Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

Preparing for an ISO 27001 Audit (Stage 1 and Stage 2)

Getting certified to ISO 27001 means passing a two-stage certification audit with an accredited certification body, preceded by your own internal audit, and followed by annual surveillance audits. Here’s how the process works and how to prepare.

Auditor interviewing a client during a review
ISO 27001 certification lasts three years, with annual surveillance audits and a full recertification audit at the end of the cycle.

Start with your own internal audit

Before the certification body arrives, ISO 27001 requires you to run your own internal audit (clause 9.2) across the whole system, followed by a management review. This is your dress rehearsal. An independent internal audit finds the gaps before the external auditor does, which is the single best way to avoid surprises at certification.

Stage 1: the readiness review

Stage 1 is mostly a documentation review. The auditor checks that your ISMS is designed correctly: your scope, information security policy, risk assessment and treatment, Statement of Applicability, and evidence that internal audit and management review have happened. They’re confirming you’re ready for Stage 2 and flagging anything that needs fixing first.

Stage 2: the implementation audit

Stage 2 is the main event. The auditor tests whether your system is actually implemented and effective, not just documented. They’ll sample records, interview staff, and check that your selected controls are operating in practice. Any gaps are raised as nonconformities (minor or major), which you close out before the certificate is issued.

Surveillance and recertification

Certification lasts three years, with annual surveillance audits to confirm you’re maintaining the system, and a full recertification audit at the end of the cycle. Keeping your internal audits, management reviews and records current through the year is what keeps surveillance audits painless.

How to prepare, and common nonconformities

The issues that most often trip organisations up are a Statement of Applicability that doesn’t match reality, risk assessments that aren’t kept up to date, missing or superficial internal audits, and controls that exist on paper but generate no records. Prepare by making sure every selected control produces evidence, your internal audit covers the whole system, and your management review is genuine rather than a formality. A gap analysis beforehand is the cheapest way to find these issues early.

Frequently asked questions

How long does ISO 27001 certification take?

For most small to mid-sized organisations, three to six months from starting the system to passing Stage 2, depending on how much is already in place. See our cost and timeline guide for details.

Who can certify us?

An accredited certification body. We’re independent of the certifier, so we prepare you for the audit and can recommend appropriately accredited bodies, but we don’t mark our own homework.

Related reading

  • ISO 27001 requirements: a practical checklist
  • ISO 27001 controls explained (Annex A)
  • ISO 27001 certification cost and timeline in Australia

Speak with an experienced ISO auditor

Preparing for an ISO 27001 audit? Email hello@streamline.business or call us:

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990
General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Manager reviewing a budget spreadsheet
    ISO 27001 Certification Cost & Timeline in Australia…
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…
  • Internal auditor working through an ISO audit checklist and records at an office desk
    Independent ISO Internal Audit Services Australia…

Filed Under: Articles Tagged With: #auditing, #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire