ISO 27001 surveillance audits: how often, how many days, and what is checked
“Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.” — BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text.
An ISO 27001 certificate is not a one-off. From the day it is granted, the certification body is required to keep checking that it still deserves to exist, and the main way it does that is the surveillance audit. It is smaller than the audit that got you certified, it happens every year, and it is the audit people most often under-prepare for — because the first one arrives just as the project team has moved on.
Surveillance audits at a glance
| Question | Answer | Clause |
|---|---|---|
| How often? | At least once every calendar year, except the year of recertification | 9.1.3.3 |
| When is the first one? | No more than 12 months after the certification decision date — not the Stage 2 date | 9.1.3.3 |
| How many per cycle? | Two: in the first and second years of the 3-year cycle | 9.1.3.2 |
| Is it a full audit? | No — “not necessarily full system audits” | 9.6.2.2 |
| On site? | Yes — “Surveillance audits are on-site audits” | 9.6.2.2 |
| How long? | One third of the initial audit time. At 25 people in scope: 2.33 days | ISO/IEC 27006 |
| What must it cover? | Eight items every time, starting with your internal audits and management review | 9.6.2.2 a)–h) |
| What if you skip it? | Refusing surveillance at the required frequency is one of the standard's examples of grounds for suspension | 9.6.5.2 |
Every row except the audit-day figure comes from ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1, the standard that every accredited certification body is assessed against. The day count comes from the separate rules for information security audits, which set surveillance at a fixed fraction of the initial audit. Neither is a certification body's house policy.
When they happen: the three-year cycle
The standard sets out the whole cycle in one sentence: “The audit programme for the initial certification shall include a two-stage initial audit, surveillance audits in the first and second years following the certification decision, and a recertification audit in the third year prior to expiration of certification.” And it says when the clock starts: “The first three-year certification cycle begins with the certification decision. Subsequent cycles begin with the recertification decision”.
| When | What | Where it is covered |
|---|---|---|
| Year 0 | Initial audit in two stages, then the certification decision | Stage 1 and Stage 2 |
| Year 1 | First surveillance audit — no later than 12 months after the certification decision | This page |
| Year 2 | Second surveillance audit — at least once in the calendar year | This page |
| Year 3 | Recertification audit, before the certificate expires | Recertification |
The first one is tied to the decision date, not the audit date
The 12-month limit runs from “the certification decision date”. The decision is taken after Stage 2, by people other than the auditors, so it is always a little later than your last audit day. The certificate must show “the effective date of granting … certification”; if you are not sure that is the decision date, ask. Then put the surveillance deadline in the diary the day the certificate arrives.
After that, the rule is per calendar year
For the later surveillance audits the requirement is written as “at least once a calendar year”, rather than as a fixed number of months after the previous visit. In practice most certification bodies keep roughly the same month each year, but that is their scheduling, not the standard. Ask yours how it plans the cycle when you sign.
When the frequency can be different
The standard allows for it: “It can be necessary to adjust the frequency of surveillance audits to accommodate factors such as seasons or management systems certification of a limited duration (e.g. temporary construction site).” The whole programme can also be adjusted. “The determination of the audit programme and any subsequent adjustments shall consider the size of the client, the scope and complexity of its management system, products and processes as well as demonstrated level of management system effectiveness and the results of any previous audits.” A management system that performed well and had few findings is, on the standard's own terms, a reason for the body to revisit its programme — and so is the opposite.
It also lists things that can be taken into account, among them:
- complaints received by the certification body about the client
- combined, integrated or joint audit
- changes to the certification requirements
- changes to legal requirements
- changes to accreditation requirements
- organizational performance data (e.g. defect levels, key performance indicators data)
- relevant interested parties’ concerns
What every surveillance audit must include
BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text sets out a list that applies to each surveillance audit, not to the cycle as a whole. The left two columns are the standard, verbatim. The right-hand column is our reading of what each item usually means for an information security management system — it is interpretation, not quotation.
| The standard (verbatim) | In an ISMS, usually (our reading) | |
|---|---|---|
| a | internal audits and management review | This year's internal audit report and management review record |
| b | a review of actions taken on nonconformities identified during the previous audit | Evidence that last audit's findings were closed, and that the fix held |
| c | complaints handling | How complaints reached you and what you did with them |
| d | effectiveness of the management system with regard to achieving the certified client’s objectives and the intended results of the respective management system (s) | Whether your information security objectives are being met, with the measurements |
| e | progress of planned activities aimed at continual improvement | What you set out to improve, and whether it happened |
| f | continuing operational control | That the controls in your Statement of Applicability are still operating |
| g | review of any changes | New systems, suppliers, sites, people, or scope since the last visit |
| h | use of marks and/or any other reference to certification | Where you say you are certified — website, bids, email signatures — and whether it is accurate |
Item (a): the internal audit and management review, every year
These are the two activities that decide whether Stage 1 lets you through to Stage 2, and they do not stop once you are certified. Each surveillance audit examines them again. A year in which neither happened is not a quiet year; it is a surveillance audit with an obvious finding.
