Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 certificate validity three-year cycle: surveillance audits in years one and two, recertification in year three

ISO 27001 Certificate Validity: The Complete 2026 Guide

ISO 27001 certificate validity is one of the few parts of certification that runs on a published rulebook — and one of the parts both sellers and buyers get wrong most often. A certificate is not a permanent award. It is a time-boxed statement that a certification body judged your ISMS conforming on a particular date, and it can be suspended, cut back or withdrawn long before the expiry date printed on it.

The rules are not ISO’s. ISO writes the standard but certifies nobody. The validity rules sit in ISO/IEC 17021-1:2015, which is what certification bodies are themselves accredited against, plus ISO/IEC 27006-1:2024 for information security management systems specifically.

This guide covers how ISO 27001 certificate validity actually works: the three-year cycle, what has to appear on the certificate, what breaks validity, and how to check a supplier’s certificate in about five minutes.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

How Long ISO 27001 Certificate Validity Lasts

ISO 27001 certificate validity normally runs three years from the certification decision — not from the stage 2 audit, and not from the day you signed the contract.

ISO/IEC 17021-1 clause 9.1.3.2 sets the shape of the programme: a two-stage initial audit, a surveillance audit in each of the first and second years following the certification decision, and a recertification audit in the third year, before certification expires. The first three-year cycle begins with the certification decision; later cycles begin with each recertification decision. A sector-specific scheme can define a cycle other than three years, but for ISO 27001 three years is the norm.

Clause 9.1.3.3 fixes the rhythm in between. Surveillance has to happen at least once per calendar year, except in recertification years, and the first surveillance audit after initial certification cannot be more than 12 months from the certification decision date.

That 12-month clock catches people out, because it starts at the decision rather than at the audit. A slow certification decision after your stage 2 audit eats into your own surveillance window, not the certification body’s.

Surveillance audits are on site, but clause 9.6.2.2 is explicit that they are not necessarily full system audits. Each one reviews your internal audits and management review, the actions you took on nonconformities from the previous audit, complaints handling, whether the ISMS is actually achieving the objectives you set, progress on planned improvement, continuing operational control, any changes, and how you are using the certification mark.

Cycle yearAuditTiming rule (ISO/IEC 17021-1)Effect on validity
Year 0Stage 1 and stage 2 initial audit, then the certification decisionCycle starts at the decision (9.1.3.2)Certificate issued on or after the decision date
Year 1First surveillance auditNo more than 12 months from the certification decision date (9.1.3.3)Missing it is grounds for suspension
Year 2Second surveillance auditAt least once per calendar year (9.1.3.3)Missing it is grounds for suspension
Year 3Recertification auditPlanned in due time for renewal before the expiry date (9.6.3.1.1)New cycle can keep the existing expiry date (9.6.3.2.3)

What a Valid ISO 27001 Certificate Has to Show

Clause 8.2.2 of ISO/IEC 17021-1 lists what the certification document has to identify. If a certificate you have been sent is missing any of these, that is a reasonable thing to query.

Required on the certificateWhat to look for
Name and geographic location of the certified clientFor multi-site certification, the headquarters plus any sites inside the scope
Effective date of granting, expanding, reducing or renewing certificationMust not pre-date the relevant certification decision
Expiry date or recertification due dateHas to be consistent with the recertification cycle
Unique identification codeThe number you quote when verifying the certificate
The standard used, including issue status“ISO/IEC 27001:2022”, not a bare “ISO 27001”
Scope of certificationActivities, products and services at each site, not misleading or ambiguous
Name, address and certification mark of the certification bodyAn accreditation symbol may also appear
Anything else the certification scheme requiresFor ISMS, see ISO/IEC 27006-1 below
A way to tell revised documents from obsolete onesRevision markers, so an old PDF cannot be passed off as current

Two of those lines settle most disputes. The scope has to describe activities, products and services without being misleading or ambiguous — so a certificate whose scope reads “information security management system” with no boundary tells a customer almost nothing about what was audited. And the standard reference has to carry its issue status, which is how you tell a 2022 certificate from a 2013 one at a glance.

