6.3 Stage 1 Certification Audit Preparation & Document Review

Key Takeaways

  • The Stage 1 certification audit focuses on assessing ISMS documented information, scope boundaries, Statement of Applicability (SoA), and overall readiness for Stage 2.
  • Mandatory prerequisites for Stage 1 include completing at least one full internal audit cycle (Clause 9.2) and top management review (Clause 9.3).
  • The Statement of Applicability (SoA) must account for all 93 Annex A:2022 controls, providing valid technical or operational justifications for every inclusion and exclusion.
  • Stage 1 audit outcomes result in formal recommendations: Ready for Stage 2, Ready Pending Action, or Not Ready for Stage 2.
  • Lead Implementers must conduct thorough pre-audit document reviews to prevent scope mismatches, missing policy approvals, or incomplete risk assessment records.
Last updated: July 2026

6.3 Stage 1 Certification Audit Preparation & Document Review

The initial certification process for ISO/IEC 27001:2022 is a formal two-stage audit conducted by an independent, accredited Certification Body (CB) (such as BSI, Bureau Veritas, SGS, or TÜV). Stage 1—frequently referred to as the Documentation Review or Readiness Assessment—is designed to verify that the ISMS is properly designed, fully documented, and compliant with standard requirements before the Certification Body commits resources to the intensive Stage 2 implementation audit. This section details the objectives, evaluation criteria, documentation requirements, and Lead Implementer strategies for passing Stage 1.


1. Primary Objectives of the Stage 1 Audit

The Stage 1 audit is governed by ISO/IEC 17021-1 (the standard governing certification bodies). The auditor's primary mission during Stage 1 is not to test technical control execution on production servers, but to evaluate management system design and audit readiness. The six core objectives of Stage 1 are:

  1. Evaluate Documented Information: Review mandatory ISMS documented information (Clauses 4 through 10) to confirm completeness and alignment with ISO/IEC 27001:2022 requirements.
  2. Verify ISMS Scope & Boundaries: Confirm the physical, logical, organizational, and technological boundaries declared in the Scope Statement (Clause 4.3), including any multi-site operational details.
  3. Assess Statement of Applicability (SoA): Evaluate the SoA (Clause 6.1.3 d) to ensure all 93 Annex A:2022 controls are addressed and that every inclusion and exclusion is supported by a documented justification.
  4. Verify Mandatory Prerequisites: Confirm that the organization has performed at least one complete cycle of Internal Audit (Clause 9.2) and Management Review (Clause 9.3) prior to Stage 1.
  5. Understand Site-Specific Conditions: Gain an understanding of the client's organization, location-specific security constraints, regulatory obligations, and operational risk profile.
  6. Plan the Stage 2 Audit: Agree on Stage 2 logistics, audit sampling plans, dates, site visit schedules, and resource requirements.

2. Essential Stage 1 Documentation Review Package

Prior to the Stage 1 audit date, the Lead Implementer must assemble and submit the formal ISMS documentation package to the lead auditor. The auditor scrutinizes these documents against standard clauses:

+-------------------------------------------------------------------------+
|                    STAGE 1 MANDATORY DOCUMENT PACKAGE                   |
+-------------------------------------------------------------------------+
| Standard Clause    | Document / Evidence Description                    |
+--------------------+----------------------------------------------------+|
| Clause 4.3         | ISMS Scope Document & Boundary Definitions         |
| Clause 5.2         | Information Security Policy (Executive Approved)   |
| Clause 6.1.2       | Risk Assessment Methodology & Risk Register        |
| Clause 6.1.3       | Risk Treatment Methodology & Risk Treatment Plan   |
| Clause 6.1.3 (d)   | Statement of Applicability (SoA Version Final)     |
| Clause 6.2         | Information Security Objectives & Measurement Plan |
| Clause 7.2 / 7.3   | Competence Evidence & Security Awareness Plan      |
| Clause 8.1         | Operational Planning & Control Procedures          |
| Clause 9.2         | Internal Audit Program, Audit Plan, & Audit Report |
| Clause 9.3         | Management Review Meeting Minutes & Actions        |
| Clause 10.1        | Corrective Action Procedure & Nonconformity Logs   |
+--------------------+----------------------------------------------------+

3. Evaluating Statement of Applicability (SoA) Integrity

The Statement of Applicability (SoA) is the single most critical document reviewed during Stage 1. It acts as the bridge between the risk assessment (Clause 6.1.2), risk treatment (Clause 6.1.3), and the 93 controls listed in Annex A:2022.

During Stage 1, the lead auditor rigorously audits the SoA for four structural integrity criteria:

  1. Completeness: Does the SoA account for all 93 Annex A controls across the four updated 2022 themes (Organizational, People, Physical, Technological)? Omitting any control from the table results in an immediate Stage 1 finding.
  2. Justification for Inclusion: For every control marked Included, does the SoA state why it was selected (e.g., risk treatment option, legal compliance, contractual requirement) and reference the implementing policy or control document?
  3. Justification for Exclusion: For every control marked Excluded, does the SoA provide a clear, valid technical or operational rationale?
    • Acceptable Rationale: Excluding Physical Control 7.4 (Physical security monitoring) for a 100% remote software startup that operates no physical offices or server rooms, relying entirely on AWS cloud infrastructure where physical security is delegated to the cloud provider under a SOC 2 Type II report.
    • Unacceptable Rationale: Excluding Control 8.8 (Management of technical vulnerabilities) because 'the IT team lacks time to scan servers' or 'vulnerability scanners are too expensive.'
  4. Implementation Status: Does the SoA accurately reflect the current operational state of each control (e.g., Implemented, In Progress, Automated)?

