Stage 1 and Stage 2 Audit Preparation Guide
Prepares the team for what the certification body will actually ask, sample and challenge in each audit stage.
Available soon
- Format
- Word
- Size
- 64 KB
- Length
- 19 pages
- Version
- 1.0
- Updated
What's inside
- Purpose
- Who this guide is for
- The two stages at a glance
- Stage 1: documentation and readiness
- Stage 2: controls in operation
- How findings are graded
- Timelines
- Worked example: the EXAMPLE firm's audit plan
- Worked example: a nonconformity written up
- Preparing people for interviews
- The evidence room
- After certification
- Common mistakes
- Readiness checklist
- Related documents
- Adapting this guide
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This guide prepares [[Organisation Name]] for the two audits that lead to ISO/IEC 27001 certification: what the certification body does in each stage, what it is likely to ask for, sample and challenge, how it grades what it finds, and how to prepare the evidence and the people. It closes with a readiness checklist to work through before each stage.
It follows the ISO 27001 Implementation Methodology & Project Plan, whose Phase 6 is the two audits, and uses the same rules (IS-01 to IS-10) and dates. It describes common practice. Each certification body works to its own procedures within the rules it is accredited under, so treat what follows as what to expect and confirm the details with your own body.
Guidance — delete before approval
Replace every interval in [[double brackets]] with the one your certification body gives you in its proposal or audit plan. Ask for them in writing when you book.
Who this guide is for
Reader | What to read |
|---|---|
ISMS manager ([[e.g. Head of Information Security]]) | All of it. You will organise both audits, run the evidence room and brief everyone else. |
Top management and the executive sponsor | 'The two stages at a glance', 'How findings are graded' and 'Preparing people for interviews'. The auditor will interview you. |
Control owners | 'What the auditor samples', the Annex A table for your controls, and 'Preparing people for interviews'. |
Internal auditor | 'How findings are graded' and the readiness checklist: your audit is the rehearsal. |
The two stages at a glance
Certification is two audits by the same certification body. Stage 1 asks whether the ISMS is designed and ready; Stage 2 asks whether it works.
Stage 1 | Stage 2 | |
|---|---|---|
Question | Is the ISMS documented, and is the organisation ready for Stage 2? | Is the ISMS operating as documented, and is it effective? |
What the auditor does | Reviews the documentation; confirms the scope and the sites; checks that the internal audit and management review have happened; plans Stage 2. | Interviews people and samples records across the clauses and the applicable Annex A controls, over the operating period. |
Where | Often partly or wholly remote. | Usually on site, at the locations in scope; some parts may be remote. |
Typical length | [[2–4]] audit days | [[8–11]] audit days |
Who takes part | Mainly the ISMS manager; a short meeting with top management. | Top management, the ISMS manager, the control owners and a sample of staff. |
What you receive | A Stage 1 report: areas of concern to resolve before Stage 2, and the Stage 2 plan. | A Stage 2 report: findings graded, and a recommendation on certification. |
Together the two stages usually take [[10–15]] audit days for an organisation of [[100 to 300]] people. The certification body works out the days from the number of people in scope, the sites and the complexity of the scope (see 'What it costs' in the ISO 27001 Implementation Methodology & Project Plan).
Stage 1: documentation and readiness
What the certification body does
- Reads the scope statement and confirms it: the services, locations, interfaces and exclusions, and whether the certificate can be worded to match.
- Reviews the required documents: whether each exists, is approved and is under control (IS-04).
- Checks the risk method and results, and that the Statement of Applicability follows from them (IS-03).
- Checks that at least one internal audit and one management review have taken place, or when they will (IS-06).
- Gathers what it needs to plan Stage 2: the sites to visit, the people to interview and the records to sample.
- Forms a view on whether the organisation is ready for Stage 2, and records any area of concern.
What it is likely to ask for
Many certification bodies ask for these [[2 to 4]] weeks before Stage 1. Every item comes from the Mandatory ISMS Documentation Checklist.
