Stage 2 Audit
Definition
The on-site certification audit. The auditor tests whether controls described in the documentation are implemented and operating effectively. A Stage 2 pass results in the certification decision.
- Focus
- Implementation and operating effectiveness of controls
- Follows
- Stage 1 documentation review
- Outcome
- Certification decision
- Standard
- ISO/IEC 27001 certification process
Common questions
What does a Stage 2 auditor actually examine on-site?+
The auditor samples evidence that controls described in the ISMS documentation are actually operating, such as access logs, incident records, training records, and interviews with staff responsible for specific controls.
Can an organisation fail Stage 2 even after passing Stage 1?+
Yes, passing Stage 1 only confirms the documentation is in order, Stage 2 tests whether those documented controls are genuinely implemented, and gaps found there can still block or delay certification.
Related terms
- Accreditation Body (AB)
- A national body that assesses and formally recognises the competence of certification bodies. Notable examples: UKAS (UK), DAkkS (Germany), COFRAC (France), NABCB...
- Certification Body (CB)
- An independent third-party organisation accredited to audit and certify that an ISMS conforms to ISO 27001. Examples include BSI, Bureau Veritas, DNV,...
- Major Nonconformity
- A finding that indicates the ISMS is absent in a required area or has failed systemically. Must be resolved with verified evidence...
- Minor Nonconformity
- A single lapse or gap that does not indicate systemic failure. The organisation must provide a corrective action plan and close the...
- Stage 1 Audit
- The documentation review phase of the initial certification audit. The auditor checks that the ISMS documentation exists, the scope is defined, the...