Skip to content

Information Security · ISO Standards

ISO 27001:2022 audit readiness: what Stage 1 and Stage 2 actually test

How to prepare an ISMS for ISO 27001:2022 certification in 2026 — scope, SoA, internal audit, and what registrars sample in Stage 2.

6 min read

ISO 27001:2022 is still the default way a SaaS or cloud company proves it runs an information security management system, not a pile of policies. Buyers ask for the certificate; registrars ask whether the system operates. Those are different tests, and mixing them up is how you burn a quarter.

The paired checklist is the execution path: scope, SoA, risk, internal audit, Stage 1 pack. This note is the judgment the checkboxes cannot make — how wide to draw the boundary, when you are actually ready to invite a registrar, and why a workshop last week is not an operating ISMS.

Most delays are not missing Annex A tools. They are an oversized scope, an SoA that does not match production, and an internal audit that only checked documents. If those three are honest, the rest of 27001 is mostly discipline.

What “ready” means in Stage 1 versus Stage 2

Stage 1 is a documented-information review: scope, policy, risk process, Statement of Applicability, and whether you look prepared for sampling. A clean Stage 1 does not mean you will pass Stage 2. It means the auditor is willing to spend time in your systems.

Stage 2 tests operating controls. Auditors interview owners and follow evidence into ticketing, access reviews, supplier files, and change records. If you cannot show a period of operation — not a policy dated last Tuesday — Stage 2 will stall or produce major nonconformities.

Treat the ISMS as a management system with owners, metrics, and management-review minutes. If the CISO is the only person who can explain a control, you do not have a system; you have a bottleneck.

A useful readiness test: pick three Annex A themes that actually matter to your product (access, change, suppliers) and ask a non-security owner to show last quarter’s evidence without coaching. If they cannot, Stage 2 will not go better with a nicer SoA PDF.

Decisions the checklist will not make for you

Scope is a business decision disguised as a security one. “All products, all regions, all contractors” looks ambitious and wrecks sampling. Narrow to systems that actually process customer data, name the locations and suppliers in the boundary, then expand in a later cycle once you have a certificate to point at.

ISO 27001 does not replace SOC 2. Many companies keep both because US enterprise security reviews still want a Type II while EU and APAC procurement wants ISO. Decide that split before you staff two evidence factories that describe the same production environment in two dialects.

Annex A is not a shopping list. The SoA has to justify inclusions and exclusions against your risk assessment. Copying every control “just in case” creates procedures nobody runs. Excluding a control because it is inconvenient, with no residual-risk acceptance, is how Stage 2 findings are born.

Where teams lose months

Policies that describe weekly access reviews while Jira shows quarterly ones are more damaging than a missing policy. Registrars sample reality. Align the sentence with the ticket, or change the ticket.

Supplier and cloud clauses (A.5.19–A.5.23) fail when the ISMS talks about “AWS” and the contract pack has no security schedule, no shared-responsibility note, and no review cadence. Your hyperscaler’s ISO certificate is inheritance, not your control.

Internal audit that only walks the document set will not find the broken joiner-mover-leaver path. Use the same sampling logic the registrar will use: pick a control, pull a population, test a sample, write a nonconformity if it fails.

Certification-body shopping on price alone is another delay. A registrar who has never sampled a multi-tenant SaaS will burn days on diagrams you thought were obvious. Ask how they sample cloud scope before you lock the week.

How to use the paired checklist

Work the phases in order. Skipping to “Stage 2 readiness” while the SoA is still a draft is how you schedule an audit you cannot sit. Use the required-documents list as the pack index, not as decoration.

When a checkbox is ambiguous — “sufficient period of operation,” “interested parties” — that is a scope or evidence decision. Record the decision in the ISMS, then tick. The checklist stores progress in your browser; it does not store your SoA.

What teams get wrong

ISO 27001 is a technical audit of firewalls and EDR.
It is a management-system audit. Tools show up as evidence that controls operate. Leadership, risk, internal audit, and management review are in scope even if your stack is excellent.
A SOC 2 Type II means we are ISO-ready.
The Trust Services Criteria overlap with Annex A, but ISO wants an ISMS: scope statement, SoA, documented risk methodology, and certification-body sampling. You can reuse evidence; you cannot reuse the opinion. Plan the ISO cycle as its own project with a registrar, not as a PDF export from the SOC 2 folder.
We should include everything so the certificate looks impressive.
Broad scope delays certification and increases nonconformity risk. Buyers care that the customer-facing system is in scope. You can widen later; you cannot easily un-fail Stage 2.

When the checklist is enough — and when it is not

  • Use the checklist to build the ISMS and assemble the Stage 1 pack with internal owners.
  • Bring an accredited registrar (or a consultant who has sat Stage 2 recently) when you need a certification window, multi-site sampling strategy, or a judgment on whether a major nonconformity is likely.
  • Use legal counsel when customer contracts promise a certificate date, when you must explain exclusions that affect a regulated workload, or when you are claiming 27001 in a market with extra overlay (finance, health, public sector).
  • Do not treat this site as a substitute for the official ISO/IEC 27001:2022 text or for the certification body’s findings.

Related checklists

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer