ISO27001

ISO 27001 Stage 1 Audit: What to Expect and How to Prepare

ISO 27001 Stage 1 Audit: What to Expect and How to Prepare
Loading advertisement...
21

Priya Deshmukh had eleven weeks until her Stage 2 audit and a $340,000 contract renewal riding on it. Meridian Health Analytics, the mid-sized healthcare data processor she'd joined as CISO nine months earlier, had a signed letter of intent from its largest customer — a regional hospital network — that made ISO 27001 certification a hard contractual deadline. Miss it, and Meridian lost the contract to a competitor who already had the certificate on the wall.

So when the Stage 1 auditor from the certification body arrived on a Tuesday morning, Priya expected a formality. She had a risk register. She had a policy binder. She had, she believed, done the work.

Four hours later, she had a very different picture. The auditor couldn't find a documented scope statement that matched what the SoA actually covered — the ISMS boundary described in one document excluded the outsourced customer support platform that the Statement of Applicability explicitly listed controls for. The risk assessment had been run, but there was no evidence anyone had approved the risk acceptance criteria before scoring began. Internal audit hadn't happened yet — not "in progress," not scheduled, just absent from any plan. And when the auditor asked to see the management review minutes, Priya realized nobody had held one.

None of this was a Stage 2 failure. It was worse, in a way — it was a Stage 1 finding, delivered five weeks before her Stage 2 date was supposed to be locked in, and it meant the certification body would not confirm readiness to proceed. The Stage 2 audit got pushed. The hospital contract's deadline did not move with it. Meridian spent the next six weeks in triage: writing a scope statement that actually matched the SoA, running a compressed internal audit, holding an emergency management review, and re-submitting evidence before the CB would greenlight Stage 2. They made it — barely, and at a cost of nearly $40,000 in expedited consulting fees and lost negotiating leverage on the contract renewal.

Priya's mistake wasn't a lack of security controls. Meridian's technical environment was, if anything, ahead of most of its peers. Her mistake was treating Stage 1 as a rubber stamp instead of what it actually is: a documentation and readiness audit that certification bodies take just as seriously as the technical audit that follows it. This article exists so you don't make the same one.

Who This Is For

This is for anyone within striking distance of a Stage 1 audit — ISMS managers, CISOs, compliance leads, and consultants who've built the management system and now need to prove, on paper and in interviews, that it's real and ready for Stage 2. You'll walk away knowing exactly what a Stage 1 auditor examines, how the audit day itself typically runs, the findings that show up most often and how to close them before the auditor arrives, and a concrete preparation checklist you can start using today. If you're still building your ISMS from scratch, read this alongside the ISO 27001 certification process roadmap to see where Stage 1 fits in the bigger sequence.

What Stage 1 Actually Is (And Isn't)

Stage 1 is a readiness review, not a controls test. The certification body auditor — typically the same lead auditor who will run your Stage 2 — spends anywhere from half a day to two days (scaled to your organization's size and scope complexity) reviewing your documented information and interviewing key people to answer one question: is this ISMS sufficiently established, documented, and understood that a Stage 2 audit would be a meaningful and fair test of it?

They are not, at Stage 1, testing whether your firewall rules are configured correctly, whether your access reviews actually happen on schedule, or whether your incident response plan works when invoked. That operational, evidence-of-effectiveness testing is Stage 2's job. Stage 1 asks a narrower but foundational question: does the paperwork hang together, does it reflect reality, and has the organization done enough of the Plan-Do-Check-Act cycle that a Stage 2 assessor would find something real to audit?

That distinction matters because it changes what "ready" means. You do not need twelve months of control operating evidence for Stage 1. You do need a defined scope, an approved policy, a completed risk assessment and treatment plan, a Statement of Applicability, and a demonstrable plan (ideally already partly executed) for internal audit and management review. Auditors describe this as checking that the ISMS "exists on paper and in practice" before they schedule the deeper Stage 2 dive.

Stage 1 vs. Stage 2: The Critical Difference

Confusing these two audits is the single most common reason organizations walk into Stage 1 underprepared. They over-index on technical evidence Stage 1 won't ask for, and under-index on the documentation coherence it will.

Dimension

Stage 1 Audit

Stage 2 Audit

Primary question

Is the ISMS documented, scoped, and ready to be audited?

Is the ISMS operating effectively and consistently?

Focus

Documentation review + readiness assessment

Evidence of control operation, interviews, sampling

Typical duration

0.5–2 days on-site or remote

2–5+ days on-site (scales with headcount/scope)

Auditor activity

Reviews documents, asks clarifying questions, tours facilities (sometimes)

Samples records, interviews control owners, tests evidence trails

Common outputs

Areas of concern, potential nonconformities, readiness confirmation

Formal nonconformities (minor/major), certification recommendation

What "failing" looks like

CB delays or declines to schedule Stage 2

Major NC blocks certification until corrective action verified

Typical gap before next stage

Weeks (commonly 2–8) for remediation

Certification decision, then surveillance cycle begins

For a full walkthrough of what happens once you clear Stage 1, see the companion piece on the Stage 2 certification audit walkthrough.

What the Auditor Examines at Stage 1

Every certification body runs Stage 1 slightly differently, but in the 200-plus organizations I've supported through certification, the review consistently converges on the same set of inputs. Treat this as your evidence checklist.

Area Reviewed

What the Auditor Looks For

Typical Evidence Requested

ISMS scope

A defined, documented boundary that matches organizational reality and the SoA

Scope statement, network/data-flow diagrams, list of locations and business units in/out of scope

Information security policy

Top-management-approved, communicated, reviewed

Approved policy document, distribution/acknowledgment records, review date

Statement of Applicability

All 93 Annex A controls addressed with justified inclusion/exclusion

SoA document cross-referenced to risk treatment plan

Risk assessment methodology & results

A repeatable method, applied consistently, with defined criteria

Risk assessment methodology document, completed risk register

Risk treatment plan

Treatment decisions mapped to controls and owners

Risk treatment plan, control implementation status

Risk acceptance criteria

Defined and approved before assessment, not after

Approved criteria document with sign-off date

Objectives and planning

Measurable information security objectives set by management

Objectives register, plans to achieve them

Roles and responsibilities

Clear ownership for ISMS activities

Org chart, RACI, role descriptions

Legal and regulatory register

Applicable obligations identified

Legal/regulatory/contractual requirements register

Internal audit programme

Planned, and ideally at least partially executed

Internal audit programme/schedule, any completed audit reports

Management review

Planned or held, with the right inputs/outputs

Management review minutes or a scheduled agenda

Competence and awareness

Evidence people understand their ISMS responsibilities

Training records, awareness campaign evidence

Mandatory documented information

The full ISO 27001 Clause 4–10 required document set

See mandatory documents checklist below

Facilities (sometimes)

A walk-through to confirm scope statements match physical reality

Facility access, physical security observations

That last row catches people off guard — some auditors do walk the floor at Stage 1, particularly if physical locations are in scope, precisely to sanity-check that what's on paper matches what's on the ground.

