ISO 27001 recertification: how long a certificate lasts and how it is renewed
“The first three-year certification cycle begins with the certification decision. Subsequent cycles begin with the recertification decision” — BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text.
An ISO 27001 certificate does not renew itself. In the third year of every cycle the certification body audits the whole management system again and decides, afresh, whether to issue a new certificate. Most of what goes wrong at recertification is timing: an audit booked too close to the expiry date leaves no room to fix anything it finds.
Recertification vs surveillance vs initial certification
| Initial certification | Surveillance | Recertification | |
|---|---|---|---|
| When | Before the first certificate | Years 1 and 2; the first within 12 months of the decision | Year 3, before the certificate expires |
| Its purpose, in the standard's words | “The purpose of stage 2 is to evaluate the implementation, including effectiveness, of the client’s management system. The stage 2 shall take place at the site(s) of the client.” (Stage 2) | To maintain confidence that the certified system “continues to fulfil requirements between recertification audits” | “The purpose of the recertification audit is to confirm the continued conformity and effectiveness of the management system as a whole, and its continued relevance and applicability for the scope of certification.” |
| How much of the standard | All of it | “not necessarily full system audits” | “all of the requirements of the relevant management system standard” |
| Stage 1? | Always | No | Only where there have been significant changes |
| Audit time | The table figure for your headcount | One third of it | Two thirds of it |
| Looks back over | Nothing — there is no history yet | The previous audit's findings | The previous surveillance reports and the whole cycle |
| Major nonconformity must be closed | Verified within 6 months of the last Stage 2 day, or Stage 2 is repeated | Within a time the certification body defines | Implemented and verified before the certificate expires |
| Ends in | A certification decision | The certificate being maintained, or a review | A decision on renewing certification |
The row that matters most is the last-but-one. At the initial audit a major nonconformity delays the certificate. At recertification it can end it, because the fix has to be verified before the existing certificate runs out — and the standard does not let the old one be extended while you finish.
How long an ISO 27001 certificate is valid
Three years. The cycle is set out in BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text: “The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” Surveillance happens in years one and two (see surveillance audits); recertification in year three.
The expiry date is printed on the certificate
The certification documents must show, among other things, “the expiry date or recertification due date consistent with the recertification cycle”. That is the date to check before you rely on a supplier's certificate, and the one to diary for your own.
Finishing early does not cost you time
“When recertification activities are successfully completed prior to the expiry date of the existing certification, the expiry date of the new certification can be based on the expiry date of the existing certification. The issue date on a new certificate shall be on or after the recertification decision.” Put simply: if you are recertified three months before expiry, the new certificate's expiry can run on from the old one rather than from the new decision. There is no reason to leave the audit late in the hope of a longer certificate.
Some schemes use a different cycle
“If specified by the industry specific certification scheme, the certification cycle can be different from three years.” Nothing we have read for ISO 27001 sets a different period, but the note explains why you will occasionally see other cycles on other kinds of certificate.
What the recertification audit must cover
“A recertification audit shall be planned and conducted to evaluate the continued fulfilment of all of the requirements of the relevant management system standard or other normative document.” That is the difference from surveillance, which samples. Everything in clauses 4 to 10 is in play again. The on-site audit must address:
| The recertification audit shall include an on-site audit that addresses | |
|---|---|
| a | the effectiveness of the management system in its entirety in the light of internal and external changes and its continued relevance and applicability to the scope of certification |
| b | demonstrated commitment to maintain the effectiveness and improvement of the management system in order to enhance overall performance |
| c | the effectiveness of the management system with regard to achieving the certified client’s objectives and the intended results of the respective management system (s) |
It looks back over the whole cycle
“The recertification activity shall include the review of previous surveillance audit reports and consider the performance of the management system over the most recent certification cycle.” Three years of findings are read together. A minor issue raised at both surveillance audits and still visible at recertification is a pattern — and the standard's definition of a major nonconformity notes that several minors on the same requirement can “demonstrate a systemic failure”. See major and minor nonconformities.
When Stage 1 comes back
“Recertification audit activities may need to have a stage 1 in situations where there have been significant changes to the management system, the organization, or the context in which the management system is operating (e.g. changes to legislation).” A merger, a move from on-premises to cloud, a new regulator, or a scope that has quietly grown are all candidates. If your organisation has changed shape since the initial audit, expect the recertification to start with something like a Stage 1, and ask the certification body early whether it will.