Clause | Documented information | Kind |
|---|---|---|
4.3 | Scope of the ISMS | Document |
5.2 | Information security policy | Document |
6.1.2 | Risk assessment process | Document |
6.1.3 | Risk treatment process | Document |
6.1.3 | Statement of Applicability | Document |
6.1.3 | Risk treatment plan | Document |
6.2 | Information security objectives | Document |
7.5.1 | Documented information the organisation decides it needs for the ISMS to be effective | Document |
9.2.2 | Internal audit programme and audit results | Record |
9.3.3 | Results of management reviews | Record |
Expect also: an organisation chart for the scope, the list of legal, regulatory and contractual requirements, the asset inventory, the supplier list, and the headline measures reported so far.
What it tends to challenge
- A scope that the auditor cannot map to real services, or exclusions without reasons (IS-02).
- A Statement of Applicability whose inclusions and exclusions are not traced to the risk assessment (IS-03).
- Documents with no approval, no owner or no review date (IS-04).
- An internal audit that did not cover the whole ISMS, or was carried out by someone auditing their own work (IS-06, IS-07).
- A management review whose minutes do not show decisions.
Guidance — delete before approval
Stage 1 is the cheapest place to find a problem. Treat every area of concern as a nonconformity-in-waiting: give it an owner and a date before Stage 2 (IS-08), and keep the evidence that it was closed.
Stage 2: controls in operation
Stage 2 tests whether the ISMS runs as documented. The auditor follows a plan, sent in advance, naming the areas, the people and the times. In each area the auditor picks a sample from a population of records, and the records need to cover the operating period: at least [[3]] months (IS-05). A control at readiness 3 (Operating) is one an auditor could sample in this way.
How sampling works
- The auditor asks for a population: for example every joiner and leaver in the operating period, every change, every incident.
- From it the auditor picks a sample, often [[3 to 10]] items, sometimes chosen to test a weakness already seen.
- For each item the auditor asks for the record that shows the control worked: the approval, the ticket, the log entry, the review.
- Where the sample shows a gap, the auditor may widen it to see how far the problem goes.
It therefore helps to be able to produce any population quickly and completely. A list that takes a day to produce, or that turns out to be incomplete, is itself a finding.
What the auditor samples, by clause
Clause | Likely to ask for or sample | Likely challenge |
|---|---|---|
4.1 Understanding the organization and its context; 4.2 Understanding the needs and expectations of interested parties | The issues and interested parties recorded, and their requirements. | How did they shape the scope and the risk assessment? |
4.3 Determining the scope of the information security management system | The scope statement; a walk through one in-scope service. | Does anything the service depends on sit outside the scope unmanaged? |
5.1 Leadership and commitment; 5.3 Organizational roles, responsibilities and authorities | An interview with top management; the record of roles and authorities. | Can top management say what the objectives are and what they decided at the review? |
5.2 Policy | The approved policy; staff asked where to find it. | Was it communicated to everyone in scope, including contractors? |
6.1.2 Information security risk assessment | The risk method; a sample of risks traced from scenario to score and owner. | Would two assessors reach the same result? When was it last run? |
6.1.3 Information security risk treatment | The Statement of Applicability and the treatment plan; a sample of inclusions and exclusions. | Which risk does this control treat? Who accepted the residual risk? |
6.2 Information security objectives and planning to achieve them | The objectives and their measures; the latest results. | Are they measurable, and is anyone acting on the results? |
7.2 Competence; 7.3 Awareness | Competence and training records for a sample of staff; short interviews. | Do people know the policy, their part in it, and how to report an incident? |
7.5 Documented information | Version, approval and review of a sample of documents; how records are kept. | Is the version in use the approved one? Who can change it? |
8.1 Operational planning and control; 8.2 Information security risk assessment; 8.3 Information security risk treatment | Records of planned activities; the latest risk assessment results and treatment progress. | Were risk assessments repeated when things changed? |
9.1 Monitoring, measurement, analysis and evaluation | The measures, with results over the operating period. | What was done when a measure missed its target? |
9.2 Internal audit | The audit programme, the reports, the auditors' independence (IS-07). | Did the audit cover the whole ISMS, and did the findings get acted on? |
9.3 Management review | Minutes of the management review with its inputs and decisions. | Were the required inputs considered, and are the decisions being carried out? |
10.1 Continual improvement; 10.2 Nonconformity and corrective action | The nonconformity log; a sample traced to closure (IS-09). | Was the root cause found, and was the fix checked to have worked? |
Commonly sampled Annex A controls
The auditor samples applicable controls across all four themes, weighted towards the risks in your assessment. These are sampled in most first audits. Controls are shown by number and title only; the notes are ours.
