Implementation
16 min read

3–5 Sample Records: ISO 27001 Audit Stages Compliance Teams Need

support@ismscalculator.com|

Auditor sampling organized ISO evidence records

ISO 27001 initial certification runs as a two-stage audit: Stage 1 checks whether your ISMS design, scope, and documentation are ready for scrutiny, and Stage 2 tests whether the system actually operates the way you said it does. Certification then continues on a three-year cycle with annual surveillance visits. The practical split matters because Stage 1 forgives gaps in evidence; Stage 2 does not.


TL;DR:

  • Stage 1 verifies that your ISMS documentation and scope are coherent enough to proceed, but it does not assess whether controls are operational.
  • Stage 2 involves detailed sampling and vertical tracing of actual records and events to confirm controls work effectively over time.
  • Evidence preparation should focus on organizing policies, logs, incident records, and change tickets by control and timeline, with 3 to 5 samples per control.
  • Closing nonconformities requires addressing root causes, with minor issues handled through corrective plans and major issues needing verified fixes within 90 days.
  • Certification longevity depends on ongoing surveillance audits, with a strict six-month window between Stage 1 and 2 to avoid repeat assessments and delays.

Table of Contents

What Are the ISO 27001 Audit Stages in the Certification Cycle?

Initial certification is only the front half of a longer relationship with your certification body. Once you pass Stage 1 and Stage 2, you get a certificate valid for three years, but that certificate depends on staying current through surveillance visits and a full recertification audit before the cycle resets.

The certification body runs every stage, but its own legitimacy depends on accreditation. Bodies performing ISO 27001 certification operate under ISO/IEC 17021-1, which mandates a two-stage initial audit. Checking the certification body’s accreditation status beforehand is important since unaccredited bodies’ certificates may carry less weight with clients and regulators.

The full cycle typically involves Stage 1 audit for documentation and readiness review taking a few days, followed by a remediation window between stages generally lasting several weeks, then Stage 2 audit for on-site verification of implementation and effectiveness, after which the certification decision is issued if no major nonconformities remain. Subsequent surveillance audits occur annually to confirm ongoing ISMS operation, with a recertification audit before the certificate expires after a multi-year cycle

Your organization owns the ISMS itself, the evidence, and the internal audit and management review that back it up. The certification body’s job is narrower: sample your evidence, interview your people, and decide whether what they see matches what you claim on paper. That division of labor is why so many teams underestimate Stage 2. Passing Stage 1 tells you the paperwork is coherent. It says nothing about whether your access reviews actually happened on schedule for the last two quarters.

What Are the ISO 27001 Audit Stages in the Certification Cycle? — overview diagram

What Happens During Stage 1: Documentation and Readiness

Stage 1 exists to answer one question: is this ISMS mature enough to survive a Stage 2 audit? The auditor is not testing whether your controls work yet. They are testing whether your scope, your risk logic, and your documented decisions hang together well enough to make a Stage 2 visit worthwhile.

During Stage 1, expect the auditor to review your documentation set, confirm the boundaries of your ISMS scope, and start planning what Stage 2 will focus on. This is also where they check that you have actually run at least one internal audit and one management review before showing up, since both are required inputs the auditor expects to see evidence of, not promises about.

Documents to have ready for Stage 1:

  1. ISMS scope statement, including physical locations, business units, and technology boundaries
  2. Statement of Applicability (SoA), showing which Annex A controls apply and why others are excluded
  3. Risk assessment methodology and a completed risk assessment for your defined scope
  4. Risk treatment plan linking identified risks to selected controls
  5. Internal audit results covering the ISMS, with findings and status
  6. Management review minutes showing leadership has reviewed ISMS performance and resourcing
  7. Key ISMS policies (information security policy, access control policy, incident response policy at minimum)

Stage 1 auditors focus on spotting inconsistencies between documents, such as mismatches between your Statement of Applicability and your risk treatment plan, which are flagged before assessing the actual implementation of controls.

