Recertification Audits
In ISO/IEC 27001 certification, a recertification audit is the formal audit a certification body conducts near the end of the three-year certification cycle to decide whether to renew the certificate. It is governed by ISO/IEC 17021-1 and ISO/IEC 27006-1. Its purpose is to confirm the continued con… In ISO/IEC 27001 certification, a recertification audit is the formal audit a certification body conducts near the end of the three-year certification cycle to decide whether to renew the certificate. It is governed by ISO/IEC 17021-1 and ISO/IEC 27006-1. Its purpose is to confirm the continued conformity and effectiveness of the Information Security Management System (ISMS) as a whole, and its continued relevance and applicability to the certified scope. Unlike surveillance audits, which sample parts of the ISMS each year, the recertification audit covers all clauses 4 to 10 and the applicable Annex A controls. From an audit programme perspective, the certification body must plan the recertification early enough that the audit, any corrective actions and the certification decision are completed before the current certificate expires. Planning considers the ISMS performance over the whole cycle, including previous surveillance reports, complaints, open nonconformities, and significant changes to the organization, its scope, technology, legal requirements or threat landscape. Where major changes have occurred, a Stage 1 type activity may be needed. Audit duration is calculated using ISO/IEC 27006-1 and is typically about two thirds of the initial certification audit time, adjusted for complexity and risk. The audit team, led by the lead auditor, evaluates the effectiveness of the entire ISMS in light of internal and external changes, top management's demonstrated commitment to maintaining and improving it, and whether its operation achieves the information security policy and objectives. Key evidence includes the updated risk assessment and treatment plan, Statement of Applicability, internal audit results, management reviews and corrective actions. Major nonconformities require correction and corrective action, verified by the certification body before expiry. If recertification is completed successfully, the new certificate is valid for a further three years. If it is not completed in time, the certificate expires, although it may be restored within six months if the outstanding recertification activities are completed.
Recertification Audits in ISO/IEC 27001: A Complete Guide for Lead Auditors
Introduction
A recertification audit is a key event in the ISO/IEC 27001 certification cycle. It decides whether an organization's Information Security Management System (ISMS) certificate is renewed for another three-year cycle. For ISO/IEC 27001 Lead Auditor candidates, recertification audits are a frequently tested topic. They sit within Managing an ISO/IEC 27001 Audit Program and draw on the requirements of ISO/IEC 17021-1, ISO/IEC 27006 and ISO 19011.
Why Recertification Audits Are Important
1. Certificate validity is time-limited: An ISO/IEC 27001 certificate is valid for three years. Without a successful recertification audit before expiry, the certificate lapses and the organization can no longer claim certification.
2. Assurance of continued effectiveness: Surveillance audits sample only parts of the ISMS. The recertification audit re-confirms that the whole ISMS is still conforming, effective and relevant.
3. Reflects organizational change: Over three years, organizations change scope, technology, threats, legal requirements, suppliers and people. Recertification checks that the ISMS has kept pace with these changes.
4. Stakeholder confidence: Customers, regulators and partners rely on certification as evidence of mature information security. Recertification keeps that trust credible.
5. Drives continual improvement: Reviewing performance over the whole cycle shows whether the organization is genuinely improving, as required by Clause 10, or just maintaining the status quo.
6. Integrity of the certification scheme: Accreditation rules require certification bodies to re-evaluate clients periodically. This keeps certificates meaningful across the industry.
What Is a Recertification Audit?
A recertification audit is a full-system audit performed by a certification body before the current certificate expires. Its purpose is to confirm the continued conformity and effectiveness of the ISMS as a whole and its continued relevance and applicability for the certified scope.
According to ISO/IEC 17021-1 (clause 9.6.3), the recertification audit must:
• Be planned and conducted to evaluate continued fulfilment of all requirements of the relevant management system standard.
• Consider the performance of the management system over the period of certification, including a review of previous surveillance audit reports.
• Include an on-site audit that addresses:
- the effectiveness of the management system in its entirety, in light of internal and external changes, and its continued relevance and applicability to the scope;
- demonstrated commitment to maintain the effectiveness and improvement of the ISMS to enhance overall performance;
- the effectiveness of the management system in achieving the client's objectives and the intended results.