"Stage 1 is where I find out whether an organization's ISMS is a living system or a folder of templates somebody downloaded three weeks ago. The tell is always consistency — does the scope statement match the SoA, does the SoA match the risk treatment plan, do the risk owners actually know they're risk owners. When those threads don't connect, I can't in good conscience send a team out for Stage 2." — Marcus Webb, Principal Auditor, Veritas Assurance Group

Mandatory Documented Information Under Scrutiny

ISO/IEC 27001:2022 specifies a set of documented information that must exist for the ISMS to conform to the standard — and Stage 1 is where a certification body auditor confirms it's all present, approved, and version-controlled, not just that it exists in draft. This includes the scope, the policy, the risk assessment and treatment methodology and results, the SoA, the risk treatment plan, information security objectives, competence records, monitoring and measurement results, the internal audit programme and results, and management review outputs, among others. If you haven't already mapped your document set against the full required list, work through the ISO 27001 mandatory documents checklist before your Stage 1 date — it's the single fastest way to find gaps while you still have time to close them. Then cross-check your evidence pack itself against PentesterWorld's downloadable Mandatory Documents Checklist, which maps directly to what a Stage 1 auditor asks to see.

Auditors don't expect every document to be perfect prose. They expect it to be approved, dated, owned, and consistent with every other document that references it. A risk register that lists a risk owner who no longer works at the company, or a policy still awaiting the CISO's signature three weeks after the "effective date" printed on it, are the kinds of small inconsistencies that snowball into a Stage 1 finding.

It helps to see exactly which clause drives which document, since that's the structure most Stage 1 auditors use to organize their review.

ISO 27001 Clause

What It Requires

Document Stage 1 Will Ask to See

Clause 4 (Context)

Understanding of internal/external issues, interested parties, scope

Context analysis, interested parties register, scope statement

Clause 5 (Leadership)

Policy, roles, management commitment

Information security policy, roles/responsibilities matrix

Clause 6 (Planning)

Risk assessment, risk treatment, objectives

Risk assessment methodology, risk register, SoA, objectives register

Clause 7 (Support)

Resources, competence, awareness, communication, documented info

Training records, awareness evidence, document control procedure

Clause 8 (Operation)

Operational planning and control, risk assessment/treatment execution

Evidence of risk treatment plan execution, operational procedures

Clause 9 (Performance Evaluation)

Monitoring, internal audit, management review

Internal audit programme/reports, management review minutes

Clause 10 (Improvement)

Nonconformity handling, corrective action, continual improvement

Nonconformity/corrective action log (even if empty, the process must exist)

How Stage 1 Runs: The Opening Meeting

Stage 1 audits — whether conducted remotely or on-site — follow a rhythm most CBs replicate closely, because it's baked into their accredited audit procedures. The day begins with an opening meeting: the lead auditor introduces themselves and confirms the audit plan, scope, and duration; your ISMS owner (often the CISO or compliance lead) introduces the key personnel who'll be available; and both sides confirm logistics — who's in the room, what documents have already been shared, whether there will be a facility tour.

This meeting is short, usually 15–30 minutes, but it sets the tone. Auditors form early impressions here about whether the organization understands its own ISMS or is performing preparedness for the day. Send your document set in advance where the CB allows it — reviewing cold, on the day, wastes audit time on reading rather than probing, and probing is where genuine gaps surface for both sides to fix.

Who actually needs to be in the room (or on the call) matters more than most organizations plan for. Missing the right person on the day is its own minor readiness failure.

Role

Why Stage 1 Needs Them

When They're Typically Pulled In

ISMS owner / CISO

Owns the overall documentation set and narrative

Present for the full audit

Top management representative

Confirms leadership commitment, approves policy/objectives

Opening meeting, closing meeting, Clause 5 review

Risk owner(s)

Explain how specific risks were scored and treated

Risk assessment/treatment review block

Internal audit lead

Walks through the internal audit programme and any findings

Clause 9 review block

HR / People lead

Speaks to screening, training, and awareness records

Competence and awareness review block

Document controller

Demonstrates version control and access management live

Throughout, on request

Facilities/security lead

Escorts and explains physical security controls

Facility walk-through, if applicable

Remote vs. On-Site Stage 1: What Changes

Many certification bodies now offer Stage 1 as a remote review, particularly for organizations with a documentation-heavy, low-physical-footprint scope. The mechanics are largely the same; what changes is logistics and the weight given to a physical walk-through.

Factor

Remote Stage 1

On-Site Stage 1

Document access

Screen-share or secure portal access

Often reviewed on organization's own systems in person

Interview logistics

Video calls scheduled in blocks

Walk-up availability, more spontaneous follow-ups

Facility walk-through

Not possible; may be deferred to Stage 2

Can happen same day

Typical suitability

Single-site, cloud-based, documentation-mature organizations

Multi-site, physically sensitive, or first-time CB relationships

Preparation impact

Screen-sharing rehearsal matters; confirm remote access works

Facility readiness (badges, visitor logs, clear desk) matters more

The Role of the Lead Auditor and Technical Experts

It's worth understanding who is actually sitting across the table, because it shapes how the review unfolds. Certification bodies typically assign a lead auditor who owns the entire audit relationship — Stage 1, Stage 2, and every subsequent surveillance visit for at least the first certification cycle. That continuity matters: the same person who forms an impression of your ISMS at Stage 1 is the person deciding, at Stage 2, whether the gaps they flagged have actually closed. Building a professional, transparent relationship with that individual starting at Stage 1 pays dividends later.

