SecurSentry
← All notes
Cyber Essentials

The ISO 27001 Audit: Stage 1, Stage 2 and Internal Audits

There are two kinds of ISO 27001 audit, and they catch people out. Here is what each one checks, in order, without the jargon.

The short version

If someone has told you an ISO 27001 audit is coming and your stomach dropped a little, this guide is for you. Most of the fear comes from not knowing what happens in the room. The reassuring truth is that an ISO 27001 audit is a structured, predictable conversation about evidence, and once you can see its shape it feels less like an ambush and more like a to-do list.

One thing trips up almost every SME, so let us clear it up first: there are two different kinds of audit under ISO 27001. One you run on yourself. One an outside body runs on you. We will walk through both, in the order you meet them.

Two kinds of audit (and why you need both)

ISO 27001 involves an internal audit you arrange yourself and an external certification audit run by an independent body, and they do genuinely different jobs.

The internal audit is your own check on your own system. You (or someone you appoint) look at your information security management system and ask honestly whether it is doing its job. This is not optional politeness; it is a mandatory requirement of the standard, under clause 9.2, which we return to below.

The external certification audit is the one people picture when they hear “audit”. It is carried out by a certification body, and in the UK you want one accredited by UKAS (the United Kingdom Accreditation Service, which oversees auditors). UKAS does not certify your business directly; it accredits the certification bodies, confirming they are competent and impartial. That external audit is what leads to the certificate on your wall.

You cannot skip the internal one and go straight to the external. The certification body expects to see that you already check your own house; if you have never run an internal audit, that itself is a finding.

The simplest way to remember it

Internal audit: you marking your own homework, honestly, before it is handed in. Certification audit: the examiner marking it for real. The first makes the second go far more smoothly.

Stage 1: the readiness review

Stage 1 is a documentation and readiness review, where the auditor checks your management system exists on paper and is likely to pass the deeper audit that follows.

The external certification audit is split into two stages, and Stage 1 is the gentler one. Sometimes called a documentation review or readiness review, it is not yet judging whether your security works in practice; the auditor is checking that you have built a genuine management system and written it down.

They will want the core documents of an ISO 27001-conformant system: your defined scope (what the ISMS actually covers), your risk assessment, your policies, and your Statement of Applicability (a document setting out which controls apply to you and why). They are gauging whether this is a coherent system that stands a reasonable chance at Stage 2.

Stage 1 is also where the auditor flags gaps, and you would far rather hear about a thin spot now, with time to fix it, than at Stage 2. Treat it as a friendly early warning, not a verdict. If you are still weighing whether the standard is right for you yet, our guide to ISO 27001 for SMEs is a good place to check first.

Stage 2: implementation and effectiveness

Stage 2 is the deeper audit that tests whether your management system is genuinely operating, using evidence, sampled records and interviews with your people.

Stage 2 is where the auditor moves from “is it written down?” to “is it actually happening?”. This is the detailed assessment against ISO/IEC 27001:2022, and it carries the weight.

The auditor collects objective evidence. They will not simply accept that a policy exists; they look for proof it is being followed. Expect them to sample records, ask to see logs or tickets, and talk to your people. Interviews are a normal, central part of Stage 2: the auditor might ask a staff member how they would report a suspected incident, or how access to a system gets granted and removed. They are checking that the way things work on paper matches the way they work in real life.

None of this is meant to catch anyone out. If your system is genuinely running, the evidence is there in the course of normal work. The businesses that find Stage 2 stressful are usually the ones that wrote their policies for the audit rather than for how they operate day to day, which is a sharp difference from a lighter scheme like Cyber Essentials.

What happens after: surveillance and recertification

Certification is not a one-off event; the certificate typically lasts three years, with shorter surveillance audits along the way and a recertification audit at the end.

Passing Stage 2 gets you the certificate, typically valid for three years. But ISO 27001 is deliberately not a set-and-forget badge. The standard runs on a three-year cycle, and the auditor comes back.

In the years between certification and recertification, you have surveillance audits. These are shorter than the full Stage 2 (for a smaller organisation, often around half a day to a day) and sample a portion of your controls rather than re-examining everything.

At the end of the three years comes recertification: a fuller audit, closer in depth to your original Stage 2, that revisits the whole system and, if you pass, starts a fresh three-year cycle. Book it ahead of your certificate’s expiry so there is no awkward gap.

So ISO 27001 is a living commitment: the certificate reflects a system you keep running, and there is an ongoing cost to that in time and fees, which we cover in what ISO 27001 certification actually costs.

