Key takeaways
- External audit preparation runs in four phases: planning 8 to 12 weeks out, evidence collection 4 to 8 weeks out, readiness and execution in the final 1 to 4 weeks, and remediation of findings afterward.
- An ISO 27001 certification audit has two stages. Stage 1 reviews your documentation and audit readiness, Stage 2 tests whether the controls actually work in operation. In practice, 4 to 8 weeks sit between them.
- An ISO 27001 certificate is valid for three years. Surveillance audits follow in years one and two, and a recertification audit in year three, which makes audit preparation a standing condition rather than a project.
- You cannot fail an audit the way you fail an exam. The auditor raises nonconformities: minor ones close through a corrective action plan, major ones must be fixed before the certification body issues the certificate.
- The most common cause of findings is not a missing control but missing evidence. Annex A of ISO 27001:2022 contains 93 controls, and most organizations declare 60 to 80 of them applicable.
External audit preparation is the difference between a calm, predictable certification and a fire drill. Whether the audit covers ISO 27001, a SOC 2 report, or another framework, the outcome is largely decided before the auditor arrives, by how methodically you planned, collected evidence, and rehearsed. This checklist walks through a phased approach so the business keeps running while the audit runs.
One thing first: the best preparation for an external audit is a clean internal audit. If you have not run one yet, start with our guide to the ISO 27001 internal audit and come back to this checklist for the certification stage.
Know which external audit you are preparing for
Preparation differs by audit type, so name yours first. A certification audit ends in a certificate from an accredited body, a SOC 2 engagement ends in a report, a C5 engagement ends in an attestation, and TISAX ends in a label. These words are not a matter of taste: saying "SOC 2 certification" in a customer conversation costs you credibility, because no such thing exists.
| Audit type | Outcome | Who assesses | Validity |
|---|---|---|---|
| Certification audit (ISO 27001, ISO 27701, ISO 42001) | Certificate | Accredited certification body such as TÜV Süd, DQS, or DEKRA, accredited by DAkkS or UKAS | 3 years, with annual surveillance audits |
| Attestation engagement (SOC 1, SOC 2, SOC 3) | Report, Type I or Type II | Licensed CPA firm | The report period, typically 3 to 12 months for Type II |
| C5 (BSI) | C5 attestation | Auditor working to ISAE 3000 | The attestation period |
| TISAX | TISAX label | Audit provider approved by the ENX Association | 3 years |
| Regulatory review (GDPR, NIS2) | No certificate, but evidence of compliance | The competent supervisory authority, for NIS2 in Germany the BSI | Ongoing |
The four phases below apply to every row in this table. What changes is the evidence you produce and the body that reviews it. Why a SOC 2 report lands differently with customers than a certificate does is something we cover separately in our piece on the benefits of a SOC 2 report.
Stage 1 and Stage 2: how an ISO 27001 certification audit runs
An ISO 27001 certification audit is not a single appointment but a two-stage process. In Stage 1, the certification body checks whether your ISMS exists on paper and is ready to be audited: scope, information security policy, risk treatment plan, Statement of Applicability, the results of your internal audit under clause 9.2, and the management review under clause 9.3. In Stage 2, the auditor tests whether all of it is actually lived, through interviews, sampling, and evidence from day-to-day operations. In practice, 4 to 8 weeks sit between the two stages, and that is precisely the window in which you work through what Stage 1 surfaced.
A common misconception: that Stage 1 is a formality. It is the most expensive wrong assumption in the whole process. Stage 1 is where a scope drawn too wide or too vaguely shows up, and correcting scope between stages costs weeks. Which controls you have to declare applicable in the first place, and what the Statement of Applicability looks like as a result, is covered in our overview of the 93 Annex A controls.
In the video below, the Kertos team walks through what actually happens in Stage 1 and Stage 2, and what the certification body holds you to at each stage.
