Where stage 1 asks whether the system is designed and documented, stage 2 asks whether it runs. The auditor moves from reading to verifying: pulling records, sampling evidence, and interviewing the people who own controls. A policy that exists satisfies stage 1; stage 2 wants the access reviews, incident tickets, and training completions that prove the policy is lived.
The engagement works through your Statement of Applicability and the ISO 27001 management clauses. Expect walkthroughs of onboarding and offboarding, change management, incident response, supplier reviews, and the management loop itself — internal audits, management review, corrective actions. Findings are classified as major or minor nonconformities; majors block certification until resolved, minors come with a corrective-action expectation.
Pass stage 2 and the auditor recommends certification; the certification body then issues a certificate that runs on a three-year cycle, with surveillance audits in between. The practical takeaway for first-timers: stage 2 is won months earlier, by operating the system long enough to generate real records. How startups build that operating runway is covered in ISO 27001 for startups.