What are the stages of an ISO 27001 audit?

Last verified 2026-08-19 · UK focus

Short answer

ISO 27001 certification uses a two-stage initial audit followed by ongoing surveillance. Stage 1 checks that the ISMS is documented and ready — scope, risk assessment, Statement of Applicability, internal audit and management review. Stage 2 tests whether controls actually operate, by sampling records. Surveillance audits then occur annually, with a full recertification audit in year three.

Key facts

  • Stage 1 is a readiness/documentation review, usually 1-2 days.
  • Stage 2 is an effectiveness audit that samples evidence, usually 2-5 days for an SME.
  • Findings are graded as major nonconformity, minor nonconformity, or opportunity for improvement.
  • Major nonconformities block certification until closed; minors are usually closed with a corrective action plan.

ISO 27001 audit stages and cadence

ISO 27001 audit stages and cadence
AuditWhenTypical length (SME)Focus
Internal auditBefore Stage 2, then at least annually1-3 daysYour own audit of the whole ISMS
Stage 1Start of certification1-2 daysDocumentation, scope, SoA, readiness
Stage 22-6 weeks after Stage 12-5 daysControl operation and evidence sampling
Surveillance 1~12 months after certification1-2 daysSubset of controls, corrective actions
Surveillance 2~24 months1-2 daysDifferent subset, continual improvement
Recertification~36 months2-4 daysFull ISMS re-audit; new three-year cycle

Caveats

  • Audit durations are set by the certification body from IAF MD 5 mandays tables and scale with headcount and scope complexity.
  • Internal audit and management review must be completed before Stage 2 — they are mandatory clause 9 requirements.

Sources

  1. ISO/IEC 27001:2022, clauses 9.2 (internal audit) and 9.3 (management review). International Organization for Standardization, 2022-10-25.
  2. IAF MD 5: Determination of Audit Time of Management Systems. International Accreditation Forum, 2025-01-01.

Check your own position

Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.

Related