Timing: plan backwards from the expiry date
The standard requires the recertification audit to be “planned and conducted in due time to enable for timely renewal before the certificate expiry date”. Two further rules make the timing matter.
Major nonconformities must be closed before expiry
“For any major nonconformity, the certification body shall define time limits for correction and corrective actions. These actions shall be implemented and verified prior to the expiration of certification.” Closing a major nonconformity means analysing the cause, correcting it and having the certification body verify the correction — possibly with a further visit. None of that is quick, and all of it has to fit between the audit and the expiry date.
If it is not finished in time
“If the certification body has not completed the recertification audit or the certification body is unable to verify the implementation of corrections and corrective actions for any major nonconformity (see 9.5.2.1) prior to the expiry date of the certification, then recertification shall not be recommended and the validity of the certification shall not be extended. The client shall be informed and the consequences shall be explained.”
That sentence is the whole risk. The certificate is not rolled over while paperwork catches up. For a supplier whose contracts require a current certificate, the gap between expiry and a new decision is a gap in which the contract condition is not met.
A rule of thumb, not a rule
The standard does not say how many months before expiry to audit. Our suggestion is to work backwards: the certification body's lead time, plus the audit, plus a realistic time to correct and verify a major nonconformity. Do that arithmetic when the second surveillance audit is booked, not after it.
What happens if the certificate expires
There is a way back, and it is narrow. “Following expiration of certification, the certification body can restore certification within 6 months provided that the outstanding recertification activities are completed, otherwise at least a stage 2 shall be conducted. The effective date on the certificate shall be on or after the recertification decision and the expiry date shall be based on prior certification cycle.”
Inside the 6 months
If the outstanding recertification work is completed within 6 months of expiry, the certification body can restore the certificate. The new certificate's effective date is on or after the recertification decision, so the period in between is not covered.
After the 6 months
At least a Stage 2 audit is needed. And in either case the expiry date is “based on prior certification cycle” — the lapse does not reset the clock in your favour.
How many days recertification takes
Under the information security audit-time rules, recertification is two thirds of the initial certification audit, and each surveillance audit is one third. Add them up and a full cycle is two and a third times the initial audit in auditor time, spread over three years.
| People in scope | Initial audit days | Recertification days | Days over the full cycle |
|---|---|---|---|
| 10 | 5 | 3.33 | 11.67 |
| 25 | 7 | 4.67 | 16.33 |
| 50 | 10 | 6.67 | 23.33 |
| 100 | 12 | 8 | 28 |
| 250 | 14 | 9.33 | 32.67 |
The fee for those days is the certification body's rate, which is not published in any standard; the cost page shows our estimated range and how we built it, and the calculator adjusts the day count for sites and complexity. Auditor travel is additional to all of these figures.
Who decides, and on what
“The certification body shall make decisions on renewing certification based on the results of the recertification audit, as well as the results of the review of the system over the period of certification and complaints received from users of certification.” Note the last item. Complaints received from users of certification — your customers, for example — are part of the renewal decision, not only the audit.
And the decision is not the auditor's: “The certification body shall ensure that the persons or committees that make the decisions for granting or refusing certification, expanding or reducing the scope of certification, suspending or restoring certification, withdrawing certification or renewing certification are different from those who carried out the audits.” The audit team recommends. Somebody else at the certification body decides.
Suspension, withdrawal and a reduced scope
A certificate can stop being valid before its expiry date. The standard gives three examples of when a certification body shall suspend one:
- the client’s certified management system has persistently or seriously failed to meet certification requirements, including requirements for the effectiveness of the management system
- the certified client does not allow surveillance or recertification audits to be conducted at the required frequencies
- the certified client has voluntarily requested a suspension
What suspension means
“Under suspension, the client’s management system certification is temporarily invalid.” It is restored if the problem is fixed: “The certification body shall restore the suspended certification if the issue that has resulted in the suspension has been resolved. Failure to resolve the issues that have resulted in the suspension in a time established by the certification body shall result in withdrawal or reduction of the scope of certification.” The standard adds: “In most cases, the suspension would not exceed six months.”
Reducing the scope instead
“The certification body shall reduce the scope of certification to exclude the parts not meeting the requirements, when the certified client has persistently or seriously failed to meet the certification requirements for those parts of the scope of certification.” A certificate that survives with a smaller scope may no longer cover the service a customer bought. Check the scope wording on the new certificate against every contract that relies on it.
