ISO 27001 major vs minor nonconformity: what each means and what happens next
“If the certification body is not able to verify the implementation of corrections and corrective actions of any major nonconformity within 6 months after the last day of stage 2, the certification body shall conduct another stage 2 prior to recommending certification.” — ISO/IEC 17021-1:2015 clause 9.5.3.2.
A nonconformity is what an auditor writes down when something required is not happening. Whether it is major or minor decides what your certification body needs from you before it can issue, keep or renew a certificate — and at two points in the cycle, the difference is measured in months.
Major vs minor nonconformity, side by side
| Major nonconformity | Minor nonconformity | |
|---|---|---|
| Definition (verbatim) | “nonconformity (3.11) that affects the capability of the management system to achieve the intended results” | “nonconformity (3.11) that does not affect the capability of the management system to achieve the intended results” |
| What tips it | Significant doubt that effective process control is in place — or several minors on the same requirement that show a systemic failure | — |
| Before the initial certification decision | The certification body must have “reviewed, accepted and verified the correction and corrective actions” | The certification body must have “reviewed and accepted the client’s plan for correction and corrective action” |
| If it is not closed after Stage 2 | Not verified within 6 months of the last day of Stage 2 ⇒ another Stage 2 | No separate deadline in the standard |
| At a surveillance audit | Reported for review by people other than the auditors, to decide whether certification can be maintained | Corrected within the time the certification body defines; reviewed at the next audit |
| At recertification | Implemented and verified before the certificate expires, or it is not renewed | Corrected within the time the certification body defines |
| Can it be logged as an “opportunity for improvement”? | No | No |
The definitions turn on a single idea: whether the problem “affects the capability of the management system to achieve the intended results”. A missed step in a process that otherwise works is minor. A process that cannot be shown to work at all — or the same small failure turning up across the business — is major.
What a nonconformity is
The definition is five words: “non-fulfilment of a requirement”. The requirement can be a clause of ISO/IEC 27001, or something your own management system commits you to — a policy that is not followed, a review that did not happen when the procedure says it would.
What the finding must contain
“A finding of nonconformity shall be recorded against a specific requirement, and shall contain a clear statement of the nonconformity, identifying in detail the objective evidence on which the nonconformity is based.” That gives you three things to check on every nonconformity you receive: which requirement, what the statement says, and what evidence it rests on. A finding that cannot point to all three is one to question before the auditor leaves.
The auditor will not tell you how to fix it
“Nonconformities shall be discussed with the client to ensure that the evidence is accurate and that the nonconformities are understood. The auditor however shall refrain from suggesting the cause of nonconformities or their solution.” And in the written report: “The audit team may identify opportunities for improvement but shall not recommend specific solutions.” This is the impartiality rule at work. The certification body cannot consult for you, so the diagnosis and the fix are yours to produce.
Opportunities for improvement are something else
“Opportunities for improvement may be identified and recorded, unless prohibited by the requirements of a management system certification scheme. Audit findings, however, which are nonconformities, shall not be recorded as opportunities for improvement.” An opportunity for improvement is advice you may act on or not. If an auditor has found a requirement not being met, it cannot be downgraded to one.
When a finding is major
A major nonconformity is a “nonconformity (3.11) that affects the capability of the management system to achieve the intended results”. The note to the definition gives two circumstances in which nonconformities could be classified as major:
- if there is a significant doubt that effective process control is in place, or that products or services will meet specified requirements
- a number of minor nonconformities associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity
Several minors can add up to a major
The second bullet is the one that catches organisations out. The same small failure found in three departments is not three minor findings; it can be read as evidence that the process itself does not work. Recertification, which reviews the whole cycle's reports, is where a pattern across years becomes visible.
What does not make it major
Severity in the everyday sense is not the test; capability is. Two illustrations of our own, not the standard's: a single missed access review, found and documented, affects one control on one occasion; a risk assessment nobody has repeated since certification leaves the system unable to show it is managing risk at all. Read against the definition, the first looks minor and the second major. The line is drawn by the auditor, against the definition — which is why the next section matters.
