ClearPenTest
ISO 27001

What to have ready before an ISO 27001 Stage 2 audit

6 min read

Stage 2 audits the management system in operation, which means the auditor is looking for records that processes ran rather than documents saying they exist. The gap between a complete policy set and a passing Stage 2 is evidence.

Stage 1 asks whether you have a management system. Stage 2 asks whether it runs. That difference is the whole exercise, and it is why a company with a complete policy set can still take nonconformities.

The thing being audited is the process, not the document

An auditor reads the policy, then asks for the records it produces. A risk assessment procedure is a document. The completed risk assessment, with dates, owners and treatment decisions, is the evidence. Only the second one demonstrates the system operates.

This reframes preparation. The question is not "do we have a policy for this" but "what does this policy leave behind when it runs, and can we produce it for a date the auditor picks".

The mandatory records

Certain clauses produce records the auditor will ask for by name:

  • Clause 6.1.2, risk assessment. The completed assessment, the methodology, and the criteria used.
  • Clause 6.1.3, risk treatment. The treatment plan and the Statement of Applicability, with a justification per control.
  • Clause 7.2, competence. Evidence that people doing security-relevant work are competent to.
  • Clause 9.1, monitoring and measurement. What you measure and what the measurements showed.
  • Clause 9.2, internal audit. The internal audit programme and the results. This one is frequently missing entirely.
  • Clause 9.3, management review. Minutes showing leadership reviewed the ISMS, with the inputs the clause lists.
  • Clause 10.1, nonconformity and corrective action. The record of issues found and what was done about them.

The four that first-time certifications most often miss

The internal audit. Clause 9.2 requires the organization to audit its own ISMS at planned intervals before an external body does. Companies skip it because it feels redundant. It is not optional, it is a clause, and its absence is a straightforward nonconformity.

Management review minutes. Clause 9.3 specifies what the review must consider, including the status of previous actions, changes in external issues, feedback on performance, and opportunities for improvement. A calendar invite is not a record. Minutes structured around the clause's inputs are.

Corrective action records. Finding a problem is expected. Clause 10.1 wants the record of what was done: the correction, the cause analysis, and whether the action worked. Corrective action is where a system proves it improves rather than only operates.

Technical vulnerability evidence. A 8.8 describes an ongoing process. A penetration test report from eleven months ago and nothing since is evidence of an event, not a process. Pair the report with the scanning cadence, the triage records, and what happened to the last few vulnerabilities that mattered.

How the sampling works

The auditor picks dates and asks what happened. If access reviews are quarterly, expect to be asked for a specific quarter's review, not a description of the process. If onboarding requires a security briefing, expect a specific new joiner's record.

This is why evidence produced as a byproduct of work beats evidence assembled afterwards. A ticket with an approval on it exists at the moment the work happened. A spreadsheet reconstructed the week before the audit tends to have gaps in exactly the months the auditor chooses.

Scope, which is checked first

The certificate states a scope, and the auditor confirms that what is in front of them matches the scope statement. A scope covering the product and its supporting infrastructure has to include the systems that actually support it, including the ones nobody thought about: the CI pipeline, the monitoring stack, the customer support tooling with production access.

Getting scope wrong in an ambitious direction adds audit work. Getting it wrong in a narrow direction produces a certificate that a customer reads and finds does not cover the thing they cared about.

A fortnight out

Pick three controls at random from your Statement of Applicability and try to produce evidence for each, for a date somebody else chooses. If that is uncomfortable, the gap is evidence generation rather than controls, and it is better to find that out now than in the room.

Questions people ask

What is the difference between Stage 1 and Stage 2 of an ISO 27001 audit?

Stage 1 reviews documentation and readiness to confirm the management system exists and can be audited. Stage 2 audits the system in operation, sampling records to confirm processes actually ran, and leads to the certification decision.

Is an internal audit required before ISO 27001 certification?

Yes. Clause 9.2 requires the organization to conduct internal audits of its own ISMS at planned intervals. Skipping it is one of the most common first-time nonconformities.

What happens if you get a nonconformity at Stage 2?

A minor nonconformity requires a corrective action plan but does not necessarily block certification. A major nonconformity blocks the certificate until it is resolved and verified.

START WITH A CLEAR SCOPE

Get a scoped price without a discovery call

Scope an assessment