4. Stage 1 Audit Outcomes & Auditor Recommendations

At the conclusion of the Stage 1 audit, the lead auditor conducts a closing meeting and issues a formal Stage 1 Audit Report. The report classifies any observed gaps and concludes with one of three official recommendations regarding Stage 2 progression:

                             STAGE 1 AUDIT EVALUATION
                                        |
         +------------------------------+------------------------------+
         |                              |                              |
         v                              v                              v
+------------------+          +-------------------+          +------------------+
| 1. READY FOR     |          | 2. READY PENDING  |          | 3. NOT READY FOR |
|    STAGE 2       |          |    ACTION         |          |    STAGE 2       || +------------------+          +-------------------+          +------------------+
| Documented ISMS  |          | Minor doc gaps    |          | Mandatory pre-   |
| fully compliant. |          | identified. Cap   |          | reqs missing     |
| Prerequisites    |          | submitted prior   |          | (e.g., no internal|
| complete.        |          | to Stage 2.       |          | audit done).     |
| Stage 2 scheduled|          | Stage 2 proceeds. |          | Stage 2 postponed|
+------------------+          +-------------------+          +------------------+

Detailed Outcome Analysis:

  • Recommendation 1: Ready for Stage 2: Documented ISMS meets all requirements, internal audit and management review are complete, SoA is fully justified. Stage 2 proceeds as planned (typically 30 to 90 days after Stage 1).
  • Recommendation 2: Ready Pending Action: The auditor identifies minor documentation gaps or concerns (termed Areas of Concern or Stage 1 Nonconformities). The organization must update documents and submit evidence to the auditor before Stage 2 commences. Stage 2 dates remain on the schedule.
  • Recommendation 3: Not Ready for Stage 2: Critical baseline prerequisites are missing—such as an incomplete internal audit, missing management review, undefined scope, or unapproved SoA. Stage 2 is cancelled, and a follow-up Stage 1 review must be scheduled after remediation, causing significant project delays.

5. Common Stage 1 Pitfalls & Lead Implementer Checklist

To ensure a seamless Stage 1 outcome, Lead Implementers must proactively audit their preparation against common audit failure points:

Common Pitfalls:

  1. Premature Scheduling: Scheduling Stage 1 before completing a full cycle of internal audits and top management review. Lead Implementer Golden Rule: Never host Stage 1 until the final Management Review minutes are signed by executive leadership.
  2. Scope Mismatch: Discrepancies between the scope written in the Scope Document and how the business is described on the corporate website or sales collateral.
  3. Unjustified Exclusions: Marking complex Annex A controls (such as secure coding or threat intelligence) as excluded without documented risk rationale.
  4. Unsigned Policies: Submitting draft policies that lack formal approval signatures and effective dates from top management (Clause 5.2).

Lead Implementer Pre-Stage 1 Checklist:

  • ISMS Scope Statement defines physical, logical, and organizational boundaries.
  • Executive Information Security Policy signed and published to all staff.
  • Risk Assessment and Risk Treatment reports fully completed with signed risk acceptances.
  • Statement of Applicability (SoA) covers all 93 controls with explicit justifications.
  • Internal Audit executed across all clauses and controls; report signed off.
  • Corrective actions opened for all internal audit nonconformities.
  • Management Review held; detailed minutes recorded and action items assigned.

6. Real-World Lead Implementer Scenario

Scenario: A SaaS company prepares for its Stage 1 audit. Two weeks prior to the audit, the Lead Implementer reviews the documentation package and notices that while an internal audit was performed for technical IT operations, standard clauses 4 through 10 and human resources controls were accidentally omitted from the internal audit scope.

Lead Implementer Execution Steps:

  1. Recognize the Prerequisite Failure: The implementer realizes that an incomplete internal audit will cause a 'Not Ready for Stage 2' finding under Clause 9.2.
  2. Execute Emergency Supplemental Audit: The implementer immediately mobilizes an independent internal auditor to conduct a rapid supplemental audit covering Clauses 4-10 and HR controls.
  3. Update Audit Report & Hold Management Review: The supplemental audit findings are merged into the final Internal Audit Report, and an extraordinary Management Review meeting is convened to review the complete audit results.
  4. Stage 1 Audit Execution: The Lead Implementer presents the complete audit package during Stage 1. The certification auditor verifies full coverage of Clause 9.2 and issues a formal recommendation: Ready for Stage 2.
Test Your Knowledge

What is the primary objective of a Stage 1 Certification Audit conducted by an accredited Certification Body?

A
B
C
D
Test Your Knowledge

During a Stage 1 document review, the certification auditor discovers that the organization has not yet conducted an internal audit or top management review. What recommendation will the auditor issue in the Stage 1 report?

A
B
C
D
Test Your Knowledge

An organization's Statement of Applicability (SoA) excludes Annex A control 8.11 (Data Masking). What must be present in the SoA for the auditor to accept this exclusion during Stage 1?

A
B
C
D