For organizations with specialized scope — cloud-native architectures, industrial control systems, payment processing environments, or highly regulated healthcare data — the CB may bring in a technical expert alongside the lead auditor. This person isn't auditing independently; they're advising the lead auditor on domain-specific questions the lead auditor may not be equipped to probe alone. If your organization operates in a specialized space, ask your CB during contracting whether a technical expert will be assigned, and if so, request their general background so you can anticipate the kind of questions they're likely to ask.

Auditor continuity and competence are also why the certification body selection conversation matters well before Stage 1 ever gets scheduled — a CB that assigns an auditor with no relevant sector experience will still complete a valid audit, but the questions will be less sharp, and your team may find itself explaining basic industry context instead of getting substantive feedback on gaps that matter.

How Stage 1 Runs: The Documentation Review

The bulk of Stage 1 is spent working through the document set in the table above, usually organized around the clause structure of ISO 27001 (Clauses 4 through 10) rather than a random walk. Auditors will ask to see documents live in your system — not printed and pre-selected — because version-control and access control matter to them as much as content. Expect questions like "who approved this?" "when was it last reviewed?" and "show me where this risk feeds into your treatment plan."

Interviews are woven through the review rather than held separately. The auditor might pull in your risk owner mid-review to ask how they scored a specific risk, or ask your HR lead how screening records are retained. This is deliberate: it tests whether the documented process and the lived process, for even the people who own it, are the same story.

If your organization is small, the lead auditor may do this alone. Larger, more complex scopes sometimes bring a second auditor or a technical expert, particularly where the scope touches specialized environments like cloud infrastructure or OT.

"I tell every client the same thing before Stage 1: the auditor is not your adversary in this meeting. They are trying to find out if Stage 2 will be a fair test. If you show them the gaps yourself and explain your remediation plan, that lands completely differently than them finding the gap unassisted." — Dana Okafor, ISMS Manager, NorthPeak Logistics

How Stage 1 Runs: The Closing Meeting

At the end of the review, the auditor holds a closing meeting to summarize what they found. This is not a surprise — reputable auditors flag concerns as they go, so the closing meeting should confirm rather than ambush. Expect the auditor to walk through: areas that met expectations, areas of concern that need attention before Stage 2, any potential nonconformities they intend to formalize in the written report, and — critically — their recommendation on whether the organization is ready to proceed to Stage 2 and on what timeline.

Ask direct questions here. If the auditor flags a concern, ask what evidence would resolve it and whether they need to see remediation before Stage 2 or whether it can be verified as part of Stage 2 itself. That single conversation often determines whether your Stage 2 date holds or slips.

A Typical Stage 1 Audit Agenda

Time Block

Activity

Who's Involved

9:00–9:30

Opening meeting: introductions, confirm scope and plan

Lead auditor, ISMS owner, top management rep

9:30–11:00

Scope, policy, and leadership commitment review (Clauses 4–5)

ISMS owner, CISO

11:00–12:30

Risk assessment methodology, register, and treatment plan review (Clause 6)

Risk owner(s), ISMS owner

12:30–13:15

Lunch / auditor prepares interim notes

13:15–14:30

SoA walkthrough, mandatory documents, competence and awareness records (Clauses 7–8)

HR lead, control owners, ISMS owner

14:30–15:15

Internal audit programme and management review status (Clause 9)

Internal audit lead, top management

15:15–15:45

Facility walk-through (if applicable)

Facilities/security lead

15:45–16:30

Auditor prepares findings summary

16:30–17:00

Closing meeting: findings, recommendation, next steps

Lead auditor, ISMS owner, top management

Multi-site or larger scopes stretch this across two days; very small organizations sometimes compress it into half a day.

Stage 1 for Multi-Site and Multi-Entity Organizations

Organizations with more than one physical location, more than one legal entity in scope, or a mix of owned and leased facilities face a version of Stage 1 that's meaningfully more complex than the single-site scenario most guidance assumes. The certification body will typically require a sampling rationale — a documented, risk-based explanation of which sites will actually be visited or reviewed in depth, and why. A CB won't necessarily audit every location during Stage 1 (or even Stage 2), but they will expect your scope statement to name every location, explain how information security is managed consistently across them, and justify the sample the auditor selects.

This is where scope-and-SoA consistency problems compound fastest. I've seen organizations with five warehouses list a single, generic scope statement that implies uniform controls everywhere, when in practice one site had a different landlord-managed physical security arrangement, another ran a legacy network segment nobody had fully documented, and a third was added after an acquisition and had never been formally folded into the ISMS. Each of those differences needs to surface in your documentation before Stage 1, not get discovered by the auditor during it.

Multi-Site Factor

What Stage 1 Auditors Check

Preparation Tip

Consistency of controls across sites

Whether the same policies and controls genuinely apply everywhere claimed

Document site-specific variations explicitly rather than implying uniformity

Legal entity boundaries

Whether the ISMS scope aligns with the entities named on the certificate

Confirm scope language matches your corporate structure exactly

Recently acquired or divested sites

Whether integration into the ISMS is complete, partial, or still pending

Flag any site still mid-integration rather than letting the auditor find it

Sampling rationale

Whether the CB's site-visit sample is justified and risk-based

Ask your CB early how they plan to sample; don't assume every site is visited

Remote/hybrid workforce

Whether distributed work is captured in scope and controls

Include remote working arrangements explicitly in scope and risk assessment

Typical Stage 1 Findings and How to Fix Them

Across dozens of Stage 1 audits I've either run as a consultant preparing clients or observed directly, the same handful of gaps recur constantly. None of them require months to fix — most are fixable in 1–3 weeks if caught early, which is exactly why running your own readiness check matters more than anything else in this article.

