Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityPublished: 15 July 2026

ISO 27001 Audit Preparation: Stage 1 and Stage 2 Checklist

What auditors really check in Stage 1 and Stage 2, and how to prepare your ISMS without last-minute evidence hunting.

An ISO 27001 audit is not just a document review. The auditor wants to understand whether your information security management system works in daily practice: whether the scope is clearly bounded, risks are assessed in a traceable way, controls from the Statement of Applicability are actually implemented and responsible people can explain their processes.

Good preparation therefore does not start by collecting as many policies as possible. It starts with a simple question: can an external person follow the path from risk, to selected control, to concrete evidence? If that connection is clear, the audit becomes much calmer. If it is missing, questions, follow-up requests and findings become more likely.

This article first explains what Stage 1 and Stage 2 each focus on. Further down, you will find an Excel checklist for structuring readiness, evidence, actions and interview preparation.

Stage 1: demonstrate certification readiness

Stage 1 is the documentation and readiness review. The auditor wants to see whether the ISMS can be audited and whether Stage 2 can be planned sensibly. For ISO 27001, this especially means: the scope must be plausible, the risk method must be defined, the risk assessment must be traceable and the Statement of Applicability must not be an isolated document.

Table 1: ISO 27001 Audit Preparation: Stage 1 and Stage 2 Checklist
Check pointWhat should be preparedTypical gap
ScopeSites, services, systems, interfaces and exclusions are justified.The scope is written like marketing copy and cannot be technically bounded.
Context and requirementsRelevant customer, legal, contractual and internal requirements are recorded.NIS2, customer requirements or processor topics are missing from the assessment.
Risk methodCriteria, scale, acceptance limits and responsibilities are approved.Risks were assessed, but the method is not explained.
SoAAll 93 controls are assessed, justified and connected to implementation/evidence.Controls are marked "applicable" without a defensible reference.
Audit programmeInternal audit and management review are planned or completed.The internal check is improvised only after Stage 1.

Example: what good Stage 1 evidence shows

Good Stage 1 evidence is not only present; it can be explained. Example scope: if a SaaS provider wants to certify only the product platform, it should be clear whether development, operations, support, cloud infrastructure, identity management and external providers are inside the scope. If customer support can access sensitive data, it cannot simply sit outside the scope because it belongs to a different team.

The same applies to risk assessment. An auditor does not necessarily expect a complex quantitative method. But criteria such as likelihood, impact, information value, risk acceptance and responsibility should be applied consistently. If two comparable risks are scored differently, the difference should be defensible.

Stage 2: show implementation and effectiveness

Stage 2 does not test whether the documentation looks tidy. The auditor follows processes, interviews responsible people and checks samples. The best preparation is therefore an evidence walkthrough: for every critical process, clarify where the evidence is stored, who can explain it and which open action still has to be closed.

Evidence that is often requested

  • approved scope, information security policy and ISMS objectives,
  • asset or information asset register with owners,
  • risk register, risk treatment plan and accepted residual risks,
  • Statement of Applicability with control status and evidence references,
  • access reviews, backup tests, logging/monitoring evidence and incident records,
  • supplier assessment, contractual security requirements and privacy/data processing references,
  • awareness and training records, internal audit, management review and action tracking.

Example: from risk to evidence

An audit-ready evidence trail connects several levels. Example: the risk register lists "unauthorised access to customer data". That leads to controls such as access control, role model, access recertification, logging and offboarding. In Stage 2, it should be visible how these controls work in practice: a current access review, an offboarding ticket, an identity management export, a role description and evidence that deviations were tracked.

A folder with isolated policies is weak if it has no clear link to the risk assessment or SoA. Strong evidence shows: this risk was identified, this control was selected, this person is responsible, this record shows implementation, and this open deviation is being tracked.

Download: ISO 27001 Audit Checklist

Once the audit logic is clear, a structured working list helps. The Excel template contains four worksheets: Stage 1 readiness, Stage 2 evidence, action tracking and interview planning. It is designed as a working file, not as a generic tick-box list.

How to fill out the template

Use the template as a working list for the project team. The dropdowns in the status and priority columns keep the assessment consistent, while the free-text fields are for concrete evidence, owners and next steps.

