← All postsHow-to

ISO 27001 certification: what the two audit stages actually look for

Certification is not a document review. Stage 1 checks whether the system exists, stage 2 whether it operates — and the second one samples your evidence.

How-toI

ISO 27001 certification is an independent assessment, by an accredited certification body, that your information security management system meets the standard. It is granted for a three-year cycle: an initial audit in two stages, then surveillance audits in the intervening years, then recertification.

The distinction that decides how the audit goes is that certification assesses a management system, not a set of documents. Policies that exist but are not followed are worse than absent ones, because the auditor now has evidence that the system says one thing while the organisation does another.

What the two ISO 27001 certification stages look for

  • Stage 1 is a readiness review: does the ISMS exist on paper, is the scope coherent, is there a risk assessment, a statement of applicability, a treatment plan, an internal audit programme and a management review. Findings here are usually about missing pieces.
  • Stage 2 is the operating audit: does the system actually run. The auditor samples evidence — access reviews performed, incidents handled, changes approved, training delivered, suppliers assessed — over a period, not on the day.

This is why organisations cannot compress the timeline indefinitely. Stage 2 needs a period of operation to sample: internal audits actually conducted, a management review actually held, evidence of controls running for some months. Documentation can be produced quickly; operating history cannot.

The documented information the standard expects

  1. Scope of the ISMS, stated precisely enough that it is clear what is excluded.
  2. Information security policy, approved by top management.
  3. Risk assessment and risk treatment methodology and results.
  4. Statement of applicability.
  5. Risk treatment plan with owners and dates.
  6. Evidence of competence, awareness and training.
  7. Internal audit programme and results.
  8. Management review minutes, including the inputs the standard requires.
  9. Records of nonconformities and corrective actions.

Check the certification body’s accreditation, not just its name. A certificate from an unaccredited body costs less and is worth correspondingly less; enterprise customers check the accreditation mark, and discovering the difference during a sales cycle is expensive.

What actually causes findings

In practice: internal audits that were planned and never done, a management review with no minutes, corrective actions closed without evidence, access reviews not performed, policies whose review date passed two years ago, and a scope statement that does not match how the business runs. Very few findings are about a clever technical control being absent.

The pattern is the same one that runs through every assurance regime — the work is often being done, and the record that it was done is missing. Building the record into the work rather than around it is the whole difference between a smooth audit and a rebuilt one.

Because the standard requires documented information under version control, the policies and procedures need a home where approvals and revisions are visible. Ettex Docs keeps each document with its approval, its review date and its history, so a policy’s current version and the date it was approved are properties of the document rather than facts someone remembers. Ettex does not certify anything and does not replace the certification body — it holds the documented information the body will ask to see.

Frequently asked

How long does ISO 27001 certification take?

Typically six to twelve months from a standing start for a small organisation, driven mostly by the operating history stage 2 needs to sample rather than by the documentation.

What is the difference between certification and compliance?

Compliance means meeting the standard’s requirements. Certification means an accredited third party has audited and confirmed it. A company can be compliant without being certified; customers usually ask for the certificate.

What happens in surveillance audits?

A subset of the system is audited each year — typically the mandatory clauses plus a rotating selection of controls — with full recertification in year three.

Can a small company get certified?

Yes. Scope and risk determine the size of the system, not headcount. Small organisations usually struggle less with controls than with sustaining internal audits and management reviews.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.