Skip to main content
Category: Audit Process

Stage 1 Audit

Also known as: Document Review, Document Audit, Readiness Review
Simply put

A Stage 1 audit is the first part of a two-stage ISO certification audit, where a certification body checks whether an organization is ready to proceed to the more detailed Stage 2 audit. It typically focuses on reviewing documentation and assessing overall readiness rather than testing how controls operate in practice. Passing Stage 1 does not itself grant certification; it determines whether the organization is prepared for the Stage 2 evaluation.

Formal definition

In the ISO certification audit process, the Stage 1 audit is the initial evaluation conducted by an accredited certification body to assess an organization's readiness to demonstrate compliance with the applicable standard. It commonly involves a review of the management system documentation (and is therefore also referred to as a Document Review, Document Audit, or Readiness Review) and an assessment of whether the organization is prepared to advance to the Stage 2 certification audit. For an ISO/IEC 27001 engagement, this typically includes examining the information security management system (ISMS) documentation such as scope-defining materials and the Statement of Applicability, though the exact focus and depth depend on the certification body and defined scope. The Stage 1 audit determines readiness only and does not, by itself, result in certification, which follows the successful completion of the Stage 2 audit.

Why it matters

The Stage 1 audit is a gatekeeping step in the ISO certification process that helps an organization avoid the wasted effort and cost of proceeding to a full Stage 2 evaluation before its management system is ready. By assessing documentation and overall readiness up front, it surfaces gaps, such as incomplete scope-defining materials or an underdeveloped Statement of Applicability in an ISO/IEC 27001 engagement, at a point where they can be remediated before the more rigorous operating-effectiveness assessment. For compliance teams, a successful Stage 1 provides early confidence that the ISMS is structurally sound enough to withstand deeper scrutiny.

It is important to understand what the Stage 1 audit does not do. Passing Stage 1 does not, by itself, result in certification; it determines readiness only, and certification follows the successful completion of the Stage 2 audit. Because a Stage 1 audit typically focuses on reviewing documentation and assessing overall readiness rather than testing how controls operate in practice, it should not be mistaken for evidence that controls are functioning effectively in day-to-day operations.

The exact focus and depth of a Stage 1 audit depend on the certification body and the defined scope of the engagement, so organizations should treat the outcome as an indicator of preparedness within those boundaries rather than a universal pass mark. Treating Stage 1 as a genuine readiness checkpoint, rather than a formality, can reduce the risk of significant findings later and help ensure that the ISMS documentation aligns with what will be tested during Stage 2.

Who it's relevant to

Compliance and GRC Managers
Compliance managers use the Stage 1 audit as an early readiness checkpoint, identifying documentation gaps, such as an incomplete Statement of Applicability or unclear ISMS scope, before committing to the more detailed Stage 2 evaluation. Understanding that Stage 1 assesses preparedness rather than granting certification helps them set accurate expectations with leadership.
Security Engineers and ISMS Owners
Those responsible for building and maintaining the ISMS rely on Stage 1 feedback to confirm that scope-defining materials and management system documentation are complete and coherent before controls are examined in practice at Stage 2. Because the focus and depth vary by certification body and scope, engineers should confirm expectations with the auditing body early.
Auditors and Certification Bodies
Accredited certification bodies conduct the Stage 1 audit to evaluate an organization's readiness to demonstrate compliance and to determine whether it is prepared to advance to Stage 2. This stage frames the scope and focus of the subsequent detailed audit while making clear that certification itself follows only after a successful Stage 2.

Inside Stage 1 Audit

Documentation Review
A Stage 1 audit primarily focuses on reviewing the ISMS documentation, including policies, procedures, the scope definition, the Statement of Applicability, and the risk assessment methodology, to confirm they exist and align with the ISO/IEC 27001 clause 4 through 10 requirements.
Readiness Assessment
It evaluates whether the organization is prepared to proceed to the Stage 2 audit by identifying gaps, deficiencies, or areas of concern in the ISMS before the certification body assesses implementation and operating effectiveness.
Scope and Statement of Applicability Confirmation
The auditor typically confirms the defined boundaries of the ISMS and reviews the Statement of Applicability, which documents the selection and justification of Annex A reference controls informed by the risk assessment. Annex A control counts depend on the edition (114 in the 2013 version; 93 across four themes in the 2022 revision), so the applicable version should be specified.
Findings and Preparation for Stage 2
The outcome typically includes observations or documented findings that the organization is expected to address before Stage 2, where the certification body evaluates whether the ISMS is implemented and operating effectively. Note that a successful ISO 27001 outcome is a certification issued by an accredited certification body, not a report or attestation.

