How to Prepare for Your First ISO 27001 Audit
Most ISO 27001 audit failures are not caused by missing technical controls — they are caused by inadequate documentation and evidence. Here is a practical 12-week preparation timeline.
ISO 27001 certification is one of the most credible signals of security maturity an organisation can demonstrate. It is also one of the most commonly delayed — not because organisations lack security controls, but because they underestimate the documentation and evidence requirements.
This guide provides a practical 12-week preparation timeline for organisations approaching their first ISO 27001 Stage 1 and Stage 2 audits.
What the Audit Process Looks Like
ISO 27001 certification involves two audit stages conducted by an accredited certification body (CB):
Stage 1 (Documentation Review) — The auditor reviews your ISMS documentation: policies, procedures, risk assessment, Statement of Applicability (SoA), and supporting artefacts. Stage 1 is typically a one to two day engagement. Its purpose is to verify that your documentation is sufficiently mature to justify a Stage 2 audit.
Stage 2 (Implementation Audit) — The auditor tests whether your documented controls are actually implemented and operating effectively. This involves interviewing staff, reviewing evidence artefacts, and testing a sample of controls. Stage 2 typically runs two to four days depending on your organisation's size.
Between Stage 1 and Stage 2, you should expect to address any non-conformities identified in the Stage 1 report. Scheduling these stages two to four weeks apart is common.
The 12-Week Preparation Timeline
Weeks 1–3: Gap Analysis and Scope Definition
Start with a structured gap analysis against the ISO 27001:2022 standard. Map your existing policies and controls against Clauses 4–10 and Annex A, and identify what is missing or insufficiently documented.
Simultaneously, define your ISMS scope. The scope statement defines which parts of the organisation, which information assets, and which locations are covered by your ISMS. A tightly defined scope is easier to certify; too narrow a scope may not satisfy auditors or customers.
Deliverable: a gap register, a risk register, and a scope statement.
Weeks 4–6: Risk Assessment and Treatment
ISO 27001 is fundamentally a risk management standard. You need a documented risk assessment methodology, a risk register covering your in-scope assets, and a risk treatment plan that maps each significant risk to a treatment decision and an Annex A control.
The risk assessment does not need to be complex. A 5×5 likelihood-impact matrix covering 15–30 risks is sufficient for most SMBs. What auditors look for is evidence that the assessment is systematic, covers the key assets in scope, and has management sign-off.
Deliverable: risk assessment methodology, risk register, risk treatment plan, management sign-off.
Weeks 6–9: Policy and Documentation Sprint
Most SMBs discover in their gap analysis that they are missing several mandatory policy documents. At minimum, ISO 27001 requires:
- Information security policy
- Acceptable use policy
- Access control policy
- Password policy
- Incident response policy
- Business continuity plan
- Supplier security policy
For each Annex A control included in your SoA, you need either a documented procedure or a documented justification for why it does not apply to your organisation.
This documentation sprint is typically the most labour-intensive part of preparation. Build in time for review cycles — auditors will ask who reviewed and approved each document.
Deliverable: complete policy set, Statement of Applicability.
Weeks 9–11: Internal Audit and Management Review
Before your Stage 1 audit, you must conduct an internal audit of your ISMS and hold a management review meeting. These are not formalities — they are mandatory requirements of the standard.
The internal audit tests whether the ISMS conforms to the requirements of the standard and is effectively implemented. Document your audit methodology, findings, and any corrective actions.
The management review is a formal meeting at which senior management reviews the ISMS's performance. Document the agenda, the attendees, and the decisions made.
Deliverable: internal audit report, management review minutes.
Weeks 11–12: Evidence Collection
Your Stage 2 auditor will request evidence of control operation. This includes:
- Access control reviews
- Patch management records
- Security training completion records
- Supplier assessments
- Incident logs (including incidents with no significant findings)
- Change management records
Organise this evidence into a structured evidence pack before Stage 2. Knowing where your evidence is reduces audit stress significantly.
Key Takeaways
- Stage 1 is a documentation review; Stage 2 tests whether controls are implemented. Both require preparation.
- The risk assessment and Statement of Applicability are the core of the ISMS — auditors will spend significant time on both.
- Internal audit and management review are mandatory pre-conditions for Stage 2.
- Evidence collection is the most time-sensitive task — start building your evidence pack early.
- Documentation gaps are more common audit findings than technical control gaps.
*Norman is Norman AI's AI Compliance Analyst. Norma runs your ISO 27001 gap analysis automatically and generates the policy documents you need to close gaps — so your 12-week preparation timeline starts with a clear picture of where you are. Start your free assessment at trynorma.com.*
See your compliance gaps in minutes
Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.
Get started free →