Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 nonconformity classification chart comparing major and minor audit findings

ISO 27001 Nonconformity: The Complete 2026 Guide to Major vs Minor Findings

An ISO 27001 nonconformity is an auditor’s formal record that a requirement of the standard is not being met, and the grade attached to it decides whether you leave the audit with a certificate or with a follow-up visit on the calendar. Most teams meet their first one during a Stage 2 audit or an internal audit, react by writing another policy, and then watch the same finding come back a year later. This guide explains how findings are classified, what your certification body expects after the closing meeting, and how to write a corrective action that closes on the first attempt.

What Counts as an ISO 27001 Nonconformity

An ISO 27001 nonconformity is the non-fulfilment of a requirement. In an information security management system (ISMS) audit, “requirement” is broader than most people expect, covering three sources:

  • Clauses 4 to 10 of the standard — the management system requirements, from context and leadership through to corrective action.
  • Annex A controls you declared applicable in your Statement of Applicability. ISO/IEC 27001:2022 lists 93 controls across four themes: 37 organizational, 8 people, 14 physical and 34 technological.
  • Your own documented ISMS. If your access control procedure promises quarterly reviews and you did two last year, that is a finding — even though the standard never mentions a quarterly cadence.

That third source catches most organizations: an ISO 27001 nonconformity raised against your own procedure rather than the standard. Over-specified documents create obligations auditors will happily sample against.

Clause 10.2 sets out what happens next: react and correct, deal with the consequences, evaluate whether action is needed to eliminate the cause, implement it, review its effectiveness, and change the ISMS if necessary. You must also retain documented information on the nature of the nonconformities, the actions taken and the results. Note the numbering — in the 2022 edition continual improvement moved to 10.1 and nonconformity and corrective action to 10.2, reversing the 2013 layout. Edition details are on the official ISO/IEC 27001 standard page.

Not everything an auditor writes down is an ISO 27001 nonconformity. Audit reports usually carry three kinds of entry:

  • Nonconformity — a requirement is not met. Corrective action is mandatory.
  • Observation — a weakness that is not yet a breach. No corrective action is required, but ignoring it for two cycles tends to convert it into a finding.
  • Opportunity for improvement (OFI) — a suggestion. Purely advisory.

Major vs Minor ISO 27001 Nonconformity

Whether an ISO 27001 nonconformity is graded major or minor is the most consequential line in the report. A minor finding is an isolated lapse inside a process that otherwise works. A major means the process is absent, broken systemically, or the failure puts information at real risk.

AspectMinor nonconformityMajor nonconformity
What it meansA single or isolated lapse in a process that is otherwise designed and operatingA required element is absent, a process has failed systemically, or a pattern of minors shows the system is not working
Typical exampleTwo of twenty leavers had access revoked late; one management review agenda missed a required inputNo internal audit programme at all; a risk assessment that exists on paper but was never performed; the Statement of Applicability does not match the risk treatment plan
Effect on initial certificationCertificate can normally still be recommended, with the finding closed afterwardsBlocks the certification decision until closure is submitted and accepted
Effect at surveillanceTracked and reviewed at the next visitCan trigger a special visit and, if unresolved, suspension of the certificate
What the certification body wantsCorrection plus a stated cause and planned corrective actionCorrection, documented root cause analysis, corrective action, and objective evidence of implementation
How closure is verifiedUsually a desk review of submitted evidenceOften a follow-up or special audit, on site or remote
Typical closure windowAround 30 to 90 days, agreed with the auditorShorter and firmer — commonly a plan within 14 to 30 days and evidence inside 60 to 90 days
Windows vary by certification body and accreditation scheme. Always work to the dates written in your own nonconformity report.

Auditors have discretion and they use it. A cluster of related minors in the same clause is often escalated to one major, because together they show the process is not controlled. The reverse also happens: a serious-looking gap you had already detected, logged and started fixing is frequently graded down, because your ISMS demonstrably worked.

The Clock That Starts at the Closing Meeting

Once an ISO 27001 nonconformity is issued, you are on a schedule. Missing a date is itself a problem — certification bodies escalate silence far faster than bad news.

StageTypical windowWhat you submit
Classification and agreementAt the closing meetingNothing yet — but this is your one chance to query wording or scope
Correction (containment)Immediately to 14 daysEvidence the specific instance has been fixed
Root cause and corrective action plan14 to 30 daysCause analysis, planned actions, named owners, target dates
Evidence of implementation30 to 90 daysRecords, screenshots, logs, updated documents
Certification body verificationAfter submissionDesk review, or a follow-up audit for majors
Effectiveness checkNext internal audit or surveillance visitEvidence the cause has not recurred

For initial certification, most bodies want Stage 2 findings resolved within roughly 90 days of the last audit day. Past that, a partial or full re-audit may be required, which costs real money. Read your own report — its dates override any rule of thumb, including this one.

