Fundamentals

ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different

Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.

The one-paragraph difference

Stage 1 asks: is your ISMS designed and documented? — the auditor reviews scope, policies, risk assessment, Statement of Applicability, internal audit, and management review records. Stage 2 asks: does the ISMS actually operate? — interviews, sampling, and evidence that controls work in practice. Stage 1 finds paperwork gaps; Stage 2 finds reality gaps.

Side-by-side

Stage 1Stage 2
TestsDocumentation and design readinessOperating effectiveness of the ISMS
DurationTypically 1–2 days2–10+ days by size and scope
FormatOften remote; document review + interviewsUsually on-site; interviews, sampling, site visits
OutputFindings to fix before Stage 2 — no certificateRecommendation for certification (or not)
Gap between stagesTypically 2–8 weeks to remediate Stage 1 findings

What sinks companies at Stage 1

What sinks companies at Stage 2

The common mistake

Treating Stage 1 as a formality and rushing into Stage 2 with open findings. The fix window between stages exists for a reason — use it. A clean Stage 1 makes Stage 2 shorter, calmer, and cheaper.

Frequently asked

Can Stage 1 and Stage 2 happen back to back?

Sometimes, but it's risky: with no remediation window, any Stage 1 finding becomes a Stage 2 problem. Most CBs recommend 2–8 weeks between them.

Does Stage 1 have to be on-site?

Often not — many CBs run Stage 1 remotely. Stage 2 is usually on-site, especially for first certifications.

Related reading

Get quotes from accredited CBs

One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.

Get a free quote

More guides

Certification bodies

How to Choose an ISO 27001 Certification Body: 8 Questions to Ask

The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.

Comparisons

ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?

Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.

Costs

How ISO 27001 Audit Fees Are Actually Calculated (Audit Days Explained)

ISO/IEC 27006 tables, day rates, and why two CBs quote different fees for the same company — plus how to sanity-check any quote.