Priya Deshmukh had eleven weeks until her Stage 2 audit and a $340,000 contract renewal riding on it. Meridian Health Analytics, the mid-sized healthcare data processor she'd joined as CISO nine months earlier, had a signed letter of intent from its largest customer — a regional hospital network — that made ISO 27001 certification a hard contractual deadline. Miss it, and Meridian lost the contract to a competitor who already had the certificate on the wall.
So when the Stage 1 auditor from the certification body arrived on a Tuesday morning, Priya expected a formality. She had a risk register. She had a policy binder. She had, she believed, done the work.
Four hours later, she had a very different picture. The auditor couldn't find a documented scope statement that matched what the SoA actually covered — the ISMS boundary described in one document excluded the outsourced customer support platform that the Statement of Applicability explicitly listed controls for. The risk assessment had been run, but there was no evidence anyone had approved the risk acceptance criteria before scoring began. Internal audit hadn't happened yet — not "in progress," not scheduled, just absent from any plan. And when the auditor asked to see the management review minutes, Priya realized nobody had held one.
None of this was a Stage 2 failure. It was worse, in a way — it was a Stage 1 finding, delivered five weeks before her Stage 2 date was supposed to be locked in, and it meant the certification body would not confirm readiness to proceed. The Stage 2 audit got pushed. The hospital contract's deadline did not move with it. Meridian spent the next six weeks in triage: writing a scope statement that actually matched the SoA, running a compressed internal audit, holding an emergency management review, and re-submitting evidence before the CB would greenlight Stage 2. They made it — barely, and at a cost of nearly $40,000 in expedited consulting fees and lost negotiating leverage on the contract renewal.
Priya's mistake wasn't a lack of security controls. Meridian's technical environment was, if anything, ahead of most of its peers. Her mistake was treating Stage 1 as a rubber stamp instead of what it actually is: a documentation and readiness audit that certification bodies take just as seriously as the technical audit that follows it. This article exists so you don't make the same one.
Who This Is For
This is for anyone within striking distance of a Stage 1 audit — ISMS managers, CISOs, compliance leads, and consultants who've built the management system and now need to prove, on paper and in interviews, that it's real and ready for Stage 2. You'll walk away knowing exactly what a Stage 1 auditor examines, how the audit day itself typically runs, the findings that show up most often and how to close them before the auditor arrives, and a concrete preparation checklist you can start using today. If you're still building your ISMS from scratch, read this alongside the ISO 27001 certification process roadmap to see where Stage 1 fits in the bigger sequence.
What Stage 1 Actually Is (And Isn't)
Stage 1 is a readiness review, not a controls test. The certification body auditor — typically the same lead auditor who will run your Stage 2 — spends anywhere from half a day to two days (scaled to your organization's size and scope complexity) reviewing your documented information and interviewing key people to answer one question: is this ISMS sufficiently established, documented, and understood that a Stage 2 audit would be a meaningful and fair test of it?
They are not, at Stage 1, testing whether your firewall rules are configured correctly, whether your access reviews actually happen on schedule, or whether your incident response plan works when invoked. That operational, evidence-of-effectiveness testing is Stage 2's job. Stage 1 asks a narrower but foundational question: does the paperwork hang together, does it reflect reality, and has the organization done enough of the Plan-Do-Check-Act cycle that a Stage 2 assessor would find something real to audit?
That distinction matters because it changes what "ready" means. You do not need twelve months of control operating evidence for Stage 1. You do need a defined scope, an approved policy, a completed risk assessment and treatment plan, a Statement of Applicability, and a demonstrable plan (ideally already partly executed) for internal audit and management review. Auditors describe this as checking that the ISMS "exists on paper and in practice" before they schedule the deeper Stage 2 dive.
Stage 1 vs. Stage 2: The Critical Difference
Confusing these two audits is the single most common reason organizations walk into Stage 1 underprepared. They over-index on technical evidence Stage 1 won't ask for, and under-index on the documentation coherence it will.
Dimension | Stage 1 Audit | Stage 2 Audit |
|---|---|---|
Primary question | Is the ISMS documented, scoped, and ready to be audited? | Is the ISMS operating effectively and consistently? |
Focus | Documentation review + readiness assessment | Evidence of control operation, interviews, sampling |
Typical duration | 0.5–2 days on-site or remote | 2–5+ days on-site (scales with headcount/scope) |
Auditor activity | Reviews documents, asks clarifying questions, tours facilities (sometimes) | Samples records, interviews control owners, tests evidence trails |
Common outputs | Areas of concern, potential nonconformities, readiness confirmation | Formal nonconformities (minor/major), certification recommendation |
What "failing" looks like | CB delays or declines to schedule Stage 2 | Major NC blocks certification until corrective action verified |
Typical gap before next stage | Weeks (commonly 2–8) for remediation | Certification decision, then surveillance cycle begins |
For a full walkthrough of what happens once you clear Stage 1, see the companion piece on the Stage 2 certification audit walkthrough.
What the Auditor Examines at Stage 1
Every certification body runs Stage 1 slightly differently, but in the 200-plus organizations I've supported through certification, the review consistently converges on the same set of inputs. Treat this as your evidence checklist.
