Skip to content
    August 25, 2026| Top Floor Team| 14 min read

    What Is an ISO 27001 Nonconformity? Major, Minor, and What Each Costs You

    A nonconformity is "non-fulfilment of a requirement." That is the whole definition in ISO/IEC 17021-1:2015 clause 3.11, the standard every accredited certification body works under, and ISO/IEC 27000:2018 defines conformity the same way from the other side, as "fulfilment of a requirement." Our glossary adds the working context: "A nonconformity is the non-fulfilment of a requirement of the standard or of the organization's own ISMS, raised by an auditor and graded as major or minor according to its severity and systemic reach." The contrarian point is about the grade. Major and minor are not measures of how dangerous the security gap was. ISO/IEC 17021-1 defines a major nonconformity as one "that affects the capability of the management system to achieve the intended results" and a minor as one "that does not affect the capability of the management system to achieve the intended results." The test is about the system, and that is why an ugly-looking technical lapse can be minor while a quiet pattern of small misses can be aggregated into a major.

    This article covers the definitions, how the grade is decided, what each grade obliges you and the certification body to do, the difference between correction and corrective action, and the questions about the clock that everyone asks and the standard deliberately does not answer.

    A note on sources. iso.org blocked every fetch during the writing of this piece. The ISO/IEC text quoted here comes from the standards' own front pages as republished in a distributor's preview PDF: ISO/IEC 17021-1:2015 clauses 1 to 6.2, which include the clause 3 definitions, and ISO/IEC 27000:2018 definitions 3.1 through 3.22. The clause 9.5.2 wording on certification decisions comes from the European co-operation for Accreditation's published Certification Committee answers, which quote it. Where the certification-body process is referred to by clause title only, that is because only the title was in the fetched text.

    Key takeaways

    • Nonconformity means "non-fulfilment of a requirement," and the requirement can be one the standard states or one your own ISMS states. Auditors test you against your own documents.
    • Major versus minor is one test: does the nonconformity affect "the capability of the management system to achieve the intended results." Severity of the lapse is not the criterion.
    • Several minors "associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity." Repeated small findings in one area are the pattern to watch.
    • A major must be corrected and the correction verified before a certification decision; a minor needs an accepted plan, verified at a later audit. The standard defines two grades, and a finding that is a nonconformity must never be recorded as an opportunity for improvement.
    • There is no universal closure deadline in the standard. The certification body sets the clock, and missing it is what turns a finding into a certificate problem.

    Two grades, one test

    ISO/IEC 17021-1:2015 clause 3.12 defines a major nonconformity as "nonconformity that affects the capability of the management system to achieve the intended results," and clause 3.13 defines a minor as "nonconformity that does not affect the capability of the management system to achieve the intended results." The note to 3.12 gives the two circumstances in which a finding could be classified major: "if there is a significant doubt that effective process control is in place, or that products or services will meet specified requirements," and where "a number of minor nonconformities associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity."

    Notice what is not in the definition: the word "serious," any reference to the sensitivity of the data involved, or any count of affected systems. The question the auditor is answering is whether the management system still works. A single missed access review in a process that otherwise runs, is owned, and has caught its own misses before is a minor: the system is capable; it lapsed once. An access review process that exists on paper and has never produced a record is a major even if nothing bad happened, because the system has no capability there at all.

    The aggregation rule is the one teams underestimate. Five minors against supplier management, each individually trivial, are evidence that supplier management is not being managed, and the auditor is entitled to write one major instead of five minors. That is why the practical advice in our Stage 1 versus Stage 2 piece is to run a real internal audit first: an internal audit is the only place a major can surface without a certification consequence.

    What the requirement can be

    "Non-fulfilment of a requirement" is deliberately broad. Three kinds of requirement produce nonconformities in an ISMS audit.

    Requirements of ISO/IEC 27001 itself. The standard "specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system," and it states that "excluding any of the requirements specified in Clauses 4 to 10 is not acceptable when an organization claims conformity to this document." A missing management review or an internal audit programme that did not run is a nonconformity against the standard.

    Requirements you wrote. Your policy says access is reviewed quarterly; the auditor finds two quarters with no review. The nonconformity is against your own documented information, and it does not help that the standard never specified a frequency. This is the mechanism behind the advice to write procedures you will actually follow. A policy that describes an aspiration is a nonconformity waiting to be sampled.

    Requirements of interested parties that your scope brought in. ISO/IEC 27001:2022 clause 4.2 asks the organization to determine "the relevant requirements" of interested parties and "which of these requirements will be addressed through the information security management system," and its note says those requirements "can include legal and regulatory requirements and contractual obligations." Once a contractual security clause is inside the ISMS, failing it is a nonconformity too.