Control | Likely to sample | Likely challenge | CISO Times support |
|---|---|---|---|
A.5.1 Policies for information security | Approval and review dates of the policies; whether staff know where to find them. | A policy past its review date; a policy approved by its own author. | Policy Framework Standard; Policy Lifecycle Operating Procedure |
A.5.9 Inventory of information and other associated assets | The asset inventory for the scope, with owners; a few assets traced from the floor or the cloud console to the list. | Assets found that are not on the list; owners who do not know they own them. | Scan Coverage & Asset Scope Register; Access Review Scope & System Inventory |
A.5.15 Access control | The access control rules and how they are applied to a sample of systems. | Rules that exist on paper while shared or generic accounts remain. | Access Review Methodology |
A.5.18 Access rights | Joiners, movers and leavers from HR records, traced to account changes; the last access review and what it removed. | A leaver's account still active; an access review with no evidence of anything changed. | Access Review Methodology; Access Review Campaign Operating Procedure |
A.5.19 Information security in supplier relationships | The supplier list, with the security requirements and checks for a sample of suppliers. | Critical suppliers with no assessment; no record of checks after the contract was signed. | Third-Party Security Policy; Supplier Security Assessment Procedure |
A.5.23 Information security for use of cloud services | How cloud services are chosen, configured and exited; the shared responsibility for the main platform. | No one able to say which controls the provider runs and which you run. | — |
A.5.24 Information security incident management planning and preparation | The incident process, the incident log and a sample of incidents from report to closure. | An empty incident log, which usually means incidents are not being recorded. | The Security Incident Management pack (P09, coming) |
A.5.30 ICT readiness for business continuity | Continuity requirements for the in-scope services, and the last test of recovery. | A plan that has never been tested, or a test with no record of the result. | The Cyber Resilience & Recovery pack (P22, coming) |
A.5.31 Legal, statutory, regulatory and contractual requirements | The list of legal, regulatory and contractual requirements, and who keeps it current. | Requirements listed but not reflected in the risk assessment or the controls. | The Regulatory Incident Notification & Reporting pack (P18, coming) |
A.6.1 Screening | Screening records for a sample of recent joiners. | Screening done for some roles and not others without a recorded reason. | — |
A.6.3 Information security awareness, education and training | Training records for a sample of staff; interviews to test whether it worked. | Completion rates with no follow-up of the people who did not complete. | Policy Attestation & Acknowledgement Tracker; Reviewer Instruction Pack & Campaign Communications |
A.8.2 Privileged access rights | The list of privileged accounts, who approved each, and when they were last reviewed. | Administrator rights granted permanently to people who need them occasionally. | The Privileged Access Management pack (P14, coming) |
A.8.5 Secure authentication | Sign-in settings for the main systems: multi-factor authentication and its exceptions. | Exceptions with no owner, no end date and no risk decision. | — |
A.8.8 Management of technical vulnerabilities | Scan results over the operating period, and the time taken to fix what they found. | Findings past their fix date with no exception recorded. | Vulnerability & Exposure Management Standard; Vulnerability Triage & Remediation Operating Procedure |
A.8.13 Information backup | Backup settings and a sample of restore tests. | Backups that run but have never been restored. | The Backup & Restore Assurance pack (P23, coming) |
A.8.15 Logging | What is logged, where, for how long, and who looks at it. | Logs collected that nobody reviews. | — |
A.8.32 Change management | A sample of changes from request to approval, test and release. | Emergency changes that were never approved after the event. | The Patch Management pack (P17, coming) |
Guidance — delete before approval
Replace this table with the controls your own risk assessment makes most important, and ask each control owner to prepare the population and three recent examples for each.
Documents named in the last column are CISO Times templates that can help produce the records; a pack marked "coming" is not yet available.
How findings are graded
Certification bodies grade what they find in broadly the same way. The names and details vary; these are the usual meanings, in our words.
Grade | What it usually means | Effect on certification | What to do |
|---|---|---|---|
Major nonconformity | A requirement not met at all, or a failure that means the ISMS cannot be relied on to do its job. Several minor findings in the same area can be raised together as a major. | Certification is not recommended until it is corrected and the certification body has verified the correction, which may need a further visit. | Correct it and show evidence within the period set, often [[90]] calendar days; follow IS-09. |
Minor nonconformity | A requirement partly met, or a single lapse, that does not undermine the system as a whole. | Certification can usually be recommended once the certification body accepts your plan to correct it. | Send a correction and corrective action plan, often within [[30]] calendar days; close it before the first surveillance audit (IS-09). |
Opportunity for improvement | Something that meets the requirement but could be better, or could become a nonconformity. | None. | Consider it, record the decision, and bring it to the management review. |
Area of concern (Stage 1) | Something that could become a nonconformity at Stage 2 if left. | None yet, but it is likely to be looked at again in Stage 2. | Close it before Stage 2 (IS-08). |
At the closing meeting the auditor presents the findings and the recommendation. That is the moment to ask about anything unclear or factually wrong, with evidence. Arguing about the grade rarely helps; showing a record the auditor did not see sometimes does.
Timelines
Interval | Typical | Who sets it |
|---|---|---|
Documents sent before Stage 1 | [[2 to 4]] weeks | The certification body's request |
Stage 1 report after the audit | [[1 to 2]] weeks | The certification body |
Stage 1 to Stage 2 | [[2 to 8]] weeks | Agreed with the certification body; long enough to close the areas of concern, short enough that Stage 1 is still current |
Plan for a minor nonconformity | [[30]] calendar days | The certification body |
Major nonconformity corrected and verified | [[90]] calendar days | The certification body; if the period runs out, Stage 2 may need to be repeated in part |
Certification decision after Stage 2 | [[2 to 6]] weeks | The certification body's independent review of the audit |
First surveillance audit | Within [[12]] months of the certification decision | The accreditation rules the body works under |
Recertification | Before the certificate expires, [[3]] years after it was issued | The accreditation rules the body works under |
Leave room between the stages. A gap that is too short leaves no time to fix what Stage 1 finds; one that is too long means the Stage 1 findings go stale and the operating period stretches without anyone checking it.
Worked example: the EXAMPLE firm's audit plan
The EXAMPLE firm is a software services company with 240 staff in two offices, an NIS2 important entity. Its scope: The design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. Stage 1 is booked for 18 January 2027 and Stage 2 for 1 March 2027, 6 weeks apart. Its internal audits run from 4 November 2026 to 9 December 2026, the management review is on 6 January 2027 and IA-07, the audit of that review, on 12 January 2027 (ISO 27001 Implementation Methodology & Project Plan, Example 1; ISMS Internal Audit Programme & Procedure). That leaves 40 calendar days between the last audit and Stage 1 to act on the findings, and 6 after IA-07. The preparation plan below is set from those fixed dates and the two stages. All dates are EXAMPLE: replace them with your own.