Area Reviewed | What the Auditor Looks For | Typical Evidence Requested |
|---|---|---|
ISMS scope | A defined, documented boundary that matches organizational reality and the SoA | Scope statement, network/data-flow diagrams, list of locations and business units in/out of scope |
Information security policy | Top-management-approved, communicated, reviewed | Approved policy document, distribution/acknowledgment records, review date |
Statement of Applicability | All 93 Annex A controls addressed with justified inclusion/exclusion | SoA document cross-referenced to risk treatment plan |
Risk assessment methodology & results | A repeatable method, applied consistently, with defined criteria | Risk assessment methodology document, completed risk register |
Risk treatment plan | Treatment decisions mapped to controls and owners | Risk treatment plan, control implementation status |
Risk acceptance criteria | Defined and approved before assessment, not after | Approved criteria document with sign-off date |
Objectives and planning | Measurable information security objectives set by management | Objectives register, plans to achieve them |
Roles and responsibilities | Clear ownership for ISMS activities | Org chart, RACI, role descriptions |
Legal and regulatory register | Applicable obligations identified | Legal/regulatory/contractual requirements register |
Internal audit programme | Planned, and ideally at least partially executed | Internal audit programme/schedule, any completed audit reports |
Management review | Planned or held, with the right inputs/outputs | Management review minutes or a scheduled agenda |
Competence and awareness | Evidence people understand their ISMS responsibilities | Training records, awareness campaign evidence |
Mandatory documented information | The full ISO 27001 Clause 4–10 required document set | See mandatory documents checklist below |
Facilities (sometimes) | A walk-through to confirm scope statements match physical reality | Facility access, physical security observations |
That last row catches people off guard — some auditors do walk the floor at Stage 1, particularly if physical locations are in scope, precisely to sanity-check that what's on paper matches what's on the ground.
"Stage 1 is where I find out whether an organization's ISMS is a living system or a folder of templates somebody downloaded three weeks ago. The tell is always consistency — does the scope statement match the SoA, does the SoA match the risk treatment plan, do the risk owners actually know they're risk owners. When those threads don't connect, I can't in good conscience send a team out for Stage 2." — Marcus Webb, Principal Auditor, Veritas Assurance Group
Mandatory Documented Information Under Scrutiny
ISO/IEC 27001:2022 specifies a set of documented information that must exist for the ISMS to conform to the standard — and Stage 1 is where a certification body auditor confirms it's all present, approved, and version-controlled, not just that it exists in draft. This includes the scope, the policy, the risk assessment and treatment methodology and results, the SoA, the risk treatment plan, information security objectives, competence records, monitoring and measurement results, the internal audit programme and results, and management review outputs, among others. If you haven't already mapped your document set against the full required list, work through the ISO 27001 mandatory documents checklist before your Stage 1 date — it's the single fastest way to find gaps while you still have time to close them. Then cross-check your evidence pack itself against PentesterWorld's downloadable Mandatory Documents Checklist, which maps directly to what a Stage 1 auditor asks to see.
Auditors don't expect every document to be perfect prose. They expect it to be approved, dated, owned, and consistent with every other document that references it. A risk register that lists a risk owner who no longer works at the company, or a policy still awaiting the CISO's signature three weeks after the "effective date" printed on it, are the kinds of small inconsistencies that snowball into a Stage 1 finding.
It helps to see exactly which clause drives which document, since that's the structure most Stage 1 auditors use to organize their review.
ISO 27001 Clause | What It Requires | Document Stage 1 Will Ask to See |
|---|---|---|
Clause 4 (Context) | Understanding of internal/external issues, interested parties, scope | Context analysis, interested parties register, scope statement |
Clause 5 (Leadership) | Policy, roles, management commitment | Information security policy, roles/responsibilities matrix |
Clause 6 (Planning) | Risk assessment, risk treatment, objectives | Risk assessment methodology, risk register, SoA, objectives register |
Clause 7 (Support) | Resources, competence, awareness, communication, documented info | Training records, awareness evidence, document control procedure |
Clause 8 (Operation) | Operational planning and control, risk assessment/treatment execution | Evidence of risk treatment plan execution, operational procedures |
Clause 9 (Performance Evaluation) | Monitoring, internal audit, management review | Internal audit programme/reports, management review minutes |
Clause 10 (Improvement) | Nonconformity handling, corrective action, continual improvement | Nonconformity/corrective action log (even if empty, the process must exist) |
How Stage 1 Runs: The Opening Meeting
Stage 1 audits — whether conducted remotely or on-site — follow a rhythm most CBs replicate closely, because it's baked into their accredited audit procedures. The day begins with an opening meeting: the lead auditor introduces themselves and confirms the audit plan, scope, and duration; your ISMS owner (often the CISO or compliance lead) introduces the key personnel who'll be available; and both sides confirm logistics — who's in the room, what documents have already been shared, whether there will be a facility tour.
This meeting is short, usually 15–30 minutes, but it sets the tone. Auditors form early impressions here about whether the organization understands its own ISMS or is performing preparedness for the day. Send your document set in advance where the CB allows it — reviewing cold, on the day, wastes audit time on reading rather than probing, and probing is where genuine gaps surface for both sides to fix.
Who actually needs to be in the room (or on the call) matters more than most organizations plan for. Missing the right person on the day is its own minor readiness failure.
Role | Why Stage 1 Needs Them | When They're Typically Pulled In |
|---|---|---|
ISMS owner / CISO | Owns the overall documentation set and narrative | Present for the full audit |
Top management representative | Confirms leadership commitment, approves policy/objectives | Opening meeting, closing meeting, Clause 5 review |
Risk owner(s) | Explain how specific risks were scored and treated | Risk assessment/treatment review block |
Internal audit lead | Walks through the internal audit programme and any findings | Clause 9 review block |
HR / People lead | Speaks to screening, training, and awareness records | Competence and awareness review block |
Document controller | Demonstrates version control and access management live | Throughout, on request |
Facilities/security lead | Escorts and explains physical security controls | Facility walk-through, if applicable |
Remote vs. On-Site Stage 1: What Changes
Many certification bodies now offer Stage 1 as a remote review, particularly for organizations with a documentation-heavy, low-physical-footprint scope. The mechanics are largely the same; what changes is logistics and the weight given to a physical walk-through.
