InfoSec

ISMS Certification: How the ISO 27001 Audit Actually Runs

Stage 1, Stage 2, nonconformities, and the deadlines your certification body is itself bound by.

Author
Andy Mura
Date
5.2.2025
Updated on
25.8.2026
ISMS Certification: How the ISO 27001 Audit Actually Runs

Key takeaways

  • ISMS certification means being certified against ISO 27001, with your management system as the object under examination. The certification body works to two further standards while doing it: ISO/IEC 17021-1 and ISO/IEC 27006-1:2024.
  • ISO/IEC 17021-1 defines a major nonconformity in clause 3.12 not by how serious the fault feels, but by whether it affects the management system's capability to achieve its intended results.
  • If the certification body cannot verify that corrections to a major nonconformity have been implemented within 6 months of the last day of the Stage 2 audit, it must conduct another Stage 2 audit (17021-1, clause 9.5.3.2).
  • Audit effort is calculated from the effective number of personnel in scope. The calculation rules have sat in the normative Annex C of ISO/IEC 27006-1 since 2024. IAF MD 5 explicitly covers quality, environmental, and occupational health and safety management systems, not ISMS.
  • When a certificate expires, certification lapses. The certification body can restore it within 6 months (clause 9.6.3.2.5), but the validity period is not extended.

What an ISMS certification actually examines

Your information security management system is what gets examined, and ISO 27001 is what you get certified against. There is no separate ISMS certificate, and anyone searching for ISMS certification almost always means this specific procedure: a two-stage external audit by an accredited body, ending in a certificate valid for three years.

The distinction between conformity and certification matters here. Your ISMS is conformant as soon as it meets the requirements of the standard, and you can establish that yourself. It is certified only once an independent body has formally confirmed it. What the standard requires, which clauses are mandatory, and how you select from the 93 Annex A controls is covered in our guide to ISO 27001 certification. This article picks up where that one stops and describes what happens in the audit room.

One point that most teams learn late changes how they prepare. The auditor assesses you against ISO 27001, but the auditor's own work is governed by a different rulebook. ISO/IEC 17021-1 sets out how certification bodies may audit management systems, and ISO/IEC 27006-1 adds requirements specific to ISMS. Those two documents determine how long an audit takes, how findings are classified, and which deadlines apply to corrections. They describe your counterpart's constraints rather than your obligations, which is exactly why they are worth knowing.

Stage 1: the readiness audit

In Stage 1 the auditor is answering a single question: is this ISMS mature enough to be meaningfully tested for effectiveness? They review your documented information, check how the scope has been drawn, read the Statement of Applicability against the output of your risk assessment, and build a picture of sites, processes, and responsibilities.

Two pieces of evidence carry disproportionate weight at this point: the completed internal audit and the documented management review. Both are mandatory under ISO 27001, both are routinely scheduled too late, and without them the auditor has no basis on which to schedule Stage 2.

Stage 1 can be conducted remotely, in whole or in part. The former rule requiring a certification body to obtain accreditation body approval where remote activity exceeded 30 percent of planned on-site audit time was removed with ISO/IEC 27006-1:2024. In its place came an obligation to report the extent and effectiveness of remote auditing in the audit report. For you that means remote audits have become normal, but they are now documented, and therefore contestable if your evidence only looks convincing in a live conversation.

A widespread misconception concerns the gap between the two stages. The often-quoted six-month limit, after which Stage 1 supposedly has to be repeated, is not in the standard. ISO/IEC 17021-1 requires in clause 9.3.1.2.4 only that the certification body consider the interval, taking into account how much time you need to resolve the areas of concern raised in Stage 1. It may then decide to repeat all or part of Stage 1. The decision rests with the auditor rather than with a fixed deadline, and it is more likely to go against you the longer you wait.

AspectStage 1Stage 2
Guiding questionIs this ISMS auditable?Does this ISMS work in practice?
Subject matterDocumentation, scope, Statement of Applicability, internal audit, management reviewImplementation and effectiveness of clauses 4 to 10 and the selected controls
LocationRemote or on site, in practice often remoteNormally at your sites
MethodReview and interviewSampling, interviews, inspection of records
OutcomeClearance for Stage 2, or reworkRecommendation for certification, if necessary after corrections

Stage 2: proving the ISMS works

Stage 2 examines implementation and effectiveness. ISO/IEC 17021-1 names in clause 9.3.1.3.2 the internal auditing processes, the management review, and performance monitoring, measuring, reporting, and reviewing against stated objectives and targets. The auditor works by sampling: they pull individual access requests, onboarding records, training confirmations, or incident reports and trace each one through your processes.

