ISO27K

Are you ready for the ISO 27001 stage 1 audit?

Stage 1 is a documentation review with a purpose: deciding whether stage 2 can usefully go ahead. This checks what you hold against what the standard requires, gives a verdict, and lists the findings that most often push stage 2 back.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

Stage 1 is not a soft opening. The auditor reads your documented information, looks at whether the management system has actually been running, and decides whether stage 2 can proceed as planned. Coming out of stage 1 with a list of areas of concern is normal. Coming out of it with stage 2 postponed is common too, and almost always for one of the same five reasons.

Answer what you hold today rather than what is in progress. The verdict appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

Which documents exist and are approved?

Tick only what is written, current and approved by whoever is supposed to approve it. A draft in someone's folder is not documented information.

Which records exist from the system actually running?

Records are different from documents. A policy says what should happen; a record shows it happened, on a date, to something real.

Has an internal audit been completed?

Has a management review been held?

Clause 9.3 lists the inputs it has to cover and asks for documented results. A standing team meeting is not one unless the minutes show those inputs were considered.

How long has the system been operating?

Operating means controls running and producing records, not documents existing.

How many people work there?

When is stage 1?

What stage 1 is for

The certification body uses stage 1 to understand your management system, check the documented information, confirm the scope makes sense, look at how ready you are for stage 2, and plan the stage 2 visit. It usually runs half a day to a day and a half depending on scope, and it is often done remotely. The output is a report with areas of concern, and a decision on whether stage 2 goes ahead on the date already in the calendar.

The two audits and what each one tests
QuestionStage 1Stage 2
What is examinedDocumented information and whether the system existsWhether the controls and clause requirements operate, sampled against evidence
Where the evidence comes fromDocuments, the Statement of Applicability, the internal audit and review recordsInterviews, system configuration, tickets, logs, records from the period
Typical lengthHalf a day to a day and a halfTwo to five days for a small scope
What goes wrongDocuments missing, or present but never usedA control described accurately and operated inconsistently
ConsequenceStage 2 delayed, usually by four to twelve weeksNonconformities to close before the certificate issues

The gap stage 1 is really measuring

Almost every document on the required list can be written in a week. What cannot be produced quickly is the evidence that the system has been running: an internal audit with findings, a management review with decisions in it, corrective actions at various stages of closure, and records dated across weeks rather than all on the same afternoon. That is the gap stage 1 detects, and it is why buying a document set does not shorten a certification project.

Common questions

Do I have to give an email address to see the result?

No. The verdict, the missing items and the likely findings render on this page as soon as you finish. The field underneath sends a written version with clause references beside each gap, which is useful for handing to the people closing them. Skipping it costs you nothing.

Can we fail stage 1?

There is no pass or fail in the way people expect. The auditor records areas of concern and decides whether stage 2 should go ahead. The bad outcome is not a failure notice, it is stage 2 being pushed back while the certification body keeps the date it had booked for somebody else, which is how a four-week gap becomes a twelve-week one.

How long between stage 1 and stage 2?

Commonly two to twelve weeks. Long enough to close what stage 1 raised, short enough that the auditor's understanding of your system is still current. A gap beyond about six months usually means parts of stage 1 get repeated. What the two audits involve in detail is on the stage 1 and stage 2 page.

How long does the system need to have been running?

There is no number in the standard. In practice auditors want to see records covering a period, and three months of the system operating is the point where the evidence stops looking manufactured. Under a month, an auditor can usually tell, because every record carries a date within the same fortnight.

What should we fix first if stage 1 is close?

The clause requirements, in this order: scope, policy, Statement of Applicability, risk assessment results, internal audit, management review. Control gaps can be recorded as applicable and not yet implemented with an owner and a date, which survives. Missing clause requirements cannot be recorded away. The gap assessment scores both halves.

Close the gaps before the auditor finds them

Tell us where you are and we will put it in front of Canadian firms doing ISO 27001 readiness work.

Get matched