Pro Tip: Treat your Stage 1 report as a study guide, not a formality to file away. Auditors typically build their Stage 2 sampling plan around whatever looked thin or unclear in Stage 1, so a vague note about “incident response documentation still in draft” is a strong signal they will ask for finished incident records at Stage 2.

Stage 1 outcomes generally fall into three buckets. You might be cleared to proceed directly to Stage 2 on schedule. You might be cleared with minor observations to address before or during Stage 2. Or, if the documentation has real structural gaps, the certification body may delay Stage 2 until you close them, sometimes requiring a partial Stage 1 repeat. That third outcome is avoidable almost every time it happens, usually because a team skipped the internal audit and management review SecComply’s guidance points to as a prerequisite rather than a nice-to-have.

How Does Stage 2 Test Whether Your ISMS Actually Works?

Stage 2 is where design meets reality. The auditor stops asking “what does your policy say” and starts asking “show me the records that prove this happened.” That shift changes everything about how you prepare, because a well-written policy earns zero credit here if the operational history behind it doesn’t exist.

Typical Stage 2 activities include interviews with control owners, direct observation of processes (watching someone perform an access review, walking through a data center, checking how a laptop gets provisioned), and systematic sampling of records across your audit period. Auditors will also check that corrective actions from your internal audit actually closed, not just that they were logged.

The technique that catches the most organizations off guard is vertical tracing. Instead of checking a control in isolation, the auditor picks one real event and follows it end to end. A common example: they select a security incident from your log, then ask to see the initial detection record, the triage notes, the corrective action ticket, the evidence that the fix was implemented, and the record showing the incident was formally closed. Elevate’s breakdown of the two stages notes that missing even one link in that chain, like a ticket that never shows a closure date, is enough to trigger a nonconformity, because it suggests the process breaks down somewhere between detection and resolution.

What auditors sample during vertical tracing:

  • Access provisioning and deprovisioning records for a sample of joiners and leavers
  • Change management tickets tied to a specific system change, from request through approval to deployment
  • A security incident from log entry to root cause to closure
  • Backup logs and a corresponding restore test for a critical system
  • Supplier due diligence records for a vendor handling sensitive data
  • Vulnerability scan results and the patching or exception record that followed

Sample sizes vary by organization size and control criticality, but a workable rule of thumb across most control areas is 3 to 5 records per control, pulled from different points in your audit window rather than clustered around the same week. That spread matters because auditors are checking consistency over time, not a single good day.

How long Stage 2 actually takes depends on headcount and complexity, with audit duration calculated under guidance tied to IAF MD 5. Small organizations typically have shorter Stage 2 audits, while larger or multi-site organizations may require longer periods.

Auditors generally expect an operating history of sufficient duration for key controls before Stage 2, often considering a few months necessary to establish an operational record to sample. A control you switched on two weeks before the audit has no history to trace, and that absence itself often reads as a risk to the auditor, regardless of how well the control is designed.

Between Stages: Timing, Priorities, and the Six-Month Rule

The gap between Stage 1 and Stage 2 is not fixed by the standard. Certification bodies set it based on your Stage 1 findings and scheduling constraints, with a window of several weeks being typical. Some organizations may proceed sooner, while others with more corrections to make require additional time.

There is a hard limit worth knowing regardless of how relaxed your certification body seems about scheduling. If Stage 1 findings aren’t resolved and Stage 2 doesn’t happen within six months of Stage 1, most certification bodies require a repeat Stage 1 review before proceeding, which resets your timeline and your budget. Treat six months as the outer edge, not a target.

Priority checklist for the gap period:

  1. Close every Stage 1 finding in writing, with an owner and a completion date attached to each
  2. Run a focused internal audit specifically on the areas Stage 1 flagged as weak, not a full ISMS re-audit
  3. Assemble an evidence pack organized by control, not by document type, so Stage 2 sampling requests are quick to answer
  4. Hold a second management review if the gap exceeds 8 weeks, so leadership sign-off stays current
  5. Brief control owners on what vertical tracing looks like, since most interview anxiety comes from not knowing the format

Pro Tip: Submit corrective evidence for Stage 1 findings to your certification body as you close them, rather than batching everything for the week before Stage 2. Auditors who see progress documented in real time walk into Stage 2 with fewer open questions, which tends to shorten the visit.

