Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Stage 1 and Stage 2 Audit Preparation Guide

Prepares the team for what the certification body will actually ask, sample and challenge in each audit stage.

Available soon

Format
Word
Size
64 KB
Length
19 pages
Version
1.0
Updated

What's inside

  • Purpose
  • Who this guide is for
  • The two stages at a glance
  • Stage 1: documentation and readiness
  • Stage 2: controls in operation
  • How findings are graded
  • Timelines
  • Worked example: the EXAMPLE firm's audit plan
  • Worked example: a nonconformity written up
  • Preparing people for interviews
  • The evidence room
  • After certification
  • Common mistakes
  • Readiness checklist
  • Related documents
  • Adapting this guide
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose

This guide prepares [[Organisation Name]] for the two audits that lead to ISO/IEC 27001 certification: what the certification body does in each stage, what it is likely to ask for, sample and challenge, how it grades what it finds, and how to prepare the evidence and the people. It closes with a readiness checklist to work through before each stage.

It follows the ISO 27001 Implementation Methodology & Project Plan, whose Phase 6 is the two audits, and uses the same rules (IS-01 to IS-10) and dates. It describes common practice. Each certification body works to its own procedures within the rules it is accredited under, so treat what follows as what to expect and confirm the details with your own body.

Guidance — delete before approval

Replace every interval in [[double brackets]] with the one your certification body gives you in its proposal or audit plan. Ask for them in writing when you book.

Who this guide is for

Reader

What to read

ISMS manager ([[e.g. Head of Information Security]])

All of it. You will organise both audits, run the evidence room and brief everyone else.

Top management and the executive sponsor

'The two stages at a glance', 'How findings are graded' and 'Preparing people for interviews'. The auditor will interview you.

Control owners

'What the auditor samples', the Annex A table for your controls, and 'Preparing people for interviews'.

Internal auditor

'How findings are graded' and the readiness checklist: your audit is the rehearsal.

The two stages at a glance

Certification is two audits by the same certification body. Stage 1 asks whether the ISMS is designed and ready; Stage 2 asks whether it works.

Stage 1

Stage 2

Question

Is the ISMS documented, and is the organisation ready for Stage 2?

Is the ISMS operating as documented, and is it effective?

What the auditor does

Reviews the documentation; confirms the scope and the sites; checks that the internal audit and management review have happened; plans Stage 2.

Interviews people and samples records across the clauses and the applicable Annex A controls, over the operating period.

Where

Often partly or wholly remote.

Usually on site, at the locations in scope; some parts may be remote.

Typical length

[[2–4]] audit days

[[8–11]] audit days

Who takes part

Mainly the ISMS manager; a short meeting with top management.

Top management, the ISMS manager, the control owners and a sample of staff.

What you receive

A Stage 1 report: areas of concern to resolve before Stage 2, and the Stage 2 plan.

A Stage 2 report: findings graded, and a recommendation on certification.

Together the two stages usually take [[10–15]] audit days for an organisation of [[100 to 300]] people. The certification body works out the days from the number of people in scope, the sites and the complexity of the scope (see 'What it costs' in the ISO 27001 Implementation Methodology & Project Plan).

Stage 1: documentation and readiness

What the certification body does

  • Reads the scope statement and confirms it: the services, locations, interfaces and exclusions, and whether the certificate can be worded to match.
  • Reviews the required documents: whether each exists, is approved and is under control (IS-04).
  • Checks the risk method and results, and that the Statement of Applicability follows from them (IS-03).
  • Checks that at least one internal audit and one management review have taken place, or when they will (IS-06).
  • Gathers what it needs to plan Stage 2: the sites to visit, the people to interview and the records to sample.
  • Forms a view on whether the organisation is ready for Stage 2, and records any area of concern.

What it is likely to ask for

Many certification bodies ask for these [[2 to 4]] weeks before Stage 1. Every item comes from the Mandatory ISMS Documentation Checklist.

Clause

Documented information

Kind

4.3

Scope of the ISMS

Document

5.2

Information security policy

Document

6.1.2

Risk assessment process

Document

6.1.3

Risk treatment process

Document

6.1.3

Statement of Applicability

Document

6.1.3

Risk treatment plan

Document

6.2

Information security objectives

Document

7.5.1

Documented information the organisation decides it needs for the ISMS to be effective

Document

9.2.2

Internal audit programme and audit results

Record

9.3.3

Results of management reviews

Record

Expect also: an organisation chart for the scope, the list of legal, regulatory and contractual requirements, the asset inventory, the supplier list, and the headline measures reported so far.

