---
title: Preparing for your ISO 27001 Stage 2 Audit
description: Preparing for your ISO 27001 Stage 2 Audit
---

[Skip to content](https://knowledge.sensiba.com/preparing-for-your-iso-27001-stage-2-audit#main-content)

English

Show submenu for translations

- Sensiba

Open main navigation

Close main navigation

- Sensiba
- English
  
  Show submenu for translations
- [Go to sensiba.com](https://sensiba.com/)

[Go to sensiba.com](https://sensiba.com/)

 Hi There! How can we help you?

- There are no suggestions because the search field is empty.

1. [Sensiba Knowledge Base](https://knowledge.sensiba.com/?hsLang=en)
2. [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)

# Preparing for your ISO 27001 Stage 2 Audit

#### The ISO 27001 certification process consists of two audit stages:

- **Stage 1 Audit** – A readiness assessment that evaluates your Information Security Management System (ISMS), documentation, and preparedness for certification.
- **Stage 2 Audit** – The certification audit that assesses whether your ISMS has been effectively implemented and is operating in accordance with ISO 27001 requirements.

Successfully completing Stage 1 is an important milestone, but it does not mean your organisation is ready for certification. Between Stage 1 and Stage 2, you'll need to address any findings, continue operating your ISMS, and gather evidence that demonstrates your security controls are working effectively.

This guide outlines what auditors will be looking for during Stage 2 and how to determine when your organisation is ready to proceed.

**Understanding the Stage 1 Audit**

The Stage 1 audit is designed to determine whether your organisation is sufficiently prepared for the certification audit.

During this assessment, auditors review the design of your ISMS, including documentation such as policies, procedures, risk assessments, the Statement of Applicability (SoA), and other core management system records. They also assess whether the scope of the ISMS is appropriate and whether the key processes required by ISO 27001 have been established.

The outcome of Stage 1 is typically a series of observations or Areas of Concern that should be addressed before proceeding to Stage 2.

**What Happens During the Stage 2 Audit?**

Stage 2 is the formal certification audit.

Rather than reviewing whether documentation exists, auditors focus on whether your ISMS has been implemented, is operating effectively, and is achieving its intended outcomes.

Throughout the audit, they will assess whether your day-to-day practices align with your documented policies and procedures.

Typical Stage 2 activities include:

- Interviews with management and key personnel responsible for the ISMS
- Sampling evidence across ISMS processes
- Reviewing operational records and documented evidence
- Testing the implementation and effectiveness of applicable Annex A controls
- Verifying that corrective actions have been completed where required

The objective is to demonstrate that your organisation is not simply documenting security practices, but actively operating and maintaining an effective ISMS.

**Address Stage 1 Findings**

The first priority after Stage 1 is addressing any Areas of Concern identified by the auditors.

This may include:

- Reviewing findings and understanding their root causes
- Completing a gap analysis where additional improvements are required
- Developing and implementing corrective action plans
- Assigning ownership and realistic completion timeframes
- Verifying that corrective actions have been implemented effectively

Being able to demonstrate how findings were resolved provides confidence that your organisation is committed to continual improvement.

**Review Your Risk Management Process**

Risk management sits at the centre of ISO 27001 and will continue to be assessed during Stage 2.

Auditors will expect to see that your organisation has an established process for identifying, evaluating, treating, and reviewing information security risks.

Before Stage 2 you should ensure that:

- Risk assessments have been reviewed and updated where necessary
- New or emerging risks have been considered
- Risk treatment plans remain current
- Risk decisions are supported by appropriate evidence

A mature and well-maintained risk management process demonstrates that your ISMS is operating as intended rather than being treated as a one-off exercise.

**Implement Your Statement of Applicability**

During Stage 1, auditors reviewed your Statement of Applicability (SoA) to confirm which Annex A controls apply to your organisation.

By Stage 2, those applicable controls should be fully implemented and operating effectively.

This means you should be able to demonstrate:

- Each applicable control has been implemented
- Supporting evidence is available
- Responsibilities are clearly defined
- Controls are being maintained as part of normal business operations

Remember that Stage 2 focuses on implementation, not intention.

**Build Security Awareness Across the Organisation**

Information security is not solely the responsibility of the security team—it should be understood across the organisation.

Auditors will often interview employees to determine whether they understand their security responsibilities and are following documented procedures.

Before Stage 2, ensure that:

- Security awareness training has been completed
- Staff understand key information security policies
- Employees know how to identify and report security incidents
- Training records and attendance evidence are maintained

A knowledgeable workforce demonstrates that information security has become embedded within your organisation.

**Internal Audit Programme**

Your internal audit programme will already have been reviewed during Stage 1, however auditors will revisit it during Stage 2 to confirm that it is operating effectively.

They will be looking for evidence that internal audits are being used to identify issues, verify compliance, and drive continual improvement.

You should be able to demonstrate:

- Internal audits are conducted regularly and objectively
- Audit results are documented
- Any identified nonconformities have been addressed
- Corrective actions have been implemented and verified
- Lessons learned are incorporated back into the ISMS

An effective internal audit programme shows that your organisation is actively monitoring the health of its management system.