Finding

Why It Happens

How to Fix It Before the Auditor Arrives

Scope statement doesn't match SoA coverage

Scope written early, SoA updated later without reconciling

Cross-check every location, system, and business unit named in the SoA against the scope document; update both together

Risk acceptance criteria defined after risk scoring

Teams start assessing risk before formally approving thresholds

Get management sign-off on acceptance criteria first, then re-validate any scoring done before approval

No internal audit evidence

Organizations save internal audit for "closer to Stage 2"

Run at least one internal audit cycle, even a partial one, before Stage 1

No management review held

Same deferral logic as internal audit

Hold a documented management review with the required inputs/outputs before Stage 1

SoA exclusions lack justification

Controls marked "not applicable" with no rationale

Write a one-line justification for every exclusion, tied to risk assessment output

Risk register missing owners

Risks assigned during workshops, owners never formally recorded

Add named, accountable owners to every risk line before the audit

Policy not formally approved

Draft circulated but never signed off by top management

Get dated sign-off from the accountable executive before Stage 1

Competence records incomplete

Training happens informally, never logged

Centralize training/awareness records with dates and completion evidence

Document version control inconsistent

Multiple copies in shared drives, no single source of truth

Move to a single controlled repository with version history before the audit

Legal/regulatory register missing or stale

Built once early in the project, never revisited

Review and date-stamp the register within weeks of Stage 1

"The scope-versus-SoA mismatch is the one I see most. It's rarely malicious — it's just that scope gets written in month one and the SoA gets finished in month four, and nobody goes back to reconcile them. Fifteen minutes of cross-checking would have caught it." — Tomás Reyes, CISO, Solvera Financial

Areas of Concern vs. Potential Nonconformities

Not every Stage 1 observation is equal, and understanding the difference changes how you should react to it. An "area of concern" is the auditor flagging something that isn't yet a formal nonconformity but that, left unaddressed, likely will become one at Stage 2 — a thin risk treatment plan, a management review agenda that's missing a required input, a competence record that's only partially complete. A "potential nonconformity" is stronger language: the auditor believes, based on what they've seen, that a specific clause or control requirement is not currently met, and they expect to see it resolved, or a credible remediation plan, before Stage 2 proceeds.

The practical difference matters for triage. Areas of concern are typically things you can fix in the weeks before Stage 2 without needing the CB to re-verify anything at Stage 1 itself. Potential nonconformities sometimes require the auditor to see evidence of correction before they'll commit to a Stage 2 date at all — which is exactly the trap Priya at Meridian fell into with her missing internal audit and management review.

Neither term appears in casual conversation with every auditor the same way — some CBs use "observations" and "concerns" instead of ISO's stricter nonconformity language until Stage 2. Ask your auditor directly, in the closing meeting, which category each item falls into and what they expect to see resolved before they'll green-light Stage 2 scheduling.

The Stage 1 Flow, End to End

It helps to see the whole sequence as one continuous flow rather than a single event on a calendar. Preparation quality at the front end determines how painless — or painful — the remediation step at the back end turns out to be.

Notice that the loop back to remediation isn't a failure state baked into the process — it's the entire reason Stage 1 exists as a separate step from Stage 2 in the first place. Catching a gap here, weeks before Stage 2, is inexpensive. Catching the same gap during Stage 2 risks a formal nonconformity on your certification record.

How to Prepare: Building Your Stage 1 Evidence Pack

The organizations that walk into Stage 1 calmly are the ones that build an "evidence pack" weeks in advance rather than scrambling to assemble documents the night before. An evidence pack is simply every document from the auditor-examines table above, gathered in one controlled location, each one checked for three things: is it approved by the right person, is it dated within a sensible review cycle, and does it agree with every other document that references it.

That last check — cross-document consistency — is where most last-minute problems live. Walk your scope statement line by line against your SoA. Walk your risk register against your risk treatment plan and confirm every treated risk maps to a specific Annex A control or a documented rationale for going outside Annex A. Walk your org chart against the roles named in your risk register and your incident response plan. None of this requires new work — it requires an afternoon of deliberate reconciliation, and it is the single highest-leverage prep activity available to you.

If you're assembling this evidence pack for the first time and want a single reference that walks through the full document set clause by clause, PentesterWorld's Complete ISO 27001 Implementation Guide eBook covers exactly this ground in more depth than a single article can.

The Stage 1 Preparation Checklist

Preparation Task

Owner

Target Timing Before Stage 1

Confirm scope statement matches SoA coverage exactly

ISMS manager

4–6 weeks out

Obtain top-management sign-off on the information security policy

CISO / top management

4–6 weeks out

Approve risk acceptance criteria before finalizing risk scores

Risk committee

4–6 weeks out

Complete risk assessment and risk treatment plan with named owners

Risk owners

3–4 weeks out

Finalize SoA with justification for every inclusion/exclusion

ISMS manager

3–4 weeks out

Run at least one internal audit cycle (full or partial scope)

Internal audit lead

3–4 weeks out

Hold a documented management review meeting

Top management

2–3 weeks out

Centralize competence and awareness training records

HR / People lead

2–3 weeks out

Update legal, regulatory, and contractual requirements register

Compliance lead

2–3 weeks out

Move all controlled documents into a single version-controlled repository

Document controller

2 weeks out

Run an internal mock Stage 1 review

ISMS manager + consultant/internal audit

1–2 weeks out

Brief interviewees on likely questions and their own role evidence

ISMS manager

1 week out

Confirm logistics: rooms, remote access, facility tour route

Admin / facilities

1 week out

Warning Signs You're Not Actually Ready

Before you even schedule a mock Stage 1, run this quick gut-check. If more than two or three of these are true, push your Stage 1 date rather than hoping the auditor won't notice.

Warning Sign

What It Usually Means

Nobody can produce a single, current version of the scope statement on demand

Scope has drifted or was never centrally owned

The SoA was finished weeks after the scope statement, and nobody reconciled them

Almost guaranteed scope/SoA mismatch

Risk scoring happened before acceptance criteria were formally approved

Risk assessment methodology will be questioned

Internal audit is "on the roadmap" rather than scheduled with a date

Stage 1 will likely flag it as missing

No management review has ever been held

Guaranteed Stage 1 concern at minimum

Training records live in people's inboxes rather than a central system

Competence evidence will be hard to produce live

Nobody has walked the SoA control-by-control against the risk treatment plan

Exclusion rationale will be weak or missing

Running a Mock Stage 1

The highest-return activity on that checklist, by a wide margin, is the mock Stage 1 itself. A mock audit means putting someone who did not build your documentation — an internal auditor from a different part of the business, or an external consultant — in the auditor's seat and having them run the exact same document walkthrough and interview questions a real CB assessor would use. The value isn't in confirming what you already know is solid. It's in exposing the blind spots that come from having built the ISMS yourself: the assumptions you didn't realize you were making, the cross-references you assumed were obvious.

