Book an Appointment

Audits & Certifications

How ISO certifications actually work: from audit typology through Stage 1 and Stage 2 to surveillance audits, recertification and the accreditation chain behind it all.

Certificates to ISO/IEC 27001 and related standards are the most common way to demonstrate that a management system is not merely documented but operated effectively. Behind every certificate stands a formalised procedure: a two-stage initial certification audit, annual surveillance audits and recertification in a three-year cycle, governed by ISO/IEC 17021-1. This evidence only becomes robust through the accreditation chain – in Germany, DAkkS monitors whether certification bodies operate competently and impartially. At the same time, the standard itself requires internal audits as an integral part of the management system; those who know the cycle and the typical nonconformities can go through audits in a plannable way and without surprises.

The Essentials at a Glance

01

Audit typology: first, second and third party

ISO 19011 defines an audit as a systematic, independent and documented process in which audit evidence is objectively evaluated against audit criteria; the guideline was published in its fourth edition in May 2026 (ISO 19011:2026, a technical revision of the 2018 edition, including expanded guidance on remote audits). Three constellations are distinguished: first-party audits (internal audits) are conducted by the organization itself or on its behalf, for example to verify conformity with the standard or to prepare for certification. Second-party audits are carried out by interested parties such as customers – typically as supplier audits within third-party risk management. Third-party audits are conducted by independent bodies, in particular certification bodies and authorities; these certification audits are governed not by ISO 19011 but by ISO/IEC 17021-1.

02

The certification process: Stage 1, Stage 2 and the 3-year cycle

Under ISO/IEC 17021-1, the initial certification audit takes place in two stages: Stage 1 assesses readiness for certification – documentation, scope, site-specific conditions and whether internal audits and the management review have already been planned and performed. Stage 2 then evaluates on site the implementation and effectiveness of the management system, including the controls from the Statement of Applicability (SoA). With the positive certification decision, the three-year certification cycle begins: surveillance audits take place at least once per calendar year – except in years with a recertification audit, with the first no later than twelve months after the certification decision – and examine selected areas on a sampling basis; in the third year, the recertification audit re-assesses the entire system before the certificate expires. Transitions to new versions of a standard follow their own rules – under IAF MD 26, the deadline for transitioning to ISO/IEC 27001:2022 ended on 31 October 2025, and older certificates to the 2013 edition have been invalid since then.

03

The accreditation chain: who audits the auditors?

For a certificate to carry weight, the issuing certification body must itself be overseen. In Germany, this is the task of DAkkS as the sole national accreditation body, based on Regulation (EC) No 765/2008 and the German Accreditation Body Act (AkkStelleG); DAkkS itself operates in accordance with ISO/IEC 17011. Certification bodies for management systems are accredited to ISO/IEC 17021-1; for ISMS certifications, the requirements of ISO/IEC 27006-1:2024 apply in addition – including those on auditor competence and minimum audit time – whose transition period for certification bodies ended on 31 March 2026. For clients this means: the accreditation symbol should be visible on the certificate – a non-accredited certificate carries considerably less evidential weight.

04

Internal audits: mandatory under Clause 9.2

In Clause 9.2, ISO/IEC 27001:2022 requires internal audits at planned intervals: they are intended to show whether the ISMS conforms to the organization's own requirements and to the requirements of the standard, and whether it is effectively implemented and maintained (9.2.1). Clause 9.2.2 requires an audit programme for this purpose, covering frequency, methods, responsibilities and reporting lines, which takes into account the importance of the processes concerned and the results of previous audits. The standard does not prescribe a fixed frequency; auditors must be selected in a way that preserves objectivity and impartiality – internal audits can therefore also be performed by external third parties on the organization's behalf. The results must be reported to the relevant level of management and retained as documented information; external auditors examine precisely this process in Stage 1 and again in every surveillance audit.

05

Audit preparation: from gap assessment to evidence package

Solid preparation starts with a cleanly delimited scope and a gap analysis against the requirements of the standard and the control catalogue. This is followed by implementing the open measures and building up audit-ready evidence: risk assessment and risk treatment plan, Statement of Applicability, and operational records, for example on access reviews, training and security incidents. Before Stage 2, at least one complete internal audit cycle and one management review should be finished, because it is precisely this maturity that the auditor already evaluates in Stage 1; “Areas of Concern” identified there can be classified as nonconformities in Stage 2. It has proven effective to generate evidence where the work is actually done – documentation compiled retroactively shortly before the audit is regularly noticed in Stage 2.

06

Common nonconformities and how to handle them

Certification auditors classify findings as major nonconformities – where the ability of the management system to achieve its intended results is in question – or as minor nonconformities; in addition, there are observations and opportunities for improvement. Recurring areas of findings in ISMS audits are gaps between documented processes and actual practice, a risk assessment without a traceable link to the Statement of Applicability, internal audits that do not cover the entire scope, incomplete management reviews, and corrective actions that are not followed up. Major nonconformities must be demonstrably closed before the certification decision; if the certification body cannot verify the corrections within six months of the end of Stage 2, ISO/IEC 17021-1 requires another Stage 2 audit. What matters is a systematic approach: root cause analysis, corrective action and verification of effectiveness instead of one-off symptom fixes.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2015

ISO/IEC 17021-1:2015 – Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements

Governs the two-stage initial certification audit, annual surveillance audits, recertification in the three-year cycle and the six-month rule for major nonconformities.

ISO/IEC · 2024

ISO/IEC 27006-1:2024 – Information security, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General

ISMS-specific additional requirements for certification bodies, including auditor competence and minimum audit time; the transition period under IAF MD 29:2024 ended on 31 March 2026.

ISO · 2026

ISO 19011:2026 – Guidelines for auditing management systems

Guidelines for first- and second-party audits, including audit principles and the definition of an audit; fourth edition (May 2026) as a technical revision of the 2018 edition.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Clause 9.2 (9.2.1/9.2.2) requires internal audits at planned intervals, including an audit programme, objective auditor selection and reporting obligations.

International Accreditation Forum (IAF) · 2023

IAF MD 26:2023 – Transition Requirements for ISO/IEC 27001:2022 (Issue 2)

Mandatory transition requirements for ISO/IEC 27001:2022; certificates to the 2013 edition lost their validity on 31 October 2025.

Deutsche Akkreditierungsstelle GmbH (DAkkS) · 2026

Rechtliche Grundlagen der DAkkS (dakks.de)

Germany's sole national accreditation body, based on Regulation (EC) No 765/2008 and the AkkStelleG; operates in accordance with ISO/IEC 17011.

Preparing your next audit in a structured way?

We support you with gap analyses, internal audits under Clause 9.2 and guidance through Stage 1 and Stage 2 – get in touch for a no-obligation initial consultation.