What are the stages of an ISO 27001 audit?
Last verified 2026-08-19 · UK focus
Short answer
ISO 27001 certification uses a two-stage initial audit followed by ongoing surveillance. Stage 1 checks that the ISMS is documented and ready — scope, risk assessment, Statement of Applicability, internal audit and management review. Stage 2 tests whether controls actually operate, by sampling records. Surveillance audits then occur annually, with a full recertification audit in year three.
Key facts
- Stage 1 is a readiness/documentation review, usually 1-2 days.
- Stage 2 is an effectiveness audit that samples evidence, usually 2-5 days for an SME.
- Findings are graded as major nonconformity, minor nonconformity, or opportunity for improvement.
- Major nonconformities block certification until closed; minors are usually closed with a corrective action plan.
ISO 27001 audit stages and cadence
| Audit | When | Typical length (SME) | Focus |
|---|---|---|---|
| Internal audit | Before Stage 2, then at least annually | 1-3 days | Your own audit of the whole ISMS |
| Stage 1 | Start of certification | 1-2 days | Documentation, scope, SoA, readiness |
| Stage 2 | 2-6 weeks after Stage 1 | 2-5 days | Control operation and evidence sampling |
| Surveillance 1 | ~12 months after certification | 1-2 days | Subset of controls, corrective actions |
| Surveillance 2 | ~24 months | 1-2 days | Different subset, continual improvement |
| Recertification | ~36 months | 2-4 days | Full ISMS re-audit; new three-year cycle |
Caveats
- Audit durations are set by the certification body from IAF MD 5 mandays tables and scale with headcount and scope complexity.
- Internal audit and management review must be completed before Stage 2 — they are mandatory clause 9 requirements.
Sources
- ISO/IEC 27001:2022, clauses 9.2 (internal audit) and 9.3 (management review). International Organization for Standardization, 2022-10-25.
- IAF MD 5: Determination of Audit Time of Management Systems. International Accreditation Forum, 2025-01-01.
Check your own position
Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.
