Stage 1 is a design review, usually conducted remotely. The auditor reads your ISMS documentation — scope statement, information security policy, risk assessment and treatment methodology, Statement of Applicability, and the records ISO 27001 mandates, like internal audit results and management review minutes. They’re answering one question: is this management system designed well enough that a full certification audit makes sense?
Auditors use stage 1 to surface problems while they’re still cheap to fix. The output is typically a short report of areas of concern — gaps that would harden into findings if they’re still present at stage 2. A thin risk assessment, an internal audit that never happened, or a scope statement that doesn’t match how the company actually operates are the classic flags. Treat the report as a punch list; the interval before stage 2 exists precisely so you can close it.
Book stage 1 once the ISMS has genuinely operated, not the day the last policy is signed — the auditor wants records proving the management loop has turned at least once. Most startups sequence a readiness push, stage 1, a few weeks of remediation, then stage 2. The full sequence, with what to have ready at each step, is laid out in ISO 27001 for startups.