Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
Almost everyone treats Stage 1 as a dry run — a friendly look round before the real thing. The rules governing certification bodies do not describe it that way, and two consequences of that are worth knowing before your first visit: the evidence gathered at Stage 1 counts towards the certification decision, and a Stage 1 that goes badly enough can be repeated with Stage 2 cancelled.
Facts checked — 2026-09-11
Stage 1 and Stage 2, side by side
| Stage 1 | Stage 2 | |
|---|---|---|
| Question | Is there a management system, is it understood, and are you ready to be audited? | Is it implemented, and is it effective? |
| Auditor | Reviews your documented system, scope, sites and legal requirements; checks whether internal audit and management review have been planned and performed. | Samples. Tests performance against your own objectives, operational control, legal and contractual compliance, internal audit, management review and management responsibility. |
| Where | Planned so its objectives can be met; you are told in advance which parts are on site. | At your site. |
| Findings | Areas of concern — explicitly identified as things that could be raised as nonconformities at Stage 2. | Nonconformities, major or minor. |
| Worst case | Stage 1 repeated in whole or part, and Stage 2 cancelled. | A major nonconformity, which must be closed before a certificate is issued. |
Paraphrased from ISO/IEC 17021-1:2015 clause 9 — the standard certification bodies are themselves accredited against. It is copyrighted and not reproduced here. The two-stage process applies to ISO management system certification generally, so this is the same for ISO 27001, ISO 22301 and ISO 9001.
What is a Stage 1 audit?
It is the first of the two visits that make up an initial certification audit, and it has seven stated objectives: review your documented management system; evaluate your preparedness for Stage 2; review your status and understanding of the standard’s requirements; obtain the information needed about scope — your sites, the processes and equipment you use, the levels of control you have established, and the statutory and regulatory requirements that apply; settle the Stage 2 arrangements with you; provide a focus for planning Stage 2; and evaluate whether internal audits and management reviews are being planned and performed.
Read that list and the shape of the visit becomes obvious. Six of the seven are about whether the system exists, is understood, and is scoped — and one, the last, is about whether two specific activities have actually happened. Nothing on the list requires the auditor to test whether a control works. That comes later.
One practical note: the rules require your certification body to plan Stage 1 so its objectives can be met, and to tell you in advance which activities will be on site. A Stage 1 conducted largely as a document review with interviews is normal, not a sign you have been given a soft auditor.
Why Stage 1 is not a rehearsal
Two provisions decide this, and neither is widely known outside the audit profession.
The first: when the audit team reaches its conclusions, it analyses all the information and audit evidence gathered during Stage 1 and Stage 2. Not Stage 2 alone. What you said and showed at the first visit is part of the record that produces the recommendation, which means an inconsistency between the two visits is itself something the auditor can see.
The second: in deciding the interval between the two stages, the certification body considers your need to resolve the areas of concern raised at Stage 1 — and may revise its arrangements for Stage 2, or repeat all or part of Stage 1, which means cancelling Stage 2. That is the real risk in a bad Stage 1. Not a hard conversation, but a cancelled second visit, a new date, and a certificate that arrives a quarter later than the one you told your customer about.
So treat it as an audit. Have the documented system finished rather than nearly finished, know your own scope statement well enough to defend its boundaries, and do not plan to build anything between the visits that Stage 1 was supposed to find already built.
The two things Stage 1 checks that most organisations have skipped
Internal audit and management review. They are the last objective on the Stage 1 list, and they are the two activities that feel most like theatre to a team that has spent months on real security work — so they are the two most often postponed until after certification, which is not an option.
Internal audit means somebody has audited your management system against the standard and recorded what they found, with enough independence that they are not auditing their own work. Management review means leadership has formally considered the system — its performance, its risks, its nonconformities, the resources it needs — and recorded decisions. Both must have happened before Stage 1, because Stage 1 asks whether they are being planned and performed, and neither can be produced retrospectively in a way that survives a date check.
This is the single most common reason a first Stage 1 goes worse than expected. Everything technical is in place, the policies are good, the risk assessment is real — and the two governance activities that demonstrate the system runs itself have no records. Schedule both early enough that the internal audit findings have somewhere to go.