I run these regularly with clients using a structured walkthrough modeled directly on real Stage 1 procedure — reviewing scope, policy, risk documentation, SoA, and audit/review evidence in the same sequence and with the same probing questions a CB auditor uses, then producing a findings list exactly like the one a real Stage 1 report would contain. PentesterWorld's Mock Stage 1 Documentation Review lab walks through this exact exercise so you can run it internally before you ever pay a certification body for the real thing. Organizations that run a mock Stage 1 two to three weeks before the real one consistently walk away from the actual audit with zero potential nonconformities — because they've already found and fixed them.

"We ran a mock Stage 1 the month before our real one and found four things we'd have otherwise handed the auditor on a plate — including a management review that technically happened but never got minuted. Fixing that took two hours. Finding it during the real audit would have cost us weeks." — Grace Lin, Internal Audit Lead, Bellwether Systems

Scope Statement Readiness

Your scope statement is the first document most Stage 1 auditors read, because everything else in the ISMS is measured against it. If your scope excludes a business unit, a data center, or a SaaS platform that your risk assessment or SoA quietly includes controls for, that inconsistency is often the very first thing flagged. Before Stage 1, revisit your scope against the practical guidance in defining the scope of your ISMS and confirm it still reflects the organization as it exists today — not as it existed when the scope was first drafted, often months or a year earlier. Scope drift is normal as businesses grow, acquire, or outsource; undocumented scope drift is the Stage 1 finding.

Statement of Applicability Readiness

The SoA is arguably the single document a Stage 1 auditor scrutinizes hardest, because it's the bridge between your risk assessment and your actual control implementation. Every one of the 93 Annex A controls needs a clear inclusion or exclusion decision with a rationale tied back to risk assessment output — not a blanket "not applicable" applied to save time. If you haven't already, walk through how to create a Statement of Applicability and confirm every control decision in your current SoA still has a documented reason behind it, especially for any control you've marked out of scope. Auditors ask "why isn't this one applicable to you?" far more often than people expect, and "we didn't think about it" is not an acceptable answer.

Risk Assessment Readiness

Because so much of the rest of the ISMS flows from it, your risk assessment gets disproportionate attention at Stage 1. The auditor wants to see a defined, repeatable methodology — not just a spreadsheet of guesses — applied consistently across the scope, with acceptance criteria approved before scoring began. If your methodology or your register feels thin, revisit the ISO 27001 risk assessment methodology step-by-step guide and confirm every risk has a named owner, a documented likelihood/impact rationale, and a clear link to a treatment decision in your SoA or treatment plan. A risk assessment that exists but can't be explained consistently by the people who ran it is functionally the same, to an auditor, as no risk assessment at all.

Internal Audit and Management Review Readiness

These two activities are the ones organizations most often defer — and the ones that most reliably produce a Stage 1 concern when they're missing. Internal audit and management review aren't Stage 2 requirements you can save for later; they're evidence the ISMS has actually started operating the Plan-Do-Check-Act cycle the standard requires, and Stage 1 auditors look for at least a credible start. Work through the full mechanics in ISO 27001 internal audit: planning, execution, and reporting if you haven't run a cycle yet, and don't wait until the week before Stage 1 to schedule your first one — a rushed internal audit with no real findings looks exactly like what it is to an experienced auditor. PentesterWorld's Internal Audit Checklist is a practical way to structure that first cycle so it produces genuine, defensible findings rather than a box-ticking exercise.

What the Stage 1 Report Actually Contains

A few days after the audit, the certification body issues a formal Stage 1 report. It typically includes: a summary of what was reviewed and by whom; a list of areas of concern with enough detail to act on them; any potential nonconformities the auditor intends to track into Stage 2; a statement of the auditor's overall recommendation — proceed to Stage 2 as planned, proceed with named conditions, or delay pending remediation; and, often, a proposed Stage 2 date or date range.

Read this report as a to-do list, not a verdict. Even a clean Stage 1 report with zero concerns doesn't mean Stage 2 is guaranteed to pass — it means the CB believes Stage 2 will be a fair and meaningful test of an ISMS that's actually operating. Conversely, a report with several areas of concern isn't a failure; it's the system working as designed, giving you the runway to fix things before they become certification-blocking nonconformities.

Reading Between the Lines: What Auditors Really Mean

Auditors are professionally careful with language, and it pays to learn to read it precisely. "We'd like to see more maturity in X before Stage 2" usually means: this exists, but the evidence trail is thin — expect this to be a focal point in Stage 2 sampling. "We were unable to confirm Y" often means: you told us this happens, but you couldn't show us records, so treat this as a near-certain Stage 2 nonconformity unless you fix the evidence gap. "This appears not yet operational" is close to as direct as auditors get before Stage 2 — it means don't expect leniency if this hasn't changed by the next visit.

The most useful thing you can do in the closing meeting is ask the auditor, plainly, "if nothing changes between now and Stage 2, what happens to this item?" Good auditors will answer directly, because a well-prepared Stage 2 serves everyone's interests — including theirs.

The Gap Between Stage 1 and Stage 2

Stage 1 findings exist precisely because certification bodies expect a gap between the two stages — time deliberately built into the process for remediation. What changes between Stage 1 and Stage 2 isn't a new set of documents; it's evidence that the documents you already showed the auditor are being lived. A risk treatment plan that was a spreadsheet at Stage 1 needs, by Stage 2, to show controls actually implemented against it. An internal audit programme that existed as a schedule at Stage 1 needs, by Stage 2, at least one completed cycle with tracked findings. A management review that was "planned" at Stage 1 needs minutes, decisions, and follow-up actions by Stage 2.

This is also where organizational discipline gets tested. It's easy to treat the weeks after a clean Stage 1 report as a green light to relax. The organizations that stumble at Stage 2 are frequently the ones that treated Stage 1's pass as the finish line rather than the starting gun for the operational evidence-building that Stage 2 will actually sample.

How Much Time to Leave Between Stage 1 and Stage 2

There's no ISO-mandated minimum gap, but certification bodies and experienced practitioners converge on a practical range based on how much genuine operating evidence the ISMS still needs to accumulate.

