Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 recertification audit timeline showing the three-year certification cycle from Stage 1 and Stage 2 through surveillance audits to year three reassessment

ISO 27001 Recertification Audit: The Complete 2026 Guide

Your ISO 27001 recertification audit is the audit that decides whether your certificate survives past year three. Surveillance visits in years one and two sample a slice of the ISMS. Recertification reopens the whole thing — scope, risk process, Statement of Applicability, control effectiveness, and whether the management system has genuinely matured since the original certification decision. Miss it, and the certificate lapses. A lapsed certificate is exactly the kind of thing a customer’s procurement team notices.

This guide walks through the ISO 27001 recertification audit the way an auditor plans it: the timing rules your certification body is bound by, what gets sampled, realistic duration and cost ranges, the six-month restoration window if you slip past expiry, and a countdown plan that starts about six months out.

What an ISO 27001 recertification audit covers

An ISO 27001 recertification audit is a full on-site reassessment of your information security management system, carried out before your current certificate expires, to decide whether a new three-year certificate should be issued.

Certification bodies do not get to invent the format. They are accredited against ISO/IEC 17021-1:2015, which sets out what a recertification audit must address. Clause 9.6.3.2.1 requires the audit to cover three things:

  • The effectiveness of the management system in its entirety, in light of internal and external changes and its continued relevance to the scope of certification
  • Demonstrated commitment to maintain the effectiveness and improvement of the management system, in order to enhance overall performance
  • Whether the operation of the certified management system contributes to the achievement of the organization’s policy and objectives

Note the emphasis. Not “do you have a policy” but “is the system working, and can you show it improved.” That is the single biggest shift in expectation between a first certification and a third-year reassessment, and it is where under-prepared teams get caught.

Clause 9.6.3.1.2 also requires the auditor to review your previous surveillance audit reports as part of planning. Every finding, every observation, every opportunity for improvement raised in years one and two is fair game. If you closed a minor nonconformity in year one on paper and never actually changed anything, this is the audit where it surfaces.

Where the ISO 27001 recertification audit sits in the three-year cycle

ISO/IEC 17021-1 clause 9.1.3.2 defines the shape of the cycle: a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration. The first three-year cycle begins with the certification decision; subsequent cycles begin with the recertification decision.

Two timing rules matter in practice. Surveillance audits must be conducted at least once a calendar year except in recertification years, and the first surveillance audit after initial certification cannot be more than 12 months from the certification decision date.

Point in cycleAudit typeDepthConsequence of failure
Month 0Stage 1 and Stage 2 initial auditFull system, two stagesNo certificate issued
Year 1Surveillance auditPartial sample, mandatory elementsSuspension if unresolved
Year 2Surveillance auditPartial sample, different areasSuspension if unresolved
Year 3, before expiryRecertification auditFull system reassessmentCertificate expires, not extended

One under-appreciated point: refusing or repeatedly postponing an audit is itself grounds for action. Clause 9.6.5.2 requires the certification body to suspend certification where the certified client does not allow surveillance or recertification audits to be conducted at the required frequencies. “We’re too busy this quarter” is not a neutral answer.

ISO 27001 recertification audit vs surveillance audit

People assume year three is “a bigger surveillance.” It is closer to a repeat of Stage 2. The table below sets out the practical differences.

DimensionSurveillance auditISO 27001 recertification audit
CoverageSampled subset; not necessarily a full system auditWhole management system, all clauses, full Annex A review
Always reviewedInternal audit, management review, previous findings, complaints, changes, use of marksAll of that, plus system effectiveness and three-year improvement trend
Stage 1 possibleNoYes, where there have been significant changes to the ISMS or to legislation
Typical durationRoughly one third of initial audit time, annuallyRoughly two thirds of what an initial audit would take today
Decision makerCan be maintained on the audit team leader’s positive conclusionFormal renewal decision based on recertification audit results and overall performance
Worst outcomeSuspensionCertificate expires and is not extended

The duration proportions above come from IAF MD 5, the mandatory document on audit duration. Its wording is precise and worth reading literally: recertification time is approximately two thirds of the audit time that would be required for an initial audit if such an audit were carried out at the time of recertification — not two thirds of what you actually paid in year zero. If you have doubled headcount since, the number goes up.

For information security specifically, audit duration is set by ISO/IEC 27006-1:2024, whose Annex C now contains dedicated calculations for surveillance, recertification, multi-site arrangements and scope extensions. The proportions land in a similar place, but the base number is driven by the effective number of people working within the ISMS scope, including freelancers and external staff. Contractors count.

What the auditor will actually ask for

Preparation for an ISO 27001 recertification audit is mostly evidence assembly. Expect the auditor to work through:

  • Scope statement. Still accurate? New products, new cloud regions, an acquisition, a switch to fully remote working — any of these can invalidate the wording on your certificate. Review your ISO 27001 scope before the auditor does.
  • Statement of Applicability. Mandatory under clause 6.1.3(d). It must reconcile against all 93 Annex A controls across the four themes — 37 organizational, 8 people, 14 physical, 34 technological — with justifications for inclusion and exclusion that still hold. A stale Statement of Applicability is one of the most common year-three findings.
  • Risk assessment and treatment. Three full cycles of it, with evidence that the risk register changed in response to real events rather than being copied forward.
  • Internal audit programme. Full coverage of the ISMS across the cycle, not the same three controls audited three times. Your ISO 27001 internal audit records are read closely at recertification.
  • Management review minutes. All required inputs and outputs, with decisions and resource allocations, for every year of the cycle.
  • Corrective actions. Root cause analysis, action taken, and verified effectiveness — not just a closure date.
  • Metrics. Objectives set, measured, missed or met, and what you did about it. This is the evidence for “improvement.”