What Stage 2 actually tests
Its stated purpose is to evaluate the implementation of your management system, including its effectiveness. That word is doing a lot of work: not whether a control is written down, and not whether it exists, but whether it achieves what you said it would.
It takes place at your site and covers six areas: information and evidence of conformity; performance monitoring, measuring, reporting and reviewing against your own key performance objectives and targets; performance against the statutory, regulatory and contractual requirements that apply to you; operational control of your processes; internal auditing and management review; and management responsibility for your policies.
The method is sampling, and this is what makes Stage 2 different in kind. The auditor picks a control, asks for the records it produced on specific dates, and follows it from your policy through to the evidence that it ran — then asks someone outside the security team about it. A control that was designed but has never operated cannot survive that, because there are no records to sample, and no amount of explanation substitutes for them.
The gap between the visits is the cheapest window you will get
Areas of concern from Stage 1 are, by definition, the things your auditor has told you could be raised as nonconformities at Stage 2. That is a forecast of the second audit, given to you in writing, with time to act on it.
Very few processes hand you the marking scheme in advance. The organisations that certify smoothly are generally not the ones with the fewest Stage 1 concerns — they are the ones that treated the list as a work plan rather than as criticism, closed each item, and could show at Stage 2 not just that it was fixed but when and by whom.
The corollary is that going quiet between the visits is the expensive choice. If an area of concern turns out to need longer than the gap allows, saying so and moving the Stage 2 date costs less than arriving with it open.
After the certificate: when the clock actually starts
Certification runs in a three-year cycle, and the date that starts it is the certification decision — not the last day of Stage 2, and not the day the certificate PDF arrives. The distinction matters because of what it governs.
The first surveillance audit after initial certification must happen no more than twelve months from that certification decision date. After that, surveillance audits run at least once a calendar year, except in recertification years, and recertification comes at the end of the three years.
So the useful thing to record when you are certified is the decision date, and to work backwards from it. Teams that diarise from the certificate’s issue date, or from the audit, can find their first surveillance window is shorter than they planned for — and a missed surveillance audit puts the certificate itself at risk, which is a considerably worse problem than a nonconformity.
Common questions
What is the difference between a Stage 1 and Stage 2 audit?
Stage 1 reviews whether a management system exists, is understood and is ready to be audited — including whether internal audit and management review have been performed. Stage 2 evaluates whether it is implemented and effective, by sampling records at your site. Stage 1 raises areas of concern; Stage 2 raises nonconformities.
Can you fail a Stage 1 audit?
Not in the sense of a pass mark, but the certification body can repeat all or part of Stage 1 and cancel Stage 2 if the areas of concern are serious enough. That is the practical failure mode: a cancelled second visit and a certificate delayed by a quarter, rather than a formal fail.
Do Stage 1 findings count against you at Stage 2?
The evidence does. The audit team reaches its conclusions by analysing all the information and audit evidence gathered during both stages, so Stage 1 is part of the record behind the certification decision. Areas of concern themselves are not nonconformities, but they are an explicit forecast of what could become one.
Do we need an internal audit and management review before Stage 1?
Yes. Evaluating whether internal audits and management reviews are being planned and performed is one of the seven stated objectives of Stage 1. Both need to have genuinely happened, with records, and neither can be produced retrospectively in a way that survives a date check. It is the most common avoidable Stage 1 problem.
How long is the gap between Stage 1 and Stage 2?
There is no fixed interval. The certification body sets it, taking into account your need to resolve the areas of concern raised at Stage 1. Treat that flexibility as useful: a realistic date you meet is better than an early one you arrive at with items still open.
When is the first surveillance audit?
No more than twelve months from the certification decision date — not from the end of Stage 2 or the certificate issue date. Surveillance then runs at least once a calendar year except in recertification years, with recertification at the end of the three-year cycle.
The bottom line
Treat Stage 1 as an audit whose evidence counts, and make sure internal audit and management review have actually happened before it. Then work the areas of concern like a work plan — it is the only time you get the second audit’s marking scheme in advance. And diarise your surveillance from the certification decision date.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.
Certification
Drawing an ISO 27001 scope you can defend, and the clause people skip
The first decision, the cheapest to get right, and the one your customer reads off the certificate.