Stage 1 Outcome

Typical Gap Before Stage 2

What Happens in Between

Clean report, no significant concerns

4–8 weeks

Continue normal operation; gather ongoing evidence (logs, reviews, training records)

Minor areas of concern noted

6–10 weeks

Close specific gaps (e.g., finish a training cycle, complete a review)

Potential nonconformities flagged

8–12+ weeks

Substantive remediation: policy re-approval, a full internal audit cycle, management review, sometimes a follow-up evidence submission to the CB

Significant gaps (scope/SoA misalignment, no ISMS operation evidence)

3+ months, sometimes a re-scheduled Stage 1

Rebuild core documentation and operate the ISMS for a meaningful period before requesting a new Stage 1 or Stage 2 date

Rushing this gap to protect a contractual deadline — as Priya at Meridian nearly did — tends to produce exactly the kind of superficial fixes that show up as fresh nonconformities at Stage 2. Build your certification timeline backward from a realistic Stage 1-to-Stage 2 gap, not forward from the date you'd prefer.

What Happens If Stage 1 Recommends Against Proceeding

The worst-case Stage 1 outcome isn't a long list of areas of concern — it's the auditor concluding that the ISMS is far enough from ready that scheduling Stage 2 wouldn't be a meaningful exercise for either party. This happens less often than organizations fear, but it does happen, typically when core elements are missing entirely rather than merely thin: no risk assessment at all, a scope statement that doesn't correspond to any real operational boundary, or a policy that was never actually approved by anyone with the authority to approve it.

In that scenario, the certification body will usually recommend a substantial remediation period — often three months or more — before a new Stage 1 is scheduled, sometimes requiring a fresh contract or revised statement of work depending on how much time has elapsed. This is not the same as failing Stage 2 and needing corrective action; it's the CB declining to certify that the organization is even ready to be tested. The financial impact is usually larger than a standard remediation delay, because it typically means re-paying part or all of the Stage 1 audit fee and absorbing months of lost calendar time against whatever business deadline drove the certification project in the first place.

The good news is that this outcome is almost entirely avoidable with basic preparation. In my experience, organizations that land here didn't lack security maturity — they lacked project management discipline around the ISMS documentation itself, often because certification was delegated to a single overworked person with no dedicated time or budget. If your ISMS effort has one person doing it alongside a full-time unrelated job, treat that as a flashing warning sign long before you ever book a Stage 1 date.

Common Mistakes Organizations Make Before Stage 1

Mistake

Consequence

Better Approach

Treating Stage 1 as a formality

Walking in with technical evidence but incoherent documentation

Prepare for Stage 1 as seriously as Stage 2 — it's a real gate, not a courtesy visit

Deferring internal audit and management review to "closer to Stage 2"

Both show up missing at Stage 1, triggering a delay

Schedule and run at least partial cycles of both well before Stage 1

Building scope and SoA in isolation from each other

Mismatches surface as the first and most common Stage 1 finding

Reconcile scope and SoA together, every time either changes

Choosing a certification body without checking accreditation scope or industry fit

Delays or re-scoping once the CB realizes they can't audit your scope

Confirm CB accreditation and sector experience before contracting — see the guide on choosing an ISO 27001 certification body

Assuming Stage 1 findings are a failure

Teams panic or become defensive instead of remediating calmly

Understand areas of concern are the process working as designed

Not briefing interviewees before the audit

Inconsistent answers between documented process and what people say

Run a short briefing so control owners know what they'll likely be asked

Skipping a mock Stage 1 entirely

Real audit becomes the first time gaps surface

Run an internal mock review 1–2 weeks before the real date

Locking in a Stage 2 date before Stage 1 findings are known

Contractual or customer deadlines collide with remediation needs

Treat the Stage 2 date as provisional until the Stage 1 report is in hand

Budgeting Time and Cost for Stage 1 Preparation

Organizations consistently underbudget the internal labor cost of Stage 1 preparation, treating it as a rounding error next to the technical control implementation work. In practice, the reconciliation and evidence-gathering work described throughout this article takes real, dedicated hours — and skipping that budget is exactly how teams end up scrambling the week before the audit.

Preparation Activity

Typical Internal Time Investment

Who Usually Does the Work

Scope/SoA reconciliation

4–8 hours

ISMS manager

Risk register and treatment plan cleanup

8–16 hours

Risk owners + ISMS manager

Internal audit cycle (first full or partial cycle)

20–40 hours

Internal audit lead + control owners

Management review preparation and meeting

6–10 hours

Top management + ISMS manager

Competence/training record consolidation

4–8 hours

HR / People lead

Mock Stage 1 review (planning, execution, remediation)

16–30 hours

External facilitator + internal team

Document repository consolidation

6–12 hours

Document controller

Add these up for a mid-sized organization and you're typically looking at 65–125 internal labor hours spread across four to six weeks, plus whatever external consulting or CB fees apply. Budget for it explicitly in your certification project plan rather than assuming it will absorb into people's existing workload — that assumption is precisely what produced Meridian's six-week scramble.

Case Study: Meridian Health Analytics — The Cost of Treating Stage 1 as a Formality

Returning to Priya Deshmukh's story: Meridian's Stage 1 findings weren't really about missing security controls — the technical environment was solid. They were about documentation discipline nobody had prioritized: a scope statement drafted in month one that nobody revisited when the SoA was finalized in month four, a risk acceptance framework approved after risk scoring rather than before it, and an internal audit and management review that existed only as line items on a project plan, never actually executed.

The remediation cost Meridian just under $40,000 in expedited consulting support and internal overtime across six weeks, plus a tense renegotiation with the hospital network client to push the certification deadline by five weeks. The certificate ultimately came through, and the contract renewed — but Priya has since told me the entire crisis was avoidable with roughly sixteen hours of deliberate document reconciliation and one internal audit cycle scheduled a month earlier. Meridian now runs a mock Stage 1 review ahead of every surveillance audit, not just the initial certification.

What made the recovery possible was triage discipline rather than panic. Priya's team didn't try to fix everything simultaneously; they ranked the Stage 1 concerns by which ones the CB had flagged as potential nonconformities versus areas of concern, closed the potential nonconformities first with documented evidence, and negotiated directly with the auditor about which items could be verified during Stage 2 itself rather than requiring pre-verification. That triage conversation — treating the auditor as a partner in sequencing the fix rather than an adversary to be managed — is, in Priya's own words, the single thing she'd tell any peer CISO facing a similar Stage 1 report.