Nonconformities and Remediation: Major vs. Minor

Not every audit finding carries the same weight, and confusing the two categories is a common way teams either panic unnecessarily or underreact to something serious.

A minor nonconformity typically means a control exists and mostly works, but has a gap: a review that ran two weeks late, a policy that wasn’t reviewed on its stated annual schedule, a log missing a signature. A major nonconformity means a control is either absent, has failed completely, or the ISMS shows a systemic breakdown, such as no evidence that access reviews happened at all for a full quarter, or multiple related minors that together point to the same root cause.

The remediation path differs by severity in ways that affect your certification timeline directly:

  • Minor nonconformities usually require a corrective action plan with evidence submitted before or at the next surveillance visit
  • Major nonconformities require root cause analysis, a corrective action, and evidence of implementation, verified by the certification body before certification can be granted
  • Certification bodies generally require major findings closed within a set window, often 90 days, before they can issue the certificate
  • If a major nonconformity remains open past that window, expect a repeat Stage 2 visit rather than a simple document review
  • Multiple unrelated majors can trigger a full audit reschedule rather than a limited follow-up

The workflow for closing any nonconformity follows the same logic regardless of severity: identify the root cause rather than just the symptom, define a corrective action that addresses that root cause, implement it, and gather evidence proving it worked before the auditor verifies closure. Skipping the root cause step is the single most common reason organizations see the same finding resurface at the next surveillance audit.

What Happens After Certification: Surveillance and Recertification

Getting certified is not the finish line. Your certificate runs on a three-year cycle, and surveillance audits in years one and two check that the ISMS is still operating, not gathering dust in a policy folder somewhere.

Surveillance audits are narrower than Stage 2 by design. Rather than re-testing every control, the auditor samples a subset, often rotating which domains get scrutinized each year, while always checking a few fixed items regardless of scope.

  • Evidence that internal audits and management reviews continued on schedule
  • Status of corrective actions from the previous audit, confirming they actually closed
  • Any significant changes to scope, systems, or risk since the last visit
  • A rotating sample of controls not deeply tested the previous year
  • Incident records and whether the incident response process was actually used, if applicable

Recertification in year three is closer to a full Stage 2 in scope, though usually compressed into fewer audit days if surveillance visits showed a stable, well-run ISMS. The exception is significant change: a merger, a new business line, a major system migration, or a scope expansion can push the certification body back into a staged approach, sometimes requiring something closer to a fresh Stage 1 before recertification proceeds. Keeping your internal audit program running consistently across all three years is what keeps recertification a formality instead of a scramble.

Evidence Checklist: What to Collect and How Much

Most Stage 2 delays come down to one problem: the evidence exists somewhere, but nobody organized it before the auditor asked for it. Building the evidence pack around your Statement of Applicability, rather than around whatever folder structure your IT team already had, cuts the back-and-forth dramatically.

Evidence types to organize before Stage 2:

  1. Policy approval records, showing sign-off dates and version history for each core policy
  2. Access review logs, covering both routine reviews and joiner/leaver processing
  3. Security incident records, from detection through root cause to closure
  4. Change management tickets, showing request, approval, testing, and deployment
  5. Backup logs paired with at least one documented restore test
  6. Vulnerability scan reports paired with remediation or exception records
  7. Supplier and third-party risk assessments for vendors handling sensitive data or systems

A practical target across most control areas is 3 to 5 sample records per control, pulled from different points across your audit window rather than the same week. That structure lets you replicate the same organizing logic across every control area in your SoA.