ISO/IEC 27006-1:2024, published on 31 March 2024, adds a line that matters for remote-first companies: where a client has few or no relevant physical sites, both the audit report and the certification document have to state that the client’s activities are conducted remotely. Its clause 8.2.3 also tightened how other standards may be referenced on an ISMS certificate. Accreditation bodies set an end date for that change — the Standards Council of Canada’s bulletin 2024-18 gives 31 March 2026 as the deadline for every certification body in its programme to complete the transition to ISO/IEC 27006-1:2024.

One thing your certificate does not do is certify a product. Clause 8.3 requires certification bodies to stop clients from applying the mark to a product, to packaging, or in any way that reads as product conformity. “ISO 27001 certified platform” is the claim that gets companies a letter from their own certification body.

What Breaks ISO 27001 Certificate Validity

Three different things can happen to a live certificate, and they are not interchangeable. Clause 9.6.5 covers suspension, withdrawal and reduction of scope, and every certification body has to hold a documented procedure for all three.

Clause 9.6.5.2 says the certification body shall suspend certification in cases such as the client failing to meet certification requirements, the client not allowing surveillance or recertification audits at the required frequency, or the client voluntarily asking for suspension. Under suspension, clause 9.6.5.3 is blunt: the certification is temporarily invalid. The PDF still exists, but you cannot claim it, and a customer checking the public database will see the status.

Clause 9.6.5.4 gives the way back — resolve the issue that caused the suspension and the certification body restores certification. Fail to resolve it in the time the body sets and the outcome is withdrawal, or a reduction of scope to cut out the parts that no longer meet the requirements. The standard’s own note is that suspension would not, in most cases, run beyond six months.

Expiry is a separate trap. Clause 9.6.3.2.2 requires time limits for correcting any major nonconformity to be defined and completed before certification expires. If recertification is not finished in time, clause 9.6.3.2.4 says recertification is not recommended and certification is not extended. After expiry, clause 9.6.3.2.5 still allows the certification body to restore certification within six months, provided the outstanding recertification activities are completed — miss that window and you need at least a stage 2 audit again.

Clause 9.6.4.2 is the one nobody plans for: certification bodies can audit at short notice or unannounced to investigate complaints, respond to changes, or follow up on suspended clients. The conditions have to be set out in advance, but you do not get the usual right to object to the audit team.

StatusTriggerCan you claim certification?Route back
SuspendedPersistent or serious failure, refused surveillance, or a voluntary request (9.6.5.2)No — temporarily invalid (9.6.5.3)Resolve the issue and the body restores it; usually within six months (9.6.5.4)
Scope reducedPart of the scope no longer meets requirements (9.6.5.5)Only for the remaining scopeApply to expand scope again, often alongside a surveillance audit (9.6.4.1)
WithdrawnSuspension issues not resolved in the set time (9.6.5.4)NoA fresh certification process
ExpiredRecertification not completed before the expiry date (9.6.3.2.4)NoRestoration within six months if activities are completed, otherwise at least a new stage 2 (9.6.3.2.5)

There is also an edition deadline that already passed. The transition from ISO/IEC 27001:2013 to the 2022 edition closed on 31 October 2025, so a certificate still naming the 2013 edition is no longer valid, whatever date is printed in its expiry field. If a supplier sends you one, they are either sending an obsolete PDF or they did not transition.

Accredited or Not: the Question Behind ISO 27001 Certificate Validity

Nothing stops an unaccredited company from printing a certificate. What accreditation adds is a chain: the certification body is assessed against ISO/IEC 17021-1 and ISO/IEC 27006-1 by an accreditation body, and that accreditation body is a signatory to a multilateral recognition arrangement for the standard in question.

Break the chain and you still have a certificate — it is just one your enterprise customers’ procurement teams can reject, and one that cannot be traced in the global database. That is usually the real question behind ISO 27001 certificate validity: not whether the document exists, but whether anyone will accept it.

The governance layer above all this changed in 2026. The International Accreditation Forum ceased operations on 1 January 2026 and its role passed to the Global Accreditation Cooperation Incorporated (Global ACI). The verification database, IAF CertSearch, continues to operate under its own name.