What it tends to challenge

  • A scope that the auditor cannot map to real services, or exclusions without reasons (IS-02).
  • A Statement of Applicability whose inclusions and exclusions are not traced to the risk assessment (IS-03).
  • Documents with no approval, no owner or no review date (IS-04).
  • An internal audit that did not cover the whole ISMS, or was carried out by someone auditing their own work (IS-06, IS-07).
  • A management review whose minutes do not show decisions.

Guidance — delete before approval

Stage 1 is the cheapest place to find a problem. Treat every area of concern as a nonconformity-in-waiting: give it an owner and a date before Stage 2 (IS-08), and keep the evidence that it was closed.

Stage 2: controls in operation

Stage 2 tests whether the ISMS runs as documented. The auditor follows a plan, sent in advance, naming the areas, the people and the times. In each area the auditor picks a sample from a population of records, and the records need to cover the operating period: at least [[3]] months (IS-05). A control at readiness 3 (Operating) is one an auditor could sample in this way.

How sampling works

  1. The auditor asks for a population: for example every joiner and leaver in the operating period, every change, every incident.
  2. From it the auditor picks a sample, often [[3 to 10]] items, sometimes chosen to test a weakness already seen.
  3. For each item the auditor asks for the record that shows the control worked: the approval, the ticket, the log entry, the review.
  4. Where the sample shows a gap, the auditor may widen it to see how far the problem goes.

It therefore helps to be able to produce any population quickly and completely. A list that takes a day to produce, or that turns out to be incomplete, is itself a finding.

What the auditor samples, by clause

Clause

Likely to ask for or sample

Likely challenge

4.1 Understanding the organization and its context; 4.2 Understanding the needs and expectations of interested parties

The issues and interested parties recorded, and their requirements.

How did they shape the scope and the risk assessment?

4.3 Determining the scope of the information security management system

The scope statement; a walk through one in-scope service.

Does anything the service depends on sit outside the scope unmanaged?

5.1 Leadership and commitment; 5.3 Organizational roles, responsibilities and authorities

An interview with top management; the record of roles and authorities.

Can top management say what the objectives are and what they decided at the review?

5.2 Policy

The approved policy; staff asked where to find it.

Was it communicated to everyone in scope, including contractors?

6.1.2 Information security risk assessment

The risk method; a sample of risks traced from scenario to score and owner.

Would two assessors reach the same result? When was it last run?

6.1.3 Information security risk treatment

The Statement of Applicability and the treatment plan; a sample of inclusions and exclusions.

Which risk does this control treat? Who accepted the residual risk?

6.2 Information security objectives and planning to achieve them

The objectives and their measures; the latest results.

Are they measurable, and is anyone acting on the results?

7.2 Competence; 7.3 Awareness

Competence and training records for a sample of staff; short interviews.

Do people know the policy, their part in it, and how to report an incident?

7.5 Documented information

Version, approval and review of a sample of documents; how records are kept.

Is the version in use the approved one? Who can change it?

8.1 Operational planning and control; 8.2 Information security risk assessment; 8.3 Information security risk treatment

Records of planned activities; the latest risk assessment results and treatment progress.

Were risk assessments repeated when things changed?

9.1 Monitoring, measurement, analysis and evaluation

The measures, with results over the operating period.

What was done when a measure missed its target?

9.2 Internal audit

The audit programme, the reports, the auditors' independence (IS-07).

Did the audit cover the whole ISMS, and did the findings get acted on?

9.3 Management review

Minutes of the management review with its inputs and decisions.

Were the required inputs considered, and are the decisions being carried out?

10.1 Continual improvement; 10.2 Nonconformity and corrective action

The nonconformity log; a sample traced to closure (IS-09).

Was the root cause found, and was the fix checked to have worked?

Commonly sampled Annex A controls

The auditor samples applicable controls across all four themes, weighted towards the risks in your assessment. These are sampled in most first audits. Controls are shown by number and title only; the notes are ours.

Control

Likely to sample

Likely challenge

CISO Times support

A.5.1 Policies for information security

Approval and review dates of the policies; whether staff know where to find them.

A policy past its review date; a policy approved by its own author.

