
Getting certified is the part everyone plans for. Keeping the certificate is the part that turns up in the calendar every year afterwards, usually at a point when the people who ran the original project have moved on to something else.
An ISO 27001 certificate runs for three years. Two audits sit inside that period, a third closes it, and each of them is scheduled by the certification body.
Certification bodies operate to ISO/IEC 17021-1, which sets out how bodies auditing and certifying management systems have to run their audit programmes. UKAS accredits certification bodies against it, which is what stands behind an accredited certificate.
The shape is consistent. A surveillance audit falls at the end of year one and another at the end of year two. A recertification audit takes place before the certificate expires, covers considerably more than the surveillance audits, and starts the cycle again.
Surveillance audits are sampled. They are not a full reassessment of the management system, and they are shorter than the Stage 2 audit that produced the certificate. Certain areas come up every year regardless of what else is sampled: previous nonconformities, internal audit, management review and risk assessment.
That list is worth reading twice, because it describes the four things an organisation is most likely to have let slide.
The auditor is checking whether the management system has been operating, not whether it was designed well. Those produce different evidence.
A system that has been operating leaves a trail with dates spread across the year. Risk assessments revisited when something changed. Internal audit carried out against a plan. A management review with decisions in it. Nonconformities from last time, closed, with the closure recorded.
A system that has been dormant produces a similar-looking set of documents, all created in the fortnight before the audit. Auditors have seen both. The pattern is not subtle.
The most common finding is a control that exists with no record of anyone having checked it since the last audit.
Two ways, and neither involves a dramatic failure.
The first is timing. Where the recertification audit is not completed before the certificate expires, the certificate lapses. A certification body's diary is not infinitely flexible, and booking recertification in the month the certificate runs out leaves nothing for a corrective action round.
The second is unclosed nonconformities. Where findings are raised late in the cycle and corrective action runs past the expiry date, there is a gap between certificates while the work completes.
A lapsed certificate stops you making the claim commercially, and it does so at a moment nobody chose. The certificate has an expiry date printed on it, and the buyer who asked for it originally kept a copy. Enterprise procurement teams and framework operators re-check at renewal, so the gap is visible to exactly the audience it costs you something with.
There is a second-order version of this worth knowing about if you also hold Cyber Essentials. That certificate runs on a twelve-month cycle of its own, and Cyber Essentials Plus has to be completed within three months of the Cyber Essentials certification underneath it. Organisations holding several certifications end up with several independent calendars, none of which line up. See Cyber Essentials renewal 2026 and what a lapse costs.
The organisations that find surveillance audits uneventful are doing something ordinary. They record the work when it happens.
Four things are worth putting on a schedule with an owner against each, rather than leaving them to be remembered.
Internal audit, planned across the year so the programme covers the system over the cycle instead of sampling the same comfortable areas each time.
Management review, with the inputs the standard expects and decisions recorded, held often enough that it reflects the year.
Risk assessment revisited when something actually changes, which means a new supplier, a new product, a new location, or an incident, and not only on a date in the calendar.
Nonconformities from the last audit, closed and evidenced, well before the next one opens.
For the full requirement set, see the ISO 27001 framework page. If you are working towards a first certificate rather than maintaining one, how long ISO 27001, Cyber Essentials and DSPT take covers the sequence.
Naq gets an organisation audit-ready and keeps it that way between audits. The certificate itself is issued by a certification body accredited by UKAS.
Controls sit against the requirements they satisfy with evidence attached, so the state of the management system is something you can look at on any given week instead of assembling it before an audit. Reviews can be scheduled with an owner and an approver, so the responsibility for each one belongs to a person. Every change is recorded on the activity stream with previous and new values, and records are archived instead of deleted, which is what produces the dated trail an auditor is looking for.
The same evidence counts towards Cyber Essentials, the NHS DSPT, ISO 9001 and your GDPR obligations, so keeping one system current maintains the others alongside it.
If your next surveillance audit is inside the next six months, book a fifteen-minute demo and we will look at what the record shows today.