Skip to main content
Category: Audit Process

Stage 2 Audit

Also known as: Main Audit, Certification Audit
Simply put

The Stage 2 audit is the main part of the ISO 27001 certification process, where an auditor from a certification body examines how well an organization's information security management system (ISMS) actually works in practice. Rather than just reviewing documents, the auditor visits the organization and tests whether the security controls are genuinely operating as described. It follows an earlier Stage 1 review and is the point at which the organization's readiness for certification is assessed.

Formal definition

In the ISO/IEC 27001 certification process, the Stage 2 audit (also called the main or certification audit) is the on-site assessment in which an accredited certification body evaluates the actual implementation and operating effectiveness of the ISMS against the requirements of the standard. It follows the Stage 1 audit, which typically focuses on documentation and readiness review, and involves the auditor gathering evidence on-site to confirm that the ISMS conforms to the certifiable requirements and that the controls selected via the Statement of Applicability are in operation. A successful Stage 2 audit supports the issuance of an ISO 27001 certificate, which covers only the defined scope of the ISMS. The specific procedures, duration, and sampling depend on the certification body and the scope of the engagement. Note that Stage 2 audit terminology is also used in other management system standards such as ISO 9001; this entry addresses the ISO/IEC 27001 context.

Why it matters

The Stage 2 audit is the decisive point in the ISO/IEC 27001 certification process, because it is where a certification body moves beyond documentation and evaluates whether the information security management system (ISMS) actually operates in practice. An organization may have well-written policies and a complete Statement of Applicability, but the Stage 2 audit tests whether the controls described are genuinely implemented and operating. For this reason, it is the stage that most directly determines whether an organization is ready for certification.

Because the outcome of a successful Stage 2 audit supports the issuance of an ISO 27001 certificate, the stakes are meaningful for organizations that rely on certification to demonstrate security assurance to customers, partners, and regulators. It is important to understand what the audit does and does not establish: the resulting certificate covers only the defined scope of the ISMS, and conformity assessed during the audit is a point-in-time judgment about how the ISMS meets the standard's requirements rather than a guarantee against future incidents or a statement about anything outside the assessed scope.

Understanding the Stage 2 audit also helps organizations avoid confusing it with similarly named audits under other management system standards. Stage 2 audit terminology is used in standards such as ISO 9001 as well, so professionals should be clear that an ISO 27001 Stage 2 audit specifically concerns the ISMS and the certifiable requirements of ISO/IEC 27001, not a quality management system or an unrelated certification.

Who it's relevant to

Compliance and GRC managers
Those responsible for coordinating an ISO 27001 certification effort need to understand that the Stage 2 audit is the main audit where the ISMS is tested in practice. Because it follows the Stage 1 readiness review and directly supports certification, GRC leaders use it to plan evidence collection and confirm that controls described in the Statement of Applicability are actually operating.
Security engineers and ISMS implementers
Practitioners who build and maintain the ISMS controls should recognize that the Stage 2 auditor gathers evidence on-site to verify that controls genuinely operate, not just that they are documented. This makes hands-on implementation and demonstrable evidence, rather than policy text alone, central to a successful outcome.
Executives and decision-makers
Leaders who rely on certification to demonstrate security assurance should understand what the Stage 2 audit establishes and its limits: a successful audit supports issuance of a certificate that covers only the defined scope of the ISMS and reflects conformity assessed by the certification body, rather than a guarantee against breaches.
Professionals distinguishing ISO 27001 from other standards
Because Stage 2 audit terminology also appears in standards such as ISO 9001, teams working across multiple management systems should be careful to scope discussions to the ISO/IEC 27001 context, where the audit concerns the ISMS and the standard's certifiable requirements.

Inside Stage 2 Audit

Certification Audit (Stage 2)
The second phase of the ISO/IEC 27001 initial certification process, conducted by an accredited certification body to evaluate whether the organization's information security management system (ISMS) is implemented and operating effectively against the requirements in clauses 4 through 10.
Evidence of Implementation
Unlike the documentation-focused Stage 1, Stage 2 gathers objective evidence that the ISMS is functioning in practice, typically through interviews, observation of activities, and review of records demonstrating that processes are being followed.
Statement of Applicability (SoA) Verification
Auditors typically assess whether the Annex A reference controls selected in the SoA, informed by the organization's risk assessment, are actually deployed and operating within the defined ISMS scope. The applicable control set depends on the version of the standard in use (for example, the 2022 revision organizes Annex A controls into four themes).
Nonconformities and Findings
The audit may result in findings, which in most schemes are categorized by severity. Major nonconformities generally must be addressed before a certificate can be recommended, while minor nonconformities typically require a corrective action plan. The exact categorization and handling depend on the certification body.
Certification Recommendation
A successful Stage 2 audit leads to a recommendation for certification, after which the accredited certification body may issue an ISO/IEC 27001 certificate covering only the defined scope of the ISMS. This is a certification outcome, not a report or attestation.
Defined ISMS Scope
Stage 2 assesses only the boundaries of the ISMS as defined by the organization. The resulting certificate covers only that scope and does not extend to systems, locations, or processes excluded from it.

