Glossary

Stage 2 audit

A stage 2 audit is the certification audit proper in ISO 27001: the auditor tests whether your ISMS and its applicable Annex A controls actually operate as documented — through evidence sampling and interviews — and, if no major nonconformities surface, recommends you for certification.
Assemble Your GRC Team
Last updated July 26, 2026