The Certification Process: Stage 1, Stage 2 & Beyond
Learn the real mechanics of getting certified — the Stage 1/Stage 2 audit split, how findings are classified, the surveillance and recertification cycle, and who accredits the certification bodies themselves.
Learning Objectives
- → Distinguish what a Stage 1 audit checks from what a Stage 2 audit checks
- → Classify a finding as a major nonconformity, minor nonconformity, or observation
- → Explain what happens after certification — the ongoing audit cycle
- → Describe what ISO/IEC 17021 accreditation means and why it matters when choosing a certification body
Everything covered so far — clauses 4-10, the 93 Annex A controls, the SoA — eventually gets tested by an external, accredited auditor. This lesson covers what that process actually looks like in practice, and what happens after the certificate is issued (certification isn't a finish line, it's the start of a recurring cycle).
Before the audit: an optional gap analysis
Many organizations (VigilForge's own ISMS work, covered as a full case study in the next lesson, is a real example) conduct an internal or third-party gap analysis before ever contacting a certification body — identifying weak controls and documentation gaps while there's still time to fix them without a certification decision on the line. This step isn't part of the formal audit sequence, but skipping it is a common reason organizations fail Stage 1 with easily avoidable findings.
Stage 1: documentation and readiness review
Stage 1 is primarily a desk review — the auditor examines your documentation (scope, policy, risk assessment, SoA, key procedures) to assess whether the ISMS is sufficiently developed to be worth auditing on-site at all. Stage 1 typically checks:
- Is the ISMS scope clearly and reasonably defined?
- Does documented risk assessment and treatment exist and appear sound?
- Is the SoA present, complete, and does it trace back to the risk assessment?
- Are the mandatory clause 4-10 requirements documented?
Stage 1 findings are usually about readiness, not deep implementation detail — if major gaps are found, Stage 2 is typically postponed until they're addressed, rather than proceeding to a doomed on-site audit.
Stage 2: implementation audit
Stage 2 is where the auditor verifies the ISMS is actually operating as documented — through direct observation, staff interviews, and sampling evidence. This is where claims from Stage 1's documentation get tested against reality: does the access review process described in the SoA actually happen quarterly, as claimed? Can the person responsible for it show you the last three reviews?
Classifying findings
Auditors don't just say "pass" or "fail" — findings are classified by severity:
| Classification | Meaning | Effect on certification |
|---|---|---|
| Major nonconformity | A significant failure — either a clause requirement isn't met at all, or a systemic breakdown affecting the ISMS's ability to achieve its objectives | Blocks certification until resolved and re-verified |
| Minor nonconformity | An isolated lapse or inconsistency that doesn't undermine the whole system | Certification can proceed, with a corrective action plan and follow-up |
| Observation / opportunity for improvement (OFI) | Not a nonconformity at all — a suggestion, or something that could become a problem if left unaddressed | No formal action required, but worth tracking |
A useful gut check: a single missed step by one person is usually minor; a missing process that would predictably cause the same failure repeatedly across the organization is usually major.
After certification: the cycle continues
Certification is issued for a fixed period (typically 3 years) but is not a one-time event after that:
- Surveillance audits — typically annual, smaller-scope audits sampling parts of the ISMS to confirm continued conformity, and checking progress on any open corrective actions
- Recertification audit — a full audit again, roughly every 3 years, similar in depth to the original Stage 2
A certificate can be suspended or withdrawn if surveillance finds major nonconformities that aren't resolved within an agreed timeframe — certification is a continuously maintained status, not a permanent achievement.
Who certifies the certifiers? ISO/IEC 17021
A natural question: what stops any company from calling itself an "ISO 27001 certification body" without real rigor? ISO/IEC 17021 is the standard that governs the competence and impartiality requirements for bodies that certify management systems. A national accreditation body (in most countries, a government-recognized authority) assesses certification bodies against ISO/IEC 17021 and accredits the legitimate ones. This is why, when choosing who certifies your organization, checking that the certification body itself holds valid accreditation under ISO/IEC 17021 (from a recognized national accreditation body) matters — an "ISO 27001 certificate" from a non-accredited issuer carries far less credibility with customers, regulators, and partners.
For each of these audit activities, decide whether it belongs to Stage 1 or Stage 2: (a) reviewing whether the SoA exists and appears complete, (b) interviewing a system administrator about how they actually perform quarterly access reviews, (c) checking whether the ISMS scope statement is clearly defined, (d) sampling actual backup logs to confirm backups really ran on schedule.
Is 'sampling actual backup logs to confirm backups really ran on schedule' a Stage 1 or Stage 2 activity?
An auditor discovers that one specific employee, during one specific week, forgot to complete their annual security awareness training on time due to being on medical leave, and it was completed two weeks late upon return. Separately, the auditor discovers that the organization has no process at all for tracking whether ANY employee completes required training. Classify each finding.
How should the isolated case of one employee's training being 2 weeks late due to medical leave typically be classified?
How should the complete absence of any process for tracking training completion typically be classified?
💪 Exercises & Challenges
The Certification Process — MCQ
The Certification Process — MCQ
Map a Fictional Company's Certification Journey
Map a Fictional Company's Certification Journey
Stage 1, Stage 2, or Surveillance?
Stage 1, Stage 2, or Surveillance?