Changing certification body at recertification
Recertification is the natural point to move, because the next cycle starts anyway. The standard requires the new body to have a process: “When a transfer of certification is envisaged from one certification body to another, the accepting certification body shall have a process for obtaining sufficient information in order to take a decision on certification.” If it takes account of your existing certificate and the previous body's audits, “Where the certification body is taking account of certification already granted to the client and to audits performed by another certification body, it shall obtain and retain sufficient evidence, such as reports and documentation on corrective actions, to any nonconformity.” It also notes that “Certification schemes can have specific rules regarding the transfer of certification.” — we have not read those scheme rules and do not summarise them here. Our page on choosing a certification body covers what to ask.
The first recertification under the 2022 edition
Certificates against ISO/IEC 27001:2013 ceased to be valid on 31 October 2025. Every recertification from here on is against ISO/IEC 27001:2022, whose Annex A has 93 controls against the old edition's 114. A certificate still naming the 2013 edition is not a current certificate, whatever expiry date it shows — worth knowing when you check a supplier's.
We cannot audit or certify anything, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. The pattern the standard itself points at is simple: recertifications that go wrong are usually booked too late, not failed on the day.
A recertification checklist
- Find the expiry date on the certificate and count back: lead time, audit, time to close a major nonconformity.
- Re-read both surveillance reports. The recertification audit will.
- List what has changed since the initial audit, and ask whether it amounts to a Stage 1.
- Run a full internal audit across every clause, because the recertification audit covers every requirement.
- Check the scope still describes the business, and that the Statement of Applicability matches it.
- Decide whether to stay with your certification body before you book, not after.
Where this fits
- Surveillance audits
- Major and minor nonconformities
- The whole process
- What it costs over three years
- Choosing a certification body
Common questions
How long is an ISO 27001 certificate valid?
Three years. ISO/IEC 17021-1 sets the cycle: “The first three-year certification cycle begins with the certification decision. Subsequent cycles begin with the recertification decision”. The certificate itself must show “the expiry date or recertification due date consistent with the recertification cycle”. It stays valid through the cycle as long as it is not suspended or withdrawn — and not allowing the surveillance audits in between is one of the standard's own examples of grounds for suspension.
What is an ISO 27001 recertification audit?
The audit in year three that decides whether you get a new certificate. “The purpose of the recertification audit is to confirm the continued conformity and effectiveness of the management system as a whole, and its continued relevance and applicability for the scope of certification.” Unlike a surveillance audit, it covers all of the requirements of the standard, and it looks back over the previous surveillance reports and the whole cycle.
How long does ISO 27001 recertification take?
Two thirds of the initial certification audit time. For 25 people in scope with no adjustments, that is 4.67 days against 7 for the initial audit. Allow time after it, too: any major nonconformity has to be implemented and verified before the certificate expires.
What happens if our ISO 27001 certificate expires?
It is no longer valid, and it is not extended. But the standard allows a way back: “Following expiration of certification, the certification body can restore certification within 6 months provided that the outstanding recertification activities are completed, otherwise at least a stage 2 shall be conducted. The effective date on the certificate shall be on or after the recertification decision and the expiry date shall be based on prior certification cycle.” Note the last part — a late renewal does not buy you a later expiry date.
When should we book the recertification audit?
Early enough to finish before expiry with room to close a major nonconformity. The standard requires the audit to be “planned and conducted in due time to enable for timely renewal before the certificate expiry date”, and it also requires any major nonconformity to be implemented and verified before expiration. An audit booked for the last fortnight of the cycle leaves no time for either.
Does recertification start a new three-year cycle?
Yes. “Subsequent cycles begin with the recertification decision”. And if you finish early you do not lose time: “the expiry date of the new certification can be based on the expiry date of the existing certification”.
Can we change certification body at recertification?
Yes. The accepting body must have a process for it: “When a transfer of certification is envisaged from one certification body to another, the accepting certification body shall have a process for obtaining sufficient information in order to take a decision on certification.” If it takes account of your existing certificate and the previous body's audits, it must obtain evidence such as the reports and the documentation on corrective actions. And “Certification schemes can have specific rules regarding the transfer of certification.”
Can an ISO 27001 certificate be suspended before it expires?
Yes. The standard's examples include a management system that has persistently or seriously failed to meet the requirements, and a client that does not allow surveillance or recertification audits at the required frequencies. “Under suspension, the client’s management system certification is temporarily invalid.”
Sources cited on this page
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Recertification due?
Say when your certificate expires. A full internal audit before the recertification visit is the usual place a consultancy helps.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.