  1. Stage 1 Readiness: Start with scope, context, risk method, risk assessment, SoA, objectives and audit planning. Set the status via dropdown and record every gap with an owner and due date.
  2. Stage 2 Evidence: Link to or describe the actual evidence. The decisive point is not that a document exists, but that the responsible owner can explain it.
  3. Actions: Move all open points from Stage 1 and Stage 2 into one consolidated list. Priority and status are prepared as dropdowns.
  4. Interview Plan: Plan which roles the auditor is likely to interview, which questions may come up and which evidence each person should show.

Plan the audit days in practice

Even a technically solid ISMS can look unnecessarily weak if the organisation is not prepared for the audit day. Define in advance who receives the auditor, who follows the audit agenda, who retrieves evidence and who is allowed to make decisions. For remote audits, also clarify how screen sharing, document access and confidential evidence will be handled.

  • Create a central evidence folder or link list with the most important records.
  • Keep one internal contact available during the audit to retrieve missing evidence.
  • Prepare short process overviews so interviews do not start from zero.
  • Record audit questions, uncertainties and potential findings during the audit.

Prepare the interviews

Many organisations prepare only the document repository. That is not enough. Top management, IT, HR, procurement and process owners should briefly understand which questions may come up and which evidence they can show. The point is not scripted answers, but a consistent understanding of the ISMS.

Table 2: ISO 27001 Audit Preparation: Stage 1 and Stage 2 Checklist
RoleTypical questionsGood preparation
Top managementWhy this scope? Which risks do you accept? Which objectives apply?Review scope, management review, ISMS objectives and residual risks together.
IT / OperationsHow are access, vulnerabilities, backups and logs controlled?Prepare samples and name system owners.
HRHow do onboarding, role changes, training and offboarding work?Check onboarding/offboarding evidence and awareness records.
Procurement / supplier ownerHow are critical suppliers assessed and monitored?Prepare supplier list, criticality and contractual requirements.

What should not happen

  • Evidence is searched for during the audit.
  • The SoA lists controls, but nobody can show implementation.
  • Risks, controls and action lists contradict each other.
  • Top management does not know the scope, objectives or residual risks.
  • Open actions are not prioritised and not dated.

If the auditor raises a finding

A finding does not automatically mean the audit has failed. What matters is that you clarify which requirement the finding relates to, what objective evidence was missing or ineffective, and what correction is needed. Then assess the cause, define corrective action and track effectiveness.

Typical example: an access review was planned but not performed. Simply completing the spreadsheet afterwards only solves part of the problem. A stronger response is to perform the review, understand why it was missed, define ownership and frequency, and prove at the next review that the process is actually running.

ISO describes ISO/IEC 27001 as a management system standard for information security, cybersecurity and privacy protection. That is why audit preparation should connect management logic with technical evidence instead of collecting isolated IT controls: ISO/IEC 27001:2022 ISO overview.

How to use the checklist

  1. Start the readiness worksheet four to six weeks before Stage 1 and only mark an item as "Done" when the evidence can be found.
  2. Transfer every gap into the action list with owner, due date, priority and next step.
  3. Before Stage 2, review the evidence list by process and control. Add links to folders, tickets, minutes or screenshots.
  4. Plan short interview preparation sessions with the roles the auditor is likely to speak to.

Connect it with your ISMS

If you are still building the system, start with the overview of ISO 27001 certification for SMEs. For audit readiness, the articles on ISO 27001 risk assessment, the Statement of Applicability and ISO 27001 and NIS2 are also relevant.

How Sternberg Consulting supports you

We review scope, risk assessment, SoA, evidence and audit interviews before Stage 1 or Stage 2. Our ISO 27001 consulting covers gap analysis, ISMS implementation and concrete audit preparation.

Discuss audit preparation

Frequently asked questions

Does everything have to be implemented before Stage 1?

Not every operational record has to be complete. But scope, risk method, key documentation, SoA and audit planning must be robust enough for Stage 2 to make sense.

Is an ISO 27001 checklist enough?

No. A checklist helps with structure, but it does not replace assessment of scope, risks, control selection, implementation and effectiveness.

Who should participate in the audit?

In addition to the ISMS owner, usually top management, IT/Operations, HR, procurement or supplier owners and affected process owners.

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.