What recertification confirms
A recertification audit looks at the whole ISMS and asks whether it has been effective over the past three years, not just since the last surveillance. The auditor considers the previous surveillance reports, the trend in findings, how the ISMS has coped with change, and whether it is still relevant to the risks the organization faces today.
What we examine
- The continued suitability of the scope, policy, and objectives
- The effectiveness of the risk assessment process across the cycle, including how new risks were identified and treated
- Results of internal audits and management reviews over the whole cycle
- Corrective actions and whether they prevented recurrence
- Implementation of Annex A controls, sampled across the full Statement of Applicability
- Any complaints or incidents and how they were handled
- How the organization has responded to changes in technology, regulation, and customer requirements
Planning ahead
We contact you six months before expiry to confirm scope, headcount, and sites, because any of these may have changed the audit time required. The audit itself is scheduled three to four months before expiry so there is room to close findings without pressure. The new certificate is issued with an expiry date three years after the original, so the cycle continues cleanly.