Factor | Remote Stage 1 | On-Site Stage 1 |
|---|---|---|
Document access | Screen-share or secure portal access | Often reviewed on organization's own systems in person |
Interview logistics | Video calls scheduled in blocks | Walk-up availability, more spontaneous follow-ups |
Facility walk-through | Not possible; may be deferred to Stage 2 | Can happen same day |
Typical suitability | Single-site, cloud-based, documentation-mature organizations | Multi-site, physically sensitive, or first-time CB relationships |
Preparation impact | Screen-sharing rehearsal matters; confirm remote access works | Facility readiness (badges, visitor logs, clear desk) matters more |
The Role of the Lead Auditor and Technical Experts
It's worth understanding who is actually sitting across the table, because it shapes how the review unfolds. Certification bodies typically assign a lead auditor who owns the entire audit relationship — Stage 1, Stage 2, and every subsequent surveillance visit for at least the first certification cycle. That continuity matters: the same person who forms an impression of your ISMS at Stage 1 is the person deciding, at Stage 2, whether the gaps they flagged have actually closed. Building a professional, transparent relationship with that individual starting at Stage 1 pays dividends later.
For organizations with specialized scope — cloud-native architectures, industrial control systems, payment processing environments, or highly regulated healthcare data — the CB may bring in a technical expert alongside the lead auditor. This person isn't auditing independently; they're advising the lead auditor on domain-specific questions the lead auditor may not be equipped to probe alone. If your organization operates in a specialized space, ask your CB during contracting whether a technical expert will be assigned, and if so, request their general background so you can anticipate the kind of questions they're likely to ask.
Auditor continuity and competence are also why the certification body selection conversation matters well before Stage 1 ever gets scheduled — a CB that assigns an auditor with no relevant sector experience will still complete a valid audit, but the questions will be less sharp, and your team may find itself explaining basic industry context instead of getting substantive feedback on gaps that matter.
How Stage 1 Runs: The Documentation Review
The bulk of Stage 1 is spent working through the document set in the table above, usually organized around the clause structure of ISO 27001 (Clauses 4 through 10) rather than a random walk. Auditors will ask to see documents live in your system — not printed and pre-selected — because version-control and access control matter to them as much as content. Expect questions like "who approved this?" "when was it last reviewed?" and "show me where this risk feeds into your treatment plan."
Interviews are woven through the review rather than held separately. The auditor might pull in your risk owner mid-review to ask how they scored a specific risk, or ask your HR lead how screening records are retained. This is deliberate: it tests whether the documented process and the lived process, for even the people who own it, are the same story.
If your organization is small, the lead auditor may do this alone. Larger, more complex scopes sometimes bring a second auditor or a technical expert, particularly where the scope touches specialized environments like cloud infrastructure or OT.
"I tell every client the same thing before Stage 1: the auditor is not your adversary in this meeting. They are trying to find out if Stage 2 will be a fair test. If you show them the gaps yourself and explain your remediation plan, that lands completely differently than them finding the gap unassisted." — Dana Okafor, ISMS Manager, NorthPeak Logistics
How Stage 1 Runs: The Closing Meeting
At the end of the review, the auditor holds a closing meeting to summarize what they found. This is not a surprise — reputable auditors flag concerns as they go, so the closing meeting should confirm rather than ambush. Expect the auditor to walk through: areas that met expectations, areas of concern that need attention before Stage 2, any potential nonconformities they intend to formalize in the written report, and — critically — their recommendation on whether the organization is ready to proceed to Stage 2 and on what timeline.
Ask direct questions here. If the auditor flags a concern, ask what evidence would resolve it and whether they need to see remediation before Stage 2 or whether it can be verified as part of Stage 2 itself. That single conversation often determines whether your Stage 2 date holds or slips.
A Typical Stage 1 Audit Agenda
Time Block | Activity | Who's Involved |
|---|---|---|
9:00–9:30 | Opening meeting: introductions, confirm scope and plan | Lead auditor, ISMS owner, top management rep |
9:30–11:00 | Scope, policy, and leadership commitment review (Clauses 4–5) | ISMS owner, CISO |
11:00–12:30 | Risk assessment methodology, register, and treatment plan review (Clause 6) | Risk owner(s), ISMS owner |
12:30–13:15 | Lunch / auditor prepares interim notes | — |
13:15–14:30 | SoA walkthrough, mandatory documents, competence and awareness records (Clauses 7–8) | HR lead, control owners, ISMS owner |
14:30–15:15 | Internal audit programme and management review status (Clause 9) | Internal audit lead, top management |
15:15–15:45 | Facility walk-through (if applicable) | Facilities/security lead |
15:45–16:30 | Auditor prepares findings summary | — |
16:30–17:00 | Closing meeting: findings, recommendation, next steps | Lead auditor, ISMS owner, top management |
Multi-site or larger scopes stretch this across two days; very small organizations sometimes compress it into half a day.
Stage 1 for Multi-Site and Multi-Entity Organizations
Organizations with more than one physical location, more than one legal entity in scope, or a mix of owned and leased facilities face a version of Stage 1 that's meaningfully more complex than the single-site scenario most guidance assumes. The certification body will typically require a sampling rationale — a documented, risk-based explanation of which sites will actually be visited or reviewed in depth, and why. A CB won't necessarily audit every location during Stage 1 (or even Stage 2), but they will expect your scope statement to name every location, explain how information security is managed consistently across them, and justify the sample the auditor selects.
This is where scope-and-SoA consistency problems compound fastest. I've seen organizations with five warehouses list a single, generic scope statement that implies uniform controls everywhere, when in practice one site had a different landlord-managed physical security arrangement, another ran a legacy network segment nobody had fully documented, and a third was added after an acquisition and had never been formally folded into the ISMS. Each of those differences needs to surface in your documentation before Stage 1, not get discovered by the auditor during it.
Multi-Site Factor | What Stage 1 Auditors Check | Preparation Tip |
|---|---|---|
Consistency of controls across sites | Whether the same policies and controls genuinely apply everywhere claimed | Document site-specific variations explicitly rather than implying uniformity |
Legal entity boundaries | Whether the ISMS scope aligns with the entities named on the certificate | Confirm scope language matches your corporate structure exactly |
Recently acquired or divested sites | Whether integration into the ISMS is complete, partial, or still pending | Flag any site still mid-integration rather than letting the auditor find it |
Sampling rationale | Whether the CB's site-visit sample is justified and risk-based | Ask your CB early how they plan to sample; don't assume every site is visited |
Remote/hybrid workforce | Whether distributed work is captured in scope and controls | Include remote working arrangements explicitly in scope and risk assessment |
Typical Stage 1 Findings and How to Fix Them
Across dozens of Stage 1 audits I've either run as a consultant preparing clients or observed directly, the same handful of gaps recur constantly. None of them require months to fix — most are fixable in 1–3 weeks if caught early, which is exactly why running your own readiness check matters more than anything else in this article.