How long an ISO 27001 recertification audit takes and what it costs

An ISO 27001 recertification audit for a single-site organization in the 50 to 200 employee range typically runs three to six auditor days, plus reporting. Larger or multi-site scopes go up from there, and the number is calculated by your certification body, not negotiated.

On cost, treat every figure you read online — including these — as a market observation rather than a published rate. Typical ranges seen in the US and UK market in 2026:

  • Certification body day rate: roughly $1,400–$2,500 per auditor day in the US; roughly £1,000–£1,400 in the UK
  • Recertification audit fee, small to mid-sized single site: roughly $6,000–$18,000
  • Relative to initial certification: commonly quoted at 60–100% of the original Stage 1 plus Stage 2 fee

Smaller accredited bodies generally quote below the large global brands. Accreditation status matters more than brand — an unaccredited certificate is worth considerably less to a customer’s vendor risk team. For a fuller picture of the whole cycle, see our breakdown of ISO 27001 certification cost.

What happens if the certificate expires

This is the part worth knowing before you need it. If recertification activities are completed successfully before the expiry date, the expiry date of the new certificate can be based on the expiry date of the existing one, so you do not lose time by auditing early. The issue date on the new certificate will be on or after the recertification decision.

If they are not completed in time, recertification is not recommended and certification is not extended. There is, however, a restoration window. Under clause 9.6.3.2.5, following expiration of certification the certification body can restore certification within six months provided the outstanding recertification activities are completed. Past six months, at least a Stage 2 audit is required.

Also note clause 9.6.3.2.2: for any major nonconformity raised at the ISO 27001 recertification audit, time limits for correction and corrective action are defined and must be completed prior to the expiration of certification. That is the real reason to book early. A major finding four weeks before expiry leaves you almost no room to fix it, verify it and get a decision made.

A six-month countdown

  1. Six months out. Confirm the ISO 27001 recertification audit date with your certification body. Check whether their accreditation and your audit will run under ISO/IEC 27006-1:2024 — see below.
  2. Five months out. Re-read the scope statement against how the business actually operates today. Raise a change with the certification body now if it has moved.
  3. Four months out. Reconcile the Statement of Applicability against all 93 Annex A controls and against the current risk treatment plan.
  4. Three months out. Complete a full-coverage internal audit, deliberately including areas surveillance never sampled.
  5. Two months out. Hold the management review. Close it with dated decisions and named owners.
  6. One month out. Clear every open corrective action and assemble evidence per clause and per control in one indexed place.
  7. Audit week. Brief control owners on what they own and where the evidence lives. Most avoidable findings are people not knowing the answer, not the answer being wrong.

What is different about recertification in 2026

Two changes make this cycle unusual.

First, ISO/IEC 27006-1:2024 was published in March 2024, and accredited certification bodies were required to complete transition to it. ANAB, for example, required all its accredited ISMS certification bodies to use ISO/IEC 27006-1:2024 for all clients no later than 31 March 2026. Practically, that means audit time for your recertification is likely being calculated under the revised Annex C rules, and remote auditing requirements have changed — the extent and effectiveness of remote auditing must now be recorded in the audit report.

Second, the ISO/IEC 27001:2013 to 2022 transition period closed on 31 October 2025. Every valid certificate is now against ISO/IEC 27001:2022. If your organization transitioned late in the window, the recertification audit may be the first time an auditor examines the 2022 control set at full depth rather than as a transition check. Separately, Amendment 1:2024 added climate action wording to clauses 4.1 and 4.2; ISO publishes it at no charge, and auditors will expect you to have considered whether climate change is a relevant issue for your ISMS, even if your documented answer is a reasoned “no.”

Frequently asked questions

How far in advance should I book the recertification audit?

Aim for the audit to complete three to four months before your expiry date. That leaves room to correct a major nonconformity and have the certification body verify it before expiry, which clause 9.6.3.2.2 requires.

Does an ISO 27001 recertification audit always include a Stage 1?

No. A Stage 1 is added where there have been significant changes to the management system, to the organization, or to the legislation affecting it. Most stable organizations go straight to the on-site reassessment.

Can the recertification audit be done remotely?

Recertification must include an on-site audit. ISO/IEC 27006-1:2024 sets requirements for how remote auditing techniques are deployed and requires the audit report to state their extent and effectiveness, so a hybrid approach is workable — a fully remote reassessment generally is not.

What happens to my certificate during the audit?

It remains valid until its expiry date. Certification is not paused while a recertification audit is in progress.

Will a minor nonconformity stop the certificate being renewed?

Not usually. Minor nonconformities require a reviewed and accepted corrective action plan. Major nonconformities must be corrected and the correction verified before expiry, or renewal is not recommended.

Getting ready

The organizations that pass an ISO 27001 recertification audit comfortably are the ones whose evidence was being generated all along rather than assembled in the final month. If your documentation has drifted over three years — an SoA that no longer matches the risk treatment plan, management review minutes that skipped a year, policies still carrying 2013-era control references — rebuilding from a maintained baseline is faster than patching.

Our ISO 27001 Toolkit includes 162 editable templates mapped to ISO/IEC 27001:2022, covering the mandatory documents, the Statement of Applicability, internal audit and management review records — the exact evidence set an ISO 27001 recertification audit works through. It is $99, one payment.

For the wider picture, start with our pillar guide to ISO 27001 certification, and for what happens in years one and two, read our guide to the ISO 27001 surveillance audit. The authoritative text of the standard itself is available from ISO.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.