ISO27K

ISO 27001 stage 1 and stage 2 audits

Certification is two audits, not one. Stage 1 reads your documents and tells you what will stop you. Stage 2 tests whether the management system actually runs. They are booked together, priced separately, and fail for completely different reasons.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Stage 1 is a documentation and readiness review. It takes one to two days, is usually remote, and costs $3,000 to $8,000 CAD. Stage 2 is the evidence audit, takes two to eight days depending on headcount and sites, and costs $9,000 to $25,000 CAD. The two are normally separated by two weeks to three months. Stage 1 cannot certify you and it cannot fail you either. Its output is an audit plan for stage 2 and a written list of what will block it, which makes it the cheapest advice a certification body will ever give you.

1 to 2 days Stage 1, usually remote

2 to 8 days Stage 2, part or all on site

2 weeks to 3 months Normal gap between them

What is the difference between stage 1 and stage 2

Stage 1 asks whether the management system exists and is coherent. Stage 2 asks whether it operates and whether anybody follows it. That distinction decides everything else about the two visits: who gets interviewed, what gets sampled, what a finding means and what it costs to be wrong.

ISO 27001 stage 1 compared with stage 2, Canadian company under 250 staff
 Stage 1Stage 2
Question being answeredIs the system designed, documented and ready to be testedDoes the system operate as documented, with records
Audit days1 to 22 to 8
FormatRemote in nearly all casesMixed, with physical scope seen in person
Who is interviewedThe management system owner, sometimes the executive sponsorEngineers, HR, IT administrators, suppliers manager, the executive who chaired the management review
What is sampledDocuments. Scope statement, policy, risk assessment, Statement of Applicability, internal audit report, management review minutesRecords. Access reviews, onboarding files, change tickets, backups, incident log, supplier reviews, training completion
Typical outcomeAn audit plan, plus areas of concern to close before stage 2Nonconformities, observations, and a recommendation for certification
What goes wrongScope wording, a Statement of Applicability with unjustified exclusions, no internal audit yetRecords that do not exist, or exist only from the last three weeks
Certification body fee, CAD$3,000 to $8,000$9,000 to $25,000
Initial certification, both stages$15,000 to $40,000 CAD, excluding travel and the certificate issue fee

Both numbers come from audit day tables rather than from a sales conversation, which is why the day count is the only figure worth comparing between two bodies. How those days are derived, and which parts of a quote are genuinely negotiable, is set out line by line on the itemised certification cost page.

What actually happens on a stage 1 audit day

It is a reading exercise with interruptions. The auditor has usually had your documents for a week and arrives with questions already written down.

  1. Opening meeting, twenty minutes. Confirmation of scope, the audit plan, confidentiality, and who is available on the day.
  2. The scope statement, first and at length. The auditor is testing whether the wording that will appear on the certificate matches the organization they are looking at, and whether anything has been carved out that cannot be.
  3. The Statement of Applicability, control by control for the exclusions. Every exclusion is a question they write down for stage 2.
  4. Risk assessment and risk treatment plan, checked for a method that is repeatable and for risk owners who are real people.
  5. Internal audit report and management review minutes. Both must have happened. This is the single most common reason a stage 1 concludes that stage 2 should be moved.
  6. A walk through your sites, systems and headcount to confirm the audit day calculation, because a scope larger than the one quoted changes the price.
  7. Closing meeting. You are told what will block stage 2, and you are given the stage 2 audit plan naming the areas, the days and the people.

Stage 1 is the only free consulting an accredited body can give you

An accredited certification body cannot advise you on how to build the system, because ISO/IEC 17021-1 forbids it and carries a two-year cool-off after any advice ends. What an auditor can do is tell you plainly that a finding would be raised against something. That is not consulting, it is the audit, and it is worth asking direct questions at the closing meeting rather than nodding through it. Ask which exclusions they doubt and which areas they intend to sample hardest at stage 2, and write the answers down.

How long can we leave between stage 1 and stage 2

Two weeks at the fast end, three months at the comfortable end. The certification body sets the interval and has to justify it, and the reasoning runs both ways. Too short and you cannot close what stage 1 raised. Too long and the documents the auditor read are no longer the documents you are running, at which point parts of stage 1 have to be repeated at your cost.

The interval is also where the operating period gets fixed. Stage 2 samples records over a window, and a window of three weeks produces three weeks of evidence. If stage 1 reveals that your access reviews started last month, the useful decision is to move stage 2 out by a quarter rather than to arrive with one review to sample. Whether you are far enough along to book at all is the subject of the readiness page, and it is a cheaper question to answer before the stage 1 invoice than after it.

What the stage 2 auditor does differently

Stage 2 is sampling, and the sample is drawn from your own claims. Every control marked implemented in the Statement of Applicability is a request for evidence, and the auditor picks which ones without telling you in advance.

