Skip to main content
RiskZeroCertifiers

Months 12 and 24

ISO 27001 surveillance audits

Annual audits in years one and two of the cycle that confirm the ISMS is maintained and your certificate stays valid.

Typical duration

Roughly one third of the Stage 2 audit time, each year

Request a quote

Fixed fee, reply within two business days.

What surveillance audits are for

A certificate is a statement that your ISMS conforms to ISO/IEC 27001 and continues to do so. Surveillance audits are how we back that statement up in years one and two of the cycle. They are shorter than the initial audit and do not re-examine everything, but they must cover certain things every year.

What is always covered

  • Internal audits and management reviews carried out since the last audit
  • Progress on any findings from the previous audit
  • Handling of complaints and security incidents
  • Changes to the organization, its scope, its risks, and its Statement of Applicability
  • Use of the certification mark and how you refer to your certification
  • The effectiveness of the ISMS in meeting its objectives

What is sampled

Across the two surveillance audits we sample the Annex A controls in your Statement of Applicability so that, together with Stage 2, the full set has been examined at least once over the cycle. We plan the sampling at certification and share it with you, so you know which areas will be looked at in each year.

How we plan them

Surveillance dates are set at the point of certification and confirmed three months in advance. The audit plan goes out at least two weeks before the visit and names the people the auditor needs to speak to. Most surveillance audits for cloud-first organizations are conducted remotely; sites with physical security controls in scope are visited at least once per cycle.

Reporting

You receive a written report within ten business days. Findings are classified as major nonconformities, minor nonconformities, or opportunities for improvement, with the clause or control reference and the evidence behind each one. Minor nonconformities need a corrective action plan; major nonconformities need to be corrected and verified within an agreed period or the certificate may be suspended.

Questions

Common questions about iso 27001 surveillance audits

When does the first surveillance audit have to happen?
Within twelve months of the certification decision date. We schedule it at the point of certification so the date is never a surprise, and we contact you three months ahead to confirm the plan.
What happens if we miss a surveillance audit?
If the audit cannot be completed by the due date, the certificate must be suspended until it is. Suspension is disclosed to anyone who asks us to verify the certificate. Talk to us early if you need to move dates; a short delay is usually manageable if agreed in advance.
Can the scope change at surveillance?
Yes. New products, offices, or acquisitions can be added to the certified scope during a surveillance audit if enough time is planned. Tell us about changes as they happen and we will adjust the audit plan.

Ready to scope your audit?

Tell us about your organization, your ISMS scope, and your target date. We reply with a fixed-fee quote and available audit dates within two business days.