Policy Framework Standard; Policy Lifecycle Operating Procedure

A.5.9 Inventory of information and other associated assets

The asset inventory for the scope, with owners; a few assets traced from the floor or the cloud console to the list.

Assets found that are not on the list; owners who do not know they own them.

Scan Coverage & Asset Scope Register; Access Review Scope & System Inventory

A.5.15 Access control

The access control rules and how they are applied to a sample of systems.

Rules that exist on paper while shared or generic accounts remain.

Access Review Methodology

A.5.18 Access rights

Joiners, movers and leavers from HR records, traced to account changes; the last access review and what it removed.

A leaver's account still active; an access review with no evidence of anything changed.

Access Review Methodology; Access Review Campaign Operating Procedure

A.5.19 Information security in supplier relationships

The supplier list, with the security requirements and checks for a sample of suppliers.

Critical suppliers with no assessment; no record of checks after the contract was signed.

Third-Party Security Policy; Supplier Security Assessment Procedure

A.5.23 Information security for use of cloud services

How cloud services are chosen, configured and exited; the shared responsibility for the main platform.

No one able to say which controls the provider runs and which you run.

—

A.5.24 Information security incident management planning and preparation

The incident process, the incident log and a sample of incidents from report to closure.

An empty incident log, which usually means incidents are not being recorded.

The Security Incident Management pack (P09, coming)

A.5.30 ICT readiness for business continuity

Continuity requirements for the in-scope services, and the last test of recovery.

A plan that has never been tested, or a test with no record of the result.

The Cyber Resilience & Recovery pack (P22, coming)

A.5.31 Legal, statutory, regulatory and contractual requirements

The list of legal, regulatory and contractual requirements, and who keeps it current.

Requirements listed but not reflected in the risk assessment or the controls.

The Regulatory Incident Notification & Reporting pack (P18, coming)

A.6.1 Screening

Screening records for a sample of recent joiners.

Screening done for some roles and not others without a recorded reason.

—

A.6.3 Information security awareness, education and training

Training records for a sample of staff; interviews to test whether it worked.

Completion rates with no follow-up of the people who did not complete.

Policy Attestation & Acknowledgement Tracker; Reviewer Instruction Pack & Campaign Communications

A.8.2 Privileged access rights

The list of privileged accounts, who approved each, and when they were last reviewed.

Administrator rights granted permanently to people who need them occasionally.

The Privileged Access Management pack (P14, coming)

A.8.5 Secure authentication

Sign-in settings for the main systems: multi-factor authentication and its exceptions.

Exceptions with no owner, no end date and no risk decision.

—

A.8.8 Management of technical vulnerabilities

Scan results over the operating period, and the time taken to fix what they found.

Findings past their fix date with no exception recorded.

Vulnerability & Exposure Management Standard; Vulnerability Triage & Remediation Operating Procedure

A.8.13 Information backup

Backup settings and a sample of restore tests.

Backups that run but have never been restored.

The Backup & Restore Assurance pack (P23, coming)

A.8.15 Logging

What is logged, where, for how long, and who looks at it.

Logs collected that nobody reviews.

—

A.8.32 Change management

A sample of changes from request to approval, test and release.

Emergency changes that were never approved after the event.

The Patch Management pack (P17, coming)

Guidance — delete before approval

Replace this table with the controls your own risk assessment makes most important, and ask each control owner to prepare the population and three recent examples for each.

Documents named in the last column are CISO Times templates that can help produce the records; a pack marked "coming" is not yet available.

How findings are graded

Certification bodies grade what they find in broadly the same way. The names and details vary; these are the usual meanings, in our words.

Grade

What it usually means

Effect on certification

What to do

Major nonconformity

A requirement not met at all, or a failure that means the ISMS cannot be relied on to do its job. Several minor findings in the same area can be raised together as a major.

Certification is not recommended until it is corrected and the certification body has verified the correction, which may need a further visit.

Correct it and show evidence within the period set, often [[90]] calendar days; follow IS-09.

Minor nonconformity

A requirement partly met, or a single lapse, that does not undermine the system as a whole.

Certification can usually be recommended once the certification body accepts your plan to correct it.

Send a correction and corrective action plan, often within [[30]] calendar days; close it before the first surveillance audit (IS-09).

Opportunity for improvement

Something that meets the requirement but could be better, or could become a nonconformity.

None.

Consider it, record the decision, and bring it to the management review.

Area of concern (Stage 1)

Something that could become a nonconformity at Stage 2 if left.