That brings a question to the front that many teams underestimate. How long does a control need to have been running before Stage 2 can take place? The usual answer is three to six months. That is a market convention, not a requirement of the standard. Neither ISO/IEC 17021-1 nor accreditation body guidance states a minimum operating period. The convention simply follows from the fact that a completed internal audit, a documented management review, and credible operating records all take time to produce. A team that can show those three things sooner can be audited sooner.

The difference is practical, because it changes the conversation with your certification body. You are not arguing about a deadline. You are arguing about depth of evidence.

A worked example: a SaaS company with 45 employees puts product, infrastructure, and customer support in scope, runs its internal audit six weeks before the Stage 2 date, and finds for itself that supplier assessments are missing for three sub-processors. That is precisely the sort of thing that becomes an external finding. Because the team closes it beforehand, it walks into the audit with a documented correction rather than an open gap. Which controls apply here is set out in our article on the 93 Annex A controls.

Nonconformities: what major and minor really mean

This is where the largest misunderstanding of the whole procedure sits. Most teams read "major" as a verdict on how bad a fault is. That is not the definition. ISO/IEC 17021-1 defines a major nonconformity in clause 3.12 as one that affects the capability of the management system to achieve its intended results. Clause 3.13 defines a minor nonconformity as its mirror image, one where that capability is not affected. What decides the classification is the effect on the system, not the number of instances and not the auditor's instinct. European Accreditation has stated explicitly that certification bodies must not depart from this definition, which is a solid argument to have to hand when a classification strikes you as disproportionate.

Minor nonconformityMajor nonconformity
Definition in ISO/IEC 17021-13.13: does not affect the capability of the management system3.12: affects the capability of the management system to achieve its intended results
Typical exampleThe policy requires quarterly access reviews and the record for one quarter is missingAccess reviews are not happening at all, although the control was declared as implemented
Consequence for certificationCorrective action plan, effectiveness usually verified at the next surveillance auditImplementation must be evidenced before certification can be recommended
Hard deadlineSet by the certification body6 months after the last day of Stage 2, otherwise a further Stage 2 audit

Deadlines carry their own persistent legend. The frequently cited 90 days for submitting corrective actions appears nowhere in the standard. ISO/IEC 17021-1 requires in clause 9.4.9 only that the certification body ask the client to analyze the cause and describe the correction and corrective action "within a defined time". How long that time is, the certification body decides, and that is negotiable before you sign the contract.

Exactly one deadline is normative and not negotiable. If the certification body cannot verify the implementation of corrections to a major nonconformity within six months of the last day of the Stage 2 audit, clause 9.5.3.2 requires another Stage 2 audit before certification can be recommended. The standard is available from ISO. Letting corrections drift after the audit does not cost you a piece of rework. It costs you a second audit.

"A finding is not a defeat. It becomes a problem when the team treats it as a formality and cuts the root cause analysis short. At the next audit, the auditor is not checking whether you repaired something. They are checking whether you understood why it broke."

Miriam Mindt, information security and compliance expert at Kertos

Audit days, surveillance audits, and recertification

The effort of an ISMS audit is derived from the effective number of personnel in scope, not from revenue and not from how many controls you selected. The calculation rules sit in the normative Annex C of ISO/IEC 27006-1:2024, supported by the informative Annex D on calculation methods. European Accreditation has clarified that the square-root reduction is applied per activity category rather than to the total headcount in full-time equivalents.

Because scope drives the effort, the obvious move is to draw it as tightly as possible. That calculation does not always work out. Miriam Mindt, information security and compliance consultant, explains in this video why a narrow scope can create more work through interfaces and exclusions than it saves:

One detail is misquoted surprisingly often: IAF MD 5 applies to quality, environmental, and occupational health and safety management systems, and explicitly not to ISMS. If a provider walks you through audit days citing MD 5, they are using the wrong table. It also means quotes from different certification bodies are only comparable up to a point, unless you know which effective number of personnel and which activity categories each one assumed. How to spot dubious providers and worthless certificates is covered separately.

After initial certification come surveillance audits in years one and two. They are shorter than the certification audit and concentrate on the framework clauses plus a subset of the controls, with particular attention to minor nonconformities left open from the previous year. The full cycle and the ongoing obligations in between are described in our overview of ISO 27001 maintenance and recertification.

Kertos customers report that preparing for those follow-up audits is where continuous operation pays for itself. One G2 review puts it this way:

"It has been substantial support in achieving ISO 27001 certification and, currently, in preparing for the Surveillance Audit."

Anonymous review, computer software company, G2

Recertification is where the formalities tighten. ISO/IEC 17021-1 requires in clause 9.6.3.1.1 that the process be planned in due time to allow renewal before the certificate expires. If corrections have not been verified by then, the certification body must not recommend recertification and must not extend validity (clause 9.6.3.2.4). The certificate lapses. Under clause 9.6.3.2.5, the certification body can restore certification within six months provided the outstanding activities are completed, and otherwise at least a Stage 2 audit is required. Those six months are a restoration window, not an extension: in the meantime you are not certified, and in our experience that is exactly the gap a major customer's vendor review lands in.

If you are looking for the complete path from preparation to certificate, the individual steps are in our overview of the ISO 27001 certification process.

Everything in this article assumes one thing: an ISMS that is actually operated day to day rather than one that exists for the audit date. How to scope it so that it survives these audits without blocking your team is covered in our guide to building an ISMS for startups.

How Kertos prepares you for the audit

The difference between a calm Stage 2 audit and a frantic one nearly always comes down to the state of the evidence. Kertos combines an agentic compliance platform with certified experts who know the audit cycle from practice. The platform maps every task to the clause it belongs to and collects evidence automatically through integrations with the systems you already run. Instead of assembling screenshots and log exports before the audit date, your records accumulate in the background.

For the audit itself, traceability is what counts. When the auditor pulls a sample, say a single access request from last quarter, that is the moment your control is either evidenced or merely asserted. That chain from policy to task to individual piece of evidence is what the platform maintains, searchable in both directions.

Across the whole customer base the audit success rate is 100 percent. If you have a certification or surveillance audit coming up, a demo is where we walk through your specific audit plan.

Frequently asked questions

What is ISMS certification?

Formal confirmation by an accredited certification body that your information security management system meets the requirements of ISO 27001. There is no separate ISMS certificate; certification is always against the standard. The certificate is valid for three years.

How does an ISO 27001 audit work?

In two stages. Stage 1 checks whether documentation, scope, internal audit, and management review add up to an auditable ISMS. Stage 2 uses sampling to check whether clauses 4 to 10 and the selected controls work in practice. Surveillance audits follow in years one and two.

What happens if you get a major nonconformity?

You have to analyze the cause, correct it, and evidence the implementation before the certification body may recommend certification. If verification does not happen within six months of the last day of the Stage 2 audit, ISO/IEC 17021-1 clause 9.5.3.2 requires another Stage 2 audit.

How long does an ISO 27001 audit take?

Audit days are calculated from the effective number of personnel in scope, using the rules in Annex C of ISO/IEC 27006-1:2024. Only your certification body's calculation is binding. Day counts taken from IAF MD 5 apply to quality, environmental, and occupational health and safety management systems, not to ISMS.

What is checked in a surveillance audit?

Framework clauses 4 to 10 plus a subset of the Annex A controls, along with nonconformities left open from the previous year and evidence that internal audits, management reviews, and risk assessments actually took place. Surveillance audits are shorter than the certification audit, but they are not a formality.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Andy Mura

Andy Mura

Head of Marketing

Andy Mura is Head of Marketing at Kertos, where he leads growth strategy for the company's compliance automation platform. A marketer and growth strategist by trade, he has spent years working in highly regulated industries such as payments, which is where his interest in compliance, data privacy, and information security first took root. That foundation has since been sharpened by extensive field research and by ongoing conversations with the CISOs and IT security leaders Kertos serves as customers. He writes about the practical realities of building and running security and compliance programs, drawing on what practitioners tell him works and what does not.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check