Item (b): last year's findings
Whatever was raised at the previous audit comes back. The auditor reviews “actions taken on nonconformities identified during the previous audit” — not only whether a fix was applied, but whether it worked. See major and minor nonconformities for what the certification body needs from you after each one.
Item (g): what has changed
A new cloud provider, an acquisition, a move to a new office, a large hiring round. Changes are where last year's risk assessment stops describing this year's organisation, and so they are where auditors look first. Keep a running list through the year; it is quicker than reconstructing one the week before.
Item (h): how you describe your certificate
Every surveillance audit covers the “use of marks and/or any other reference to certification”. That includes the claims your sales team makes. Certificates are issued for a scope, and saying the company is certified when only one service is in scope is exactly what this item exists to catch. Our guide to certified, compliant and accredited covers the wording.
Not the whole standard every time
“Surveillance audits are on-site audits, but are not necessarily full system audits, and shall be planned together with the other surveillance activities so that the certification body can maintain confidence that the client’s certified management system continues to fulfil requirements between recertification audits.”
Beyond the eight fixed items the auditor samples. The standard requires the certification body to plan surveillance “so that representative areas and functions covered by the scope of the management system are monitored on a regular basis”. So over the two surveillance audits of a cycle, expect different parts of the business and different controls to be looked at. What was not sampled this year is a reasonable guess for next year.
Surveillance is more than the audit
The on-site audit is mandatory: “Surveillance activities shall include on-site auditing of the certified client’s management system’s fulfilment of specified requirements with respect to the standard to which the certification is granted.” The standard then lists other surveillance activities a certification body may use between visits:
| Other surveillance activities may include | |
|---|---|
| a | enquiries from the certification body to the certified client on aspects of certification |
| b | reviewing any certified client’s statements with respect to its operations (e.g. promotional material, website) |
| c | requests to the certified client to provide documented information (on paper or electronic media) |
| d | other means of monitoring the certified client’s performance |
Item (b) is the one that surprises people. Your certification body is entitled to read your website and your marketing, and it has a reason to: the same standard requires that “There shall be no ambiguity, in the mark or accompanying text, as to what has been certified and which certification body has granted the certification.” A certificate issued for one product line and advertised as covering the company is a surveillance finding waiting to be written.
How many days a surveillance audit takes
The information security audit-time rules set surveillance at one third of the initial certification audit, and recertification at two thirds. The starting point for the initial figure is the headcount in scope — “The total number of persons doing work under the organization’s control for all shifts within the scope of the certification is the starting point for determination of audit time.” — which is why the standard also requires that “Where the client operates shifts, the activities that take place during shift working shall be considered when developing the audit programme and audit plans.”
| People in scope | Initial audit days | Each surveillance audit | Both surveillance audits |
|---|---|---|---|
| 10 | 5 | 1.67 | 3.34 |
| 25 | 7 | 2.33 | 4.66 |
| 50 | 10 | 3.33 | 6.66 |
| 100 | 12 | 4 | 8 |
| 250 | 14 | 4.67 | 9.34 |
These are the same figures the calculator uses, and they move with it: more sites or adjusting factors raise the initial figure, and surveillance follows. Two things are not in them. “Auditor travel time is not included in this calculation and is additional to the audit time referenced in the chart.” And the fee for each day is the certification body's own rate, which is why the full cost breakdown shows surveillance as a range, every year, for as long as you hold the certificate.
Budget for it before you are certified
Surveillance is the part of the cost that never stops. Year one is an initial audit; years two and three are each one third of it; year three adds recertification. A quote that shows only the first number is a third of the picture.
What happens to findings at a surveillance audit
The standard lets a certification body keep your certificate running on the audit team leader's positive conclusion, without a fresh decision every year — but only if it has a system under which any major nonconformity, or anything else that may lead to suspension or withdrawal, is reported for review by competent people other than those who did the audit.
So a clean surveillance audit ends at the closing meeting. One with a major nonconformity goes to somebody else to decide whether the certificate can be maintained. Either way, “The certification body shall require the client to analyse the cause and describe the specific correction and corrective actions taken, or planned to be taken, to eliminate detected nonconformities, within a defined time.” The detail — what makes a finding major, and what the body needs from you for each kind — is on the nonconformity page.