None yet, but it is likely to be looked at again in Stage 2.

Close it before Stage 2 (IS-08).

At the closing meeting the auditor presents the findings and the recommendation. That is the moment to ask about anything unclear or factually wrong, with evidence. Arguing about the grade rarely helps; showing a record the auditor did not see sometimes does.

Timelines

Interval

Typical

Who sets it

Documents sent before Stage 1

[[2 to 4]] weeks

The certification body's request

Stage 1 report after the audit

[[1 to 2]] weeks

The certification body

Stage 1 to Stage 2

[[2 to 8]] weeks

Agreed with the certification body; long enough to close the areas of concern, short enough that Stage 1 is still current

Plan for a minor nonconformity

[[30]] calendar days

The certification body

Major nonconformity corrected and verified

[[90]] calendar days

The certification body; if the period runs out, Stage 2 may need to be repeated in part

Certification decision after Stage 2

[[2 to 6]] weeks

The certification body's independent review of the audit

First surveillance audit

Within [[12]] months of the certification decision

The accreditation rules the body works under

Recertification

Before the certificate expires, [[3]] years after it was issued

The accreditation rules the body works under

Leave room between the stages. A gap that is too short leaves no time to fix what Stage 1 finds; one that is too long means the Stage 1 findings go stale and the operating period stretches without anyone checking it.

Worked example: the EXAMPLE firm's audit plan

The EXAMPLE firm is a software services company with 240 staff in two offices, an NIS2 important entity. Its scope: The design, development, hosting and support of the company's software services, from its two offices, including the cloud platform they run on. Stage 1 is booked for 18 January 2027 and Stage 2 for 1 March 2027, 6 weeks apart. Its internal audits run from 4 November 2026 to 9 December 2026, the management review is on 6 January 2027 and IA-07, the audit of that review, on 12 January 2027 (ISO 27001 Implementation Methodology & Project Plan, Example 1; ISMS Internal Audit Programme & Procedure). That leaves 40 calendar days between the last audit and Stage 1 to act on the findings, and 6 after IA-07. The preparation plan below is set from those fixed dates and the two stages. All dates are EXAMPLE: replace them with your own.

Date

Anchor (weeks)

What happens

16 December 2026

Last audit + 1

Findings from the internal audits closed or planned (IS-09); evidence room set up and indexed.

21 December 2026

Stage 1 − 4

Documents the certification body asked for sent ahead of Stage 1; the audit plan confirmed.

23 December 2026

Programme report

Internal audit programme report issued, as an input to the management review.

6 January 2027

Management review

Management review, which takes the Stage 1 go or no-go: readiness reassessed (IS-10), every required document approved (IS-04).

12 January 2027

IA-07

IA-07: the internal audit of the management review itself, and of progress on corrective actions.

18 January 2027

Stage 1

Stage 1 audit.

25 January 2027

Stage 1 + 1

Stage 1 report expected; an owner and a date set for each area of concern (IS-08).

8 February 2027

Stage 2 − 3

Mock interviews with every control owner the audit plan names.

15 February 2027

Stage 2 − 2

Stage 2 go or no-go: every Stage 1 concern closed; every blocking item operating (ISM-01); the IS-05 period met.

22 February 2027

Stage 2 − 1

Sample populations ready: joiners, leavers, changes, incidents, suppliers, access reviews, training.

1 March 2027

Stage 2

Stage 2 audit.

After Stage 2 (EXAMPLE, on the placeholder intervals). A plan for any minor nonconformity would be due by 31 March 2027. If the certification decision follows within the month, the first surveillance audit falls due by about 1 March 2028 and recertification by about 1 March 2030. Readiness continues to be reassessed monthly until certification (IS-10): the EXAMPLE plan has 8 reassessments before Stage 2.

Guidance — delete before approval

The EXAMPLE's Stage 1 preparation runs across the year-end holidays. If yours does too, send the Stage 1 documents before the break, and agree with the certification body when its questions will arrive.

Worked example: a nonconformity written up

The EXAMPLE firm's policy register (from the Security Policy Management pack, P04) shows, as at 30 September 2026 (EXAMPLE), that AUP-001 Acceptable Use Policy was due for review on 1 July 2026 and BKP-001 Backup Standard on 15 August 2026; neither has been reviewed. Left until Stage 2, an auditor sampling A.5.1 Policies for information security and clause 7.5 Documented information would probably raise it. This is how it would be answered under IS-09.