At the closing meeting
“Any nonconformities shall be presented in such a manner that they are understood, and the timeframe for responding shall be agreed.” The standard then adds a note that is worth knowing: ““Understood” does not necessarily mean that the nonconformities have been accepted by the client.”
Among the things the certification body must tell you at that meeting:
| The closing meeting shall also include | |
|---|---|
| c | the certification body’s process for handling nonconformities including any consequences relating to the status of the client’s certification |
| d | the timeframe for the client to present a plan for correction and corrective action for any nonconformities identified during the audit |
If you disagree
“The audit team leader shall attempt to resolve any diverging opinions between the audit team and the client concerning audit evidence or findings, and unresolved points shall be recorded.” And at the closing meeting, “Any diverging opinions that are not resolved shall be recorded and referred to the certification body.” Put your view on the record at the time, so that there is something to refer back to if you later use the certification body's complaint and appeal process.
What you have to send back
“The certification body shall require the client to analyse the cause and describe the specific correction and corrective actions taken, or planned to be taken, to eliminate detected nonconformities, within a defined time.”
Cause, correction, corrective action
The standard asks for three distinct things, and it helps to keep them separate in what you send back. The cause is why it happened. The correction deals with the instance that was found. The corrective action removes the cause so that it does not happen again. Formal definitions of the last two sit in ISO/IEC 27000, which we have not quoted here; the working distinction above is how 17021-1 uses the terms.
How the certification body checks it
“The certification body shall review the corrections, identified causes and corrective actions submitted by the client to determine if these are acceptable. The certification body shall verify the effectiveness of any correction and corrective actions taken.” How it verifies depends on the finding: “The client shall be informed if an additional full audit, an additional limited audit, or documented evidence (to be confirmed during future audits) will be needed to verify effective correction and corrective actions.” And the note: “Verification of effectiveness of correction and corrective action can be carried out based on a review of documented information provided by the client, or where necessary, through verification on-site. Usually this activity is done by a member of the audit team.”
An additional audit is additional audit time — ask your certification body how it charges for one before you need it. For a major nonconformity, that extra visit is often the most concrete cost: not the finding itself, but verifying the fix.
Deadlines at each stage of the cycle
| Audit | Major nonconformity | Minor nonconformity | Clause |
|---|---|---|---|
| Initial certification | Correction and corrective action verified before the decision; if not within 6 months of the last Stage 2 day, a new Stage 2 | Plan for correction and corrective action accepted before the decision | 9.5.2, 9.5.3.2 |
| Surveillance | Cause, correction and corrective action within a defined time; review of whether the certificate can be maintained | Cause, correction and corrective action within a defined time | 9.4.9, 9.6.1 |
| Recertification | Implemented and verified before expiry; otherwise not renewed and not extended | Cause, correction and corrective action within a defined time | 9.6.3.2.2, 9.6.3.2.4 |
At initial certification
Before deciding, the certification body must have, “for any major nonconformities, it has reviewed, accepted and verified the correction and corrective actions”, and “for any minor nonconformities it has reviewed and accepted the client’s plan for correction and corrective action”. For a major nonconformity the 6-month limit then applies. Miss it and the Stage 2 audit is repeated — paid for again, and scheduled again.
At surveillance
A major nonconformity at a surveillance audit is reported for a review by competent people other than those who did the audit, to decide whether the certificate can be maintained. Every surveillance audit also includes “a review of actions taken on nonconformities identified during the previous audit”, so a minor raised this year is checked next year.
At recertification
“For any major nonconformity, the certification body shall define time limits for correction and corrective actions. These actions shall be implemented and verified prior to the expiration of certification.” If that does not happen, “recertification shall not be recommended and the validity of the certification shall not be extended”. See recertification for why this is the strongest argument for booking the audit early.
