1 audit.
- Usually shorter than Stage 2.
- For ISO/IEC 27001, ISO/IEC 27006 generally expects at least part of Stage 1 to be on-site, unless justified. In practice, the documentation review may be done off-site or remotely.
- The auditor examines ISMS documentation, interviews key personnel and may tour facilities.
- The output is a Stage 1 report. It documents conclusions, including any areas of concern that could be classified as nonconformities during Stage 2.
- Stage 1 findings are normally not raised as formal major or minor nonconformities. They are communicated as concerns or issues to resolve before Stage 2.
Step 3: Decision on readiness.
- If the organisation is ready, Stage 2 is scheduled. Timing must allow the client to resolve the areas of concern, but not be so long that Stage 1 information becomes outdated. ISO/IEC 17021-1 states that the certification body must consider the time needed to resolve concerns.
- If the organisation is not ready, Stage 2 may be postponed. Stage 1 may be partly or fully repeated if significant changes occur.
Step 4: Stage 2 audit planning. The audit plan is prepared using Stage 1 information. It covers sampling of sites and processes, control areas, interviews and timing. It is communicated to the auditee.
Step 5: Stage 2 audit execution.
- Opening meeting.
- Collection and verification of evidence through interviews, observation and records review.
- Testing that controls in the SoA are implemented and effective.
- Findings are graded as major nonconformities, minor nonconformities or opportunities for improvement.
- Closing meeting and audit report.
Step 6: Certification decision. Majors need correction and corrective action verified, usually within a defined timeframe. Minors require an accepted corrective action plan. An independent person or committee within the certification body, not the audit team, makes the certification decision.
Key Comparison
- Focus: Stage 1 covers design, documentation and readiness. Stage 2 covers implementation and effectiveness.
- Question asked: Stage 1 asks whether the ISMS exists and is ready to be audited. Stage 2 asks whether the ISMS works and conforms to all requirements.
- Location: Stage 1 may be partly off-site or remote. Stage 2 is normally on-site.
- Findings: Stage 1 raises areas of concern. Stage 2 raises graded nonconformities.
- Output: Stage 1 produces a readiness conclusion and Stage 2 planning input. Stage 2 produces a recommendation for or against certification.
- Sampling depth: Stage 1 is limited. Stage 2 is extensive, with evidence-based sampling.
Common Pitfalls and Nuances
- Stage 1 is part of the certification audit. It is not consultancy, so auditors must not advise on how to implement fixes.
- A pre-audit or gap analysis is optional, separate from Stage 1 and not part of certification.
- Stage 1 and Stage 2 can sometimes be carried out back-to-back. The risk is that unresolved Stage 1 concerns lead directly to Stage 2 nonconformities.
- An ISMS lacking at least one completed internal audit and management review cycle is typically not ready for Stage 2. Expect exam questions on this.
- Surveillance audits (years 1 and 2) and recertification audits do not have a Stage 1. A recertification audit may include a Stage 1 only when there have been significant changes.
Exam Tips: Answering Questions on Stage 1 Versus Stage 2 Audit
1. Use the keyword test. Words like readiness, documentation review, scope confirmation, planning Stage 2, understanding the context, areas of concern signal Stage 1. Words like implementation, effectiveness, evidence of operation, sampling records, nonconformities, certification recommendation signal Stage 2.
2. Remember the purpose of Stage 1. Stage 1 is about deciding whether to proceed to Stage 2 and how to plan it. If an option says Stage 1 grants certification or raises major nonconformities, it is likely wrong.
3. Watch for scenario traps. Suppose a scenario says the risk assessment has not been done or the SoA does not exist. The correct response at Stage 1 is usually to record it as an area of concern and conclude that the organisation is not ready, so Stage 2 is postponed. Do not proceed and raise a major nonconformity.
4. Know the evidence types. Reviewing the policy, scope and SoA is Stage 1. Interviewing staff about how they apply access control, then checking logs, is Stage 2.
5. Remember the timing rule. The interval between stages must allow concerns to be resolved without making Stage 1 information obsolete. If significant changes occur, Stage 1 may need repeating.
6. Remember who decides. The audit team recommends. The certification body's independent decision-makers decide.
7. Do not confuse a pre-audit with Stage 1. A pre-audit is optional and informal. Stage 1 is mandatory for initial certification.
8. Use the right standards. ISO/IEC 17021-1 defines the two stages and ISO/IEC 27006 adds ISMS specifics. ISO 19011 provides general auditing guidance but does not define Stage 1 and 2 for certification.
9. Answer essay questions in a structure. Define each stage, state its objectives, then give examples of activities, outputs and the decision between stages. Close with why the separation matters, such as efficiency, planning and credibility.
10. Stay independent. If a question asks how to respond when the auditee requests advice on fixing a Stage 1 concern, the correct answer is to decline consultancy. Explain the requirement only.
Quick Memory Aid
Stage 1 = Is it there and are you Ready? (Review, Readiness, Roadmap for Stage 2)
Stage 2 = Does it Work? (Walk the floor, Witness evidence, Weigh conformity)
Summary
Stage 1 confirms that the ISMS is designed, documented and mature enough to be audited, and it informs Stage 2 planning. Stage 2 verifies, through on-site evidence, that the ISMS is implemented and effective against every requirement of ISO/IEC 27001. Mastering the purpose, activities, outputs and decision points of each stage will help you answer both multiple-choice and scenario-based exam questions confidently.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!