Illumen · A Field Guide
What to Expect When You’re Expectingan ISO 27001 Audit
A calm, phase-by-phase guide to certification, for the person who has to run it.
26 illustrated pages · Free · No form, no email, no gate

Yes, this is shaped like a pregnancy guide. The joke is load-bearing. Both processes run about a year, involve strangers reading your documents, and are enormously improved by somebody telling you which of the alarming things are normal.
A gap found at Stage 1 is routine. The same gap found at Stage 2 is a nonconformity.
Same finding, same words in the same report, and the consequence turns almost entirely on when it surfaces. Most of the painful ISO 27001 outcomes we have watched are not security problems. They are right-thing-at-the-wrong-moment problems, which is a much better problem to have, because it is one you can schedule.

Conception
Standing up the ISMS
Scope, policy, risk method, Statement of Applicability. Nobody is watching this phase, which is precisely why it is the one most often done badly. Every other phase has an external deadline attached to a person who will show up and ask questions. This one has none, and it expands to fill whatever time is available.
Statement of Applicability
The document listing the controls you deem necessary, measured against Annex A, with your justification for what you included and what you left out.

The First Scan
The internal audit
Clause 9.2 makes an internal audit mandatory, and 9.2.2 requires objectivity: whoever designed the management system should not be the person auditing it. Findings raised here are findings you close on your own timetable rather than the certification body’s, provided you actually close them.
Objectivity
The auditor has no stake in the answer. It is a requirement of the standard, not a courtesy, and it is the reason a self-audit rarely survives contact with Stage 2.

The Twelve-Week Appointment
Stage 1, the documentation review
The certification body reads your management system rather than testing it. Most of Stage 1 is spent on the management system rather than the 93 Annex A controls, which surprises teams who spent their preparation on the controls. Expect an opening meeting, a walk through the mandatory documents, a conversation about Clauses 4 to 10, a list of findings, and a Stage 2 date.
Area of concern
Something the certification body wants resolved before Stage 2. Not a nonconformity, and it is the normal output of a first Stage 1.

Delivery
Stage 2, evidence and effectiveness
The auditor stops reading about your management system and starts testing whether it operates. They pick a period, pull a sample, and trace it. They talk to people who are not you. Sampling is the mechanical fact the whole phase turns on, and operating history is the one input you cannot create retrospectively.
Evidence
A dated artefact showing a control operated: a timestamped export, an approval record, a ticket, a signed minute. “We do that every quarter” is a claim about evidence that should exist.

The Fourth Trimester
Certification and surveillance
The certificate runs three years: surveillance in year one, again in year two, recertification in year three. The difference is not that surveillance finally tests effectiveness, because Stage 2 already did. The difference is the period. Stage 2 judged you on the months you had with a deadline in the room, and surveillance judges a whole year in which nobody was watching.
Administrative drift
Not a security problem. The system stopped being run because the deadline that was making it run has gone.
The thing you cannot fake
A control that started operating three weeks ago has three weeks of evidence. No document, no policy quality and no explanation makes an auditor sample a period that does not exist. Operating history is the one input you cannot create retrospectively, and it is why the gap between Stage 1 and Stage 2 matters more than most decisions you make inside it.
A major nonconformity at Stage 2. It stops certification until it is resolved, and resolution means evidence that the corrective action worked, not a plan to take one. The window is usually months rather than weeks, with an outer bound of six months from the last day of Stage 2 under ISO/IEC 17021-1. Miss it and the certification body has to run Stage 2 again.
It is recoverable, and organisations recover from it regularly. It is also the reason every earlier phase pushes you to find things sooner.
What surveillance checks, every time
Alongside a rotating subset of controls, ISO/IEC 17021-1 clause 9.6.2.2 sets a fixed list:
- Your internal audits and management review
- Actions taken on the previous audit’s nonconformities
- How you handle complaints
- Whether the system is achieving the objectives you set for it
- Progress on continual improvement
- Continuing operational control
- Any change to scope, structure or risk
- Correct use of the certification mark
Most of that is the management system rather than the individual controls, which is the opposite of where most teams put their preparation. The controls still get sampled and operational control is on the list every time, so this is a reason to prepare for both rather than a reason to relax about the technical half.
Questions you are too embarrassed to ask
What is the difference between an ISO 27001 Stage 1 and Stage 2 audit?
Stage 1 is a documentation review. The certification body checks whether your management system is designed: scope, policy, risk methodology, Statement of Applicability, and whether the mandatory clauses exist. Stage 2 evaluates implementation, including effectiveness. The auditor selects a period, samples records from it, traces each one end to end, and interviews the people who operate the control rather than the people who wrote the policy.
What happens if I get a major nonconformity at Stage 2?
It stops certification until it is resolved, and resolution means evidence that the corrective action worked, not a plan to take one. Under ISO/IEC 17021-1, if the certification body cannot verify implementation within six months of the last day of Stage 2, it has to conduct another Stage 2 before recommending certification. It is recoverable, and organisations recover from it regularly.
How long should the gap between Stage 1 and Stage 2 be?
Long enough to generate operating history, because a control that started operating three weeks ago has three weeks of evidence and no document compensates for that. But an over-long interval carries its own risk: the certification body may repeat all or part of Stage 1, which means a rebooked and re-invoiced audit. Two months is a common working answer, though your certification body sets the terms.
What is the difference between a major and a minor nonconformity?
Broadly, absence versus partial. A required control or clause that is entirely absent, or a systemic breakdown, is a major. A requirement that is partly met, or an isolated lapse, is a minor. It is not the whole test: a nonconformity raising significant doubt about the system’s capability to achieve its intended results can be major even where the requirement is partly met, and a cluster of related minors against one clause is routinely escalated.
What does an ISO 27001 surveillance audit check?
ISO/IEC 17021-1 clause 9.6.2.2 sets a fixed list covered every time: internal audits and management review, actions taken on the previous audit’s nonconformities, complaints handling, effectiveness against your objectives, progress on continual improvement, continuing operational control, any changes, and correct use of the certification mark. A rotating subset of controls is sampled alongside it.
Is this guide free, and do I have to give you my email address?
It is free and there is no form. Download the PDF, or read the whole thing on this page. Nothing is gated.
Who is this guide for?
The person inside the organisation who owns the certification programme. Usually someone who volunteered, inherited it, or was in the wrong meeting, and who now has to run a process that takes about a year and that nobody has explained end to end.
When it stops being a calendar problem
Illumen is a boutique GRC firm. We run ISO 27001 internal audits, act as vCISO for companies without a security team of their own, and get organisations through certification with the certification body of their choice. We do not audit programmes we designed.

Illumen · illumen.io
Related Resources
Tools, templates, and articles for ISO 27001 compliance

Cost Calculator
ISO 27001 Cost Calculator
Estimate your ISO 27001 certification costs including implementation, audit, and ongoing maintenance.

ISO 27001
What to Expect When You're Expecting an ISO 27001 Audit
The standard tells you what must be true, never what will happen to you. A free 26-page illustrated guide to the whole ISO 27001 certification arc, for the person who has to run it.

Identity Security
Non-Human Identity Security: Your Access Review Covers 1% of Your Identities
Machine identities outnumber humans 100:1, OWASP ranks improper offboarding as the top non-human identity risk, and only 21% of organizations have a process to decommission an AI agent. How to extend the access review you already built.