Evidence type Where to extract it Recommended sample size
Access review logs Identity and access management system exports 3–5 review cycles across the audit period
Incident records Incident tracking tool or ticketing system 3–5 incidents, including at least one closed end to end
Change tickets Change management or DevOps tooling 3–5 changes spanning different systems
Backup and restore evidence Backup software logs and a documented restore test 1 restore test plus 3–5 backup completion logs
Vulnerability and patching records Vulnerability scanner reports and patch management logs 3–5 scan cycles with matched remediation evidence
Supplier assessments Vendor risk questionnaires or due diligence files 3–5 vendors, prioritizing those with data access

Pre-indexing evidence this way, mapped directly to SoA controls, reduces both the time an auditor spends per control and the number of follow-up requests you get mid-audit. For a broader map of what counts as acceptable evidence across control types, a practical guide to audit evidence types is worth reviewing before you start pulling exports.

Turning Audit Requirements Into an Evidence Pack

Reading the requirements and actually organizing evidence against them are two different jobs, and most teams underestimate how much time the second one takes. A readiness tool built specifically for ISO 27001 preparation can compress that gap significantly by translating abstract requirements into a checklist tied to your specific scope, industry, and maturity level.

The outputs that matter most to an auditor aren’t generic advice. They’re a domain-by-domain maturity score across the 14 ISO 27001 domains, a checklist of evidence gaps by control, and a Gantt-style timeline showing what still needs to close before Stage 1 or Stage 2. Those three outputs map almost directly onto what a Stage 1 auditor wants to see and what a Stage 2 auditor will sample.

  • Maturity scores flag which domains are audit-ready versus still forming
  • Evidence checklists convert Annex A requirements into concrete artifacts to collect
  • Gantt timelines show whether your remediation pace will actually clear findings before the six-month window closes

Pro Tip: Export your readiness assessment results and attach them to your internal audit report before Stage 1. Auditors respond well to seeing that gaps were identified and tracked internally before they ever walked in the door.

Tools like ISMS Calculator’s certification checklist work well alongside this kind of readiness scoring, since the checklist gives you the granular steps while the assessment tells you where you actually stand against them.

An Auditor’s-Eye View of What Actually Gets You Certified

Three rules cover most of what separates a smooth Stage 2 from a painful one. Run your internal audit and management review before you even book Stage 1, not as a checkbox but as a genuine test of your own ISMS. Pre-assemble your evidence by control, indexed and dated, before the auditor asks for it. And treat your Stage 1 report as the exam paper it actually is: whatever the auditor flagged as unclear or thin is exactly where Stage 2 sampling will concentrate.

The most avoidable findings I see traced back to the same handful of causes: controls turned on too recently to have any operating history, access reviews that happened but were never documented, and corrective actions from internal audits that got logged but never actually verified as closed. None of those require new technology to fix. They require discipline in record keeping that most teams already have the capacity for.

Interview prep matters more than most compliance officers plan for. Control owners who can point to a specific record instead of describing a process in the abstract come across as credible almost immediately, and that credibility shortens the interview. The teams that struggle most are the ones who prepared the paperwork but never rehearsed the conversation.

— Martin

Get Your ISMS Audit-Ready Before You Book Stage 1

Ismscalculator gives you what a spreadsheet and a generic checklist can’t: a tailored readiness estimate that accounts for your company size, industry, and current security maturity, then converts that into the actual evidence checklist and timeline an auditor will expect to see.

Ismscalculator

Instead of guessing whether you’re three months or three quarters away from a clean Stage 1, the ISO 27001 Readiness Assessment scores you across all 14 ISO domains, flags the exact gaps holding you back, and builds a Gantt timeline showing what needs to close and when. You can save multiple estimates, compare scenarios if your scope changes, and export results as a report to hand your internal audit team or your certification body contact. If you want a faster gut check first, the platform’s free 2-minute readiness check gives you a starting maturity read before you commit to the full assessment. Run your readiness assessment now and see exactly where your ISMS stands before you schedule Stage 1.

Sources

Before finalizing your audit timeline or contract with a certification body, it’s worth reading the primary standards rather than relying solely on secondary summaries.

Checking a certification body’s accreditation status against a national accreditation body before signing a contract is a small step that avoids a much bigger problem: a certificate that clients or regulators won’t recognize as valid.

Ready to Estimate Your ISO 27001 Costs?

Use our free calculator to get a tailored cost, effort, and timeline estimate based on your company profile.

Back to all articles