Edition 2026.09 · Desk research from public vendor pages, last reviewed 29 September 2026

Lesson 8 of 10 · Track C · · Updated

The ISO 27001 certification audit, from stage 1 to surveillance

Short answer

ISO 27001 certification is granted by a certification body after an external audit. As general guidance, certification bodies commonly run the initial audit in two stages, a review of ISMS design and readiness followed by an audit of whether it works in practice, and then return for periodic surveillance audits. Confirm the exact plan and cycle with your certification body.

G-01

Who can certify you?

A certification body, not the platform vendor and not ISO itself. ISO publishes the standard but does not issue certificates. Buyers usually prefer a certification body that is accredited by a recognised accreditation body, so ask for the accreditation before you sign.

G-02

What happens in stage 1 and stage 2?

This is how certification bodies commonly describe the two stages; your certification body's audit plan is the reference. Stage 1 checks that the ISMS is designed and documented: scope, risk assessment, Statement of Applicability, policies, internal audit and management review. It tells you whether you are ready for stage 2. Stage 2 tests whether the ISMS operates as documented, by interviewing staff and sampling evidence for controls. Findings are graded, and certification bodies generally expect major nonconformities to be closed before they issue a certificate.

G-03

What happens after the certificate?

A certificate is not a one-off. Certification bodies commonly schedule surveillance audits between the initial certification and a later recertification; ask yours for the cycle and dates in writing. Each surveillance audit samples part of the ISMS, so the loop of risk review, internal audit and management review has to keep running.

G-04

How do platforms connect you to auditors?

The vendors on this site describe different routes. Scytale lists Built-In Audit with partner auditors and says it takes over full management of the audit process with your chosen auditor. Vanta describes access to a network of experienced auditors and a Vanta Audit product. Sprinto lists network auditor access and bring your own auditor on its Foundation plan. Secureframe lists access to its Audit Partner Network on Fundamentals. Drata lists auditors among its partners. We did not find an auditor route described on Scrut's pages.

G-05

What should you check about the auditor?

Check the certification body's accreditation, who will lead the audit and their experience with companies like yours, and how the auditor relates to the platform vendor. A partner auditor can make scheduling easier; it is still your job to be satisfied that the audit is rigorous. If you also plan SOC 2, note that SOC 2 reports are issued by licensed CPA firms under AICPA standards, and the AICPA has published guidance on business arrangements between CPA firms and SOC tool providers (AICPA Ethics Staff Insights, 13 April 2026).

G-06

How long does preparation take?

It depends on scope, existing controls and who does the work, and we do not publish timelines because vendors describe them in very different ways. The fixed points come from the standard: the ISMS needs a completed risk assessment, a Statement of Applicability, an internal audit and a management review, and certification bodies generally expect to see these, with enough operating history to sample, before the main audit. Plan backwards from the audit date, book the certification body early, and treat the internal audit as a rehearsal.