Date | Anchor (weeks) | What happens |
|---|---|---|
16 December 2026 | Last audit + 1 | Findings from the internal audits closed or planned (IS-09); evidence room set up and indexed. |
21 December 2026 | Stage 1 − 4 | Documents the certification body asked for sent ahead of Stage 1; the audit plan confirmed. |
23 December 2026 | Programme report | Internal audit programme report issued, as an input to the management review. |
6 January 2027 | Management review | Management review, which takes the Stage 1 go or no-go: readiness reassessed (IS-10), every required document approved (IS-04). |
12 January 2027 | IA-07 | IA-07: the internal audit of the management review itself, and of progress on corrective actions. |
18 January 2027 | Stage 1 | Stage 1 audit. |
25 January 2027 | Stage 1 + 1 | Stage 1 report expected; an owner and a date set for each area of concern (IS-08). |
8 February 2027 | Stage 2 − 3 | Mock interviews with every control owner the audit plan names. |
15 February 2027 | Stage 2 − 2 | Stage 2 go or no-go: every Stage 1 concern closed; every blocking item operating (ISM-01); the IS-05 period met. |
22 February 2027 | Stage 2 − 1 | Sample populations ready: joiners, leavers, changes, incidents, suppliers, access reviews, training. |
1 March 2027 | Stage 2 | Stage 2 audit. |
After Stage 2 (EXAMPLE, on the placeholder intervals). A plan for any minor nonconformity would be due by 31 March 2027. If the certification decision follows within the month, the first surveillance audit falls due by about 1 March 2028 and recertification by about 1 March 2030. Readiness continues to be reassessed monthly until certification (IS-10): the EXAMPLE plan has 8 reassessments before Stage 2.
Guidance — delete before approval
The EXAMPLE's Stage 1 preparation runs across the year-end holidays. If yours does too, send the Stage 1 documents before the break, and agree with the certification body when its questions will arrive.
Worked example: a nonconformity written up
The EXAMPLE firm's policy register (from the Security Policy Management pack, P04) shows, as at 30 September 2026 (EXAMPLE), that AUP-001 Acceptable Use Policy was due for review on 1 July 2026 and BKP-001 Backup Standard on 15 August 2026; neither has been reviewed. Left until Stage 2, an auditor sampling A.5.1 Policies for information security and clause 7.5 Documented information would probably raise it. This is how it would be answered under IS-09.
Part | EXAMPLE |
|---|---|
Finding | Two approved documents in the scope, AUP-001 and BKP-001, are past their review dates. Likely grade: minor nonconformity — the document control process exists and most documents are in date. |
Correction | Review and re-approve AUP-001 and BKP-001; update the register. Owners: Head of IT and IT Operations Manager. |
Root cause | Two overdue documents with different owners point to the process, not to one person: review reminders depended on each owner's own calendar, and nobody checked the register for dates passing. |
Corrective action | The ISMS manager checks the register monthly for reviews due within [[60]] calendar days and sends reminders; overdue reviews are reported with the headline measures. |
Effectiveness check | After [[3]] monthly checks, confirm that no document has passed its review date. Record the result and close the nonconformity. |
Better still, the readiness reassessment (IS-10) catches this before the auditor does, and it goes to the gap tracker with an owner and a date (IS-08).
Preparing people for interviews
The auditor will talk to top management, the ISMS manager, the control owners and a sample of staff. Interviews test whether the ISMS is understood and followed, not whether people can recite it.
Advice for everyone interviewed
- Answer the question asked, then stop. Offer the record that shows it: open the ticket, the log, the review.
- Say 'I don't know, but I know who does' rather than guess. A wrong answer given confidently causes more trouble than an honest one.
- Be straightforward about gaps. If something is not done yet, say so and say what is planned; a gap the auditor finds for themselves after it was glossed over does more damage.
- Describe what you actually do. If it differs from the procedure, the procedure may need changing, and that is a better conversation than a surprise in the records.
- Keep to your own area. Point the auditor to the right person for anything else.
