Skip to content

ISO 27001 stage 1 audit

Stage 1 assesses the starting position and readiness for stage 2. Discuss scope, documentation, implementation and areas of concern with the certification body.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

What does stage 1 examine?

Stage 1 is the first part of an initial certification assessment. The certification body examines the management system’s boundaries and preparation to support planning for stage 2. It is neither a separate certificate nor a guarantee that stage 2 will produce no nonconformities. NQA describes the two stages in its certification process. Agree the specific agenda and requested information with your chosen body.

Prepare connections, not a document pile

Start with a clear scope. Show which services, locations and dependencies are included. Connect those boundaries to the risk assessment and selected controls. Make sure staff can identify current versions and explain how records relate to everyday work.

Show implementation as well: which checks have taken place, which results have been reviewed and which improvements remain open? Be transparent about the status of internal audit and management review. An empty template shows an intended method; a completed record can demonstrate how that method has been used. Explain limitations instead of presenting planned activities as completed work.

Check these connections before assessment

TopicPractical check
ScopeDo the boundaries match actual service delivery?
RisksHas the assessment method been applied to relevant situations?
SoAAre control selection and implementation status supported?
EvaluationAre audit and management review results available?
PlanningAre responsible people and evidence locations known?

Fictional example: an outsourced service desk

A fictional SaaS provider includes its application in scope but has not considered its outsourced service desk in the risk assessment. Preparation reveals that the supplier can reset customer accounts. The organisation clarifies this dependency, assesses the risks and documents relevant agreements and checks. This requires substantive work; simply adding “service desk” to a document does not supply the missing assessment.

Address results before the next stage

Discuss each area of concern with the certification body: what is expected, what evidence is needed and how does it affect scheduling? Track actions and owners. Do not assume a universal correction deadline or mandatory waiting period; the circumstances and arrangements with the body matter. Then read what the stage 2 audit examines. ISO does not issue certificates itself; certification bodies carry out that work.

Primary sources for this topic

Frequently asked questions

Does a successful stage 1 audit result in an ISO 27001 certificate?
No. Stage 1 forms part of the initial certification assessment and helps determine readiness for stage 2. A certification decision is not based solely on this preparatory stage. The certification body also needs to address the results of the further assessment and any nonconformities under its certification process before a certificate can be issued.
How should areas of concern from stage 1 be handled?
For each issue, record what is missing, who will address it and what evidence supports the change. Discuss with the certification body what is needed before stage 2 and how this affects the schedule. Use the finding to improve actual operation; changing a document alone may not adequately resolve the underlying issue.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)