Common questions

Answers to the questions practitioners most commonly ask about Stage 1 Audit.

Is a Stage 1 audit just a pass/fail test where you either get certified or fail?
No. The Stage 1 audit is not a pass/fail certification decision. It is typically a readiness or documentation review in which the certification body evaluates whether your ISMS documentation and overall preparedness are sufficient to proceed to the Stage 2 audit. Certification is not granted at Stage 1; the outcome usually identifies gaps or areas of concern to address before Stage 2, where the auditor assesses the implementation and operating effectiveness of the ISMS.
Does the Stage 1 audit produce a SOC 2-style report or attestation?
No. Stage 1 is a phase within the ISO/IEC 27001 certification process conducted by an accredited certification body, not an attestation examination performed by a CPA firm under SSAE 18. It does not result in a SOC 2 report or an attestation. Its purpose is to prepare for the Stage 2 audit that supports a certification decision, and the two frameworks should not be conflated.
What does a certification body typically review during a Stage 1 audit?
In most engagements, a certification body reviews the ISMS documentation, which may include items such as the scope definition, the Statement of Applicability, the risk assessment approach, and related policies and procedures. The review focuses on whether the ISMS is sufficiently designed and documented to proceed to Stage 2, though the exact focus depends on the certification body and the defined scope.
How should an organization prepare for a Stage 1 audit?
Preparation typically involves ensuring that ISMS documentation is complete and internally consistent, that the scope is clearly defined, and that the Statement of Applicability reflects the results of the risk assessment. Organizations often confirm that required documentation for clauses 4 through 10 is in place, since these are the certifiable requirements. Specific expectations vary by certification body and scope.
What typically happens between the Stage 1 and Stage 2 audits?
Between Stage 1 and Stage 2, organizations generally address any gaps or areas of concern the certification body identified during Stage 1. This period is often used to remediate documentation deficiencies and strengthen ISMS implementation before the Stage 2 audit assesses implementation and operating effectiveness. The interval between stages is set by scheduling and scoping decisions rather than a fixed rule.
Does passing the Stage 1 audit guarantee a successful certification outcome?
No. A satisfactory Stage 1 outcome indicates that the ISMS documentation and readiness are sufficient to proceed, but it does not guarantee certification. The Stage 2 audit still assesses the implementation and operating effectiveness of the ISMS within the defined scope, and the certification decision depends on those findings. The certificate, when issued, covers only the defined scope of the ISMS.

Common misconceptions

Passing the Stage 1 audit means the organization is certified to ISO 27001.
Stage 1 is typically a documentation and readiness review only. Certification is not granted until after the Stage 2 audit, where implementation and operating effectiveness of the ISMS are assessed by the accredited certification body, and any findings are resolved.
A Stage 1 audit is equivalent to a SOC 2 examination or produces a similar report.
The Stage 1 audit is part of the ISO/IEC 27001 certification process against a management system standard. A SOC 2 engagement is a separate attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certification. Satisfying one framework does not automatically satisfy the other.
The Stage 1 audit verifies that all Annex A controls are fully operating.
Stage 1 typically concentrates on reviewing documentation, scope, the Statement of Applicability, and readiness. Assessment of whether controls are implemented and operating effectively generally occurs during the Stage 2 audit, depending on the certification body and scope.

Best practices

Ensure the ISMS documentation covering clauses 4 through 10 is complete and internally consistent before the Stage 1 audit, including the scope statement, risk assessment methodology, and Statement of Applicability.
Clearly define and document the ISMS scope, since the eventual certificate covers only the defined boundaries of the ISMS.
Prepare the Statement of Applicability to show that Annex A control selections are justified by the risk assessment, and specify the ISO 27001 edition being applied to avoid confusion over control counts.
Treat Stage 1 findings as a readiness checklist and remediate documented gaps before proceeding to Stage 2, where implementation and operating effectiveness are typically assessed.
Confirm expectations, review period, and scoping decisions with the certification body in advance, since specific procedures can vary by certification body and scope.
Avoid assuming Stage 1 success guarantees certification or freedom from security incidents; certification depends on completing Stage 2 and covers only the defined ISMS scope.