Questions to rehearse
Who | Questions they are often asked |
|---|---|
Top management | Why did you decide to certify? What are the security objectives, and how are they going? What did the last management review decide? How do you know the ISMS has the resources it needs? |
ISMS manager | How was the scope decided? Walk me through a risk from assessment to control. How do you know controls are working? What did the internal audit find, and what happened next? |
Control owners | What does your control do, and how do you know it works? Show me the last three times it ran. What happens when it fails? Who covers when you are away? |
Staff | Where is the security policy? How would you report a security incident? What training have you had? What would you do with a suspicious email? |
Consider mock interviews run by the internal auditor in the weeks before each stage, with each control owner the audit plan names. The first time someone explains their control out loud should not be in front of the certification body.
The evidence room
The evidence room is where the auditor's requests are met: usually a shared folder, sometimes a physical room as well. It is documented information in its own right (7.5 Documented information), so it is worth keeping it under the same control as the rest.
How to set it up
- Index it by clause and by Statement of Applicability control, so any request can be answered from the index.
- Hold the approved version of each document, with its ID, version, owner and approval date. Link to the controlled copy rather than making a new one.
- Prepare the populations the auditor is likely to sample, for the whole operating period: joiners, movers and leavers; changes; incidents; suppliers; access reviews; training; backup and restore tests; vulnerability scans.
- Give auditors read access to the evidence room, not to live systems. Show live systems by screen share with the control owner at the controls.
- Name a runner who fetches what the auditor asks for, and keep a log of each request and what was given.
- Mark anything confidential and agree how the auditor may keep it. Certification bodies are bound by confidentiality, but share only what the audit needs.
What to avoid
- Creating or back-dating records during the audit. Anything created after the request looks like what it is.
- Handing over everything at once. A flood of documents slows the audit and invites questions about things out of scope.
- Evidence that contradicts itself: two versions of a policy, or a population that does not match the register.
After certification
The certificate names the scope and is usually valid for [[3]] years, provided the surveillance audits go well.
When | What happens | What the auditor usually looks at |
|---|---|---|
Every year: surveillance audits | Shorter audits, the first within [[12]] months of the certification decision. | The internal audit, the management review, the nonconformity log and the corrective actions from the last audit, changes to the ISMS, and a rotating part of the controls. |
Between audits | The ISMS keeps running: measures, reviews, audits and records. | — |
When something significant changes | Tell the certification body: a change of scope, ownership, sites or a serious incident. | It may adjust the next audit or visit sooner. |
At [[3]] years: recertification | A full audit before the certificate expires. | The whole ISMS and its performance over the cycle. |
The phases of the ISO 27001 Implementation Methodology & Project Plan become a yearly cycle: risk assessment, operation, internal audit, management review. The headline measures keep being reported, and ISM-03 (Gaps overdue) matters most between audits.
Common mistakes
Mistake | What tends to happen | Better |
|---|---|---|
Booking Stage 2 before the ISMS has run | Records cover weeks, not months; the auditor has too little to sample. | Keep the IS-05 period of [[3]] months; move the date early if needed. |
Treating Stage 1 as a formality | Areas of concern become nonconformities at Stage 2. | Close every concern before Stage 2, with evidence (IS-08). |
Preparing documents instead of records | Stage 2 samples records; new documents do not help. | Spend the last weeks checking populations and records. |
Only the ISMS manager can answer | Control owners defer every question; the auditor concludes the ISMS belongs to one person. | Rehearse control owners; let them answer. |
Guessing in interviews | An answer contradicts the records, and the auditor widens the sample. | 'I don't know, but I know who does.' |
Populations that cannot be produced | A list takes a day to build, or turns out incomplete. | Build and check the populations before Stage 2. |
Fixing the symptom only | The same nonconformity returns at the first surveillance audit. | Root cause, corrective action and an effectiveness check (IS-09). |
Disputing grades at the closing meeting | Time spent, little changed. | Correct factual errors with evidence; accept the rest and plan the fix. |
Readiness checklist
Work through this checklist before confirming Stage 1 and again before Stage 2. It uses the readiness scale of the Certification Readiness Self-Assessment and the go and no-go conditions of the ISO 27001 Implementation Methodology & Project Plan.