**Management Review**

Management review is another core ISMS process that auditors will revisit during Stage 2.

They will assess whether senior leadership continues to review the performance of the ISMS and whether management decisions are driving continual improvement.

Evidence should demonstrate that:

- Management reviews occur at planned intervals
- Required ISO 27001 inputs have been considered
- Actions from previous management reviews have been completed
- Decisions and improvement opportunities are documented
- Management remains actively engaged in the effectiveness of the ISMS

Leadership involvement is a key indicator that the ISMS is supported across the organisation.

**How Do You Know You're Ready for Stage 2?**

One of the most common questions organisations ask is how long they should wait between Stage 1 and Stage 2.

The answer is that there is no prescribed timeframe within ISO 27001.

Rather than focusing on a specific number of weeks or months, organisations should proceed to Stage 2 once they can demonstrate that the ISMS has completed at least one operational cycle and sufficient evidence exists to show that its processes and applicable Annex A controls are functioning effectively.

Every organisation's readiness timeline will be different depending on its size, complexity, and level of maturity.

**Key Takeaways**

You are generally ready to proceed with your Stage 2 audit when you can demonstrate that:

- Stage 1 findings have been addressed.
- Your ISMS has been operating for at least one complete management cycle.
- Risk assessments and treatment activities are current.
- Applicable Annex A controls have been implemented.
- Employees understand their information security responsibilities.
- Internal audits have been completed and corrective actions addressed.
- Management reviews have been conducted and resulting actions implemented.
- Objective evidence exists to demonstrate the effectiveness of your ISMS.

Stage 2 is your opportunity to demonstrate that information security is embedded into your organisation's day-to-day operations. By ensuring your ISMS is operating effectively, continually improving, and supported by objective evidence, you'll be well positioned for a successful certification audit and, ultimately, ISO 27001 certification.

- [Platform](https://knowledge.sensiba.com/platform?hsLang=en#main-content)

    - [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)
    - [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)
    - [Scrut](https://knowledge.sensiba.com/platform?hsLang=en#scrut)
    - [Sprinto](https://knowledge.sensiba.com/platform?hsLang=en#sprinto)
- [Best Practices Series](https://knowledge.sensiba.com/best-practices-series?hsLang=en#main-content)

    - [Risk management & internal controls](https://knowledge.sensiba.com/best-practices-series?hsLang=en#risk-management-internal-controls)
    - [Information & communication](https://knowledge.sensiba.com/best-practices-series?hsLang=en#information-communication)
    - [Data protection](https://knowledge.sensiba.com/best-practices-series?hsLang=en#data-protection)
    - [System security](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-security)
    - [Change management](https://knowledge.sensiba.com/best-practices-series?hsLang=en#change-management)
    - [System operations](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-operations)
    - [Control environment](https://knowledge.sensiba.com/best-practices-series?hsLang=en#control-environment)
- [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#main-content)

    - [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)
    - [Vulnerability Management](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#vulnerability-management)
    - [Security Awareness](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#security-awareness)
    - [Anti-malware](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#anti-malware)
    - [Information Asset Lifecycle](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#information-asset-lifecycle)
    - [Access Control](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#access-control)
    - [Governance Requirements](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#governance-requirements)
- [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)
- [Control Environment](https://knowledge.sensiba.com/control-environment?hsLang=en)
- [Information and Communication](https://knowledge.sensiba.com/information-and-communication?hsLang=en)
- [Risk Management](https://knowledge.sensiba.com/risk-management?hsLang=en)
- [Vendor Management](https://knowledge.sensiba.com/vendor-management?hsLang=en)
- [System Security](https://knowledge.sensiba.com/system-security?hsLang=en)
- [System Operations](https://knowledge.sensiba.com/system-operations?hsLang=en)
- [Change Management](https://knowledge.sensiba.com/change-management?hsLang=en)
- [Confidentiality](https://knowledge.sensiba.com/confidentiality?hsLang=en)
- [Privacy](https://knowledge.sensiba.com/privacy?hsLang=en)
- [CDR Reps](https://knowledge.sensiba.com/cdr-reps?hsLang=en)
- [Access reviews](https://knowledge.sensiba.com/access-reviews?hsLang=en)
- [Governance](https://knowledge.sensiba.com/governance?hsLang=en)
- [Employee management](https://knowledge.sensiba.com/employee-management?hsLang=en)
- [FAQs](https://knowledge.sensiba.com/faqs?hsLang=en)
- [Sensiba Audit Tools](https://knowledge.sensiba.com/sensiba-audit-tools?hsLang=en)

- Sensiba

[![Sensiba Logo](https://knowledge.sensiba.com/hs-fs/hubfs/Sensiba_Logo_Hubspot-01.png?width=247&height=48&name=Sensiba_Logo_Hubspot-01.png "Sensiba Logo")](https://sensiba.com/)

Copyright © 2026, Sensiba LLP