Part

EXAMPLE

Finding

Two approved documents in the scope, AUP-001 and BKP-001, are past their review dates. Likely grade: minor nonconformity — the document control process exists and most documents are in date.

Correction

Review and re-approve AUP-001 and BKP-001; update the register. Owners: Head of IT and IT Operations Manager.

Root cause

Two overdue documents with different owners point to the process, not to one person: review reminders depended on each owner's own calendar, and nobody checked the register for dates passing.

Corrective action

The ISMS manager checks the register monthly for reviews due within [[60]] calendar days and sends reminders; overdue reviews are reported with the headline measures.

Effectiveness check

After [[3]] monthly checks, confirm that no document has passed its review date. Record the result and close the nonconformity.

Better still, the readiness reassessment (IS-10) catches this before the auditor does, and it goes to the gap tracker with an owner and a date (IS-08).

Preparing people for interviews

The auditor will talk to top management, the ISMS manager, the control owners and a sample of staff. Interviews test whether the ISMS is understood and followed, not whether people can recite it.

Advice for everyone interviewed

  • Answer the question asked, then stop. Offer the record that shows it: open the ticket, the log, the review.
  • Say 'I don't know, but I know who does' rather than guess. A wrong answer given confidently causes more trouble than an honest one.
  • Be straightforward about gaps. If something is not done yet, say so and say what is planned; a gap the auditor finds for themselves after it was glossed over does more damage.
  • Describe what you actually do. If it differs from the procedure, the procedure may need changing, and that is a better conversation than a surprise in the records.
  • Keep to your own area. Point the auditor to the right person for anything else.

Questions to rehearse

Who

Questions they are often asked

Top management

Why did you decide to certify? What are the security objectives, and how are they going? What did the last management review decide? How do you know the ISMS has the resources it needs?

ISMS manager

How was the scope decided? Walk me through a risk from assessment to control. How do you know controls are working? What did the internal audit find, and what happened next?

Control owners

What does your control do, and how do you know it works? Show me the last three times it ran. What happens when it fails? Who covers when you are away?

Staff

Where is the security policy? How would you report a security incident? What training have you had? What would you do with a suspicious email?

Consider mock interviews run by the internal auditor in the weeks before each stage, with each control owner the audit plan names. The first time someone explains their control out loud should not be in front of the certification body.

The evidence room

The evidence room is where the auditor's requests are met: usually a shared folder, sometimes a physical room as well. It is documented information in its own right (7.5 Documented information), so it is worth keeping it under the same control as the rest.

How to set it up

  • Index it by clause and by Statement of Applicability control, so any request can be answered from the index.
  • Hold the approved version of each document, with its ID, version, owner and approval date. Link to the controlled copy rather than making a new one.
  • Prepare the populations the auditor is likely to sample, for the whole operating period: joiners, movers and leavers; changes; incidents; suppliers; access reviews; training; backup and restore tests; vulnerability scans.
  • Give auditors read access to the evidence room, not to live systems. Show live systems by screen share with the control owner at the controls.
  • Name a runner who fetches what the auditor asks for, and keep a log of each request and what was given.
  • Mark anything confidential and agree how the auditor may keep it. Certification bodies are bound by confidentiality, but share only what the audit needs.

What to avoid

  • Creating or back-dating records during the audit. Anything created after the request looks like what it is.
  • Handing over everything at once. A flood of documents slows the audit and invites questions about things out of scope.
  • Evidence that contradicts itself: two versions of a policy, or a population that does not match the register.

After certification

The certificate names the scope and is usually valid for [[3]] years, provided the surveillance audits go well.

When

What happens

What the auditor usually looks at

Every year: surveillance audits

Shorter audits, the first within [[12]] months of the certification decision.

The internal audit, the management review, the nonconformity log and the corrective actions from the last audit, changes to the ISMS, and a rotating part of the controls.

Between audits

The ISMS keeps running: measures, reviews, audits and records.

—

When something significant changes

Tell the certification body: a change of scope, ownership, sites or a serious incident.

It may adjust the next audit or visit sooner.

At [[3]] years: recertification

A full audit before the certificate expires.

The whole ISMS and its performance over the cycle.

The phases of the ISO 27001 Implementation Methodology & Project Plan become a yearly cycle: risk assessment, operation, internal audit, management review. The headline measures keep being reported, and ISM-03 (Gaps overdue) matters most between audits.