Finding | Why It Happens | How to Fix It Before the Auditor Arrives |
|---|---|---|
Scope statement doesn't match SoA coverage | Scope written early, SoA updated later without reconciling | Cross-check every location, system, and business unit named in the SoA against the scope document; update both together |
Risk acceptance criteria defined after risk scoring | Teams start assessing risk before formally approving thresholds | Get management sign-off on acceptance criteria first, then re-validate any scoring done before approval |
No internal audit evidence | Organizations save internal audit for "closer to Stage 2" | Run at least one internal audit cycle, even a partial one, before Stage 1 |
No management review held | Same deferral logic as internal audit | Hold a documented management review with the required inputs/outputs before Stage 1 |
SoA exclusions lack justification | Controls marked "not applicable" with no rationale | Write a one-line justification for every exclusion, tied to risk assessment output |
Risk register missing owners | Risks assigned during workshops, owners never formally recorded | Add named, accountable owners to every risk line before the audit |
Policy not formally approved | Draft circulated but never signed off by top management | Get dated sign-off from the accountable executive before Stage 1 |
Competence records incomplete | Training happens informally, never logged | Centralize training/awareness records with dates and completion evidence |
Document version control inconsistent | Multiple copies in shared drives, no single source of truth | Move to a single controlled repository with version history before the audit |
Legal/regulatory register missing or stale | Built once early in the project, never revisited | Review and date-stamp the register within weeks of Stage 1 |
"The scope-versus-SoA mismatch is the one I see most. It's rarely malicious — it's just that scope gets written in month one and the SoA gets finished in month four, and nobody goes back to reconcile them. Fifteen minutes of cross-checking would have caught it." — Tomás Reyes, CISO, Solvera Financial
Areas of Concern vs. Potential Nonconformities
Not every Stage 1 observation is equal, and understanding the difference changes how you should react to it. An "area of concern" is the auditor flagging something that isn't yet a formal nonconformity but that, left unaddressed, likely will become one at Stage 2 — a thin risk treatment plan, a management review agenda that's missing a required input, a competence record that's only partially complete. A "potential nonconformity" is stronger language: the auditor believes, based on what they've seen, that a specific clause or control requirement is not currently met, and they expect to see it resolved, or a credible remediation plan, before Stage 2 proceeds.
The practical difference matters for triage. Areas of concern are typically things you can fix in the weeks before Stage 2 without needing the CB to re-verify anything at Stage 1 itself. Potential nonconformities sometimes require the auditor to see evidence of correction before they'll commit to a Stage 2 date at all — which is exactly the trap Priya at Meridian fell into with her missing internal audit and management review.
Neither term appears in casual conversation with every auditor the same way — some CBs use "observations" and "concerns" instead of ISO's stricter nonconformity language until Stage 2. Ask your auditor directly, in the closing meeting, which category each item falls into and what they expect to see resolved before they'll green-light Stage 2 scheduling.
The Stage 1 Flow, End to End
It helps to see the whole sequence as one continuous flow rather than a single event on a calendar. Preparation quality at the front end determines how painless — or painful — the remediation step at the back end turns out to be.
flowchart LR
A[Internal Prep:<br/>docs, scope, SoA,<br/>risk assessment] --> B[Documentation Review:<br/>auditor examines evidence]
B --> C[Readiness Assessment:<br/>auditor forms a view]
C --> D[Stage 1 Report:<br/>concerns, potential NCs,<br/>readiness recommendation]
D --> E{Ready for Stage 2?}
E -->|Yes, minor items only| F[Address areas of concern<br/>in parallel]
E -->|No, significant gaps| G[Remediate before<br/>Stage 2 is scheduled]
F --> H[Stage 2 Audit]
G --> HNotice that the loop back to remediation isn't a failure state baked into the process — it's the entire reason Stage 1 exists as a separate step from Stage 2 in the first place. Catching a gap here, weeks before Stage 2, is inexpensive. Catching the same gap during Stage 2 risks a formal nonconformity on your certification record.
How to Prepare: Building Your Stage 1 Evidence Pack
The organizations that walk into Stage 1 calmly are the ones that build an "evidence pack" weeks in advance rather than scrambling to assemble documents the night before. An evidence pack is simply every document from the auditor-examines table above, gathered in one controlled location, each one checked for three things: is it approved by the right person, is it dated within a sensible review cycle, and does it agree with every other document that references it.
That last check — cross-document consistency — is where most last-minute problems live. Walk your scope statement line by line against your SoA. Walk your risk register against your risk treatment plan and confirm every treated risk maps to a specific Annex A control or a documented rationale for going outside Annex A. Walk your org chart against the roles named in your risk register and your incident response plan. None of this requires new work — it requires an afternoon of deliberate reconciliation, and it is the single highest-leverage prep activity available to you.
If you're assembling this evidence pack for the first time and want a single reference that walks through the full document set clause by clause, PentesterWorld's Complete ISO 27001 Implementation Guide eBook covers exactly this ground in more depth than a single article can.
