skip to content

In ISO/IEC 27001 certification, what do the stage 1 and stage 2 audits check, and how do nonconformities play out over the three-year cycle?

level: seniorimportance: should knowfreq 45%

answer

  1. readiness, then effectiveness
  2. documents first, operation second
  3. major blocks, minor is planned
  4. annual surveillance visits
  5. recertify before year three ends

basics

~20 s

Stage 1 checks readiness: scope, documents, risk method, Statement of Applicability, and that internal audit and management review have run. Stage 2 checks the ISMS operates effectively. Major nonconformities block certification until closed; minors need an accepted plan. Surveillance audits follow, then recertification.

solid answer

~50 s

Certification is done by a certification body accredited to audit ISMSs. **Stage 1** is a readiness review: the ISMS scope, policy, risk assessment and treatment method, Statement of Applicability, and evidence that at least one internal audit and management review have happened. It decides whether stage 2 can go ahead. **Stage 2** tests implementation and effectiveness: interviews, records and control operation across the scope. Findings are graded. A **major nonconformity** — a required element missing or broken down, or doubt that the ISMS achieves its outcomes — must be corrected and verified before the certificate is issued. A **minor nonconformity** is an isolated lapse; the organization submits a correction and corrective action plan, verified at the next visit. The certificate lasts **three years**, with **surveillance audits** at least annually and a **recertification audit** before expiry. Unresolved minors can escalate to major at surveillance.

go deeper

for a junior

Recall that stage 1 checks readiness and documents, stage 2 checks the ISMS works, and the certificate runs for three years with surveillance audits.

for a middle

Explain the difference between major and minor nonconformities and what each does to the certification decision.

for a senior

Show how you would prepare a first-time company for stage 2 and respond to a major nonconformity found on the audit's last day.

for a principal

Discuss choosing a certification body, planning scope extensions over the cycle, and keeping the ISMS alive between surveillance visits.

## Who certifies ISO does not issue certificates. Independent **certification bodies**, accredited by a national accreditation body to audit information security management systems, perform the audits and grant the certificate. Accreditation matters: a certificate from an unaccredited body carries little weight with customers. Certification bodies follow ISO/IEC 17021-1, the general requirement for management-system certification, and ISO/IEC 27006, its ISMS-specific supplement. ## Stage 1: is the ISMS ready? Stage 1 is usually shorter and document-focused. The auditor checks: - The **scope** is defined and sensible, with interfaces to what is outside it. - The **information security policy**, objectives and roles exist and are approved by top management. - The **risk assessment and treatment** method is defined and has been applied. - The **Statement of Applicability** covers the Annex A controls with justified exclusions. - At least one **internal audit** and one **management review** have taken place. The output is a report of areas of concern that could become nonconformities at stage 2, and a decision on whether stage 2 can proceed. ## Stage 2: does it work? Stage 2 tests the ISMS in operation across the scope: interviews with staff and management, records of risk treatment, evidence that controls in the SoA operate, measurement of objectives, and follow-through on internal audit findings. Its aim is to confirm the ISMS **conforms** to ISO/IEC 27001 and is **effective**. ## Grading findings | Finding | Typical meaning | Consequence | |---|---|---| | **Major nonconformity** | A requirement not met at all, a total breakdown of a process, or significant doubt the ISMS achieves its intended results | Certificate withheld until correction is made and verified, often by a follow-up visit | | **Minor nonconformity** | An isolated or partial lapse that does not undermine the system | Certificate can be granted once a credible correction and corrective action plan is accepted; verified at next audit | | **Opportunity for improvement** | Not a nonconformity; a suggestion | No obligation, but auditors look at what was done with it | For a 250-person SaaS company, "no internal audit has ever been performed" is typically major; "two leavers' accounts were disabled late" is typically minor, unless it reveals that offboarding does not work at all. ## The three-year cycle 1. **Initial certification** — stage 1 and stage 2, then the certification decision. 2. **Surveillance audits** — at least once a year in the years between, each sampling part of the ISMS and always covering core elements such as internal audit, management review, corrective action and use of the certification mark. 3. **Recertification audit** — before the certificate expires, a fuller audit of the whole ISMS to renew for another three years. Minor nonconformities not closed by the next surveillance can be raised as major. A lapse in surveillance can lead to suspension or withdrawal of the certificate. ## Scope changes and the 2022 transition - Extending scope, such as adding a new product line, is usually handled at a surveillance audit or a special audit, and the certificate is reissued with the new scope. - Certificates to the 2013 edition had to transition to ISO/IEC 27001:2022 within a fixed transition period, which has ended; transition audits focused on the new Annex A controls and the updated Statement of Applicability. ## Preparing well - Run the internal audit early enough to fix what it finds before stage 2. - Make sure SoA status matches reality; a control marked implemented but not operating is a finding. - Brief control owners; auditors interview people, not only documents.

  • What turns a minor nonconformity into a major one?
    Several related minors that together show a process has broken down, a minor that was not corrected by the next audit, or new evidence that the lapse was systemic rather than isolated. For example, one late account removal is minor; late removals across teams with no working offboarding process suggests a requirement is not being met at all, which auditors grade as major.
  • Why must at least one internal audit and management review happen before stage 2?
    Because they are the clause 9 mechanisms that prove the ISMS evaluates and corrects itself. Without them there is no evidence the system is more than documents, and the auditor cannot conclude it is effective. Certification bodies therefore expect a complete cycle, including internal audit and management review, before recommending certification.

saying these in an interview costs you the question

  • Stage 1 is where controls are sampled and tested in depth.
  • Once issued, the certificate stays valid for three years with no further audits.
  • A minor nonconformity blocks the certificate until it is closed.
  • ISO itself audits organizations and issues ISO/IEC 27001 certificates.
  • Any certification body's certificate carries the same weight, accredited or not.