InfoSec

External Audit Preparation: A Step-by-Step Checklist

A phased plan for certification and attestation audits, from planning to closing the nonconformities.

Author
Johannes Hussak
Date
24.2.2026
Updated on
24.8.2026
External Audit Preparation: A Step-by-Step Checklist

Key takeaways

  • External audit preparation runs in four phases: planning 8 to 12 weeks out, evidence collection 4 to 8 weeks out, readiness and execution in the final 1 to 4 weeks, and remediation of findings afterward.
  • An ISO 27001 certification audit has two stages. Stage 1 reviews your documentation and audit readiness, Stage 2 tests whether the controls actually work in operation. In practice, 4 to 8 weeks sit between them.
  • An ISO 27001 certificate is valid for three years. Surveillance audits follow in years one and two, and a recertification audit in year three, which makes audit preparation a standing condition rather than a project.
  • You cannot fail an audit the way you fail an exam. The auditor raises nonconformities: minor ones close through a corrective action plan, major ones must be fixed before the certification body issues the certificate.
  • The most common cause of findings is not a missing control but missing evidence. Annex A of ISO 27001:2022 contains 93 controls, and most organizations declare 60 to 80 of them applicable.

External audit preparation is the difference between a calm, predictable certification and a fire drill. Whether the audit covers ISO 27001, a SOC 2 report, or another framework, the outcome is largely decided before the auditor arrives, by how methodically you planned, collected evidence, and rehearsed. This checklist walks through a phased approach so the business keeps running while the audit runs.

One thing first: the best preparation for an external audit is a clean internal audit. If you have not run one yet, start with our guide to the ISO 27001 internal audit and come back to this checklist for the certification stage.

Know which external audit you are preparing for

Preparation differs by audit type, so name yours first. A certification audit ends in a certificate from an accredited body, a SOC 2 engagement ends in a report, a C5 engagement ends in an attestation, and TISAX ends in a label. These words are not a matter of taste: saying "SOC 2 certification" in a customer conversation costs you credibility, because no such thing exists.

Audit type Outcome Who assesses Validity
Certification audit (ISO 27001, ISO 27701, ISO 42001)CertificateAccredited certification body such as TÜV Süd, DQS, or DEKRA, accredited by DAkkS or UKAS3 years, with annual surveillance audits
Attestation engagement (SOC 1, SOC 2, SOC 3)Report, Type I or Type IILicensed CPA firmThe report period, typically 3 to 12 months for Type II
C5 (BSI)C5 attestationAuditor working to ISAE 3000The attestation period
TISAXTISAX labelAudit provider approved by the ENX Association3 years
Regulatory review (GDPR, NIS2)No certificate, but evidence of complianceThe competent supervisory authority, for NIS2 in Germany the BSIOngoing

The four phases below apply to every row in this table. What changes is the evidence you produce and the body that reviews it. Why a SOC 2 report lands differently with customers than a certificate does is something we cover separately in our piece on the benefits of a SOC 2 report.

Stage 1 and Stage 2: how an ISO 27001 certification audit runs

An ISO 27001 certification audit is not a single appointment but a two-stage process. In Stage 1, the certification body checks whether your ISMS exists on paper and is ready to be audited: scope, information security policy, risk treatment plan, Statement of Applicability, the results of your internal audit under clause 9.2, and the management review under clause 9.3. In Stage 2, the auditor tests whether all of it is actually lived, through interviews, sampling, and evidence from day-to-day operations. In practice, 4 to 8 weeks sit between the two stages, and that is precisely the window in which you work through what Stage 1 surfaced.

A common misconception: that Stage 1 is a formality. It is the most expensive wrong assumption in the whole process. Stage 1 is where a scope drawn too wide or too vaguely shows up, and correcting scope between stages costs weeks. Which controls you have to declare applicable in the first place, and what the Statement of Applicability looks like as a result, is covered in our overview of the 93 Annex A controls.

In the video below, the Kertos team walks through what actually happens in Stage 1 and Stage 2, and what the certification body holds you to at each stage.