Case Study: NorthPeak Logistics — A Clean Stage 1 Built on a Mock Audit

NorthPeak Logistics, a 340-employee freight and warehousing company pursuing ISO 27001 to satisfy a major retail customer's vendor security requirements, took a different path. Its ISMS manager, Dana Okafor, scheduled a full-day mock Stage 1 review three weeks before the real audit, run by an internal auditor from NorthPeak's finance risk team who had no involvement in building the ISMS documentation.

The mock review surfaced four gaps: an outdated legal and regulatory register that hadn't been touched in eight months, two risk register entries with a departed employee still listed as owner, a management review that had happened but was never formally minuted, and a handful of SoA exclusions with no written justification. Every one of them was fixed within twelve days. When the real Stage 1 auditor arrived, the review closed in one day with zero areas of concern and a straightforward recommendation to proceed to Stage 2 on the original schedule — no delay, no renegotiation, no scramble. NorthPeak's total incremental cost for the mock exercise was roughly $6,000 in internal auditor time, against what Dana estimates would have been a minimum four-week delay had the same gaps surfaced during the real audit.

Dana credits the choice of internal auditor as much as the exercise itself. Pulling someone from finance risk rather than the security team meant the mock reviewer had no stake in defending existing documentation and no assumptions about what "obviously" made sense — they asked the same naive-but-pointed questions a real CB auditor would, like "who told you this control applies here" and "show me where that's written down." NorthPeak has since folded a lightweight version of this mock review into its annual surveillance audit preparation, treating it as standard practice rather than a one-time initial-certification exercise.

Case Study: Solvera Financial — When a Missing Risk Treatment Plan Nearly Sank the Timeline

Solvera Financial, a fintech processor pursuing certification to support enterprise banking clients, hit a different wall. Its risk assessment was thorough and its SoA was well-constructed — but the risk treatment plan connecting the two existed only as informal notes in project management tickets, not as a controlled document with named owners and target dates. The Stage 1 auditor flagged it as a potential nonconformity rather than a minor area of concern, because without a consolidated treatment plan there was no way to verify that identified risks were actually being addressed in a structured way.

CISO Tomás Reyes and his team spent three weeks consolidating eighteen months of scattered treatment decisions into a single controlled risk treatment plan, cross-referencing every entry against the SoA and assigning accountable owners with realistic target dates. The certification body required a follow-up evidence submission — not a full re-visit — before confirming the Stage 2 date, adding roughly five weeks to Solvera's original timeline. Tomás's takeaway, which he's repeated to every peer CISO who'll listen: "Track risk treatment as a living, owned document from day one, not a side effect of the risk assessment workshop."

The deeper lesson from Solvera is that a strong risk assessment and a strong SoA aren't sufficient on their own — the connective tissue between them is a distinct deliverable that needs its own owner, its own review cadence, and its own place in the controlled document set. Tomás now requires his risk committee to review the treatment plan as a standing agenda item every month, specifically so it never again drifts into informal tracking between formal reviews.

Case Study Outcomes at a Glance

Three organizations, three different starting points, and a stark illustration of what preparation is actually worth in dollars and weeks.

Organization

Stage 1 Outcome

Root Cause

Remediation Cost

Timeline Impact

Meridian Health Analytics

Delay recommended; multiple potential nonconformities

Scope/SoA mismatch, no internal audit or management review evidence

~$40,000 in expedited consulting and overtime

5–6 week delay, contract renegotiation

NorthPeak Logistics

Clean pass, zero areas of concern

Ran a mock Stage 1 three weeks early and fixed findings

~$6,000 in internal auditor time

No delay; original schedule held

Solvera Financial

Potential nonconformity on risk treatment plan

Risk treatment tracked informally, not as a controlled document

~3 weeks of consolidation effort plus follow-up CB review

~5 week delay

The pattern holds across every organization I've supported through this stage: the cost of finding a gap during preparation is a rounding error compared to the cost of the same gap surfacing in front of the certification body.

Choosing the Right Certification Body Shapes Stage 1 Too

Stage 1 outcomes are also shaped by a decision made months earlier: which certification body you engaged. A CB with genuine experience in your sector will ask sharper, more relevant questions — and will also be less likely to flag a legitimate industry-specific risk treatment approach as a concern simply because it's unfamiliar to them. Before you sign with a CB, confirm their accreditation actually covers your scope and industry code, and ask how their Stage 1 process typically runs — remote or on-site, single auditor or team, typical duration for an organization your size. The guide on how to choose an ISO 27001 certification body covers the accreditation and scoping questions worth asking before you commit.

A Note for Organizations Also Pursuing SOC 2

Many of the organizations I work with are pursuing ISO 27001 and SOC 2 in parallel, often because different customers demand different frameworks. The good news is that the documentation discipline Stage 1 demands — a defined scope, a real risk assessment, evidence of ongoing monitoring — overlaps substantially with what a SOC 2 Type II auditor expects to see during their own readiness review. If you're running both processes, it's worth aligning your ISO 27001 Stage 1 preparation with your SOC 2 readiness assessment timeline so the same evidence pack serves both audits rather than duplicating the reconciliation work twice. The same logic applies if your organization is also mapping to the NIST Cybersecurity Framework for a customer or regulator — the underlying risk assessment and control evidence rarely needs to be built twice, only cross-referenced.

"Looking back, our Stage 1 finding was the best thing that happened to our certification project. It hurt, and it cost us real money, but it forced discipline into our documentation that would otherwise have surfaced as a formal nonconformity at Stage 2 — with our biggest customer watching the clock." — Priya Deshmukh, CISO, Meridian Health Analytics

Stage 1 as a Business Opportunity, Not Just a Gate

It's tempting to think of Stage 1 purely as an obstacle between your organization and a certificate — something to survive rather than something to use. I'd push back on that framing after fifteen years of watching organizations go through this process. A well-prepared Stage 1 is a genuinely useful forcing function: it's the moment your organization is required, by an external and objective party, to prove that security governance isn't just a slide deck for the board but a functioning system with real owners, real evidence, and real discipline.

