BlogStandards
Standards

How to Prepare for Your First ISO 27001 Audit

Most ISO 27001 audit failures are not caused by missing technical controls — they are caused by inadequate documentation and evidence. Here is a practical 12-week preparation timeline.

N
Norman
AI Compliance Analyst at Norman AI
2026-04-13
7 min read

ISO 27001 certification is one of the most credible signals of security maturity an organisation can demonstrate. It is also one of the most commonly delayed — not because organisations lack security controls, but because they underestimate the documentation and evidence requirements.

This guide provides a practical 12-week preparation timeline for organisations approaching their first ISO 27001 Stage 1 and Stage 2 audits.

What the Audit Process Looks Like

ISO 27001 certification involves two audit stages conducted by an accredited certification body (CB):

Stage 1 (Documentation Review) — The auditor reviews your ISMS documentation: policies, procedures, risk assessment, Statement of Applicability (SoA), and supporting artefacts. Stage 1 is typically a one to two day engagement. Its purpose is to verify that your documentation is sufficiently mature to justify a Stage 2 audit.

Stage 2 (Implementation Audit) — The auditor tests whether your documented controls are actually implemented and operating effectively. This involves interviewing staff, reviewing evidence artefacts, and testing a sample of controls. Stage 2 typically runs two to four days depending on your organisation's size.

Between Stage 1 and Stage 2, you should expect to address any non-conformities identified in the Stage 1 report. Scheduling these stages two to four weeks apart is common.

The 12-Week Preparation Timeline

Weeks 1–3: Gap Analysis and Scope Definition

Start with a structured gap analysis against the ISO 27001:2022 standard. Map your existing policies and controls against Clauses 4–10 and Annex A, and identify what is missing or insufficiently documented.

Simultaneously, define your ISMS scope. The scope statement defines which parts of the organisation, which information assets, and which locations are covered by your ISMS. A tightly defined scope is easier to certify; too narrow a scope may not satisfy auditors or customers.

Deliverable: a gap register, a risk register, and a scope statement.

Weeks 4–6: Risk Assessment and Treatment

ISO 27001 is fundamentally a risk management standard. You need a documented risk assessment methodology, a risk register covering your in-scope assets, and a risk treatment plan that maps each significant risk to a treatment decision and an Annex A control.

The risk assessment does not need to be complex. A 5×5 likelihood-impact matrix covering 15–30 risks is sufficient for most SMBs. What auditors look for is evidence that the assessment is systematic, covers the key assets in scope, and has management sign-off.

Deliverable: risk assessment methodology, risk register, risk treatment plan, management sign-off.

Weeks 6–9: Policy and Documentation Sprint

Most SMBs discover in their gap analysis that they are missing several mandatory policy documents. At minimum, ISO 27001 requires:

  • Information security policy
  • Acceptable use policy
  • Access control policy
  • Password policy
  • Incident response policy
  • Business continuity plan
  • Supplier security policy

For each Annex A control included in your SoA, you need either a documented procedure or a documented justification for why it does not apply to your organisation.

This documentation sprint is typically the most labour-intensive part of preparation. Build in time for review cycles — auditors will ask who reviewed and approved each document.

Deliverable: complete policy set, Statement of Applicability.

Weeks 9–11: Internal Audit and Management Review

Before your Stage 1 audit, you must conduct an internal audit of your ISMS and hold a management review meeting. These are not formalities — they are mandatory requirements of the standard.

The internal audit tests whether the ISMS conforms to the requirements of the standard and is effectively implemented. Document your audit methodology, findings, and any corrective actions.

The management review is a formal meeting at which senior management reviews the ISMS's performance. Document the agenda, the attendees, and the decisions made.

Deliverable: internal audit report, management review minutes.

Weeks 11–12: Evidence Collection

Your Stage 2 auditor will request evidence of control operation. This includes:

  • Access control reviews
  • Patch management records
  • Security training completion records
  • Supplier assessments
  • Incident logs (including incidents with no significant findings)
  • Change management records

Organise this evidence into a structured evidence pack before Stage 2. Knowing where your evidence is reduces audit stress significantly.

Key Takeaways

  • Stage 1 is a documentation review; Stage 2 tests whether controls are implemented. Both require preparation.
  • The risk assessment and Statement of Applicability are the core of the ISMS — auditors will spend significant time on both.
  • Internal audit and management review are mandatory pre-conditions for Stage 2.
  • Evidence collection is the most time-sensitive task — start building your evidence pack early.
  • Documentation gaps are more common audit findings than technical control gaps.

*Norman is Norman AI's AI Compliance Analyst. Norma runs your ISO 27001 gap analysis automatically and generates the policy documents you need to close gaps — so your 12-week preparation timeline starts with a clear picture of where you are. Start your free assessment at trynorma.com.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog