ISO 27001 Surveillance Audits: What Years 2 and 3 Actually Take
An accredited ISO 27001 certificate is valid for three years, and your certification body comes back every year of them. Under ISO/IEC 17021-1 the first surveillance audit has to be conducted within 12 months of the certification decision date, a second surveillance follows in year two, and a full recertification audit happens before the certificate expires. The effort is not a rounding error. The planning convention certification bodies work to across accredited schemes puts each surveillance audit at approximately one third of the initial certification audit time, and recertification at approximately two thirds of what an initial audit would take if it were run at recertification. Those proportions are written down in IAF MD 5:2023 clauses 5 and 6; note that IAF MD 5 is the audit-time document for quality, environmental and occupational health and safety schemes rather than for information security, so treat these as planning ratios and ask your own body for the days it derived. Surveillance audits rarely catch out programs that kept operating; they catch programs that went quiet the week the certificate arrived.
Below: the cycle mechanics, what each visit actually samples, how a certificate gets suspended or withdrawn, and how to plan years two and three so they are boring.
Key takeaways
- The certificate runs on a three-year cycle: surveillance in years one and two, recertification in year three, then the cycle restarts.
- The first surveillance audit must happen within 12 months of the certification decision, per ISO/IEC 17021-1. That date is fixed by your certification decision, not by your convenience.
- Plan audit effort at roughly one third of initial audit time for each surveillance and roughly two thirds for recertification, then confirm the derived days with your certification body. Budget audit days, not a flat annual line.
- Surveillance is a sample, not a re-audit, but clause 9.2 internal audit, clause 9.3 management review and open nonconformities are checked every single time.
- Missing a surveillance audit is the most common route to suspension, and a suspended certificate is worse commercially than a lapsed one, because customers can see it.
The three-year cycle, precisely
Your certification decision date is the anchor for everything that follows.
Year one surveillance. ISO/IEC 17021-1 requires the first surveillance audit following initial certification to be conducted within 12 months of the certification decision date. Note the anchor: not twelve months after Stage 2 finished, and not twelve months after the certificate was printed. If remediation delayed your decision, your surveillance date moved with it.
Year two surveillance. A second surveillance, on the annual cadence your certification body schedules.
Year three recertification. A full audit of the whole management system, planned so the certification decision lands before the current certificate expires. This is not a surveillance visit with a different name: recertification evaluates continued conformity and effectiveness of the ISMS in its entirety, including its performance over the whole cycle.
Then the cycle starts again, with a new certificate and a new decision date.
One scheduling trap. If recertification slips past expiry, you are not in a grace period by right; certification bodies have documented rules about what happens, and the outcome can be a lapsed certificate and a return to initial certification, which means Stage 1 and Stage 2 again. Book recertification early in the final year, not late.
What a surveillance audit actually samples
Surveillance is deliberately narrower than the certification audit. It is a sample, and the sample is not random.
Every visit, without exception, the auditor looks at the management-system spine: your internal audit under clause 9.2 and whether it covered what it claimed, your management review under clause 9.3 and whether top management actually participated, your handling of nonconformities and corrective actions under clause 10, and the status of anything raised at the previous audit. If you carried a minor nonconformity out of Stage 2, its closure is on the agenda before anything else.
Then the auditor samples a rotating slice of the control set, so that across the three-year cycle the whole ISMS gets covered. They will also follow anything that changed: new products, new sites, acquisitions, significant headcount growth, a change of cloud provider, a security incident. Changes are the highest-yield place to look, and auditors know it.
They also verify use of the certification mark and references to your certified status. Marketing that overstates the scope of the certificate is a surprisingly common finding, and an easy one to avoid.
Budgeting years two and three honestly
We do not publish a dollar figure for any of this, for the reason set out in our ISO 27001 and SOC 2 comparison: the ranges that circulate are wide enough to mislead, and the honest input is your own audit-day count. Use our budget planner for money. Use this arithmetic for effort.
Take the total audit days your certification body derived for initial certification under ISO/IEC 27006-1. Call it D. Then, as an approximation good enough for planning: each surveillance audit is about D divided by three, and recertification is about two thirds of D. One caveat on that last number. The two-thirds proportion is measured against an initial audit priced at the time of recertification, not against the audit you actually paid for in year zero, so if you have grown or widened scope since certification, recertification is two thirds of a larger D than the one on your original quote.
That is auditor time. Your internal time behaves differently and is the part teams underestimate. The internal audit and management review are annual obligations that do not shrink with the surveillance sample, and evidence collection is continuous rather than seasonal. Companies that run compliance as an annual sprint pay for it here, because a surveillance auditor sampling a rotating slice will land on the quarter you stopped doing access reviews.
The year-two drop-off, and how to see it coming
There is a pattern worth naming because it is close to universal. Certification is a project, with a deadline, an owner and executive attention. The month after the certificate arrives, all three evaporate. Access reviews slip a quarter, the risk assessment is not revisited, supplier assessments stop happening for new vendors, and the internal audit gets booked three weeks before the surveillance visit instead of running as a programme.
None of that is visible from inside, because nothing breaks. The controls that lapsed were the periodic ones, and a periodic control that has not run yet looks identical to a periodic control that will never run again.
Three cheap instruments make it visible before your auditor does. First, put every periodic control on a calendar with a named owner, and review the calendar at the management review under clause 9.3 rather than reviewing a narrative. Second, treat the internal audit programme as a programme: audit a slice each quarter rather than everything in one week, which also spreads the effort and produces findings early enough to fix. Third, log changes as they happen, because your surveillance auditor will sample against exactly the changes you did not write down. New product, new region, new subprocessor, new office, significant headcount growth: each is both a sampling target and a possible scope change your certification body should hear about early.
The companies that find surveillance audits uneventful are not the ones with the best controls. They are the ones whose controls kept running on a schedule somebody owned.
How certificates get suspended or withdrawn
Certification bodies operate documented rules for suspension and withdrawal under ISO/IEC 17021-1, and while the specific timeframes vary by body, the triggers are consistent.
Missing or refusing a surveillance audit. The most common cause, and the most avoidable. Suspension for a missed audit is administrative, not a judgment on your security.
Failing to close a major nonconformity in the time allowed. Certification bodies publish a limit for correction and verification of majors, commonly measured in weeks to a few months. Miss it and suspension follows.
Persistent failure of the ISMS to meet requirements, including the management-system clauses. A pattern of the same finding at three consecutive audits is a systemic failure even if each instance looked minor.
Misuse of the certificate or mark, such as claiming a scope you do not hold.
Suspension is public in the sense that matters: an accredited certificate's status is verifiable, and buyers increasingly check. Withdrawal is worse and generally follows an unresolved suspension. Both are recoverable, and both are far more expensive than the surveillance audit you skipped.
When you should not buy ongoing support
We sell continuous compliance support, so weigh this section accordingly. Three situations where you should not.
Your ISMS runs itself and nothing changed. A stable company, a stable scope, a security lead who owns clause 9 and a year with no acquisitions does not need a retained consultancy to pass a surveillance audit. Book the internal audit and go.
You are buying support instead of ownership. If the reason surveillance feels risky is that nobody internal owns the ISMS, outsourced support treats the symptom. The right first step is naming an owner with authority, which our piece on who owns compliance works through, and only then deciding what to outsource around them.
The certificate no longer matches your commercial reality. If the customers who demanded ISO 27001 are gone and your pipeline now asks for something else, the honest analysis is whether to keep the certificate at all rather than how to support it. Letting a certificate lapse deliberately is a legitimate decision. Paying to maintain one nobody asks for is not.
Where Top Floor fits
The recurring work that actually determines a surveillance outcome is clause 9: an internal audit with genuine independence, and a management review that produces decisions rather than minutes. The independence constraint is why we keep that in audit and assurance rather than bundling it with build work, and our piece on outsourcing the ISO 27001 internal audit explains the constraint in detail. Where the gap is continuous evidence and program cadence between audits, that is compliance-as-a-service, and where scope or the risk assessment needs rework before a recertification year, that is ISO 27001 work.
How to decide this week
1. Find your certification decision date and count 12 months. That is your surveillance deadline, and it is probably earlier than you think.
2. List every nonconformity from your last audit and check each one is closed with evidence, not just with a plan.
3. Diary the internal audit and the management review for this cycle now, with named people. These are the two items surveillance auditors check every time.
4. Write down what changed since the last audit: sites, products, providers, headcount, incidents. That list is your auditor's sampling plan; get ahead of it.
5. If recertification falls in the next twelve months, book it now and work backwards from the decision date, not the expiry date.
Frequently asked questions
Does an ISO 27001 certificate expire?
Yes. An accredited certificate is issued for a three-year cycle and expires at the end of it unless a recertification audit is completed and a new certification decision is made in time. During those three years the certificate also depends on annual surveillance audits: ISO/IEC 17021-1 requires the first to be conducted within 12 months of the certification decision date, and missing a surveillance audit can lead to suspension well before the expiry date arrives.
What happens if you fail a surveillance audit?
Surveillance audits do not have a pass mark; they produce findings. Minor nonconformities are handled with a correction and corrective action plan that the certification body verifies, usually at the next visit, and the certificate continues. A major nonconformity starts a clock: the body sets a limit for correction and verification, commonly weeks to a few months, and failure to close it within that window leads to suspension of the certificate. Suspension is recoverable, but the certificate is not usable with customers while it lasts.
How much shorter is a surveillance audit than the original?
Roughly a third of the initial certification audit time. That is the planning convention across accredited management system schemes: approximately one third of the initial certification audit time for each surveillance visit, and approximately two thirds for recertification. So if your initial certification took nine audit days across Stage 1 and Stage 2, plan on about three days for each surveillance visit and about six for recertification, before any adjustment for changes in your size or scope. Your certification body derives the actual days under ISO/IEC 27006-1, so ask it for the number rather than budgeting off the ratio alone.
Is recertification the same as the first certification audit?
No, and the difference is mostly Stage 1. Recertification evaluates the continued conformity and effectiveness of the whole management system, including its performance across the completed cycle, and it carries about two thirds of the audit time an initial certification audit would take at that point, which is not the same as two thirds of the days on your original quote. It does not normally repeat a separate Stage 1, because the auditor already knows your documentation. If your scope, organization or ISMS has changed significantly since certification, the certification body can add a Stage 1 style review back in, which is a good reason to raise big changes with them early rather than at the audit.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.