The Stage 1 Preparation Checklist
Preparation Task | Owner | Target Timing Before Stage 1 |
|---|---|---|
Confirm scope statement matches SoA coverage exactly | ISMS manager | 4–6 weeks out |
Obtain top-management sign-off on the information security policy | CISO / top management | 4–6 weeks out |
Approve risk acceptance criteria before finalizing risk scores | Risk committee | 4–6 weeks out |
Complete risk assessment and risk treatment plan with named owners | Risk owners | 3–4 weeks out |
Finalize SoA with justification for every inclusion/exclusion | ISMS manager | 3–4 weeks out |
Run at least one internal audit cycle (full or partial scope) | Internal audit lead | 3–4 weeks out |
Hold a documented management review meeting | Top management | 2–3 weeks out |
Centralize competence and awareness training records | HR / People lead | 2–3 weeks out |
Update legal, regulatory, and contractual requirements register | Compliance lead | 2–3 weeks out |
Move all controlled documents into a single version-controlled repository | Document controller | 2 weeks out |
Run an internal mock Stage 1 review | ISMS manager + consultant/internal audit | 1–2 weeks out |
Brief interviewees on likely questions and their own role evidence | ISMS manager | 1 week out |
Confirm logistics: rooms, remote access, facility tour route | Admin / facilities | 1 week out |
Warning Signs You're Not Actually Ready
Before you even schedule a mock Stage 1, run this quick gut-check. If more than two or three of these are true, push your Stage 1 date rather than hoping the auditor won't notice.
Warning Sign | What It Usually Means |
|---|---|
Nobody can produce a single, current version of the scope statement on demand | Scope has drifted or was never centrally owned |
The SoA was finished weeks after the scope statement, and nobody reconciled them | Almost guaranteed scope/SoA mismatch |
Risk scoring happened before acceptance criteria were formally approved | Risk assessment methodology will be questioned |
Internal audit is "on the roadmap" rather than scheduled with a date | Stage 1 will likely flag it as missing |
No management review has ever been held | Guaranteed Stage 1 concern at minimum |
Training records live in people's inboxes rather than a central system | Competence evidence will be hard to produce live |
Nobody has walked the SoA control-by-control against the risk treatment plan | Exclusion rationale will be weak or missing |
Running a Mock Stage 1
The highest-return activity on that checklist, by a wide margin, is the mock Stage 1 itself. A mock audit means putting someone who did not build your documentation — an internal auditor from a different part of the business, or an external consultant — in the auditor's seat and having them run the exact same document walkthrough and interview questions a real CB assessor would use. The value isn't in confirming what you already know is solid. It's in exposing the blind spots that come from having built the ISMS yourself: the assumptions you didn't realize you were making, the cross-references you assumed were obvious.
I run these regularly with clients using a structured walkthrough modeled directly on real Stage 1 procedure — reviewing scope, policy, risk documentation, SoA, and audit/review evidence in the same sequence and with the same probing questions a CB auditor uses, then producing a findings list exactly like the one a real Stage 1 report would contain. PentesterWorld's Mock Stage 1 Documentation Review lab walks through this exact exercise so you can run it internally before you ever pay a certification body for the real thing. Organizations that run a mock Stage 1 two to three weeks before the real one consistently walk away from the actual audit with zero potential nonconformities — because they've already found and fixed them.
"We ran a mock Stage 1 the month before our real one and found four things we'd have otherwise handed the auditor on a plate — including a management review that technically happened but never got minuted. Fixing that took two hours. Finding it during the real audit would have cost us weeks." — Grace Lin, Internal Audit Lead, Bellwether Systems
Scope Statement Readiness
Your scope statement is the first document most Stage 1 auditors read, because everything else in the ISMS is measured against it. If your scope excludes a business unit, a data center, or a SaaS platform that your risk assessment or SoA quietly includes controls for, that inconsistency is often the very first thing flagged. Before Stage 1, revisit your scope against the practical guidance in defining the scope of your ISMS and confirm it still reflects the organization as it exists today — not as it existed when the scope was first drafted, often months or a year earlier. Scope drift is normal as businesses grow, acquire, or outsource; undocumented scope drift is the Stage 1 finding.
Statement of Applicability Readiness
The SoA is arguably the single document a Stage 1 auditor scrutinizes hardest, because it's the bridge between your risk assessment and your actual control implementation. Every one of the 93 Annex A controls needs a clear inclusion or exclusion decision with a rationale tied back to risk assessment output — not a blanket "not applicable" applied to save time. If you haven't already, walk through how to create a Statement of Applicability and confirm every control decision in your current SoA still has a documented reason behind it, especially for any control you've marked out of scope. Auditors ask "why isn't this one applicable to you?" far more often than people expect, and "we didn't think about it" is not an acceptable answer.
Risk Assessment Readiness
Because so much of the rest of the ISMS flows from it, your risk assessment gets disproportionate attention at Stage 1. The auditor wants to see a defined, repeatable methodology — not just a spreadsheet of guesses — applied consistently across the scope, with acceptance criteria approved before scoring began. If your methodology or your register feels thin, revisit the ISO 27001 risk assessment methodology step-by-step guide and confirm every risk has a named owner, a documented likelihood/impact rationale, and a clear link to a treatment decision in your SoA or treatment plan. A risk assessment that exists but can't be explained consistently by the people who ran it is functionally the same, to an auditor, as no risk assessment at all.
Internal Audit and Management Review Readiness
These two activities are the ones organizations most often defer — and the ones that most reliably produce a Stage 1 concern when they're missing. Internal audit and management review aren't Stage 2 requirements you can save for later; they're evidence the ISMS has actually started operating the Plan-Do-Check-Act cycle the standard requires, and Stage 1 auditors look for at least a credible start. Work through the full mechanics in ISO 27001 internal audit: planning, execution, and reporting if you haven't run a cycle yet, and don't wait until the week before Stage 1 to schedule your first one — a rushed internal audit with no real findings looks exactly like what it is to an experienced auditor. PentesterWorld's Internal Audit Checklist is a practical way to structure that first cycle so it produces genuine, defensible findings rather than a box-ticking exercise.
What the Stage 1 Report Actually Contains
A few days after the audit, the certification body issues a formal Stage 1 report. It typically includes: a summary of what was reviewed and by whom; a list of areas of concern with enough detail to act on them; any potential nonconformities the auditor intends to track into Stage 2; a statement of the auditor's overall recommendation — proceed to Stage 2 as planned, proceed with named conditions, or delay pending remediation; and, often, a proposed Stage 2 date or date range.