What the standard does not set
A number of days for closing a minor nonconformity. That is agreed with your certification body at the closing meeting. If a figure is quoted to you as the standard's, ask which clause.
Your own nonconformities: ISO 27001 clause 10.2
Everything above is about the certification body's findings. ISO/IEC 27001 also requires your management system to handle nonconformities it finds itself — through your internal audit, incidents, or anyone noticing that a control is not operating. The clause is 10.2, “Nonconformity and corrective action”, in the standard's improvement clause. We have read its title, not its text, so we do not paraphrase it here.
What we can say from 17021-1 is how the two connect. Stage 2 and every surveillance audit examine your internal audits, and a nonconformity your own system found, recorded and corrected is evidence that the system works. The same issue found first by the certification body is a finding against you.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. The pattern that follows from the standard is that the cheapest nonconformity is the one your own internal audit found first.
Responding to a nonconformity, step by step
- At the audit, check the three parts: the requirement, the statement, the evidence. Raise disagreement then, so it is recorded.
- Agree the timeframe at the closing meeting, and diary it.
- Find the cause before writing the fix. The standard asks for the cause analysis explicitly, not only the correction.
- Separate correction from corrective action in what you submit.
- Keep the evidence that it worked. The next audit reviews it.
- For a major, count back from the deadline: 6 months after Stage 2, or the certificate's expiry date.
Where this fits
Common questions
What is the difference between a major and a minor nonconformity?
Whether it affects what the management system can achieve. ISO/IEC 17021-1 defines a major nonconformity as a “nonconformity (3.11) that affects the capability of the management system to achieve the intended results” and a minor one as a “nonconformity (3.11) that does not affect the capability of the management system to achieve the intended results”. The practical difference is in what the certification body needs before it can decide: for a major, the correction must be verified; for a minor, your plan must be accepted.
What is a nonconformity in ISO 27001?
A nonconformity is “non-fulfilment of a requirement” — the definition in ISO/IEC 17021-1, the standard certification bodies audit to. A finding of nonconformity must be recorded against a specific requirement, with the objective evidence it is based on.
Can you get ISO 27001 certified with a major nonconformity?
Not until it is dealt with. Before the certification decision the certification body must have “for any major nonconformities, it has reviewed, accepted and verified the correction and corrective actions”. And “If the certification body is not able to verify the implementation of corrections and corrective actions of any major nonconformity within 6 months after the last day of stage 2, the certification body shall conduct another stage 2 prior to recommending certification.”
Can you get certified with minor nonconformities?
Yes, if the certification body accepts your plan to fix them. Before the decision it must have “for any minor nonconformities it has reviewed and accepted the client’s plan for correction and corrective action” — the plan, not the completed fix. The next audit will check that the plan was carried out.
How long do you have to close a nonconformity?
The standard does not set a number of days for most cases. It requires the certification body to make you analyse the cause and describe the correction and corrective action “within a defined time”, and the timeframe is agreed at the closing meeting. It does set two hard limits for major nonconformities: 6 months after the last day of Stage 2 at initial certification, and the certificate's expiry date at recertification.
Can several minor nonconformities become a major one?
Yes. The note to the definition says that “a number of minor nonconformities associated with the same requirement or issue could demonstrate a systemic failure and thus constitute a major nonconformity”.
Will the auditor tell us how to fix a nonconformity?
No. The standard says the auditor “shall refrain from suggesting the cause of nonconformities or their solution”, and that “The audit team may identify opportunities for improvement but shall not recommend specific solutions.” Certification bodies are also barred from consultancy. Working out the fix is yours — or a consultant's.
What if we disagree with a nonconformity?
Say so at the audit. The audit team leader must try to resolve diverging opinions, and “Any diverging opinions that are not resolved shall be recorded and referred to the certification body.” The certification body must also tell you at the closing meeting about its complaint and appeal processes.
Sources cited on this page
- BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Holding a nonconformity with a deadline?
Say what was raised and when it is due. Root-cause work and the corrective action plan are what a consultancy can help with.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.