Organizations that treat Stage 1 preparation seriously tend to walk away from it with more than a favorable report — they walk away with a genuinely more mature ISMS, a leadership team that has now sat through a real management review, and an internal audit function that's run at least one real cycle instead of existing only on paper. That maturity compounds. It shows up in a smoother Stage 2, a cleaner first surveillance audit a year later, and a security program that can credibly support new sales conversations with customers who ask hard security questions before they'll sign a contract. Certification, done right, isn't paperwork theater — it's a competitive asset, and Stage 1 is where you either start building that asset seriously or you don't.

"Clients ask me all the time whether Stage 1 prep is worth the time investment given how much work Stage 2 still requires afterward. My answer is always the same: everything you do well for Stage 1 is work you don't have to redo, panicked, in the six weeks before Stage 2." — Elena Vasquez, Principal Consultant, Cascade Compliance Partners

If you want a second set of eyes on your Stage 1 readiness before you commit to a date with your certification body, PentesterWorld's consulting team runs exactly this kind of pre-audit review — reconciling scope, SoA, risk documentation, and audit/review evidence against what a real CB auditor will ask for, and handing you a prioritized punch list instead of a surprise. Reach out through PentesterWorld's ISO 27001 advisory services to schedule a readiness review, or start with our Certification Readiness Checklist if you'd rather run the first pass yourself. Either way, the goal is the same one this whole article has been building toward: walk into Stage 1 knowing exactly what's coming, and walk out of it with a clear, short path to Stage 2 — not a surprise six-week detour like the one Meridian Health Analytics barely survived.

Quick Reference: Stage 1 at a Glance

Question

Answer

What is it?

A documentation and readiness review conducted by your certification body before Stage 2

How long does it take?

0.5–2 days, scaled to organization size and scope complexity

Who's involved?

Lead auditor, ISMS owner/CISO, risk owners, HR, internal audit lead, top management

What's reviewed?

Scope, policy, SoA, risk assessment/treatment, mandatory documents, internal audit and management review status

What are the possible outcomes?

Clean readiness confirmation; areas of concern; potential nonconformities; recommendation to delay Stage 2

What's the best single prep step?

A mock Stage 1 review 1–3 weeks before the real audit

How much gap before Stage 2?

Typically 4–12+ weeks depending on findings severity

Resource

Why It Helps

ISO 27001 certification process roadmap

See exactly where Stage 1 sits in the full certification sequence

Stage 2 certification audit walkthrough

Understand what changes once you clear Stage 1

ISO 27001 internal audit: planning, execution, and reporting

Build the internal audit evidence Stage 1 checks for

ISO 27001 mandatory documents checklist

Confirm your full required document set is present

ISO 27001 Statement of Applicability (SoA): how to create one

Reconcile your SoA before the auditor does it for you

Defining the scope of your ISMS

Make sure your scope statement matches organizational reality

ISO 27001 risk assessment methodology step-by-step guide

Strengthen the document Stage 1 auditors scrutinize hardest

How to choose an ISO 27001 certification body

Pick a CB whose Stage 1 process and sector experience fit your organization

ISO 27001 terminology and glossary

Look up any Stage 1 term you encountered in this article


Frequently asked questions

Is Stage 1 pass/fail like Stage 2?

Not in the same sense. Stage 1 doesn't issue formal minor/major nonconformities the way Stage 2 does; it issues areas of concern, potential nonconformities, and a readiness recommendation. But a Stage 1 report that recommends against proceeding to Stage 2 functions, practically, like a failure — it stops your certification timeline until you remediate.

How long after Stage 1 is Stage 2 usually scheduled?

Commonly somewhere between four and twelve weeks, depending on how many areas of concern or potential nonconformities came out of Stage 1. A clean report supports a shorter gap; significant gaps warrant longer, and rushing that gap tends to produce fresh problems at Stage 2 rather than solving the original ones.

Can Stage 1 and Stage 2 happen back-to-back?

Some certification bodies will run them close together for very small, simple organizations with a mature, well-documented ISMS already in place. It's not advisable if there's any real chance of Stage 1 findings, because you won't have time to remediate before Stage 2 samples the same evidence.

Does Stage 1 include testing whether our controls actually work?

No — that's Stage 2's job. Stage 1 checks that the ISMS is documented, scoped correctly, and that foundational activities like risk assessment, internal audit, and management review have at least begun. Deep sampling of control operation (log reviews, access recertifications, incident response walkthroughs) happens at Stage 2.

What if we're not ready — can we push our own Stage 1 date?

Yes, and you should. Certification bodies would much rather reschedule a Stage 1 than run one against an ISMS that clearly isn't ready, because an obviously premature Stage 1 wastes time on both sides and produces a report full of findings that a few more weeks of preparation would have prevented.

Do auditors visit our physical facilities during Stage 1?

Sometimes. It depends on the certification body, whether your scope includes physical locations, and the auditor's judgment about whether a walk-through adds value at this stage. Don't assume it won't happen — keep physical security evidence (badge logs, visitor records, clear desk compliance) as ready as your document set.

Can a small company skip Stage 1 entirely?

No. Stage 1 and Stage 2 are both required parts of the initial certification audit under accredited certification schemes, regardless of organization size — though the duration and depth scale down considerably for smaller, simpler scopes.

What's the single best thing we can do to prepare?

Run a mock Stage 1 review two to three weeks before the real one, using someone who didn't build the documentation to run it. Every other preparation task on this article's checklist matters, but nothing surfaces genuine blind spots as reliably as a dry run conducted with real auditor rigor.

Does the same person run our Stage 1 and Stage 2?

Usually yes — certification bodies typically assign a lead auditor who owns the full initial certification cycle, which is one more reason the closing meeting conversation at Stage 1 matters: whatever you agree with that auditor about what needs fixing is exactly what they'll be checking for at Stage 2.

What happens at our first surveillance audit if Stage 1 had significant concerns?

Areas of concern and potential nonconformities from Stage 1 that get resolved before Stage 2 typically don't resurface at the first surveillance audit unless the underlying discipline slips again. Certification bodies do, however, sometimes flag a specific area for closer attention at the next visit if it was borderline at Stage 2 — ask your auditor directly whether anything from your Stage 1/Stage 2 history carries forward as a watch item.

21

About the author

Cybersecurity Expert

Satish Kumar writes about cybersecurity, offensive security, and practical defense strategies on PentesterWorld.

Related Articles

Comments (0)

No comments yet. Be the first to share your thoughts!