Read this report as a to-do list, not a verdict. Even a clean Stage 1 report with zero concerns doesn't mean Stage 2 is guaranteed to pass — it means the CB believes Stage 2 will be a fair and meaningful test of an ISMS that's actually operating. Conversely, a report with several areas of concern isn't a failure; it's the system working as designed, giving you the runway to fix things before they become certification-blocking nonconformities.
Reading Between the Lines: What Auditors Really Mean
Auditors are professionally careful with language, and it pays to learn to read it precisely. "We'd like to see more maturity in X before Stage 2" usually means: this exists, but the evidence trail is thin — expect this to be a focal point in Stage 2 sampling. "We were unable to confirm Y" often means: you told us this happens, but you couldn't show us records, so treat this as a near-certain Stage 2 nonconformity unless you fix the evidence gap. "This appears not yet operational" is close to as direct as auditors get before Stage 2 — it means don't expect leniency if this hasn't changed by the next visit.
The most useful thing you can do in the closing meeting is ask the auditor, plainly, "if nothing changes between now and Stage 2, what happens to this item?" Good auditors will answer directly, because a well-prepared Stage 2 serves everyone's interests — including theirs.
The Gap Between Stage 1 and Stage 2
Stage 1 findings exist precisely because certification bodies expect a gap between the two stages — time deliberately built into the process for remediation. What changes between Stage 1 and Stage 2 isn't a new set of documents; it's evidence that the documents you already showed the auditor are being lived. A risk treatment plan that was a spreadsheet at Stage 1 needs, by Stage 2, to show controls actually implemented against it. An internal audit programme that existed as a schedule at Stage 1 needs, by Stage 2, at least one completed cycle with tracked findings. A management review that was "planned" at Stage 1 needs minutes, decisions, and follow-up actions by Stage 2.
This is also where organizational discipline gets tested. It's easy to treat the weeks after a clean Stage 1 report as a green light to relax. The organizations that stumble at Stage 2 are frequently the ones that treated Stage 1's pass as the finish line rather than the starting gun for the operational evidence-building that Stage 2 will actually sample.
How Much Time to Leave Between Stage 1 and Stage 2
There's no ISO-mandated minimum gap, but certification bodies and experienced practitioners converge on a practical range based on how much genuine operating evidence the ISMS still needs to accumulate.
Stage 1 Outcome | Typical Gap Before Stage 2 | What Happens in Between |
|---|---|---|
Clean report, no significant concerns | 4–8 weeks | Continue normal operation; gather ongoing evidence (logs, reviews, training records) |
Minor areas of concern noted | 6–10 weeks | Close specific gaps (e.g., finish a training cycle, complete a review) |
Potential nonconformities flagged | 8–12+ weeks | Substantive remediation: policy re-approval, a full internal audit cycle, management review, sometimes a follow-up evidence submission to the CB |
Significant gaps (scope/SoA misalignment, no ISMS operation evidence) | 3+ months, sometimes a re-scheduled Stage 1 | Rebuild core documentation and operate the ISMS for a meaningful period before requesting a new Stage 1 or Stage 2 date |
Rushing this gap to protect a contractual deadline — as Priya at Meridian nearly did — tends to produce exactly the kind of superficial fixes that show up as fresh nonconformities at Stage 2. Build your certification timeline backward from a realistic Stage 1-to-Stage 2 gap, not forward from the date you'd prefer.
What Happens If Stage 1 Recommends Against Proceeding
The worst-case Stage 1 outcome isn't a long list of areas of concern — it's the auditor concluding that the ISMS is far enough from ready that scheduling Stage 2 wouldn't be a meaningful exercise for either party. This happens less often than organizations fear, but it does happen, typically when core elements are missing entirely rather than merely thin: no risk assessment at all, a scope statement that doesn't correspond to any real operational boundary, or a policy that was never actually approved by anyone with the authority to approve it.
In that scenario, the certification body will usually recommend a substantial remediation period — often three months or more — before a new Stage 1 is scheduled, sometimes requiring a fresh contract or revised statement of work depending on how much time has elapsed. This is not the same as failing Stage 2 and needing corrective action; it's the CB declining to certify that the organization is even ready to be tested. The financial impact is usually larger than a standard remediation delay, because it typically means re-paying part or all of the Stage 1 audit fee and absorbing months of lost calendar time against whatever business deadline drove the certification project in the first place.
The good news is that this outcome is almost entirely avoidable with basic preparation. In my experience, organizations that land here didn't lack security maturity — they lacked project management discipline around the ISMS documentation itself, often because certification was delegated to a single overworked person with no dedicated time or budget. If your ISMS effort has one person doing it alongside a full-time unrelated job, treat that as a flashing warning sign long before you ever book a Stage 1 date.
Common Mistakes Organizations Make Before Stage 1
Mistake | Consequence | Better Approach |
|---|---|---|
Treating Stage 1 as a formality | Walking in with technical evidence but incoherent documentation | Prepare for Stage 1 as seriously as Stage 2 — it's a real gate, not a courtesy visit |
Deferring internal audit and management review to "closer to Stage 2" | Both show up missing at Stage 1, triggering a delay | Schedule and run at least partial cycles of both well before Stage 1 |
Building scope and SoA in isolation from each other | Mismatches surface as the first and most common Stage 1 finding | Reconcile scope and SoA together, every time either changes |
Choosing a certification body without checking accreditation scope or industry fit | Delays or re-scoping once the CB realizes they can't audit your scope | Confirm CB accreditation and sector experience before contracting — see the guide on choosing an ISO 27001 certification body |
Assuming Stage 1 findings are a failure | Teams panic or become defensive instead of remediating calmly | Understand areas of concern are the process working as designed |
Not briefing interviewees before the audit | Inconsistent answers between documented process and what people say | Run a short briefing so control owners know what they'll likely be asked |
Skipping a mock Stage 1 entirely | Real audit becomes the first time gaps surface | Run an internal mock review 1–2 weeks before the real date |
Locking in a Stage 2 date before Stage 1 findings are known | Contractual or customer deadlines collide with remediation needs | Treat the Stage 2 date as provisional until the Stage 1 report is in hand |
Budgeting Time and Cost for Stage 1 Preparation
Organizations consistently underbudget the internal labor cost of Stage 1 preparation, treating it as a rounding error next to the technical control implementation work. In practice, the reconciliation and evidence-gathering work described throughout this article takes real, dedicated hours — and skipping that budget is exactly how teams end up scrambling the week before the audit.