Common questions

Answers to the questions practitioners most commonly ask about Stage 2 Audit.

Does passing a Stage 2 audit result in a report or attestation like SOC 2?
No. A Stage 2 audit is part of the ISO/IEC 27001 certification process, not an attestation examination. When completed successfully, it leads to a certification issued by an accredited certification body against the ISMS requirements in clauses 4 through 10, not a report or attestation. A SOC 2 report, by contrast, is produced by a licensed CPA firm under the AICPA SSAE 18 standard. The two outcomes are distinct and should not be described interchangeably.
Is the Stage 2 audit the same thing as the Stage 1 audit, just more detailed?
Not exactly. Stage 1 and Stage 2 typically serve different purposes within the certification process. Stage 1 generally focuses on reviewing documentation and readiness of the ISMS, while Stage 2 assesses the implementation and operating effectiveness of the management system and the controls selected via the Statement of Applicability. Treating Stage 2 as merely a deeper version of Stage 1 understates the shift from documentation review to evaluating how the ISMS operates in practice. The specific approach depends on the certification body and the defined scope.
How should we prepare for a Stage 2 audit after completing Stage 1?
In most engagements, preparation centers on addressing any findings or observations raised during Stage 1 and ensuring the ISMS is operating as documented. This typically includes confirming that risk assessment outputs, the Statement of Applicability, and the selected Annex A reference controls are implemented and generating evidence. Because expectations vary by certification body and scope, it is advisable to confirm the specific evidence and interviews the auditor anticipates rather than assuming a fixed checklist.
What kind of evidence do auditors typically look for during Stage 2?
Auditors generally look for evidence that the ISMS requirements in clauses 4 through 10 are being met and that the controls selected through the Statement of Applicability are operating. Depending on scope, this can include records, logs, meeting minutes, interviews with personnel, and demonstrations of processes. The exact evidence depends on the auditor, the certification body, and the boundaries of the defined ISMS, so the mix varies from engagement to engagement.
What happens if nonconformities are identified during a Stage 2 audit?
When nonconformities are raised, the organization is typically required to respond with corrective action, and the certification body assesses whether the response is adequate before certification can proceed. The handling of major versus minor nonconformities and the timelines for resolution vary by certification body and are set within their procedures. Because outcomes depend on the specific findings and the certification body's requirements, it is best to confirm the applicable process directly with the auditor.
Does a successful Stage 2 audit mean our whole organization is certified?
No. An ISO 27001 certificate covers only the defined scope of the ISMS as assessed. A successful Stage 2 audit supports certification for that scope, not necessarily the entire organization. It is important to clarify the ISMS boundaries when interpreting what the resulting certificate covers, and to recognize that the certificate does not guarantee freedom from security incidents outside or even within the assessed controls.

Common misconceptions

Stage 2 produces a report similar to a SOC 2 examination.
Stage 2 is part of an ISO/IEC 27001 certification process performed by an accredited certification body, resulting in a certificate against a management system standard. A SOC 2 engagement is a separate attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and produces a report, not a certificate. The two are distinct and satisfying one does not automatically satisfy the other.
Passing Stage 2 guarantees the organization is free from security breaches.
A certificate confirms only that the ISMS met the standard's requirements within the defined scope at the time of assessment. It does not guarantee freedom from incidents or breaches, and it does not cover systems or processes outside the certified scope.
Stage 2 simply re-checks the documentation reviewed in Stage 1.
Stage 1 typically focuses on readiness and documentation, whereas Stage 2 seeks objective evidence that the ISMS is implemented and operating effectively in practice, depending on the certification body's approach.

Best practices

Ensure that the controls selected in your Statement of Applicability are not only documented but actively implemented and supported by records, since Stage 2 typically looks for evidence of operation rather than intent.
Confirm which version of the standard your certification body is auditing against and align your control references accordingly, as Annex A control organization differs between editions.
Address any findings raised in Stage 1 before Stage 2, and prepare corrective action processes so that minor nonconformities can be resolved through documented plans.
Clearly define and communicate the ISMS scope internally, ensuring staff in interviews can speak to the processes within that boundary, since the resulting certificate covers only the defined scope.
Prepare relevant personnel to demonstrate ISMS activities through interviews and observation, as auditors in most engagements gather evidence directly from operations rather than documents alone.
Maintain records that demonstrate risk assessment, control operation, and management system activity over time, so evidence of effective implementation is readily available to the audit team.