Once your ISMS is operational, certification follows a fixed sequence: internal audit, management review, an external Stage 1 documentation audit, an external Stage 2 implementation audit, and a certification decision — typically 3–6 months end-to-end. Most delays occur not because the ISMS is weak, but because evidence isn't structured as auditors expect.
NorthGRC's platform keeps that evidence — control status, justifications, and audit trails — generated continuously rather than assembled under deadline pressure.
A "functioning ISMS" means policies are approved, risks are assessed, and controls are applied in daily operations. Certification is the independent confirmation that this system meets the requirements of ISO/IEC 27001. The sequence looks like this:
Each of these steps produces documentation that an auditor will request later. Compliance teams that treat internal audit and management review as separate, one-off exercises — rather than an ongoing cycle — are the ones scrambling in the weeks leading up to Stage 1.
NorthGRC's internal audit and nonconformity templates structure this evidence as it's produced, not retrofitted afterwards.
These two audits are often confused, but they test fundamentally different things.
| Stage 1 Audit | Stage 2 Audit | |
|---|---|---|
| Focus | Documentation completeness | Operational effectiveness |
| What's reviewed | ISMS scope, policies, risk assessment methodology, Statement of Applicability | Control implementation, records, staff awareness, evidence sampling |
| Typical duration |
1–2 days | 2–5 days, depending on scope and headcount |
| Common outcome | List of documentation gaps to close before Stage 2 | Certification decision, or minor/major nonconformities requiring correction |
| Who's involved |
ISMS owner, document custodians | Control owners across departments, not just the compliance team |
A Stage 1 finding usually means a document is missing, outdated, or inconsistent with what's actually happening — for example, a Statement of Applicability that references controls no longer relevant to your organisation's current scope.
A Stage 2 finding means the documented process and the observed practice don't match. Both are avoidable with continuous evidence generation rather than a pre-audit sprint.
Compliance leaders often assume audit readiness is about having every document in place. It's necessary, but not sufficient. Auditors also expect:
NorthGRC's Compliance module gives control owners a single, live view of implementation status, flagging overdue tasks, rejected documents, or controls marked "not implemented" long before an auditor would.
Across compliance teams preparing for ISO 27001, the same handful of gaps recur — often not because the underlying security practice is weak, but because the documentation hasn't kept pace with it.
| Gap | Why It Delay Certification |
|---|---|
| Outdated Statement of Applicability |
If control status hasn't been updated since the risk assessment was last revised, the SoA no longer reflects reality — a near-guaranteed Stage 1 finding. |
| Missing rationale for excluded controls | Marking a control "not applicable" without a documented justification is one of the most frequent nonconformities cited in ISO 27001 audits. |
| No internal audit before Stage 1 | Skipping the internal audit clause (9.2) removes your own early-warning system — issues surface for the first time in front of the certification body instead. |
| Management review treated as a checkbox | A management review meeting without documented inputs, decisions, and follow-up actions doesn't satisfy clause 9.3, even if the meeting happened. |
| Evidence scattered across shared drives | When evidence for a single control lives in three different folders (or three different people's inboxes), Stage 2 interviews expose inconsistencies fast. |
| ISMS still referencing the 2013 control set | Since the ISO 27001:2022 transition deadline passed on 31 October 2025, certificates and initial certifications are only issued against the 2022 edition's 93 Annex A controls — organisations still working from a 2013-structured ISMS need to remap before certification. |
None of these gaps requires rebuilding the ISMS. They require the documentation and the operational reality to stay in sync — which is precisely what breaks down when evidence is collected manually, close to a deadline.
NorthGRC's gap analysis view surfaces exactly these mismatches — overdue tasks, rejected documents, unimplemented controls — as they happen, rather than the week before Stage 1.
Certification isn't a finish line. Certificates are typically valid for three years, with annual surveillance audits checking that the ISMS is still operating as certified, followed by a full recertification audit at the end of the cycle. Organisations that treat the ISMS as "done" after certification often find surveillance audits harder than the original Stage 2 — because improvement activity has visibly stalled.
ISO 27001 certification volumes have grown sharply: the 2024 ISO Survey recorded 96,709 valid certificates worldwide, up from 36,362 in 2019 — reflecting how central information security assurance has become to procurement and contractual requirements, particularly in regulated sectors. That growth also means certification bodies are auditing more organisations against a tighter control set (93 Annex A controls across four themes, replacing the 2013 edition's 114 controls in fourteen domains), which raises the bar on documentation consistency during Stage 1 and Stage 2 reviews alike.
NorthGRC supports this ongoing cycle the same way it supports initial certification: by keeping the Statement of Applicability, risk register, and audit trail live year-round, so surveillance audits draw on the same continuously updated evidence rather than a fresh scramble every twelve months.
The gap between a functioning ISMS and a certified one is rarely about security maturity — it's about whether your evidence, documentation, and operational reality tell the same consistent story that an auditor can trace end-to-end. Internal audit, management review, Stage 1, Stage 2, and the certification decision each test a different piece of that story, and the most common gaps — outdated SoAs, undocumented exclusions, scattered evidence — are the ones a continuously maintained system prevents by design.
If you're preparing for certification, download How to Develop a Statement of Applicability — the exact document a Stage 1 auditor asks for first.
Most organisations move from internal audit through Stage 1, Stage 2, and certification decision in three to six months, depending on how much of that evidence is already structured versus scattered across manual documentation.
Stage 1 checks whether your documentation is complete and consistent enough to proceed. Stage 2 checks whether what's documented is actually happening in practice, through interviews and evidence sampling.
Yes — auditors issue minor or major nonconformities rather than an outright "fail." Minor nonconformities usually require a corrective action plan within an agreed timeframe; major nonconformities can delay certification until they're resolved and re-verified.
Yes — clause 9.2 requires it, and skipping it means your organisation has no early warning of the issues an external auditor will find first.
Annually, through surveillance audits, with a full recertification audit at the end of the three-year certification cycle.