    What each grade obliges: you, and the certification body

    The consequences are set by ISO/IEC 17021-1 clause 9.5.2, titled "Actions prior to making a decision." The European co-operation for Accreditation quotes it in its Certification Committee answers: prior to making a certification decision, the body must ensure "that for any major non-conformities, the certification body has reviewed, accepted and verified the correction and corrective actions," and "that for any minor nonconformities it has reviewed and accepted the client's plan for correction and corrective action." EA's answer to question 35.10 adds the timing for minors: verification of effective implementation happens at a subsequent audit, such as the first surveillance.

    Major nonconformityMinor nonconformityOpportunity for improvement
    Definition (ISO/IEC 17021-1:2015)Affects the capability of the management system to achieve the intended resultsDoes not affect that capabilityNot a nonconformity; no requirement is unfulfilled
    What you submitCorrection, cause analysis and corrective action, with evidenceA plan for correction and corrective actionNothing is required
    What the body does before a certification decisionReviews, accepts and verifies the correction and corrective actionsReviews and accepts the planNothing; it may note the item
    When effectiveness is verifiedBefore the decisionAt a subsequent audit, typically the next surveillanceNot applicable
    Effect on an initial certificationBlocks the decision until verifiedDoes not by itself block the decisionNone

    The third column is worth a sentence. ISO/IEC 17021-1:2015 defines two grades of nonconformity and no third, and its clause 9.4.5.2, quoted in EA's answer to question 39.1, permits opportunities for improvement to be recorded while insisting that audit findings "which are nonconformities, shall not be recorded as opportunities for improvement." The same EA answer allows a body to use the word "observation" only if its auditors "can clearly and easily differentiate" observations from opportunities for improvement. Whatever label your body uses, ask which of the two grades or the one non-grade an item falls into. Remediation budget spent on observations while a minor sits open is budget spent in the wrong place.

    Correction is not corrective action

    ISO/IEC 27000:2018 defines the two words separately, and certification bodies audit them separately. A correction is "action to eliminate a detected nonconformity." A corrective action is "action to eliminate the cause of a nonconformity and to prevent recurrence." Re-running the two missed access reviews is a correction. Working out why they were missed and changing the process so it cannot be missed silently again is the corrective action.

    ISO/IEC 17021-1's process clause carries two sub-clauses on exactly this, titled "Cause analysis of nonconformities" (9.4.9) and "Effectiveness of corrections and corrective actions" (9.4.10). Your submission is judged on both: was the cause found, and did what you did about it work. A response that fixes the sampled instances and stops is the most common incomplete response there is, and ISO/IEC 27001's own clause 10.2, "Nonconformity and corrective action," is the requirement on your side of the table. Writing the plan an auditor accepts, including the root-cause classification, the named owner and the population-wide fix, is owned by our piece on remediation plans, and the vocabulary section there is where the SOC 2 and ISO terms are kept apart.

    One practical consequence of the definitions: a minor is closed by a verified corrective action, not by the correction. If your plan for the minor says only what you re-did, the surveillance auditor who comes to verify it will be looking for the part you did not write.

    The clock, and why nobody will give you one number

    The question asked under the most pressure after a Stage 2 is how long you have. The standard does not say, and the accurate answer is that your certification body does.

    What the fetched text establishes is the shape of the constraint rather than a figure. For an initial certification, a major blocks the decision until the correction and corrective action are verified, so the clock is whatever the body's rules allow before it treats the audit as closed without a decision. For a certified organization, ISO/IEC 17021-1 lists "suspending, withdrawing or reducing the scope of certification" among the body's decisions, and clause 9.6.5 is titled for exactly that; our surveillance audit guide covers how a major raised at surveillance leads to suspension when it is not closed in the time the body allows, and it is the page that owns the certificate consequences. Both articles say the same thing on purpose: the deadline is the body's, and you should ask for it in writing.

    The hardest edge is expiry. EA's Certification Committee, answering question 34.2 on a recertification delayed by audit scheduling and nonconformity closure, states that during the period between the certificate expiring and the successful completion of recertification "the organization is not certified," quoting ISO/IEC 17021-1 clause 9.6.3.2.4: "then recertification shall not be recommended and the validity of the certification shall not be extended. The client shall be informed and the consequences shall be explained." An open major in the final year of the cycle is therefore not a paperwork problem. It is the difference between holding a certificate and not holding one on the day a customer checks.

    And customers can check. ISO/IEC 17021-1 clause 4.5.1 expects a certification body to provide public access to information about "the certification status (i.e. the granting, maintaining of certification, expanding or reducing the scope of certification, renewing, suspending or restoring, or withdrawing of certification) of any organization."

    Can the certification body help you fix it?

    Not in the way people hope, and it is worth knowing where the line is before you ask.

