iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 major vs minor nonconformity: what each means and what happens next

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 10 min read
5 primary sources cited on this page. How we check what is on this site
The hard deadline 6 months after Stage 2

“If the certification body is not able to verify the implementation of corrections and corrective actions of any major nonconformity within 6 months after the last day of stage 2, the certification body shall conduct another stage 2 prior to recommending certification.” — ISO/IEC 17021-1:2015 clause 9.5.3.2.

A nonconformity is what an auditor writes down when something required is not happening. Whether it is major or minor decides what your certification body needs from you before it can issue, keep or renew a certificate — and at two points in the cycle, the difference is measured in months.

Major vs minor nonconformity, side by side

Major and minor nonconformities in ISO/IEC 17021-1, the standard certification bodies work to
Major nonconformityMinor nonconformity
Definition (verbatim)“nonconformity (3.11) that affects the capability of the management system to achieve the intended results”“nonconformity (3.11) that does not affect the capability of the management system to achieve the intended results”
What tips itSignificant doubt that effective process control is in place — or several minors on the same requirement that show a systemic failure
Before the initial certification decisionThe certification body must have “reviewed, accepted and verified the correction and corrective actions”The certification body must have “reviewed and accepted the client’s plan for correction and corrective action”
If it is not closed after Stage 2Not verified within 6 months of the last day of Stage 2 ⇒ another Stage 2No separate deadline in the standard
At a surveillance auditReported for review by people other than the auditors, to decide whether certification can be maintainedCorrected within the time the certification body defines; reviewed at the next audit
At recertificationImplemented and verified before the certificate expires, or it is not renewedCorrected within the time the certification body defines
Can it be logged as an “opportunity for improvement”?NoNo

The definitions turn on a single idea: whether the problem “affects the capability of the management system to achieve the intended results”. A missed step in a process that otherwise works is minor. A process that cannot be shown to work at all — or the same small failure turning up across the business — is major.

What a nonconformity is

The definition is five words: “non-fulfilment of a requirement”. The requirement can be a clause of ISO/IEC 27001, or something your own management system commits you to — a policy that is not followed, a review that did not happen when the procedure says it would.

What the finding must contain

“A finding of nonconformity shall be recorded against a specific requirement, and shall contain a clear statement of the nonconformity, identifying in detail the objective evidence on which the nonconformity is based.” That gives you three things to check on every nonconformity you receive: which requirement, what the statement says, and what evidence it rests on. A finding that cannot point to all three is one to question before the auditor leaves.

The auditor will not tell you how to fix it

“Nonconformities shall be discussed with the client to ensure that the evidence is accurate and that the nonconformities are understood. The auditor however shall refrain from suggesting the cause of nonconformities or their solution.” And in the written report: “The audit team may identify opportunities for improvement but shall not recommend specific solutions.” This is the impartiality rule at work. The certification body cannot consult for you, so the diagnosis and the fix are yours to produce.

Opportunities for improvement are something else

“Opportunities for improvement may be identified and recorded, unless prohibited by the requirements of a management system certification scheme. Audit findings, however, which are nonconformities, shall not be recorded as opportunities for improvement.” An opportunity for improvement is advice you may act on or not. If an auditor has found a requirement not being met, it cannot be downgraded to one.

When a finding is major

A major nonconformity is a “nonconformity (3.11) that affects the capability of the management system to achieve the intended results”. The note to the definition gives two circumstances in which nonconformities could be classified as major:

  • if there is a significant doubt that effective process control is in place, or that products or services will meet specified requirements
  • a number of minor nonconformities associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity

Several minors can add up to a major

The second bullet is the one that catches organisations out. The same small failure found in three departments is not three minor findings; it can be read as evidence that the process itself does not work. Recertification, which reviews the whole cycle's reports, is where a pattern across years becomes visible.

What does not make it major

Severity in the everyday sense is not the test; capability is. Two illustrations of our own, not the standard's: a single missed access review, found and documented, affects one control on one occasion; a risk assessment nobody has repeated since certification leaves the system unable to show it is managing risk at all. Read against the definition, the first looks minor and the second major. The line is drawn by the auditor, against the definition — which is why the next section matters.