  • Interviews rather than documents. The auditor asks the engineer who runs the access review to show it, not the person who wrote the procedure. Answers that do not match the document are the finding, and it usually goes against the document.
  • Population and sample. Give the auditor a list of the twelve joiners this year and they will pick four and ask for the screening record, the signed agreement and the training completion for each. One missing record in a sample of four is a finding you cannot fix on the day.
  • Trace one incident end to end. Detection, ticket, assessment, response, lessons learned, and whether the risk register moved as a result. This single trace tells an auditor more than a day of reading.
  • Physical scope, in person. If an office is in scope, someone looks at it. If nothing physical is in scope, say so in the scope statement rather than hoping it is not asked about.
  • Technical vulnerability management. The scan schedule, the remediation timeline against your own policy, and whether an independent penetration test exists and whether the findings from it went through the same process as everything else.

The closing meeting gives you every nonconformity in writing, graded major or minor, and the auditor's recommendation. The recommendation is not the decision. An independent reviewer inside the certification body makes the certification decision, which is why the certificate arrives two to eight weeks after the audit rather than on the day. What the grades mean, how long you have to close each, and what happens if you do not, is covered on major and minor nonconformities.

When you should move stage 2 rather than sit it

Most published advice on this subject assumes you should push on. Frequently you should not, and the certification body would rather you moved it than failed it, because a rescheduled audit costs them nothing and a stage 2 that produces four majors costs them a follow-up visit and an argument.

Move stage 2 if any of the following is true on the day the auditor asks for dates. You have not completed an internal audit covering the whole management system. No management review has been held with the clause 9.3 inputs. Your recurring controls have run once rather than on their stated frequency. A significant part of the scope changed in the last month, such as a new cloud region or an acquisition. Or the person who built the system has left and nobody can answer for it in an interview.

The counter-case is worth stating too, because postponement is not free. Every month of delay is another month of consultant retainer, another month the deal that funded the project is not closed, and a stage 1 that ages past three months starts to need redoing. If the only gap is a thin evidence window and that window closes in six weeks, sitting the audit six weeks late beats moving it a quarter.

What the two audits cost together in Canada

For a Canadian company under 250 staff, the certification body portion of initial certification is $15,000 to $40,000 CAD across both stages, plus travel where the audit is not remote and a certificate issue fee of $500 to $2,000 CAD. That is between a fifth and a third of what year one costs in total, since the consultant, the internal time and the testing sit outside it. The full Canadian cost picture puts the audit fee next to everything else, and the cost calculator runs your own headcount through the same arithmetic.

Get stage 1 and stage 2 quoted in days

Tell us your scope and headcount and we will put it in front of Canadian certification bodies and readiness firms who will break the days out.

Get matched

Common questions

Can you fail a stage 1 audit?

Not in a pass or fail sense, because stage 1 makes no certification decision. What it can conclude is that you are not ready for stage 2, in which case the auditor documents the gaps and the stage 2 booking moves. Some bodies raise formal nonconformities at stage 1 and some record areas of concern instead, and the practical effect is the same either way: those items are the first thing looked at when stage 2 opens.

How long is the gap between stage 1 and stage 2?

Two weeks to three months is the normal range, and the certification body decides it based on how much stage 1 raised. There is no fixed maximum in the standard, but a long gap means the documented information the auditor reviewed is out of date, so bodies will repeat parts of stage 1 if the interval stretches much past three months.

Can stage 1 and stage 2 be done in the same week?

Some bodies will combine them for a very small, very well prepared organization, and it is worth asking. It is a bad idea when anything at all is uncertain, because the value of stage 1 is the chance to fix what it finds. Combining them converts a warning into a nonconformity on your certification record.

Do we need the internal audit done before stage 1 or before stage 2?

Before stage 1. Clause 9.2 requires an internal audit and clause 9.3 requires a management review, and a stage 1 auditor checks that both have happened as part of judging readiness. Arriving at stage 1 without them is the most common reason a certification timeline slips. What the internal audit has to cover and who is allowed to run it is on the internal audit page.

Is the stage 2 audit remote or on site?

Mixed for most Canadian companies. A cloud-hosted organization with no data centre and one small office can have the large majority of stage 2 conducted remotely, and accredited bodies apply limits on how much of an audit can be remote. Anything physical in your scope statement generally needs someone present. Confirm the split before accepting a quote, because travel and expenses of $0 to $6,000 CAD ride on the answer.

How soon after stage 2 does the certificate arrive?

Two to eight weeks, assuming no major nonconformities. The auditor recommends, and a separate reviewer inside the certification body who was not part of the audit makes the decision. If a major was raised, the clock does not start until the closure evidence has been accepted.