Preparation Activity | Typical Internal Time Investment | Who Usually Does the Work |
|---|---|---|
Scope/SoA reconciliation | 4–8 hours | ISMS manager |
Risk register and treatment plan cleanup | 8–16 hours | Risk owners + ISMS manager |
Internal audit cycle (first full or partial cycle) | 20–40 hours | Internal audit lead + control owners |
Management review preparation and meeting | 6–10 hours | Top management + ISMS manager |
Competence/training record consolidation | 4–8 hours | HR / People lead |
Mock Stage 1 review (planning, execution, remediation) | 16–30 hours | External facilitator + internal team |
Document repository consolidation | 6–12 hours | Document controller |
Add these up for a mid-sized organization and you're typically looking at 65–125 internal labor hours spread across four to six weeks, plus whatever external consulting or CB fees apply. Budget for it explicitly in your certification project plan rather than assuming it will absorb into people's existing workload — that assumption is precisely what produced Meridian's six-week scramble.
Case Study: Meridian Health Analytics — The Cost of Treating Stage 1 as a Formality
Returning to Priya Deshmukh's story: Meridian's Stage 1 findings weren't really about missing security controls — the technical environment was solid. They were about documentation discipline nobody had prioritized: a scope statement drafted in month one that nobody revisited when the SoA was finalized in month four, a risk acceptance framework approved after risk scoring rather than before it, and an internal audit and management review that existed only as line items on a project plan, never actually executed.
The remediation cost Meridian just under $40,000 in expedited consulting support and internal overtime across six weeks, plus a tense renegotiation with the hospital network client to push the certification deadline by five weeks. The certificate ultimately came through, and the contract renewed — but Priya has since told me the entire crisis was avoidable with roughly sixteen hours of deliberate document reconciliation and one internal audit cycle scheduled a month earlier. Meridian now runs a mock Stage 1 review ahead of every surveillance audit, not just the initial certification.
What made the recovery possible was triage discipline rather than panic. Priya's team didn't try to fix everything simultaneously; they ranked the Stage 1 concerns by which ones the CB had flagged as potential nonconformities versus areas of concern, closed the potential nonconformities first with documented evidence, and negotiated directly with the auditor about which items could be verified during Stage 2 itself rather than requiring pre-verification. That triage conversation — treating the auditor as a partner in sequencing the fix rather than an adversary to be managed — is, in Priya's own words, the single thing she'd tell any peer CISO facing a similar Stage 1 report.
Case Study: NorthPeak Logistics — A Clean Stage 1 Built on a Mock Audit
NorthPeak Logistics, a 340-employee freight and warehousing company pursuing ISO 27001 to satisfy a major retail customer's vendor security requirements, took a different path. Its ISMS manager, Dana Okafor, scheduled a full-day mock Stage 1 review three weeks before the real audit, run by an internal auditor from NorthPeak's finance risk team who had no involvement in building the ISMS documentation.
The mock review surfaced four gaps: an outdated legal and regulatory register that hadn't been touched in eight months, two risk register entries with a departed employee still listed as owner, a management review that had happened but was never formally minuted, and a handful of SoA exclusions with no written justification. Every one of them was fixed within twelve days. When the real Stage 1 auditor arrived, the review closed in one day with zero areas of concern and a straightforward recommendation to proceed to Stage 2 on the original schedule — no delay, no renegotiation, no scramble. NorthPeak's total incremental cost for the mock exercise was roughly $6,000 in internal auditor time, against what Dana estimates would have been a minimum four-week delay had the same gaps surfaced during the real audit.
Dana credits the choice of internal auditor as much as the exercise itself. Pulling someone from finance risk rather than the security team meant the mock reviewer had no stake in defending existing documentation and no assumptions about what "obviously" made sense — they asked the same naive-but-pointed questions a real CB auditor would, like "who told you this control applies here" and "show me where that's written down." NorthPeak has since folded a lightweight version of this mock review into its annual surveillance audit preparation, treating it as standard practice rather than a one-time initial-certification exercise.
Case Study: Solvera Financial — When a Missing Risk Treatment Plan Nearly Sank the Timeline
Solvera Financial, a fintech processor pursuing certification to support enterprise banking clients, hit a different wall. Its risk assessment was thorough and its SoA was well-constructed — but the risk treatment plan connecting the two existed only as informal notes in project management tickets, not as a controlled document with named owners and target dates. The Stage 1 auditor flagged it as a potential nonconformity rather than a minor area of concern, because without a consolidated treatment plan there was no way to verify that identified risks were actually being addressed in a structured way.
CISO Tomás Reyes and his team spent three weeks consolidating eighteen months of scattered treatment decisions into a single controlled risk treatment plan, cross-referencing every entry against the SoA and assigning accountable owners with realistic target dates. The certification body required a follow-up evidence submission — not a full re-visit — before confirming the Stage 2 date, adding roughly five weeks to Solvera's original timeline. Tomás's takeaway, which he's repeated to every peer CISO who'll listen: "Track risk treatment as a living, owned document from day one, not a side effect of the risk assessment workshop."
The deeper lesson from Solvera is that a strong risk assessment and a strong SoA aren't sufficient on their own — the connective tissue between them is a distinct deliverable that needs its own owner, its own review cadence, and its own place in the controlled document set. Tomás now requires his risk committee to review the treatment plan as a standing agenda item every month, specifically so it never again drifts into informal tracking between formal reviews.
Case Study Outcomes at a Glance
Three organizations, three different starting points, and a stark illustration of what preparation is actually worth in dollars and weeks.
