# How to Prepare for an ISO 27001 Audit | Secureframe

> Learn how to complete a risk assessment, undergo an internal audit, collect evidence for your auditor, and more.

canonical: https://secureframe.com/hub/iso-27001/preparation

If you’re just getting started, the process of getting ready for ISO 27001 certification can be overwhelming.  

Completing a risk assessment, building your ISMS, writing policies and implementing controls — it’s difficult to know where to start, and little practical guidance is available for those pursuing ISO 27001 certification for the first time. 

We’ve created this section to help you understand best practices so you go into your ISO 27001 audit confidently, and save time and effort along the way. 

Everything in this section reflects the current ISO/IEC 27001:2022 standard, which fully replaced the 2013 edition when the transition period closed in October 2025.

## Intermediate: I’m preparing for an audit

**So you’re in prep mode for your first ISO 27001 certification. **

Completing a series of ISO 27001 audits is a major project that involves collaboration across your entire organization, from your executive leadership to your newest hire. Knowing what to expect can help you prepare for a successful audit, making it easier to manage the entire process and set expectations with internal stakeholders. 

Here's what you need to know. 

![](https://images.prismic.io/secureframe-com/5cacca27-9931-4aa5-9e34-c0d74d3626ae_blog-modal-header.png?auto=compress,format)

## What happens during ISO 27001 certification audits?

Once you’ve finished preparing your ISO 27001 documentation and evidence and have completed the internal audit, the Stage 1 audit begins. During this documentation review, the ISO 27001 auditor will go over your ISMS documentation. This includes any policies and processes you’ve established to promote information security across your organization. 

Once the Stage 1 audit is complete, a Stage 2 audit will begin. During this phase, the auditor will conduct a detailed assessment of your organization’s controls and business processes. 

Types of evidence your auditor might request include: 

- Asset inventories
- Risk and change management policies
- Equipment maintenance records
- System backup logs
- Code of conduct and ethics policies
- Business continuity and incident response plans

It’s likely your auditor will have follow-up questions and/or want to interview members of your team about specific processes or controls. They may also request additional documentation as evidence.

At the end of the audit, If the auditor determines you’re in compliance with ISMS and Annex A requirements, you will be issued ISO 27001 certification. This certification is valid for three years. 

## How to prepare for an ISO 27001 certification audit

Preparing for an ISO 27001 audit is less about scrambling before assessment day and more about building a repeatable, well-documented process over time. From defining scope and documenting controls to collecting evidence and validating implementation, each step plays a role in showing auditors that your information security management system is not only designed well, but operating as intended.

### Conducting a risk assessment

Risk assessments are often one of the first steps organizations take on their path to certification. As soon as you’ve identified which information assets to include in the ISMS scope, the very next step is to identify the risks to those assets. A thorough risk assessment arms you with the knowledge you need to build a secure ISMS that meets certification requirements. 

ISO 27001 risk assessment requirements include:

- Establishing criteria for evaluating information security risk 
- Identifying risks for all of the information assets within scope of the ISMS 
- Assigning owners for each risk
- Creating a repeatable, consistent risk assessment process

Secureframe’s platform approaches the risk assessment portion of ISO 27001 certification by integrating with your tech stack and infrastructure (such as your Cloud Service Provider), and first assessing your controls, identifying any failing controls or gaps in your compliance posture. The risk assessment is still an essential step in ISO 27001 compliance but can be completed after testing the controls your organization already has in place to quickly pinpoint and prioritize unresolved risks. 

### Preparing ISO 27001 documentation

Preparing required documents is a major part of demonstrating ISO 27001 compliance to your auditor. 

Everything related to your ISMS needs to be documented, and documents must be kept up-to-date and organized. Policies and processes need to be regularly reviewed, updated, versioned, and approved, and must be accessible to the appropriate teams. 

The list of required ISO 27001 documentation can span dozens of items. Some of the essential compliance documents include:

- [ISMS Scope Statement](https://secureframe.com/compliance-resources/iso-27001-scope-statement-template) 
- [Information Security Policy](https://secureframe.com/blog/iso-27001-information-security-policy)
- [Statement of Applicability](https://secureframe.com/blog/iso-27001-statement-of-applicability)
- [Risk Assessment](https://secureframe.com/hub/iso-27001/risk-assessment) and [Treatment Plan](https://secureframe.com/compliance-resources/risk-treatment-plan-template) 
- [Asset Inventory](https://secureframe.com/blog/it-asset-management)
- [Business Continuity Plan](https://secureframe.com/hub/grc/business-continuity-plan)
- [Access Control Policy](https://secureframe.com/blog/access-control-policy) 
- Internal Audit Reports and Management Reviews
- Incident Logs

### Choosing an ISO 27001 auditor

Only a certified auditor can perform an ISO 27001 audit, and only a certification body can issue your company a certification. Find an [accredited firm](https://secureframe.com/hub/iso-27001/audit-firms) that’s worked with companies like yours. Discuss the process and timeline for certification so you know when an auditor will be on-site and what to expect. 

## Streamline your audit prep with compliance automation 

[Compliance automation software](https://secureframe.com/hub/iso-27001/manual-vs-automated) can cut out hundreds of hours of legwork when you’re preparing for an ISO 27001 audit. Secureframe’s platform integrates with your tech stack and infrastructure to quickly assess your ISO 27001 compliance readiness, streamlining the process significantly. Here’s how we approach framework compliance: 

- Framework requirements represent the compliance obligations that organizations must meet
- Controls serve as the means by which organizations meet those requirements
- Tests provide evidence that your organization is adhering to those requirements 

Through the hundreds of integrations, Secureframe can assess the controls you already have (or do not have) in place, test those controls to automatically gather evidence that controls meet ISO 27001 requirements, and flag any gaps in your compliance posture so you can quickly see what still needs to be done before an audit. 

![](https://images.prismic.io/secureframe-com/910f0d2d-45be-43c7-a42c-e7e30604d397_Controls-Hero%403x.png?auto=format,compress)

With this clear, up-to-date picture of your control status, you can then complete a risk assessment to close any remaining gaps and further strengthen your security posture. Our platform continuously monitors your controls to ensure all tests are passing, identify failing tests, and provide remediation guidance, making it easier to maintain compliance for your annual ISO audits. 

This continuous monitoring also helps you meet Clause 10 requirements for continuous improvement. With detailed, real-time visibility into your ISMS, you can demonstrate a proactive approach to tracking performance, identifying vulnerabilities, and strengthening your information security practices.