At the closing meeting

“Any nonconformities shall be presented in such a manner that they are understood, and the timeframe for responding shall be agreed.” The standard then adds a note that is worth knowing: ““Understood” does not necessarily mean that the nonconformities have been accepted by the client.”

Among the things the certification body must tell you at that meeting:

What the closing meeting shall include (ISO/IEC 17021-1:2015 clause 9.4.7.2), verbatim extract
The closing meeting shall also include
cthe certification body’s process for handling nonconformities including any consequences relating to the status of the client’s certification
dthe timeframe for the client to present a plan for correction and corrective action for any nonconformities identified during the audit

If you disagree

“The audit team leader shall attempt to resolve any diverging opinions between the audit team and the client concerning audit evidence or findings, and unresolved points shall be recorded.” And at the closing meeting, “Any diverging opinions that are not resolved shall be recorded and referred to the certification body.” Put your view on the record at the time, so that there is something to refer back to if you later use the certification body's complaint and appeal process.

What you have to send back

“The certification body shall require the client to analyse the cause and describe the specific correction and corrective actions taken, or planned to be taken, to eliminate detected nonconformities, within a defined time.”

Cause, correction, corrective action

The standard asks for three distinct things, and it helps to keep them separate in what you send back. The cause is why it happened. The correction deals with the instance that was found. The corrective action removes the cause so that it does not happen again. Formal definitions of the last two sit in ISO/IEC 27000, which we have not quoted here; the working distinction above is how 17021-1 uses the terms.

How the certification body checks it

“The certification body shall review the corrections, identified causes and corrective actions submitted by the client to determine if these are acceptable. The certification body shall verify the effectiveness of any correction and corrective actions taken.” How it verifies depends on the finding: “The client shall be informed if an additional full audit, an additional limited audit, or documented evidence (to be confirmed during future audits) will be needed to verify effective correction and corrective actions.” And the note: “Verification of effectiveness of correction and corrective action can be carried out based on a review of documented information provided by the client, or where necessary, through verification on-site. Usually this activity is done by a member of the audit team.”

An additional audit is additional audit time — ask your certification body how it charges for one before you need it. For a major nonconformity, that extra visit is often the most concrete cost: not the finding itself, but verifying the fix.

Deadlines at each stage of the cycle

When nonconformities have to be dealt with, from ISO/IEC 17021-1
AuditMajor nonconformityMinor nonconformityClause
Initial certificationCorrection and corrective action verified before the decision; if not within 6 months of the last Stage 2 day, a new Stage 2Plan for correction and corrective action accepted before the decision9.5.2, 9.5.3.2
SurveillanceCause, correction and corrective action within a defined time; review of whether the certificate can be maintainedCause, correction and corrective action within a defined time9.4.9, 9.6.1
RecertificationImplemented and verified before expiry; otherwise not renewed and not extendedCause, correction and corrective action within a defined time9.6.3.2.2, 9.6.3.2.4

At initial certification

Before deciding, the certification body must have, “for any major nonconformities, it has reviewed, accepted and verified the correction and corrective actions”, and “for any minor nonconformities it has reviewed and accepted the client’s plan for correction and corrective action”. For a major nonconformity the 6-month limit then applies. Miss it and the Stage 2 audit is repeated — paid for again, and scheduled again.

At surveillance

A major nonconformity at a surveillance audit is reported for a review by competent people other than those who did the audit, to decide whether the certificate can be maintained. Every surveillance audit also includes “a review of actions taken on nonconformities identified during the previous audit”, so a minor raised this year is checked next year.

At recertification

“For any major nonconformity, the certification body shall define time limits for correction and corrective actions. These actions shall be implemented and verified prior to the expiration of certification.” If that does not happen, “recertification shall not be recommended and the validity of the certification shall not be extended”. See recertification for why this is the strongest argument for booking the audit early.