Phase 1: Plan (8 to 12 weeks out)
Good outcomes start long before the audit. Begin roughly 8 to 12 weeks out with four steps:
- Define scope and objectives. Determine which standards apply, which systems, processes, and locations are in scope, and what a successful outcome looks like, then confirm all of it with your certification body. An unclear scope is the single most common cause of surprise findings.
- Assemble the team. Name an audit coordinator, an executive sponsor, subject matter experts, evidence owners, and remediation owners, so that both the knowledge and the authority to act are in the room.
- Run a pre-audit gap analysis. This is where your internal audit does the work: review previous findings, test controls, check that documentation is current, and prioritize the gaps you need to close.
- Build a timeline and a communication plan. Set milestones and deadlines, agree who needs which information and when, and schedule regular checkpoints.
Plan auditor days and internal effort realistically
You do not set the duration of the external audit yourself. For ISMS audits, the number of auditor days follows the mandatory IAF document MD 5, which derives audit duration from the number of effective personnel and the complexity of the scope. For an organization of roughly 50 people, initial certification across Stage 1 and Stage 2 typically lands at about 5 to 6 auditor days. Internal effort is the larger line item, and it is the one most teams underestimate.
| Phase | Window | Primary owner | Internal effort, guide figure for 50 people |
|---|---|---|---|
| Planning and gap analysis | 8 to 12 weeks out | Audit coordinator, executive sponsor | 10 to 15 person-days |
| Evidence collection | 4 to 8 weeks out | Control owners, IT | 15 to 25 person-days |
| Readiness and execution | 1 to 4 weeks out, plus the audit days | Audit coordinator, subject matter experts | 8 to 12 person-days |
| Remediation and lessons learned | Up to 12 weeks after | Remediation owners | 5 to 10 person-days |
Together that is roughly 38 to 62 person-days of internal effort for an initial certification. Teams that start from continuous evidence collection move most of it into day-to-day operations instead of concentrating it in a single quarter.
Phase 2: Collect evidence (4 to 8 weeks out)
Evidence collection is the most demanding part of preparation. Treat it as a structured process, not a search. Start roughly 4 to 8 weeks out:
- Inventory the evidence. Map the required evidence to each requirement, define quality criteria, and build a traceability matrix that links evidence to controls.
- Collect systematically. Assign owners and deadlines, standardize formats for common evidence types, and track progress so nothing is missing on the day.
- Centralize. Keep everything in one repository with sensible access rights, consistent file naming, and version control, organized by control area.
- Check quality and completeness. Review the evidence with the same rigor the auditor will, and close the gaps before the auditor sees them.
The mistake most teams make here: they collect evidence for the auditor rather than for the business. A screenshot taken the day before the audit proves a state, not effectiveness across the review period. The auditor asks for samples spanning twelve months, not twelve hours, and this is exactly where well-run programs with sound controls come unstuck.
A concrete example: a SaaS company of 45 people goes into initial ISO 27001 certification, declares 71 of the 93 controls applicable, and names one internal owner at 50 percent of her capacity. Of roughly 180 evidence requests, 120 arrive automatically from connected systems and the remaining 60 are assembled by hand. The evidence phase takes five weeks instead of the nine originally planned. How much time this phase really burns when nothing is automated is something we broke down in our piece on the true cost of audit fatigue.
Phase 3: Get ready and run the audit (1 to 4 weeks out)
Once the evidence is in place, the final weeks are about people and logistics:
- Prepare the people. Brief everyone who will speak with the auditor on scope and process, and rehearse answers to likely questions. Budget 60 to 90 minutes per interviewee.
- Sort the logistics. Book rooms, arrange system access, produce the audit schedule, and share contacts. Logistical chaos reads as control chaos, even when the controls are solid.
- Run a final readiness check. Confirm that evidence is complete, gaps are closed, and demo environments work.
- Manage the audit actively. Have a coordinator run it, track evidence requests, and hold daily debriefs so issues surface and get fixed the same day.