Phase 1: Plan (8 to 12 weeks out)

Good outcomes start long before the audit. Begin roughly 8 to 12 weeks out with four steps:

  • Define scope and objectives. Determine which standards apply, which systems, processes, and locations are in scope, and what a successful outcome looks like, then confirm all of it with your certification body. An unclear scope is the single most common cause of surprise findings.
  • Assemble the team. Name an audit coordinator, an executive sponsor, subject matter experts, evidence owners, and remediation owners, so that both the knowledge and the authority to act are in the room.
  • Run a pre-audit gap analysis. This is where your internal audit does the work: review previous findings, test controls, check that documentation is current, and prioritize the gaps you need to close.
  • Build a timeline and a communication plan. Set milestones and deadlines, agree who needs which information and when, and schedule regular checkpoints.

Plan auditor days and internal effort realistically

You do not set the duration of the external audit yourself. For ISMS audits, the number of auditor days follows the mandatory IAF document MD 5, which derives audit duration from the number of effective personnel and the complexity of the scope. For an organization of roughly 50 people, initial certification across Stage 1 and Stage 2 typically lands at about 5 to 6 auditor days. Internal effort is the larger line item, and it is the one most teams underestimate.

Phase Window Primary owner Internal effort, guide figure for 50 people
Planning and gap analysis8 to 12 weeks outAudit coordinator, executive sponsor10 to 15 person-days
Evidence collection4 to 8 weeks outControl owners, IT15 to 25 person-days
Readiness and execution1 to 4 weeks out, plus the audit daysAudit coordinator, subject matter experts8 to 12 person-days
Remediation and lessons learnedUp to 12 weeks afterRemediation owners5 to 10 person-days

Together that is roughly 38 to 62 person-days of internal effort for an initial certification. Teams that start from continuous evidence collection move most of it into day-to-day operations instead of concentrating it in a single quarter.

Phase 2: Collect evidence (4 to 8 weeks out)

Evidence collection is the most demanding part of preparation. Treat it as a structured process, not a search. Start roughly 4 to 8 weeks out:

  • Inventory the evidence. Map the required evidence to each requirement, define quality criteria, and build a traceability matrix that links evidence to controls.
  • Collect systematically. Assign owners and deadlines, standardize formats for common evidence types, and track progress so nothing is missing on the day.
  • Centralize. Keep everything in one repository with sensible access rights, consistent file naming, and version control, organized by control area.
  • Check quality and completeness. Review the evidence with the same rigor the auditor will, and close the gaps before the auditor sees them.

The mistake most teams make here: they collect evidence for the auditor rather than for the business. A screenshot taken the day before the audit proves a state, not effectiveness across the review period. The auditor asks for samples spanning twelve months, not twelve hours, and this is exactly where well-run programs with sound controls come unstuck.

A concrete example: a SaaS company of 45 people goes into initial ISO 27001 certification, declares 71 of the 93 controls applicable, and names one internal owner at 50 percent of her capacity. Of roughly 180 evidence requests, 120 arrive automatically from connected systems and the remaining 60 are assembled by hand. The evidence phase takes five weeks instead of the nine originally planned. How much time this phase really burns when nothing is automated is something we broke down in our piece on the true cost of audit fatigue.

Phase 3: Get ready and run the audit (1 to 4 weeks out)

Once the evidence is in place, the final weeks are about people and logistics:

  • Prepare the people. Brief everyone who will speak with the auditor on scope and process, and rehearse answers to likely questions. Budget 60 to 90 minutes per interviewee.
  • Sort the logistics. Book rooms, arrange system access, produce the audit schedule, and share contacts. Logistical chaos reads as control chaos, even when the controls are solid.
  • Run a final readiness check. Confirm that evidence is complete, gaps are closed, and demo environments work.
  • Manage the audit actively. Have a coordinator run it, track evidence requests, and hold daily debriefs so issues surface and get fixed the same day.

The difference between a calm audit and a chaotic one almost never comes down to the quality of the controls. It comes down to whether one person in the room can answer any evidence request in minutes rather than days. Where that role is not explicitly named, the team spends three days negotiating about file locations instead of talking about security.

Phase 4: Close the nonconformities

The work does not end when the auditor leaves. An audit ends in findings, and the terminology matters here: a minor nonconformity closes through a corrective action plan that the certification body reviews and accepts. A major nonconformity must be demonstrably fixed before the certificate is issued, in practice usually within 90 days. Remediate at the root cause rather than the symptom, with named owners, deadlines, and retained evidence of the fix.