    ISO/IEC 17021-1 clause 5.2.5 says the certification body "shall not offer or provide management system consultancy," which clause 3.3 defines as "participation in establishing, implementing or maintaining a management system," including "giving specific advice, instructions or solutions." The note to 5.2.5 keeps the door ajar for the useful part: it "does not preclude the possibility of exchange of information (e.g. explanation of findings or clarification of requirements) between the certification body and its clients." ISO/IEC 27006-1:2024 clause 5.2.2 puts the ISMS-specific version plainly: bodies "may add value during certification and surveillance audits (e.g. by identifying opportunities for improvement, as they become evident during the audit, without recommending specific solutions)."

    So the questions to ask your auditor are "what requirement is unfulfilled, and what would you need to see to consider it closed?" Those are explanation and clarification. "What should we implement?" is consultancy, and a body that answers it is compromising the certificate you are paying for. The same standard is what makes a single vendor offering to both build and certify your ISMS a red flag, a point our consultant versus platform piece covers.

    The honest caveat: findings are the system working

    We prepare organizations for these audits, so read this with that in mind. Nonconformities at a first Stage 2 are ordinary, and a certification audit that raises none is not proof of much: ISO/IEC 17021-1 states that "any audit is based on sampling within an organization's management system and therefore is not a guarantee of 100 % conformity with requirements." An audit is a sample of a system, and a minor is the system's own error-correction loop being exercised by an outsider.

    The thing to fear is not a finding. It is a finding you argue with instead of analysing, a corrective action that addresses the two sampled items and nothing else, or a major that surfaces at surveillance because the internal audit was a formality. If the same nonconformity appears two audits running, the cause was never found, and that is the point at which outside help earns its fee. Before that point, a competent internal owner with the definitions above will close most minors without anyone's help.

    Where Top Floor fits

    The useful outside contribution is the cause analysis and the completeness sweep: classifying whether the control was never adequate or simply not followed, checking the rest of the population rather than the sampled items, and writing a corrective action a surveillance auditor can verify. That is audit and assurance work, and it stays separate from building the ISMS so the clause 9.2 internal audit keeps its independence. Where the finding reveals that nobody owns the ISMS between audits, the fix is a running compliance programme rather than a one-off response. The build-side work, scope, risk assessment and the documents you will be audited against, sits in our ISO 27001 practice.

    How to decide this week

    • For each open finding, write the requirement that is unfulfilled in one sentence, citing the clause or the paragraph of your own policy. If you cannot, ask the auditor to clarify; that is an exchange the standard permits.
    • Separate correction from corrective action on the page. Two columns, two dates.
    • Group findings by requirement. Three minors against one area are a candidate major, whether or not the auditor wrote it that way, and should be treated as one systemic fix.
    • Ask the certification body, in writing, for its closure time limits and what evidence it will need to verify each grade.
    • If any finding is one you have seen before, stop and find the cause before writing the response.

    Frequently asked questions

    What makes an ISO 27001 nonconformity major rather than minor?

    One test, stated in ISO/IEC 17021-1:2015: whether the nonconformity "affects the capability of the management system to achieve the intended results." A major does; a minor does not. The note to the definition names the circumstances that point to major: significant doubt that effective process control is in place, or that products or services will meet specified requirements, and a number of minors associated with the same requirement or issue that together demonstrate a systemic failure. The severity of the underlying security lapse is not the criterion, which is why a missing process with no consequences can be major while a real but isolated lapse in a working process is minor.

    How long do you have to close an ISO 27001 nonconformity?

    The standard does not set a number, and an article that gives you one has invented it. What ISO/IEC 17021-1 fixes is the sequence: a major must be corrected and the correction and corrective action verified before a certification decision, while a minor needs an accepted plan whose implementation is verified at a subsequent audit. The time allowed for each is set by your certification body under its own rules, so ask for it in writing the day the finding is raised. For a certified organization the outer limit is expiry: if recertification is not completed before the certificate expires, the organization is not certified in the gap.

    Is an observation the same as a nonconformity?

    No. ISO/IEC 17021-1:2015 defines two nonconformity grades, major and minor, and its clause 9.4.5.2, as quoted by the European co-operation for Accreditation, permits opportunities for improvement to be recorded while requiring that findings which are nonconformities never be recorded as opportunities for improvement. The same EA answer allows a certification body to use the term "observation" only where its auditors can clearly and easily differentiate it from an opportunity for improvement. A nonconformity means a requirement is unfulfilled and obliges you to respond; an opportunity for improvement or observation does not. If a report is ambiguous about which category an item is in, ask, because the response and the certificate consequence differ completely.

    Can the certification body tell us how to fix a nonconformity?

    It can explain and it cannot advise. ISO/IEC 17021-1 bars a certification body from providing management system consultancy, which includes giving specific advice, instructions or solutions, and ISO/IEC 27006-1:2024 allows it to identify opportunities for improvement only "without recommending specific solutions." What the body can and should do is explain the finding and clarify the requirement, and tell you what evidence it will need in order to verify closure. Ask those questions freely; a body that starts designing your controls is undermining the independence that gives the certificate its value.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.