Book an Appointment

Audits & Certifications

How ISO certifications actually work: from audit typology through Stage 1 and Stage 2 to surveillance audits, recertification and the accreditation chain behind it all.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

2stages in the initial certification audit under ISO/IEC 17021-1
3years in the certification cycle up to the recertification audit
12months after the certification decision — the latest point for the first surveillance audit
6months after Stage 2 to verify corrections — otherwise another Stage 2 audit is required

Certificates to ISO/IEC 27001 and related standards are the most common way to demonstrate that a management system is not merely documented but operated effectively. Behind every certificate stands a formalised procedure: a two-stage initial certification audit, annual surveillance audits and recertification in a three-year cycle, governed by ISO/IEC 17021-1. This evidence only becomes robust through the accreditation chain – in Germany, DAkkS monitors whether certification bodies operate competently and impartially. At the same time, the standard itself requires internal audits as an integral part of the management system; those who know the cycle and the typical nonconformities can go through audits in a plannable way and without surprises.

Milestones in the standards landscape

Three key dates around standard transitions and the audit guideline — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Audit typology

Three constellations under ISO 19011 — who audits whom, and which standard applies.

Internal audits
  • Conducted by the organization itself or on its behalf.
  • Typical purposes: verifying conformity with the standard or preparing for certification.
  • The benchmark is ISO 19011 — published in its fourth edition in May 2026.
ISO 19011ConformityRemote audits

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2015

ISO/IEC 17021-1:2015 – Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements

Governs the two-stage initial certification audit, annual surveillance audits, recertification in the three-year cycle and the six-month rule for major nonconformities.

ISO/IEC · 2024

ISO/IEC 27006-1:2024 – Information security, cybersecurity and privacy protection — Requirements for bodies providing audit and certification of information security management systems — Part 1: General

ISMS-specific additional requirements for certification bodies, including auditor competence and minimum audit time; the transition period under IAF MD 29:2024 ended on 31 March 2026.

ISO · 2026

ISO 19011:2026 – Guidelines for auditing management systems

Guidelines for first- and second-party audits, including audit principles and the definition of an audit; fourth edition (May 2026) as a technical revision of the 2018 edition.

ISO/IEC · 2022

ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Clause 9.2 (9.2.1/9.2.2) requires internal audits at planned intervals, including an audit programme, objective auditor selection and reporting obligations.

International Accreditation Forum (IAF) · 2023

IAF MD 26:2023 – Transition Requirements for ISO/IEC 27001:2022 (Issue 2)

Mandatory transition requirements for ISO/IEC 27001:2022; certificates to the 2013 edition lost their validity on 31 October 2025.

Deutsche Akkreditierungsstelle GmbH (DAkkS) · 2026

Rechtliche Grundlagen der DAkkS (dakks.de)

Germany's sole national accreditation body, based on Regulation (EC) No 765/2008 and the AkkStelleG; operates in accordance with ISO/IEC 17011.

Preparing your next audit in a structured way?

We support you with gap analyses, internal audits under Clause 9.2 and guidance through Stage 1 and Stage 2 – get in touch for a no-obligation initial consultation.