Blocking items
Each blocking item is best at readiness 3 (Operating) before Stage 2 (ISM-01).
Clause | Title | What the auditor will ask to see | Stage 1 | Stage 2 |
|---|---|---|---|---|
4.3 | Determining the scope of the information security management system | The approved scope statement, with interfaces and every exclusion's reason | [[ ]] | [[ ]] |
5.2 | Policy | The approved policy, and evidence it was communicated to the people in scope | [[ ]] | [[ ]] |
6.1.2 | Information security risk assessment | The approved risk method and the results of the risk assessment, with owners | [[ ]] | [[ ]] |
6.1.3 | Information security risk treatment | The Statement of Applicability, the risk treatment plan and the owners' acceptance of residual risk | [[ ]] | [[ ]] |
6.2 | Information security objectives and planning to achieve them | The objectives, with measures, owners, dates and the latest results | [[ ]] | [[ ]] |
9.2.2 | Internal audit programme | The internal audit programme and at least one full cycle of audit reports (IS-06) | [[ ]] | [[ ]] |
9.3.3 | Management review results | Minutes of at least one management review, with its decisions and actions (IS-06) | [[ ]] | [[ ]] |
10.2 | Nonconformity and corrective action | The nonconformity log, each entry with root cause, correction, corrective action and effectiveness check (IS-09) | [[ ]] | [[ ]] |
Required documents and records
From the Mandatory ISMS Documentation Checklist. Documents are best approved before Stage 1; records are best covering the operating period by Stage 2.
Clause | Documented information | Kind | Blocking? | Ready? |
|---|---|---|---|---|
4.3 | Scope of the ISMS | Document | Yes | [[ ]] |
5.2 | Information security policy | Document | Yes | [[ ]] |
6.1.2 | Risk assessment process | Document | Yes | [[ ]] |
6.1.3 | Risk treatment process | Document | Yes | [[ ]] |
6.1.3 | Statement of Applicability | Document | Yes | [[ ]] |
6.1.3 | Risk treatment plan | Document | Yes | [[ ]] |
6.2 | Information security objectives | Document | Yes | [[ ]] |
7.2 | Evidence of competence | Record | [[ ]] | |
7.5.1 | Documented information the organisation decides it needs for the ISMS to be effective | Document | [[ ]] | |
8.1 | Evidence that processes have been carried out as planned | Record | [[ ]] | |
8.2 | Results of risk assessments | Record | [[ ]] | |
8.3 | Results of risk treatment | Record | [[ ]] | |
9.1 | Results of monitoring and measurement | Record | [[ ]] | |
9.2.2 | Internal audit programme and audit results | Record | Yes | [[ ]] |
9.3.3 | Results of management reviews | Record | Yes | [[ ]] |
10.2 | Nonconformities, actions taken and results of corrective action | Record | Yes | [[ ]] |
Before Stage 1
- Every required document exists, is approved and is under document control (IS-04).
- The scope is approved by top management and names interfaces and exclusions with reasons (IS-01, IS-02).
- The Statement of Applicability traces every inclusion and exclusion to the risk assessment (IS-03).
- A full internal audit and a management review have been completed (IS-06), by auditors independent of what they audited (IS-07).
- ISM-01 shows every blocking item at readiness 2 or better.
- The documents the certification body asked for have been sent, and the Stage 1 plan is confirmed.
Before Stage 2
- Every Stage 1 area of concern is closed, with evidence.
- Every blocking item is at readiness 3 (ISM-01); no gap on the critical path is overdue (ISM-03).
- The ISMS has run for at least [[3]] months, with records (IS-05).