Position in the Certification Cycle
• Year 0: Initial certification audit (Stage 1 + Stage 2). The certificate is issued.
• Year 1: First surveillance audit. It must take place within 12 months of the certification decision date.
• Year 2: Second surveillance audit.
• Year 3: Recertification audit, completed before the certificate expires. A new three-year cycle then begins.
How Recertification Differs from Other Audit Types
• Initial certification audit: A two-stage audit. Stage 1 assesses readiness and documentation. Stage 2 assesses implementation and effectiveness.
• Surveillance audit: A partial audit sampling selected processes and controls. It always includes internal audits, management review, corrective actions, complaints, changes and use of marks.
• Recertification audit: A full-scope audit of all ISMS requirements. Stage 1 is normally not required. It may be needed when there have been significant changes, such as major changes to the organization, the ISMS, its scope or its context.
• Special audits: Extensions to scope or short-notice audits triggered by complaints, incidents or changes.
How a Recertification Audit Works
Step 1 – Planning and Scheduling
• The certification body plans the audit well before expiry. This leaves time to correct any nonconformities and make the certification decision.
• Audit time is set using ISO/IEC 27006 guidance. Recertification time is typically about two-thirds of the time required for an initial certification audit (Stage 1 + Stage 2) for the same organization, adjusted for complexity and changes.
• The audit team reviews the following inputs:
- previous audit reports, including surveillance reports;
- open nonconformities;
- changes to scope, sites, processes, legal requirements or risks;
- complaints and incidents.
• Decide whether a Stage 1 is needed because of significant changes.
• Confirm the audit team's competence and impartiality. Rotate auditors where needed to avoid familiarity threats.
Step 2 – Audit Plan Preparation
• The audit plan covers all clauses 4–10 of ISO/IEC 27001 and the controls listed in the Statement of Applicability (SoA). It is based on Annex A of ISO/IEC 27001:2022.
• For multi-site organizations, sampling follows ISO/IEC 27006 and IAF MD 1 rules. Central functions are always included.
Step 3 – Conducting the On-Site Audit
Auditors use ISO 19011 techniques: interviews, observation, document and record review, and technical verification. Key focus areas are:
• Context and scope (Clause 4): Is the scope still appropriate? Have interested parties and issues changed?
• Leadership (Clause 5): Is top management commitment still demonstrated? Is the policy current?
• Planning (Clause 6): Is the risk assessment up to date? Is risk treatment effective? Is the SoA justified? Are objectives measurable and monitored?
• Support (Clause 7): Competence, awareness, communication and documented information.
• Operation (Clause 8): Are risk assessments performed at planned intervals or after changes? Are treatment plans implemented?
• Performance evaluation (Clause 9): Monitoring and measurement, internal audits across the full cycle, and management reviews.
• Improvement (Clause 10): Are corrective actions effective? Is there evidence of continual improvement over three years?
• Annex A controls: Is their implementation effective, given new threats such as cloud, remote work and ransomware?
Step 4 – Reporting Findings
• Findings are graded as major nonconformities, minor nonconformities or opportunities for improvement.
• The report includes a recommendation on whether to renew certification.
Step 5 – Handling Nonconformities
• For major nonconformities, the certification body sets time limits for correction and corrective action. These must be implemented and verified before the expiration of certification.
• For minor nonconformities, the client submits an acceptable corrective action plan. Verification may take place at the next surveillance audit.
Step 6 – Recertification Decision
• An independent person or committee makes the decision. It must not be the audit team.
• The decision is based on:
- the results of the recertification audit;
- a review of the system over the certification period;
- complaints received from users of certification.
• If renewed, the new certificate's expiry date is based on the expiry date of the previous certificate. This applies when recertification activities and the decision are completed before expiry.
Step 7 – Expiry and Restoration Scenarios
• If recertification is not completed, or majors are not verified before expiry, the certificate shall not be recommended for renewal. Its validity shall not be extended.
• Under ISO/IEC 17021-1 (9.6.3.2.5), the certification body can restore certification within 6 months of expiry, provided outstanding recertification activities are completed. Otherwise, at least a Stage 2 audit is required.