The difference between a calm audit and a chaotic one almost never comes down to the quality of the controls. It comes down to whether one person in the room can answer any evidence request in minutes rather than days. Where that role is not explicitly named, the team spends three days negotiating about file locations instead of talking about security.
Phase 4: Close the nonconformities
The work does not end when the auditor leaves. An audit ends in findings, and the terminology matters here: a minor nonconformity closes through a corrective action plan that the certification body reviews and accepts. A major nonconformity must be demonstrably fixed before the certificate is issued, in practice usually within 90 days. Remediate at the root cause rather than the symptom, with named owners, deadlines, and retained evidence of the fix.
Which brings us to the question managing directors ask most often: you cannot "fail" an ISO 27001 audit the way you fail an exam. There is no grade. There are nonconformities, deadlines to close them, and, at worst, a certification body that withholds the certificate until the major points are resolved. The video below explains what actually happens when an audit goes badly.
And one more point teams plan for too late: initial certification is not the finish line. The certificate is valid for three years, but a surveillance audit follows in year one and again in year two, with recertification in year three. Budget initial certification as a project with an end date and you will be sitting in the same evidence phase twelve months later. What the shift from certification to steady state looks like is described in our ISO 27001 automation playbook.
Afterward, run a short lessons learned session and update your audit playbook. Treating every audit as input to the next one is what makes the cycle lighter over time.
From fire drill to background process
Every step above can be done by hand, but the teams for whom audits are painless no longer do it that way. The Kertos platform connects to your source systems through integrations, collects evidence throughout the year, and monitors technical and organizational measures continuously rather than at audit time. One control set maps to several frameworks, so a single evidence base serves ISO 27001, a SOC 2 report, and GDPR requirements at once.
Then there is the part software alone does not solve: certified Kertos experts take on the gap analysis, the internal audit, and the exchange with the certification body. That combination is what customers on G2 mention most often, particularly because it holds up not only for initial certification but for the first surveillance audit as well.
"Kertos and its experts help us cover the full range and lifecycle of GDPR and ISO 27001 compliance. It has been substantial support in achieving ISO 27001 certification and, currently, in preparing for the Surveillance Audit. In addition, we are evaluating whether to pursue ISO 42001 certification as well, which will also be supported by the Kertos tool."
Verified User in Computer Software, Small Business, 4.5 out of 5 on G2
That is the shift this whole checklist points toward: away from the audit as a periodic emergency, toward the audit as routine confirmation that the program already works. The clearest way to see what that looks like for your scope is live: book a demo.
Frequently asked questions
How far in advance should you prepare for an external audit?
Start planning and gap analysis roughly 8 to 12 weeks out, evidence collection 4 to 8 weeks out, and use the final 1 to 4 weeks for readiness and logistics. For an initial certification at around 50 people, that is roughly 38 to 62 person-days of internal effort. Continuous evidence collection mainly shortens the evidence phase.
Can you fail an ISO 27001 audit?
Not in the sense of an exam with a grade. The auditor raises nonconformities. Minor ones close through a corrective action plan, major ones must be demonstrably fixed before the certificate is issued, in practice usually within 90 days. The certificate is delayed, not denied.
What is the difference between Stage 1 and Stage 2 of an ISO 27001 audit?
Stage 1 reviews the ISMS documentation and audit readiness, meaning scope, Statement of Applicability, the internal audit under clause 9.2, and the management review under clause 9.3. Stage 2 tests through interviews and sampling whether the controls work in operation. Typically 4 to 8 weeks sit between the two stages.
Do I need an internal audit before the external audit?
For ISO 27001, yes: clause 9.2 requires it, and it is your best rehearsal for Stage 2. How to set one up and act on the results is covered in our guide to the ISO 27001 internal audit.
What is the most common cause of audit findings?
An unclear scope, plus evidence that is missing or hard to trace, rather than missing controls. Many organizations have the controls but cannot demonstrate them across the full review period. A pre-audit gap analysis is what surfaces exactly that gap.