Common mistakes

Mistake

What tends to happen

Better

Booking Stage 2 before the ISMS has run

Records cover weeks, not months; the auditor has too little to sample.

Keep the IS-05 period of [[3]] months; move the date early if needed.

Treating Stage 1 as a formality

Areas of concern become nonconformities at Stage 2.

Close every concern before Stage 2, with evidence (IS-08).

Preparing documents instead of records

Stage 2 samples records; new documents do not help.

Spend the last weeks checking populations and records.

Only the ISMS manager can answer

Control owners defer every question; the auditor concludes the ISMS belongs to one person.

Rehearse control owners; let them answer.

Guessing in interviews

An answer contradicts the records, and the auditor widens the sample.

'I don't know, but I know who does.'

Populations that cannot be produced

A list takes a day to build, or turns out incomplete.

Build and check the populations before Stage 2.

Fixing the symptom only

The same nonconformity returns at the first surveillance audit.

Root cause, corrective action and an effectiveness check (IS-09).

Disputing grades at the closing meeting

Time spent, little changed.

Correct factual errors with evidence; accept the rest and plan the fix.

Readiness checklist

Work through this checklist before confirming Stage 1 and again before Stage 2. It uses the readiness scale of the Certification Readiness Self-Assessment and the go and no-go conditions of the ISO 27001 Implementation Methodology & Project Plan.

Blocking items

Each blocking item is best at readiness 3 (Operating) before Stage 2 (ISM-01).

Clause

Title

What the auditor will ask to see

Stage 1

Stage 2

4.3

Determining the scope of the information security management system

The approved scope statement, with interfaces and every exclusion's reason

[[ ]]

[[ ]]

5.2

Policy

The approved policy, and evidence it was communicated to the people in scope

[[ ]]

[[ ]]

6.1.2

Information security risk assessment

The approved risk method and the results of the risk assessment, with owners

[[ ]]

[[ ]]

6.1.3

Information security risk treatment

The Statement of Applicability, the risk treatment plan and the owners' acceptance of residual risk

[[ ]]

[[ ]]

6.2

Information security objectives and planning to achieve them

The objectives, with measures, owners, dates and the latest results

[[ ]]

[[ ]]

9.2.2

Internal audit programme

The internal audit programme and at least one full cycle of audit reports (IS-06)

[[ ]]

[[ ]]

9.3.3

Management review results

Minutes of at least one management review, with its decisions and actions (IS-06)

[[ ]]

[[ ]]

10.2

Nonconformity and corrective action

The nonconformity log, each entry with root cause, correction, corrective action and effectiveness check (IS-09)

[[ ]]

[[ ]]

Required documents and records

From the Mandatory ISMS Documentation Checklist. Documents are best approved before Stage 1; records are best covering the operating period by Stage 2.

Clause

Documented information

Kind

Blocking?

Ready?

4.3

Scope of the ISMS

Document

Yes

[[ ]]

5.2

Information security policy

Document

Yes

[[ ]]

6.1.2

Risk assessment process

Document

Yes

[[ ]]

6.1.3

Risk treatment process

Document

Yes

[[ ]]

6.1.3

Statement of Applicability

Document

Yes

[[ ]]

6.1.3

Risk treatment plan

Document

Yes

[[ ]]

6.2

Information security objectives

Document

Yes

[[ ]]

7.2

Evidence of competence

Record

[[ ]]

7.5.1

Documented information the organisation decides it needs for the ISMS to be effective

Document

[[ ]]

8.1

Evidence that processes have been carried out as planned

Record

[[ ]]

8.2

Results of risk assessments

Record

[[ ]]

8.3

Results of risk treatment

Record

[[ ]]

9.1

Results of monitoring and measurement

Record

[[ ]]

9.2.2

Internal audit programme and audit results

Record

Yes

[[ ]]

9.3.3

Results of management reviews

Record

Yes

[[ ]]

10.2

Nonconformities, actions taken and results of corrective action

Record

Yes

[[ ]]

Before Stage 1

  • Every required document exists, is approved and is under document control (IS-04).
  • The scope is approved by top management and names interfaces and exclusions with reasons (IS-01, IS-02).
  • The Statement of Applicability traces every inclusion and exclusion to the risk assessment (IS-03).
  • A full internal audit and a management review have been completed (IS-06), by auditors independent of what they audited (IS-07).
  • ISM-01 shows every blocking item at readiness 2 or better.
  • The documents the certification body asked for have been sent, and the Stage 1 plan is confirmed.