What the standard does not set

A number of days for closing a minor nonconformity. That is agreed with your certification body at the closing meeting. If a figure is quoted to you as the standard's, ask which clause.

Your own nonconformities: ISO 27001 clause 10.2

Everything above is about the certification body's findings. ISO/IEC 27001 also requires your management system to handle nonconformities it finds itself — through your internal audit, incidents, or anyone noticing that a control is not operating. The clause is 10.2, “Nonconformity and corrective action”, in the standard's improvement clause. We have read its title, not its text, so we do not paraphrase it here.

What we can say from 17021-1 is how the two connect. Stage 2 and every surveillance audit examine your internal audits, and a nonconformity your own system found, recorded and corrected is evidence that the system works. The same issue found first by the certification body is a finding against you.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. The pattern that follows from the standard is that the cheapest nonconformity is the one your own internal audit found first.

Responding to a nonconformity, step by step

  1. At the audit, check the three parts: the requirement, the statement, the evidence. Raise disagreement then, so it is recorded.
  2. Agree the timeframe at the closing meeting, and diary it.
  3. Find the cause before writing the fix. The standard asks for the cause analysis explicitly, not only the correction.
  4. Separate correction from corrective action in what you submit.
  5. Keep the evidence that it worked. The next audit reviews it.
  6. For a major, count back from the deadline: 6 months after Stage 2, or the certificate's expiry date.

Where this fits

Common questions

What is the difference between a major and a minor nonconformity?

Whether it affects what the management system can achieve. ISO/IEC 17021-1 defines a major nonconformity as a “nonconformity (3.11) that affects the capability of the management system to achieve the intended results” and a minor one as a “nonconformity (3.11) that does not affect the capability of the management system to achieve the intended results”. The practical difference is in what the certification body needs before it can decide: for a major, the correction must be verified; for a minor, your plan must be accepted.

What is a nonconformity in ISO 27001?

A nonconformity is “non-fulfilment of a requirement” — the definition in ISO/IEC 17021-1, the standard certification bodies audit to. A finding of nonconformity must be recorded against a specific requirement, with the objective evidence it is based on.

Can you get ISO 27001 certified with a major nonconformity?

Not until it is dealt with. Before the certification decision the certification body must have “for any major nonconformities, it has reviewed, accepted and verified the correction and corrective actions”. And “If the certification body is not able to verify the implementation of corrections and corrective actions of any major nonconformity within 6 months after the last day of stage 2, the certification body shall conduct another stage 2 prior to recommending certification.”

Can you get certified with minor nonconformities?

Yes, if the certification body accepts your plan to fix them. Before the decision it must have “for any minor nonconformities it has reviewed and accepted the client’s plan for correction and corrective action” — the plan, not the completed fix. The next audit will check that the plan was carried out.

How long do you have to close a nonconformity?

The standard does not set a number of days for most cases. It requires the certification body to make you analyse the cause and describe the correction and corrective action “within a defined time”, and the timeframe is agreed at the closing meeting. It does set two hard limits for major nonconformities: 6 months after the last day of Stage 2 at initial certification, and the certificate's expiry date at recertification.

Can several minor nonconformities become a major one?

Yes. The note to the definition says that “a number of minor nonconformities associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity”.

Will the auditor tell us how to fix a nonconformity?

No. The standard says the auditor “shall refrain from suggesting the cause of nonconformities or their solution”, and that “The audit team may identify opportunities for improvement but shall not recommend specific solutions.” Certification bodies are also barred from consultancy. Working out the fix is yours — or a consultant's.

What if we disagree with a nonconformity?

Say so at the audit. The audit team leader must try to resolve diverging opinions, and “Any diverging opinions that are not resolved shall be recorded and referred to the certification body.” The certification body must also tell you at the closing meeting about its complaint and appeal processes.

Sources cited on this page

  1. BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
  2. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
  3. BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
  4. BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
  5. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Holding a nonconformity with a deadline?

Say what was raised and when it is due. Root-cause work and the corrective action plan are what a consultancy can help with.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now