Stage 1 Audit
A Stage 1 audit is the first part of a two-stage ISO certification audit, where a certification body checks whether an organization is ready to proceed to the more detailed Stage 2 audit. It typically focuses on reviewing documentation and assessing overall readiness rather than testing how controls operate in practice. Passing Stage 1 does not itself grant certification; it determines whether the organization is prepared for the Stage 2 evaluation.
In the ISO certification audit process, the Stage 1 audit is the initial evaluation conducted by an accredited certification body to assess an organization's readiness to demonstrate compliance with the applicable standard. It commonly involves a review of the management system documentation (and is therefore also referred to as a Document Review, Document Audit, or Readiness Review) and an assessment of whether the organization is prepared to advance to the Stage 2 certification audit. For an ISO/IEC 27001 engagement, this typically includes examining the information security management system (ISMS) documentation such as scope-defining materials and the Statement of Applicability, though the exact focus and depth depend on the certification body and defined scope. The Stage 1 audit determines readiness only and does not, by itself, result in certification, which follows the successful completion of the Stage 2 audit.
Why it matters
The Stage 1 audit is a gatekeeping step in the ISO certification process that helps an organization avoid the wasted effort and cost of proceeding to a full Stage 2 evaluation before its management system is ready. By assessing documentation and overall readiness up front, it surfaces gaps, such as incomplete scope-defining materials or an underdeveloped Statement of Applicability in an ISO/IEC 27001 engagement, at a point where they can be remediated before the more rigorous operating-effectiveness assessment. For compliance teams, a successful Stage 1 provides early confidence that the ISMS is structurally sound enough to withstand deeper scrutiny.
It is important to understand what the Stage 1 audit does not do. Passing Stage 1 does not, by itself, result in certification; it determines readiness only, and certification follows the successful completion of the Stage 2 audit. Because a Stage 1 audit typically focuses on reviewing documentation and assessing overall readiness rather than testing how controls operate in practice, it should not be mistaken for evidence that controls are functioning effectively in day-to-day operations.
The exact focus and depth of a Stage 1 audit depend on the certification body and the defined scope of the engagement, so organizations should treat the outcome as an indicator of preparedness within those boundaries rather than a universal pass mark. Treating Stage 1 as a genuine readiness checkpoint, rather than a formality, can reduce the risk of significant findings later and help ensure that the ISMS documentation aligns with what will be tested during Stage 2.
Who it's relevant to
Inside Stage 1 Audit
Common questions
Answers to the questions practitioners most commonly ask about Stage 1 Audit.