Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is the ISO 27001 Stage 1 Audit?

The ISO 27001 Stage 1 Audit is the first part of the two-stage external ISO certification process. The Stage 1 Audit consists of an extensive documentation review in which an external ISO 27001 auditor reviews an organization’s policies and procedures to ensure they meet the requirements of the ISO standard and the organization’s Information Security Management System (ISMS). After completing the Stage 1 audit, the auditor will provide feedback outlining whether the organization is ready to move to the Stage 2 audit

If the auditor determines the ISMS fails to meet the requirements of the ISO 27001 standard, the auditor will typically outline areas of concern—referred to as nonconformities—and will require corrective action or corrective action plans before proceeding to the Stage 2 audit.

An ISO 27001 certification is valid for three years; however, ISO requires surveillance audits be performed each year to ensure the ISMS and its implemented controls continue to operate effectively. Every 12 months during the three-year cycle, an organization’s ISMS must undergo an external audit, where an auditor will assess portions of the ISMS.

{{cta_withimage2="/cta-modules"}}

Additional resources you might like:

ISO 27001
Blog
The Australian startups guide to ISO 27001

Understand the benefits, steps to certification, and how Vanta simplifies the journey.

SOC 2
Blog
What is SOC 2 and why Australian startups need it

SOC 2 for Aussie startups.

Compliance
Events
3 Steps to Kick Off First-Time Compliance in 2026

Join us for a session on how to make compliance work at your pace, without slowing momentum, stalling deals, or putting revenue at risk.

Additional resources you might like:

ISO 27001
Blog
The Australian startups guide to ISO 27001

Understand the benefits, steps to certification, and how Vanta simplifies the journey.

SOC 2
Blog
What is SOC 2 and why Australian startups need it

SOC 2 for Aussie startups.

Compliance
Events
3 Steps to Kick Off First-Time Compliance in 2026

Join us for a session on how to make compliance work at your pace, without slowing momentum, stalling deals, or putting revenue at risk.

Vendor Risk Management
Events
Office Hour: Transform how you manage third-party and internal risk

Join us for a live, interactive Office Hour as we dive deeper into Vanta’s vision for unified, continuous, AI-powered risk management, and what it means for your business today.

Compliance
Events
Live Demo: Accelerate Security and Compliance Workflows with AI

Join us for a live demo to see how Vanta AI streamlines your security and compliance workflows.

SOC 2
Events
Live Demo: Automating SOC 2, ISO 27001 & More with Vanta

Join our demo to see how leading startups and security teams are automating compliance across 35+ frameworks, including SOC 2, ISO 27001, and HIPAA.

Compliance
Events
Navigating Fintech Compliance in an Evolving Regulatory Landscape

Watch on-demand to hear from Vanta and Codat on how to future-proof your fintech’s compliance strategy and transform it into a competitive advantage. 

Comparisons and reviews
Blog
Why enterprise leaders choose Vanta over Drata to prove and manage trust

Learn how Vanta is uniquely equipped to meet the needs of large, complex organizations.

GRC
Events
The New Growth Playbook: How GRC Unlocks Trust and Speed at Scale

Watch this on-demand webinar to hear Vanta and Sensiba discuss how to evolve your approach to risk and compliance — turning it from a blocker into a business accelerator.