Audit and compliance
Stage 1 and Stage 2 audit
Also called: ISO 27001 stages, certification audit stages
ISO 27001 certification is performed in two stages. Stage 1 reviews documentation and readiness to confirm the management system is capable of being audited. Stage 2 audits the system in operation and leads to the certification decision.
Penetration test evidence is usually requested at Stage 2. Producing it after Stage 2 has raised a nonconformity is the expensive order to do it in.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.