Organization | Stage 1 Outcome | Root Cause | Remediation Cost | Timeline Impact |
|---|---|---|---|---|
Meridian Health Analytics | Delay recommended; multiple potential nonconformities | Scope/SoA mismatch, no internal audit or management review evidence | ~$40,000 in expedited consulting and overtime | 5–6 week delay, contract renegotiation |
NorthPeak Logistics | Clean pass, zero areas of concern | Ran a mock Stage 1 three weeks early and fixed findings | ~$6,000 in internal auditor time | No delay; original schedule held |
Solvera Financial | Potential nonconformity on risk treatment plan | Risk treatment tracked informally, not as a controlled document | ~3 weeks of consolidation effort plus follow-up CB review | ~5 week delay |
The pattern holds across every organization I've supported through this stage: the cost of finding a gap during preparation is a rounding error compared to the cost of the same gap surfacing in front of the certification body.
Choosing the Right Certification Body Shapes Stage 1 Too
Stage 1 outcomes are also shaped by a decision made months earlier: which certification body you engaged. A CB with genuine experience in your sector will ask sharper, more relevant questions — and will also be less likely to flag a legitimate industry-specific risk treatment approach as a concern simply because it's unfamiliar to them. Before you sign with a CB, confirm their accreditation actually covers your scope and industry code, and ask how their Stage 1 process typically runs — remote or on-site, single auditor or team, typical duration for an organization your size. The guide on how to choose an ISO 27001 certification body covers the accreditation and scoping questions worth asking before you commit.
A Note for Organizations Also Pursuing SOC 2
Many of the organizations I work with are pursuing ISO 27001 and SOC 2 in parallel, often because different customers demand different frameworks. The good news is that the documentation discipline Stage 1 demands — a defined scope, a real risk assessment, evidence of ongoing monitoring — overlaps substantially with what a SOC 2 Type II auditor expects to see during their own readiness review. If you're running both processes, it's worth aligning your ISO 27001 Stage 1 preparation with your SOC 2 readiness assessment timeline so the same evidence pack serves both audits rather than duplicating the reconciliation work twice. The same logic applies if your organization is also mapping to the NIST Cybersecurity Framework for a customer or regulator — the underlying risk assessment and control evidence rarely needs to be built twice, only cross-referenced.
"Looking back, our Stage 1 finding was the best thing that happened to our certification project. It hurt, and it cost us real money, but it forced discipline into our documentation that would otherwise have surfaced as a formal nonconformity at Stage 2 — with our biggest customer watching the clock." — Priya Deshmukh, CISO, Meridian Health Analytics
Stage 1 as a Business Opportunity, Not Just a Gate
It's tempting to think of Stage 1 purely as an obstacle between your organization and a certificate — something to survive rather than something to use. I'd push back on that framing after fifteen years of watching organizations go through this process. A well-prepared Stage 1 is a genuinely useful forcing function: it's the moment your organization is required, by an external and objective party, to prove that security governance isn't just a slide deck for the board but a functioning system with real owners, real evidence, and real discipline.
Organizations that treat Stage 1 preparation seriously tend to walk away from it with more than a favorable report — they walk away with a genuinely more mature ISMS, a leadership team that has now sat through a real management review, and an internal audit function that's run at least one real cycle instead of existing only on paper. That maturity compounds. It shows up in a smoother Stage 2, a cleaner first surveillance audit a year later, and a security program that can credibly support new sales conversations with customers who ask hard security questions before they'll sign a contract. Certification, done right, isn't paperwork theater — it's a competitive asset, and Stage 1 is where you either start building that asset seriously or you don't.
"Clients ask me all the time whether Stage 1 prep is worth the time investment given how much work Stage 2 still requires afterward. My answer is always the same: everything you do well for Stage 1 is work you don't have to redo, panicked, in the six weeks before Stage 2." — Elena Vasquez, Principal Consultant, Cascade Compliance Partners
If you want a second set of eyes on your Stage 1 readiness before you commit to a date with your certification body, PentesterWorld's consulting team runs exactly this kind of pre-audit review — reconciling scope, SoA, risk documentation, and audit/review evidence against what a real CB auditor will ask for, and handing you a prioritized punch list instead of a surprise. Reach out through PentesterWorld's ISO 27001 advisory services to schedule a readiness review, or start with our Certification Readiness Checklist if you'd rather run the first pass yourself. Either way, the goal is the same one this whole article has been building toward: walk into Stage 1 knowing exactly what's coming, and walk out of it with a clear, short path to Stage 2 — not a surprise six-week detour like the one Meridian Health Analytics barely survived.
Quick Reference: Stage 1 at a Glance
Question | Answer |
|---|---|
What is it? | A documentation and readiness review conducted by your certification body before Stage 2 |
How long does it take? | 0.5–2 days, scaled to organization size and scope complexity |
Who's involved? | Lead auditor, ISMS owner/CISO, risk owners, HR, internal audit lead, top management |
What's reviewed? | Scope, policy, SoA, risk assessment/treatment, mandatory documents, internal audit and management review status |
What are the possible outcomes? | Clean readiness confirmation; areas of concern; potential nonconformities; recommendation to delay Stage 2 |
What's the best single prep step? | A mock Stage 1 review 1–3 weeks before the real audit |
How much gap before Stage 2? | Typically 4–12+ weeks depending on findings severity |
Related Reading and Tools
Resource | Why It Helps |
|---|---|
See exactly where Stage 1 sits in the full certification sequence | |
Understand what changes once you clear Stage 1 | |
ISO 27001 internal audit: planning, execution, and reporting | Build the internal audit evidence Stage 1 checks for |
Confirm your full required document set is present | |
ISO 27001 Statement of Applicability (SoA): how to create one | Reconcile your SoA before the auditor does it for you |
Make sure your scope statement matches organizational reality | |
Strengthen the document Stage 1 auditors scrutinize hardest | |
Pick a CB whose Stage 1 process and sector experience fit your organization | |
Look up any Stage 1 term you encountered in this article |