The internal audit (clause 9.2), run proportionately

Clause 9.2 makes the internal audit a mandatory requirement, but a small business can run one sensibly and in proportion to its size.

The internal audit is the part SMEs most often underestimate. Clause 9.2 of ISO 27001 requires you to conduct internal audits at planned intervals to check that your management system both meets the standard and is working effectively. You must complete at least one before your external certification audit, and keep doing them regularly afterwards, usually at least once a year.

That can sound heavy for a ten-person company, but it need not be. The standard asks you to plan a programme and cover your system over time, not to build a department. A proportionate approach for a small business looks like this:

Why the internal audit is your friend

Every issue you catch in your own internal audit is one you fix on your own timetable, quietly, before it becomes a formal finding on someone else's report. It is the cheapest, calmest way to improve your odds at Stage 2, and it means the external auditor rarely tells you anything you did not already know.

Nonconformities, and what “failing” really means

Audit findings are recorded as nonconformities, classed major or minor, and most are a prompt for corrective action rather than a slammed door.

When an auditor finds that something does not meet a requirement, they record it as a nonconformity: a requirement of the standard, a control, or one of your own policies is not being met. Nonconformities come in two grades.

A minor nonconformity is an isolated slip or partial gap that does not undermine your system as a whole: a record left out of date, say, or a policy followed almost-but-not-quite. You can usually still certify, or stay certified, with minor nonconformities recorded against you, provided you commit to a clear plan and timeline to put them right.

A major nonconformity is more serious. It points to something systemic, or something that simply is not working, and it undermines the integrity of the management system. A major nonconformity will typically hold up certification until you have resolved it and the auditor has verified the fix.

Either way, the response is the same: corrective action. Find the genuine root cause, fix it so it does not happen again, and show the evidence. Avoid the cosmetic fix that leaves the real cause untouched, because a finding that recurs is treated more seriously than a first-time one. “Failing” in the dramatic sense is rare; what is common is a handful of findings and a to-do list, which is a normal, manageable outcome.

How to prepare, and what auditors want to see

Preparation is mostly about being able to show, quickly and honestly, that your system is real and running.

You do not prepare for an ISO 27001 audit by rehearsing answers, but by making the evidence of a working system easy to reach. A few practical pointers:

Much of the underlying discipline carries over from Cyber Essentials, so our Cyber Essentials explained guide is a useful companion for the technical basics that feed into an ISMS. And the mindset that serves you best is simple: the auditor is not trying to fail you, but to confirm that what you have told the world about your security is true. If it is, the audit is mostly a matter of showing your working.


SecurSentry is launching soon to help UK SMEs build and keep the evidence and routines an ISO 27001 audit looks for, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.

This article is for general information only and does not constitute legal or compliance advice. Audit scope and outcomes vary by organisation; where in doubt, consult a qualified professional or an accredited certification body.

Frequently asked questions

What is the difference between an ISO 27001 internal audit and the certification audit?

The internal audit is one you arrange yourself, under clause 9.2 of the standard. Its job is to check, before anyone external looks, that your management system is doing what it should. The certification audit is carried out by an independent, UKAS-accredited certification body, and it is the one that leads to the actual certificate. You need both: you cannot pass certification without having run at least one internal audit first, because the certification body will expect to see that you check your own system.

What is the difference between the Stage 1 and Stage 2 audit?

Stage 1 is a readiness or documentation review. The auditor checks that your management system exists on paper: your scope, policies, risk assessment and Statement of Applicability, and whether it looks likely to pass the deeper audit. Stage 2 tests whether the system is genuinely operating day to day. The auditor gathers evidence, samples records, and interviews people to confirm the controls you have written down are actually being used. Stage 1 asks 'is it there?'; Stage 2 asks 'does it work?'.

What happens if you fail an ISO 27001 audit?

You rarely 'fail' in a single final sense. Findings are recorded as nonconformities and classed major or minor. Minor nonconformities usually do not stop certification, as long as you agree a plan to fix them. A major nonconformity is more serious and will typically hold up certification until you have corrected it and the auditor has verified the fix. In both cases the route forward is corrective action: find the root cause, fix it properly, and show the evidence.

How often do you need ISO 27001 audits after certification?

The certificate typically runs on a three-year cycle. After the initial Stage 1 and Stage 2, you have shorter surveillance audits in the intervening years, and a fuller recertification audit at the end of the three years to renew for another cycle. Separately from all of that, you keep running your own internal audits on a regular basis, because clause 9.2 requires it throughout the life of the certification, not just once at the start.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

21 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

14 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.