ISO 19011 defines an audit as a systematic, independent and documented process in which audit evidence is objectively evaluated against audit criteria; the guideline was published in its fourth edition in May 2026 (ISO 19011:2026, a technical revision of the 2018 edition, including expanded guidance on remote audits). Three constellations are distinguished: first-party audits (internal audits) are conducted by the organization itself or on its behalf, for example to verify conformity with the standard or to prepare for certification. Second-party audits are carried out by interested parties such as customers – typically as supplier audits within third-party risk management. Third-party audits are conducted by independent bodies, in particular certification bodies and authorities; these certification audits are governed not by ISO 19011 but by ISO/IEC 17021-1.
Audits & Certifications
How ISO certifications actually work: from audit typology through Stage 1 and Stage 2 to surveillance audits, recertification and the accreditation chain behind it all.
Certificates to ISO/IEC 27001 and related standards are the most common way to demonstrate that a management system is not merely documented but operated effectively. Behind every certificate stands a formalised procedure: a two-stage initial certification audit, annual surveillance audits and recertification in a three-year cycle, governed by ISO/IEC 17021-1. This evidence only becomes robust through the accreditation chain – in Germany, DAkkS monitors whether certification bodies operate competently and impartially. At the same time, the standard itself requires internal audits as an integral part of the management system; those who know the cycle and the typical nonconformities can go through audits in a plannable way and without surprises.
Milestones in the standards landscape
Three key dates around standard transitions and the audit guideline — tap a milestone for details.
End of the ISO/IEC 27001:2022 transition
Under IAF MD 26, the deadline for transitioning to ISO/IEC 27001:2022 ended. Certificates to the 2013 edition have been invalid since then.
End of the ISO/IEC 27006-1:2024 transition
The transition period for certification bodies ended. The standard adds requirements for ISMS certifications, including auditor competence and minimum audit time.
ISO 19011:2026 published
The audit guideline appeared in its fourth edition — a technical revision of the 2018 edition, including expanded guidance on remote audits.
The Essentials at a Glance
Six topic blocks — tap to expand.
Audit typology
Three constellations under ISO 19011 — who audits whom, and which standard applies.
- Conducted by the organization itself or on its behalf.
- Typical purposes: verifying conformity with the standard or preparing for certification.
- The benchmark is ISO 19011 — published in its fourth edition in May 2026.
- Carried out by interested parties such as customers.
- Typically as supplier audits within third-party risk management.
- Conducted by independent bodies — in particular certification bodies and authorities.
- These certification audits are governed not by ISO 19011 but by ISO/IEC 17021-1.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/IEC 17021-1:2015 – Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements
Governs the two-stage initial certification audit, annual surveillance audits, recertification in the three-year cycle and the six-month rule for major nonconformities.
ISO/IEC 27006-1:2024 – Information security, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General
ISMS-specific additional requirements for certification bodies, including auditor competence and minimum audit time; the transition period under IAF MD 29:2024 ended on 31 March 2026.
ISO 19011:2026 – Guidelines for auditing management systems
Guidelines for first- and second-party audits, including audit principles and the definition of an audit; fourth edition (May 2026) as a technical revision of the 2018 edition.
ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Clause 9.2 (9.2.1/9.2.2) requires internal audits at planned intervals, including an audit programme, objective auditor selection and reporting obligations.
IAF MD 26:2023 – Transition Requirements for ISO/IEC 27001:2022 (Issue 2)
Mandatory transition requirements for ISO/IEC 27001:2022; certificates to the 2013 edition lost their validity on 31 October 2025.
Rechtliche Grundlagen der DAkkS (dakks.de)
Germany's sole national accreditation body, based on Regulation (EC) No 765/2008 and the AkkStelleG; operates in accordance with ISO/IEC 17011.
Preparing your next audit in a structured way?
We support you with gap analyses, internal audits under Clause 9.2 and guidance through Stage 1 and Stage 2 – get in touch for a no-obligation initial consultation.