Six Findings That Generate Most ISO 27001 Nonconformity Reports

Across certification bodies, the same handful of gaps come up again and again:

  1. Statement of Applicability out of step with the risk treatment plan. Controls marked applicable with no corresponding treatment, or exclusions with no justification. Clause 6.1.3 makes the SoA mandatory, and auditors read it line by line.
  2. An internal audit programme that does not cover the whole ISMS. Clause 9.2 expects the full system to be audited across the cycle. Auditing the same three easy clauses every year is a finding. Our guide to the ISO 27001 internal audit walks through building a programme that survives scrutiny.
  3. Management reviews missing required inputs. Clause 9.3 lists what must be considered. A thirty-minute meeting with no minutes covering audit results, risk status, objectives and interested-party feedback will be written up.
  4. A risk assessment performed once and never repeated. Risk assessment has to run at planned intervals and when significant changes occur — not only in the month before the audit.
  5. Access reviews and the leaver process without evidence. The policy exists, the reviews are claimed, but no signed records exist. If it is not recorded, the auditor treats it as not done.
  6. Supplier controls documented but not applied. A supplier security policy with no evidence of assessment, contract clauses or monitoring for the actual vendors handling your data.

Every item on that list is detectable in advance — which is the argument for treating your internal audit as a rehearsal rather than a formality, and for reviewing gaps months before a surveillance audit.

How to Close an ISO 27001 Nonconformity on the First Attempt

Certification bodies reject corrective action submissions constantly, almost always for the same reasons. A response that gets accepted has five parts.

1. Separate correction from corrective action. Correction fixes the instance the auditor found — you revoke the three accounts. Corrective action fixes the reason those accounts survived — the offboarding checklist had no IT sign-off step. Submitting only the correction is the most common reason a response bounces.

2. Do a real root cause analysis. “Human error” is not a root cause; it is where the analysis stops too early. Ask why until you reach something you can change: a missing control point, an unclear owner, a process that depended on one person remembering. Five Whys or a simple cause-and-effect diagram is enough — the technique matters less than the evidence that you actually did it.

3. Check whether the same cause exists elsewhere. Clause 10.2 asks whether similar nonconformities exist or could potentially occur. If the auditor sampled one system and found the gap, look at the other systems yourself and say what you found. This single step converts a defensive response into a credible one.

4. Make actions specific, owned and dated. Each needs a named person, a date and a deliverable someone else could verify. “Improve awareness” is unverifiable. “Add an IT revocation step to the offboarding form, owned by the HR Operations Lead, live by 15 October, evidenced by the next five leaver records” is.

5. Plan the effectiveness check. Say how and when you will confirm the cause is gone — a targeted sample of leavers at the next internal audit, for instance. Closing an ISO 27001 nonconformity without one is how the same finding reappears at recertification.

Mistakes That Turn a Minor Finding Into a Major One

Escalation is usually self-inflicted. Five habits reliably turn a manageable ISO 27001 nonconformity into a major one:

  • Arguing the classification after the closing meeting. Raise factual errors immediately and politely, with evidence. Once the report is issued, energy spent disputing it is energy not spent fixing it.
  • Fixing only what was sampled. Auditors sample. If they found two late revocations in a sample of twenty, they assume the rest of the population looks similar until you prove otherwise.
  • Writing a new policy as the whole answer. A new document is rarely a root cause fix, and it adds another commitment you will be audited against next year.
  • Going quiet on a deadline. If you will miss a date, say so before it passes and propose a new one. Bodies accommodate reasoned delays and escalate unexplained ones.
  • Closing internal findings without verification. A finding closed by the person who caused it, with no independent check, is itself a clause 10.2 problem waiting to happen.

ISO 27001 Nonconformity: Frequently Asked Questions

Can you still get certified with an open minor ISO 27001 nonconformity?

Usually yes. Most certification bodies will recommend certification with minor findings outstanding, provided you submit an accepted correction and corrective action plan within the agreed window. Majors are different — they generally have to be closed and verified before the certificate is issued.

How many minor findings add up to a major?

There is no fixed number. Escalation is driven by pattern, not arithmetic. Several minors against the same clause, or the same finding repeated from a previous audit, signal that the management system is not correcting itself, and that is what turns them into a major.

What is the difference between an observation and a nonconformity?

An observation flags a weakness or a trend without asserting that a requirement has been breached, so no corrective action is mandatory. An ISO 27001 nonconformity asserts a requirement is not met and obliges you to respond under clause 10.2. Treat repeated observations as early warnings.

Can a major nonconformity cost you your certificate?

It can. At surveillance or recertification, an unresolved major typically leads to suspension, and a suspension that is not lifted within the body’s stated period leads to withdrawal. Meeting the agreed dates is what prevents that, not the severity of the original finding.

Who is allowed to close an internal nonconformity?

Someone independent of the work that produced it. In a small company that need not mean a separate department, but the reviewer must not be the person who performed the corrective action. Record who verified closure and on what evidence.

Getting Ahead of the Next Finding

Nearly every ISO 27001 nonconformity traces back to a gap between what your documentation promises and what your records prove. The fastest route to fewer findings is an ISMS that is realistic about cadence, owners and evidence, plus an internal audit honest enough to test it. If you are rebuilding documentation after a finding, the ISO 27001 Toolkit gives you 175 editable templates — policies, procedures, registers and audit records aligned to the 2022 edition — for $99, so you edit rather than start from a blank page.

For the wider picture on how the assessment cycle fits together, start with our guide to ISO 27001 certification.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.