• The effective date on a restored certificate is on or after the recertification decision. The expiry date is based on the prior certification cycle.
• There is no valid certification between the expiry date and the restoration date.
Practical Example
Consider a cloud services provider certified in March 2022, with its certificate expiring in March 2025.
• The certification body schedules recertification for December 2024.
• Over the cycle, the company opened a new data centre and adopted a new SaaS platform. The audit team assesses whether these changes justify a Stage 1. They conclude the scope change was handled through a special audit in 2023, so no Stage 1 is needed.
• During the audit, they raise one major nonconformity: no management review has been held for 14 months. They also raise two minors.
• The organization holds a management review and implements corrective action by February 2025. The auditor verifies this, and the decision committee renews the certificate before March 2025.
• The new certificate expires in March 2028.
Common Pitfalls Auditors Look For
• Outdated risk assessments that do not reflect new technologies or threats.
• An internal audit program that did not cover all ISMS processes and controls during the cycle.
• Management reviews lacking required inputs, such as feedback from interested parties, risk assessment results or opportunities for improvement.
• Recurring nonconformities, which show ineffective corrective action.
• An SoA that is not aligned with the risk treatment plan.
• Objectives that are not measured or not evaluated.
Exam Tips: Answering Questions on Recertification Audits
Tip 1 – Remember the key numbers: Certificate validity is 3 years. The first surveillance audit takes place within 12 months of the certification decision. Restoration is possible within 6 months of expiry. Recertification audit time is about 2/3 of initial audit time.
Tip 2 – Full system vs. sample: If a question asks what distinguishes recertification from surveillance, the answer is that recertification evaluates the entire ISMS and performance over the whole certification period.
Tip 3 – Stage 1 is conditional: Choose answers stating that Stage 1 is required only when there are significant changes. Do not choose answers that make it mandatory every time.
Tip 4 – Major NCs before expiry: Correction and corrective action for major nonconformities must be implemented and verified before the certificate expires. A plan alone is not enough for majors.
Tip 5 – Inputs to recertification: Look for options that include a review of previous surveillance reports, complaints and changes. These are mandatory considerations.
Tip 6 – Independence of decision: The recertification decision is made by competent personnel not involved in the audit. Reject answers saying the lead auditor grants recertification.
Tip 7 – Scenario questions: When given a scenario, follow these steps:
(a) identify the audit type;
(b) check timelines against certificate expiry;
(c) classify findings as major or minor;
(d) state the required action and who is responsible.
Tip 8 – Classify nonconformities correctly: A major NC is the absence or total breakdown of a requirement, or doubt about the ISMS achieving its intended results. A minor NC is an isolated lapse. For example, no internal audit performed during the whole cycle would be major.
Tip 9 – Use auditor language in essay answers: Refer to objective evidence, audit criteria, sampling, the audit plan and the audit conclusion. Cite ISO/IEC 17021-1 and ISO/IEC 27006 where relevant.
Tip 10 – Consider changes and context: Strong answers mention re-validating the scope, context (Clause 4.1/4.2), risk assessment and the SoA in light of changes over three years.
Tip 11 – Expired certificates: If the certificate has already expired, remember that there is no grace extension of validity. Restoration is possible within 6 months; after that, a Stage 2 audit is required.
Tip 12 – Eliminate extreme answers: Options using words like always, never or automatically renewed are usually wrong. Recertification is never automatic.
Quick Revision Summary
• What: A full-system audit to renew ISO/IEC 27001 certification for another 3 years.
• When: Before the certificate expires, usually in Year 3 of the cycle.
• Why: To confirm the ISMS's continued conformity, effectiveness, relevance and improvement.
• How: Plan (review history and changes), audit all requirements on-site, report findings, resolve NCs (majors verified before expiry), then an independent decision is made.
• Key references: ISO/IEC 17021-1 clause 9.6.3, ISO/IEC 27006, ISO 19011, ISO/IEC 27001 clauses 4–10 and Annex A.
Master these points and you will be able to answer recertification audit questions confidently, whether they are multiple-choice, scenario-based or essay-style.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!