Your ISO 27001 surveillance audit is the check that decides whether the certificate you worked months for stays valid, and most teams underestimate it badly. The initial certification gets all the attention, the budget and the project plan. Then year two arrives, the certification body emails a date, and someone realizes nobody has run an internal audit since the stage 2 closing meeting.
This guide covers what auditors actually look at in an ISO 27001 surveillance audit, when it is due, what it costs in 2026, and how to prepare without treating it like a second certification project.
What an ISO 27001 Surveillance Audit Actually Covers
A surveillance audit is not a full re-audit of your information security management system. It is a targeted on-site review of the parts of the ISMS most likely to have decayed since the last visit.
ISO/IEC 17021-1:2015 — the accreditation standard your certification body has to follow — sets out in clause 9.6.2.2 exactly what each surveillance audit must include:
- Internal audits and management review
- Actions taken on nonconformities raised at the previous audit
- Complaints handling
- Effectiveness of the ISMS against your own stated objectives
- Progress on planned continual improvement activities
- Continuing operational control
- Review of any changes to the organization or the ISMS
- Use of certification marks and how you describe your certification publicly
That list is the whole game. Every ISO 27001 surveillance audit will hit those eight items, whatever else the auditor samples. Two of them cause more failures than the rest combined: internal audits and management review. Both are annual obligations under clauses 9.2 and 9.3 of the standard, both are easy to postpone, and both leave an unmissable evidence gap when they have not happened.
The auditor will also sample Annex A controls. Not all 93 of them — ISO/IEC 27001:2022 organizes its controls into four themes (37 organizational, 8 people, 14 physical, 34 technological) and a surveillance visit typically samples across themes rather than working through the full Statement of Applicability. Expect access reviews, supplier management, logging and incident records to come up almost every year.
When Your ISO 27001 Surveillance Audit Is Due
Certification runs on a three-year cycle that starts on the date of the certification decision, not the date of your stage 2 audit. Under clause 9.1.3.2, the audit programme for that cycle is fixed: a two-stage initial audit, a surveillance audit in each of the first and second years following the decision, and a recertification audit in year three before the certificate expires.
Clause 9.1.3.3 adds two timing rules that catch people out:
- Surveillance audits happen at least once per calendar year, except in the recertification year.
- The first one must take place no more than 12 months from the certification decision date.
That second rule is a hard boundary, not a target. If your certification decision was 10 March, your first ISO 27001 surveillance audit has to be conducted by 10 March the following year — and the certification body will usually want to book it for month 10 or 11 to leave room for findings. Work backwards from the decision date on your certificate, not from the audit dates in your project plan.
ISO 27001 Surveillance Audit vs Recertification vs Initial Audit
The three audit types in a certification cycle differ in scope, depth and consequence. Understanding which one you are facing changes how you prepare.
| Factor | Initial certification (stage 1 + 2) | Surveillance audit | Recertification audit |
|---|---|---|---|
| When | Before certification is granted | Years 1 and 2 of the cycle | Year 3, before certificate expiry |
| Scope | Whole ISMS, all clauses, full Statement of Applicability | Mandatory items in clause 9.6.2.2 plus a sample of controls | Whole ISMS again, plus review of previous surveillance reports |
| Typical duration | Baseline, set by ISO/IEC 27006-1 Annex C | Roughly one third of the initial audit time | Roughly two thirds of the initial audit time |
| Typical fee | Largest fee of the cycle | Commonly $3,000–$12,000 per year for small and mid-sized organizations | Commonly $7,000–$16,000 |
| Stage 1 required? | Yes, always | No | Only if there have been significant changes to the ISMS or to legislation |
| Consequence of failure | Certification withheld | Suspension, then withdrawal if unresolved | Certificate expires and is not renewed |
ISO 27001 Surveillance Audit Cost and Duration in 2026
Audit time for ISMS certification is not set by your certification body’s commercial instincts. It is calculated under Annex C of ISO/IEC 27006-1:2024, driven mainly by the effective number of people in scope, the number of sites, and the complexity of what you do. A surveillance audit is a fraction of the initial audit — a third is the common planning assumption across accredited certification schemes, and it is unusual for one to come in under a full audit day.
Published 2026 figures for an ISO 27001 surveillance audit cluster between $3,000 and $12,000 a year, with organizations under about 50 staff most often quoted in the $6,000–$7,500 band. Treat these as typical ranges, not quotes. The variables that actually move the number are headcount in scope, how many locations the auditor has to visit, whether the audit can be conducted remotely, and your certification body’s day rate.
Budget for the internal cost too. The audit fee is usually the smaller half. Preparing evidence, running the internal audit programme and holding a management review costs staff time that never appears on the certification body’s invoice. If you want the wider picture across the whole three years, our ISO 27001 certification cost breakdown sets out where the money goes.
What Changed for 2026: ISO/IEC 27006-1:2024
One update is worth knowing about if your audit fee has moved. ISO/IEC 27006-1:2024 was published in March 2024, replacing ISO/IEC 27006:2015 and its 2020 amendment. It is the standard that governs how bodies audit and certify an ISMS, and it rewrote the audit time rules in Annex C — introducing the concept of persons performing certain identical activities when counting people in scope, adding rules for scope extensions, and clarifying multi-site calculations. For anyone booking an ISO 27001 surveillance audit this year, that is the rulebook the auditor is working from.
