Get Demo
↑

ISO 27001 Stage 1 vs Stage 2 Audit: What Auditors Check

ISO 27001 certification audits: Stage 1.

Published: September 2026 Compliance · ISO 27001 10–14 min read

Accredited certification to ISO/IEC 27001 uses a two-stage initial audit model under management-system certification rules (ISO/IEC 17021-1 family / ISO/IEC 27006 for ISMS). This page separates Stage 1 from Stage 2, then summarizes the ongoing cycle.

Cycle lock: Typical certificate validity is three years with annual surveillance, then recertification. Exact plans are set by your CAB.

Stage 1 — What Auditors Check

Stage 2 — What Auditors Check

After Certification

Surveillance audits typically occur annually. Recertification occurs at the end of the ~3-year cycle.

Operationalize ISO 27001:2022 with Continuous Evidence

CyberSilo CSA tracks SoA and mandatory records; ThreatHawk supports logging and monitoring artefacts for technological controls.

Frequently Asked Questions

What is Stage 1?

The initial certification audit stage focused on reviewing documented information and readiness of the ISMS for Stage 2 (certification-body practice under ISO/IEC 17021-1 / ISO/IEC 27006).

What is Stage 2?

The on-site (or remote-equivalent) evaluation of ISMS implementation and effectiveness before a certification decision.

How long is the certificate cycle?

Typically three years, with annual surveillance audits, then recertification — per accredited certification practice.

ISO 27001 hub · 93 controls · SoA · CSA · How long certification takes

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!