What can suspend the certificate
The standard gives three examples of when a certification body shall suspend a certificate. One of them is directly about surveillance:
- the client’s certified management system has persistently or seriously failed to meet certification requirements, including requirements for the effectiveness of the management system
- the certified client does not allow surveillance or recertification audits to be conducted at the required frequencies
- the certified client has voluntarily requested a suspension
“Under suspension, the client’s management system certification is temporarily invalid.” For a supplier whose contracts require the certificate, a suspension is not a technicality — it is the certificate not being valid while the contract says it must be. Suspension, withdrawal and what happens if the certificate lapses at the end of the cycle are covered on the recertification page.
Scope changes and short-notice audits
Adding to the scope
“The certification body shall, in response to an application for expanding the scope of a certification already granted, undertake a review of the application and determine any audit activities necessary to decide whether or not the extension may be granted. This may be conducted in conjunction with a surveillance audit.” If a customer needs a service covered that is not in your current scope, the surveillance audit is the natural moment — but the extension is a decision for the certification body, and the audit time may grow with it.
Audits you did not schedule
“It may be necessary for the certification body to conduct audits of certified clients at short notice or unannounced to investigate complaints, or in response to changes, or as follow up on suspended clients.” The certification body must tell you in advance, typically in its contract terms, under what conditions it would do this. Read that clause when you sign; it is the one that matters if a customer ever complains to your certification body about you.
We do not audit, certify or consult, and we are paid the same fixed fee per enquiry whichever certification body or consultancy you use. What we can say from the standard is that the surveillance audit is where management systems that were built for a certificate, rather than for the business, first show it.
Preparing for a surveillance audit
- Hold the internal audit and the management review before the visit, and keep the records. Item (a), every year.
- Close last year's findings and keep the evidence that the fix held. Item (b).
- List what has changed since the last audit: systems, suppliers, sites, people, scope. Item (g).
- Refresh the risk assessment where those changes touch it, and check the Statement of Applicability still describes what is running.
- Check every place you claim the certificate — website, bid templates, email footers — against the scope on the certificate. Item (h).
- Have the objectives and their measurements ready. Item (d) asks whether the system is achieving them.
Where this fits
- Recertification
- Major and minor nonconformities
- Stage 1 and Stage 2
- What certification costs
- The whole process
Common questions
How often is an ISO 27001 surveillance audit?
At least once a calendar year. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text: “Surveillance audits shall be conducted at least once a calendar year, except in recertification years. The date of the first surveillance audit following initial certification shall not be more than 12 months from the certification decision date.” In a normal three-year cycle that means two surveillance audits, in years one and two, and a recertification audit in year three.
When is the first surveillance audit after certification?
Within 12 months of the certification decision date. That is the date your certification body decided to grant the certificate, which comes after the Stage 2 audit, so the gap from Stage 2 to the first surveillance visit can be slightly longer than a year.
How long does an ISO 27001 surveillance audit take?
One third of the initial certification audit time, under the ISMS audit-time rules. For 25 people in scope with no adjustments that is 2.33 days, against 7 for the initial audit. Auditor travel is not included in that number.
Is a surveillance audit a full audit?
No. The standard says: “Surveillance audits are on-site audits, but are not necessarily full system audits, and shall be planned together with the other surveillance activities so that the certification body can maintain confidence that the client’s certified management system continues to fulfil requirements between recertification audits.” It must include eight things every time — including your internal audits and management review, last time's nonconformities, and your use of the certification mark — and beyond those the certification body samples, so that representative areas are covered over the cycle.
Can a surveillance audit be postponed?
The requirement is at least once a calendar year, and the standard notes that the frequency may sometimes need adjusting — for seasons, for example. But one of its three examples of when a certificate shall be suspended is a client that “does not allow surveillance or recertification audits to be conducted at the required frequencies”. Agree any change with your certification body in advance; do not let the year run out.
Can you fail a surveillance audit?
There is no pass mark. What a surveillance audit can produce is nonconformities, which you must analyse and correct within a time the certification body defines. A major nonconformity, or anything that may lead to suspension, has to be reviewed by competent people other than the auditors to decide whether the certificate can be maintained.
Can we add to our scope at a surveillance audit?
Yes, if the certification body agrees. “The certification body shall, in response to an application for expanding the scope of a certification already granted, undertake a review of the application and determine any audit activities necessary to decide whether or not the extension may be granted. This may be conducted in conjunction with a surveillance audit.” Tell them before the visit is planned, because extra scope usually means extra audit time.
Does the surveillance audit check our website?
It can. Surveillance is not only the audit: the standard lists “reviewing any certified client’s statements with respect to its operations (e.g. promotional material, website)” as one of the other surveillance activities, and every surveillance audit must cover the use of marks and any other reference to certification.
Sources cited on this page
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- ISO/IEC 27006:2015/Amd 1:2020, Requirements for bodies providing audit and certification of information security management systems — Amendment 1
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Surveillance audit coming up?
Say when it is and what was raised last time. An internal audit before the visit is the usual place a consultancy helps.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.