ANAB gave its accredited certification bodies until 31 March 2026 to transition every client to the new edition. That deadline has now passed, so if you certified in 2023 under the old rules and your renewal quote looks different from what you budgeted, the recalculated audit time is the likely explanation. It is a fair question to put to your certification body — ask them to show the Annex C calculation.
The other change worth noting: Annex E of ISO/IEC 27006-1:2024 was realigned to the ISO/IEC 27001:2022 Annex A control set. If you were certified against the 2013 edition, that transition closed on 31 October 2025 and is no longer available.
How to Prepare for Your ISO 27001 Surveillance Audit
Preparation for an ISO 27001 surveillance audit is mostly about proving the ISMS ran for twelve months, not about producing new documents. Work through this in the quarter before the visit.
- Close out last year’s findings first. Clause 9.6.2.2 puts actions on previous nonconformities near the top of the mandatory list. An open corrective action from the last visit is the fastest route to an escalated finding this time.
- Run the internal audit and evidence it. The ISO 27001 internal audit is a clause 9.2 requirement, and the auditor will want the programme, the plan, the report and the resulting actions — not just an assertion that it happened.
- Hold the management review with the right inputs. Clause 9.3 specifies what top management has to consider. Minutes that record attendance, the inputs reviewed and the decisions taken are what gets sampled.
- Update the risk assessment and Statement of Applicability for changes. New systems, new suppliers, new offices, headcount growth — each of these should be visible in your risk treatment records. Silence here reads as a system nobody is running.
- Check your certification marks. Website, proposals, email footers and sales decks. Claiming certification for services outside your certified scope is a finding under the mark-usage item, and it is entirely avoidable.
- Assemble twelve months of operational records. Access reviews, supplier assessments, incident tickets, training completion, backup tests, vulnerability scans. Continuing operational control is proven by records with dates spread across the year, not a batch created last week.
What Happens If You Fail or Miss One
Missing the audit is worse than failing it. Under clause 9.6.5.2, a certification body must suspend certification where a certified client does not allow surveillance or recertification audits at the required frequency. Suspension makes the certificate temporarily invalid — which means it is invalid in the eyes of the customer whose vendor questionnaire prompted you to certify in the first place. Suspension is normally capped at around six months; if the underlying issue is not resolved, the outcome is withdrawal or a reduction in scope.
Failing on findings is more recoverable. Minor nonconformities are closed with a corrective action plan and evidence. Major nonconformities need correction, root cause analysis and verification within a defined time limit, and the certification body may require an additional audit, full or limited, to confirm the fix. None of that is fatal, provided you respond inside the timeframe agreed at the closing meeting.
Frequently Asked Questions
How long does an ISO 27001 surveillance audit take?
Most run one to two days on site for small and mid-sized organizations. Audit time is calculated under Annex C of ISO/IEC 27006-1:2024, and a surveillance visit is commonly planned at about a third of the initial certification audit time. It is unusual for one to be shorter than a single audit day.
Can an ISO 27001 surveillance audit be done remotely?
Partly, and increasingly so. ISO/IEC 17021-1 requires surveillance activities to include on-site auditing, but ISO/IEC 27006-1:2024 sets out requirements for deploying remote audits and removed the previous need for accreditation body approval when remote work exceeded 30% of planned on-site time. The extent and effectiveness of remote auditing now has to be recorded in the audit report. Agree the split with your certification body in advance.
Do I need a new internal audit before every surveillance audit?
Yes. Clause 9.2 requires internal audits at planned intervals, and the certification body checks them at every visit. A single internal audit covering the full ISMS scope once a year is the minimum most organizations run; larger scopes are usually split across a rolling programme.
What is the difference between a surveillance audit and a recertification audit?
A surveillance audit samples the mandatory items in clause 9.6.2.2 plus a selection of controls, and happens in years one and two. Recertification in year three re-evaluates the entire ISMS, reviews the previous surveillance reports, and may require a stage 1 if the ISMS or the applicable legislation has changed significantly. Recertification is longer, costs more, and must be completed before the certificate expires.
What happens if my certificate expires before recertification is finished?
Under clause 9.6.3.2.5, a certification body can restore certification within six months of expiry if the outstanding recertification activities are completed. Miss that window and you face at least a full stage 2 audit again. Book recertification early enough that findings can be closed before the expiry date.
Turn the Cycle Into a Routine
The organizations that find surveillance audits painless are the ones running the ISMS as an operating rhythm rather than a certification sprint. The documented backbone matters: an internal audit programme, a management review agenda, a nonconformity procedure, a maintained Statement of Applicability and a risk register that shows movement.
If yours are thin, the ISO 27001 Toolkit gives you 162 editable templates covering exactly those artifacts — internal audit plans and checklists, management review agendas, the nonconformity and corrective action procedures, the risk register and the Statement of Applicability — aligned to ISO/IEC 27001:2022 for $99.
For the wider picture of how the cycle fits together, start with our guide to ISO 27001 certification, and check the current edition of the standard on the official ISO/IEC 27001:2022 page. Note that Amendment 1:2024, which adds the climate action changes, is available from ISO at no cost.