How to Check ISO 27001 Certificate Validity in Five Minutes

Checking ISO 27001 certificate validity for a supplier is a short, repeatable job. Do it in this order.

  1. Search the certificate in IAF CertSearch. The database holds more than 3.7 million certifications from roughly 2,500 certification bodies and 81 accreditation bodies, and cross-checks three sources to confirm that the certificate is valid, that the certification body was accredited to issue it, and that the accreditation body is recognised for that standard.
  2. Read the nine fields from clause 8.2.2. Unique code, effective date, expiry date, standard with its issue status, scope, certification body details.
  3. Check the edition. It should say ISO/IEC 27001:2022.
  4. Read the scope statement against what you are buying. A certificate scoped to a head office does not cover the development team in another country, and a scope naming one product line does not cover the rest.
  5. Ask for the date of the last surveillance audit. A certificate in year two of its cycle with no surveillance evidence behind it is the single clearest warning sign.

If you are on the other side of that conversation, the fastest way to end it is to send the certificate PDF, the scope statement and the last surveillance date together, unprompted.

Keeping ISO 27001 Certificate Validity Between Audits

Most certificates are not lost to a dramatic breach. They are lost to a management system that stopped running once the certificate arrived, because surveillance looks straight at the evidence that goes stale first.

Four habits protect ISO 27001 certificate validity between audits. Run internal audits and management review on a schedule and keep the records, because clause 9.6.2.2 makes both the first thing a surveillance auditor opens. Close nonconformities from the previous audit with evidence, not intentions. Tell your certification body about significant changes — ownership, scope, new sites, a new product line — rather than letting the auditor discover them. And keep the Statement of Applicability current against all 93 Annex A controls in the 2022 edition, across the four themes of organizational, people, physical and technological controls; the SoA is mandatory under clause 6.1.3, and a stale one is an easy finding.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

If you are rebuilding that evidence base from scratch, our ISO 27001 Toolkit ships the mandatory documents — SoA, risk register, internal audit programme, management review pack and the rest — as editable templates, so the surveillance file writes itself rather than being reconstructed the week before the audit.

ISO 27001 Certificate Validity FAQs

How long is an ISO 27001 certificate valid?

Three years in normal practice, starting from the certification decision rather than the audit date, with surveillance audits in years one and two and recertification in year three. The exact expiry date is printed on the certificate under clause 8.2.2.

Does an ISO 27001 certificate expire if you miss a surveillance audit?

Not immediately, but refusing or missing surveillance at the required frequency is explicitly listed in clause 9.6.5.2 as a reason the certification body must suspend certification — and suspended certification is temporarily invalid.

What happens if the certificate expires before recertification finishes?

Certification is not extended. The certification body can restore it within six months of expiry if the outstanding recertification activities are completed; after that you need at least a stage 2 audit again.

Is a non-accredited ISO 27001 certificate valid?

It exists, but it is not traceable through the accreditation chain and will not appear in IAF CertSearch. Expect enterprise customers and regulated buyers to reject it.

Are ISO 27001:2013 certificates still valid in 2026?

No. The transition to ISO/IEC 27001:2022 closed on 31 October 2025, so any certificate still naming the 2013 edition is out of date regardless of its printed expiry.

The Short Version

ISO 27001 certificate validity is a three-year window that depends on the certification decision date, two surveillance audits, a recertification audit scheduled before expiry, and a certificate that carries the nine items clause 8.2.2 requires. It is suspended, reduced or withdrawn for failures you can see coming — missed surveillance, unclosed major nonconformities, a scope that no longer matches reality.

If you want the primary sources, the standard that governs certification bodies is ISO/IEC 17021-1:2015, and the ISMS-specific requirements are in ISO/IEC 27006-1:2024. For the standard your own ISMS is certified against, see ISO/IEC 27001 on iso.org.

Related reading: how to get ISO 27001 certified, what happens in an ISO 27001 surveillance audit, how the ISO 27001 recertification audit works, and how to choose an ISO 27001 certification body.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.