Which brings us to the question managing directors ask most often: you cannot "fail" an ISO 27001 audit the way you fail an exam. There is no grade. There are nonconformities, deadlines to close them, and, at worst, a certification body that withholds the certificate until the major points are resolved. The video below explains what actually happens when an audit goes badly.

And one more point teams plan for too late: initial certification is not the finish line. The certificate is valid for three years, but a surveillance audit follows in year one and again in year two, with recertification in year three. Budget initial certification as a project with an end date and you will be sitting in the same evidence phase twelve months later. What the shift from certification to steady state looks like is described in our ISO 27001 automation playbook.

Afterward, run a short lessons learned session and update your audit playbook. Treating every audit as input to the next one is what makes the cycle lighter over time.

From fire drill to background process

Every step above can be done by hand, but the teams for whom audits are painless no longer do it that way. The Kertos platform connects to your source systems through integrations, collects evidence throughout the year, and monitors technical and organizational measures continuously rather than at audit time. One control set maps to several frameworks, so a single evidence base serves ISO 27001, a SOC 2 report, and GDPR requirements at once.

Then there is the part software alone does not solve: certified Kertos experts take on the gap analysis, the internal audit, and the exchange with the certification body. That combination is what customers on G2 mention most often, particularly because it holds up not only for initial certification but for the first surveillance audit as well.

"Kertos and its experts help us cover the full range and lifecycle of GDPR and ISO 27001 compliance. It has been substantial support in achieving ISO 27001 certification and, currently, in preparing for the Surveillance Audit. In addition, we are evaluating whether to pursue ISO 42001 certification as well, which will also be supported by the Kertos tool."

Verified User in Computer Software, Small Business, 4.5 out of 5 on G2

That is the shift this whole checklist points toward: away from the audit as a periodic emergency, toward the audit as routine confirmation that the program already works. The clearest way to see what that looks like for your scope is live: book a demo.

Frequently asked questions

How far in advance should you prepare for an external audit?

Start planning and gap analysis roughly 8 to 12 weeks out, evidence collection 4 to 8 weeks out, and use the final 1 to 4 weeks for readiness and logistics. For an initial certification at around 50 people, that is roughly 38 to 62 person-days of internal effort. Continuous evidence collection mainly shortens the evidence phase.

Can you fail an ISO 27001 audit?

Not in the sense of an exam with a grade. The auditor raises nonconformities. Minor ones close through a corrective action plan, major ones must be demonstrably fixed before the certificate is issued, in practice usually within 90 days. The certificate is delayed, not denied.

What is the difference between Stage 1 and Stage 2 of an ISO 27001 audit?

Stage 1 reviews the ISMS documentation and audit readiness, meaning scope, Statement of Applicability, the internal audit under clause 9.2, and the management review under clause 9.3. Stage 2 tests through interviews and sampling whether the controls work in operation. Typically 4 to 8 weeks sit between the two stages.

Do I need an internal audit before the external audit?

For ISO 27001, yes: clause 9.2 requires it, and it is your best rehearsal for Stage 2. How to set one up and act on the results is covered in our guide to the ISO 27001 internal audit.

What is the most common cause of audit findings?

An unclear scope, plus evidence that is missing or hard to trace, rather than missing controls. Many organizations have the controls but cannot demonstrate them across the full review period. A pre-audit gap analysis is what surfaces exactly that gap.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Johannes Hussak

Johannes Hussak

COO & Co-Founder at Kertos

Kertos is already Johannes' third founding venture. Following his two master's degrees (Mechanical Engineering and International Management) from the Technical University of Munich, as well as the UnternehmerTUM entrepreneur program "Manage&More," he founded his first e-commerce company. Johannes then joined a Munich-based research and development company, where he led the innovation department for more than two years. In 2020, Johannes founded Aitaro GmbH, a development and consulting company focusing on data-driven innovation, before taking on the challenge of developing the next generation of data protection solutions – Kertos. Johannes is passionate about product development and operations, elevating Kertos to a new level.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check