Before Stage 2

  • Every Stage 1 area of concern is closed, with evidence.
  • Every blocking item is at readiness 3 (ISM-01); no gap on the critical path is overdue (ISM-03).
  • The ISMS has run for at least [[3]] months, with records (IS-05).
  • Every internal audit nonconformity has a root cause, a correction, a corrective action and an effectiveness check, or a dated plan for one (IS-09).
  • The evidence room is indexed; the populations are ready; a runner is named.
  • Every person on the audit plan has had a mock interview.
  • Rooms, access, screen sharing and the timetable are agreed with the certification body.

Guidance — delete before approval

Mark each line with a date and a name when it is done, and keep the completed checklist as evidence of preparation. If any Stage 2 line is still open two weeks before the audit, raise it with the sponsor that week.

Related documents

Document

Relationship

ISO 27001 Implementation Methodology & Project Plan

The rules, the phases and the plan whose Phase 6 is these two audits

Statement of Applicability Template

What the auditor samples Annex A controls against

Mandatory ISMS Documentation Checklist

The required documents and records the checklist uses

Certification Readiness Self-Assessment

The readiness scale and the monthly reassessment (IS-10)

ISMS Gap & Remediation Tracker

Stage 1 concerns and nonconformities, with owners and dates (IS-08)

ISMS Internal Audit Programme & Procedure

The internal audit that rehearses Stage 2 (IS-06, IS-07)

Management Review Meeting Pack

The management review the auditor will ask about

Adapting this guide

Guidance — delete before approval

Small organisation: Stage 1 may be short and remote, and one person may answer for several areas. Rehearse that person across all of them, and consider a contracted internal auditor for a mock audit a few weeks before Stage 2. The auditor will expect the same records in smaller numbers.

Regulated entity: ISO/IEC 27001:2022 is the requirement the certification body audits against. It will not assess compliance with NIS2, DORA or other laws, and a certificate is evidence of a working management system, not proof of compliance with a law. Regulators and customers may still ask for the certificate and the Statement of Applicability. Make sure the legal and regulatory requirements are listed and reflected in the risk assessment, because the auditor is likely to sample them.

IT run by a service provider: the auditor will sample how you oversee the provider, and may want to see records the provider holds, such as access reviews, backup tests or change records. Agree in advance that the provider will produce them and attend interviews if needed. A provider's own certificate helps only if its scope covers the service you use.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 9.2 — Internal audit

The internal audit as the rehearsal for Stage 2; what the auditor samples; readiness checklist

ISO/IEC 27001:2022

Clause 9.3 — Management review

Management review evidence the auditor asks for at both stages

ISO/IEC 27001:2022

Clause 10.2 — Nonconformity and corrective action

How findings are graded; the nonconformity worked example (IS-09)

ISO/IEC 27001:2022

Clause 7.5 — Documented information

The evidence room; document control sampled at both stages

NIST CSF 2.0

GV.OC-03 — “Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed”

Legal, regulatory and contractual requirements the auditor samples; regulated-entity tailoring

NIST CSF 2.0

ID.IM-01 — “Improvements are identified from evaluations”

Improvements from the audits: nonconformities, opportunities and corrective action

Definitions

Term

Meaning in this guide

Area of concern

A Stage 1 observation that could become a nonconformity at Stage 2 if it is not resolved.

Audit plan

The certification body's timetable for an audit: areas, people, sites and times.

Certification body

An organisation accredited to audit and certify management systems against ISO/IEC 27001.

Evidence room

The indexed collection of documents and records the auditor is given access to.

Major nonconformity

A requirement not met, or a failure that means the ISMS cannot be relied on; it stops certification until corrected and verified.

Minor nonconformity

A requirement partly met, or a single lapse, that does not undermine the system.

Opportunity for improvement

A suggestion from the auditor; no response required.

Population

Every record of one kind in the operating period, from which the auditor draws a sample.

Recertification audit

The full audit before the certificate expires.

Runner

The person who fetches evidence for the auditor and logs each request.

Stage 1 audit

The certification body's review of the documentation and of readiness for Stage 2.

Stage 2 audit

The certification body's audit of the ISMS in operation, by sampling controls and records.

Surveillance audit

A shorter yearly audit between certification and recertification.