- Every internal audit nonconformity has a root cause, a correction, a corrective action and an effectiveness check, or a dated plan for one (IS-09).
- The evidence room is indexed; the populations are ready; a runner is named.
- Every person on the audit plan has had a mock interview.
- Rooms, access, screen sharing and the timetable are agreed with the certification body.
Guidance — delete before approval
Mark each line with a date and a name when it is done, and keep the completed checklist as evidence of preparation. If any Stage 2 line is still open two weeks before the audit, raise it with the sponsor that week.
Related documents
Document | Relationship |
|---|---|
ISO 27001 Implementation Methodology & Project Plan | The rules, the phases and the plan whose Phase 6 is these two audits |
Statement of Applicability Template | What the auditor samples Annex A controls against |
Mandatory ISMS Documentation Checklist | The required documents and records the checklist uses |
Certification Readiness Self-Assessment | The readiness scale and the monthly reassessment (IS-10) |
ISMS Gap & Remediation Tracker | Stage 1 concerns and nonconformities, with owners and dates (IS-08) |
ISMS Internal Audit Programme & Procedure | The internal audit that rehearses Stage 2 (IS-06, IS-07) |
Management Review Meeting Pack | The management review the auditor will ask about |
Adapting this guide
Guidance — delete before approval
Small organisation: Stage 1 may be short and remote, and one person may answer for several areas. Rehearse that person across all of them, and consider a contracted internal auditor for a mock audit a few weeks before Stage 2. The auditor will expect the same records in smaller numbers.
Regulated entity: ISO/IEC 27001:2022 is the requirement the certification body audits against. It will not assess compliance with NIS2, DORA or other laws, and a certificate is evidence of a working management system, not proof of compliance with a law. Regulators and customers may still ask for the certificate and the Statement of Applicability. Make sure the legal and regulatory requirements are listed and reflected in the risk assessment, because the auditor is likely to sample them.
IT run by a service provider: the auditor will sample how you oversee the provider, and may want to see records the provider holds, such as access reviews, backup tests or change records. Agree in advance that the provider will produce them and attend interviews if needed. A provider's own certificate helps only if its scope covers the service you use.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 9.2 — Internal audit | The internal audit as the rehearsal for Stage 2; what the auditor samples; readiness checklist |
ISO/IEC 27001:2022 | Clause 9.3 — Management review | Management review evidence the auditor asks for at both stages |
ISO/IEC 27001:2022 | Clause 10.2 — Nonconformity and corrective action | How findings are graded; the nonconformity worked example (IS-09) |
ISO/IEC 27001:2022 | Clause 7.5 — Documented information | The evidence room; document control sampled at both stages |
NIST CSF 2.0 | GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed” | Legal, regulatory and contractual requirements the auditor samples; regulated-entity tailoring |
NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Improvements from the audits: nonconformities, opportunities and corrective action |
Definitions
Term | Meaning in this guide |
|---|---|
Area of concern | A Stage 1 observation that could become a nonconformity at Stage 2 if it is not resolved. |
Audit plan | The certification body's timetable for an audit: areas, people, sites and times. |
Certification body | An organisation accredited to audit and certify management systems against ISO/IEC 27001. |
Evidence room | The indexed collection of documents and records the auditor is given access to. |
Major nonconformity | A requirement not met, or a failure that means the ISMS cannot be relied on; it stops certification until corrected and verified. |
Minor nonconformity | A requirement partly met, or a single lapse, that does not undermine the system. |
Opportunity for improvement | A suggestion from the auditor; no response required. |
Population | Every record of one kind in the operating period, from which the auditor draws a sample. |
Recertification audit | The full audit before the certificate expires. |
Runner | The person who fetches evidence for the auditor and logs each request. |
Stage 1 audit | The certification body's review of the documentation and of readiness for Stage 2. |
Stage 2 audit | The certification body's audit of the ISMS in operation, by sampling controls and records. |
Surveillance audit | A shorter yearly audit between certification and recertification. |