Skip to main content
Category: Certification and Accreditation

Certification Maintenance

Also known as: Maintenance Certification, Certification Renewal, Ongoing Certification Maintenance
Simply put

Certification maintenance is the ongoing process of keeping a credential or certification active after it is first earned. Rather than being a one-time event, a certification typically requires continued effort, such as periodic reviews, updated exams, or evidence of continued competence, to remain valid. The specific requirements vary depending on the certifying body and the type of certification involved.

Formal definition

Certification maintenance refers to the recurring activities required to keep a professional credential or organizational certification in an active, valid state after initial award. For individual professional credentials, the evidence indicates this commonly involves demonstrating continued competence, completing periodic maintenance exams, or meeting other renewal requirements set by the certifying organization. Note that the evidence provided addresses certification maintenance in general and professional-credential contexts rather than the specific mechanics of ISO/IEC 27001 certification maintenance; for an ISO/IEC 27001 certificate, maintenance is typically administered by the accredited certification body over the certification cycle and applies only to the defined scope of the ISMS, though the precise cadence and requirements depend on the certification body and are not detailed in the sources cited here. This term should not be conflated with a SOC 2 attestation, which is a report covering a defined period rather than a certification subject to maintenance.

Why it matters

Certification maintenance matters because a certification is rarely a permanent, one-time achievement. In most contexts, a credential or certification must be actively kept in a valid state through recurring effort, periodic reviews, updated or maintenance exams, or ongoing evidence of continued competence. Without this ongoing attention, a certification can lapse, undermining the assurance it was intended to provide to employers, clients, or other stakeholders who rely on it.

For professional credentials, maintenance ensures that the holder's knowledge stays current as practices evolve. The evidence describes maintenance certifications in fields such as reliability, asset management, and maintenance practice, where credentials like the CMRT test competency across defined domains, and platforms such as Salesforce require maintenance exams to keep certifications valid. In each case, the underlying principle is the same: the value of a certification depends on it reflecting present, not merely past, competence.

In an organizational compliance context, the same logic applies to certifications such as ISO/IEC 27001, though the specific mechanics differ and are not detailed in the sources cited here. An ISO/IEC 27001 certificate covers only the defined scope of the information security management system, and maintaining it typically involves ongoing oversight by the accredited certification body over the certification cycle. This is distinct from a SOC 2 attestation, which is a report covering a defined period rather than a certification subject to maintenance, so certification maintenance concepts should not be applied to SOC 2 outcomes.

Who it's relevant to

GRC and Compliance Managers
Compliance managers responsible for organizational certifications need to track ongoing maintenance obligations so that a certification does not lapse. For ISO/IEC 27001 specifically, this means understanding that maintenance is administered by the accredited certification body over the certification cycle and applies only to the defined ISMS scope, with the precise cadence set by the certification body.
Individual Credential Holders
Professionals holding personal certifications, such as those in reliability, asset management, or platform-specific credentials, must meet renewal requirements to keep their credentials active. Depending on the certifying organization, this may involve demonstrating continued competence, completing periodic maintenance exams, or satisfying other renewal criteria.
Auditors and Assessors
Auditors and assessors should recognize the distinction between certifications that require ongoing maintenance and attestation reports such as SOC 2, which cover a defined period rather than being subject to certification maintenance. Understanding this boundary helps ensure the correct assurance model is applied to each engagement.
Certifying Bodies and Program Administrators
Organizations that award credentials define and administer the maintenance requirements, the exams, reviews, or evidence of competence, that holders must satisfy to remain valid. These requirements vary by certifying body and by the type of certification involved.

Inside Certification Maintenance

Surveillance Audits
For ISO/IEC 27001, the accredited certification body typically conducts periodic surveillance audits during the certification cycle to confirm the ISMS continues to operate and conform to the clause 4-10 requirements. The exact frequency and scope are set by the certification body and depend on the defined ISMS scope.
Recertification
An ISO/IEC 27001 certificate is generally valid for a defined cycle, after which a recertification audit is typically performed to renew it. This reassesses the ISMS against the current version of the standard and the organization's Statement of Applicability.
Recurring SOC 2 Reporting
SOC 2 is not maintained through a certificate but through recurring examinations. Because a SOC 2 Type II report attests to operating effectiveness over a defined review period, organizations typically commission successive reports to provide stakeholders with continuous coverage, with the period length set by scoping decisions.
Ongoing Control Operation
Maintenance depends on controls continuing to operate as designed between assessments. For SOC 2 Type II, evidence of operating effectiveness must accumulate across the review period; for ISO 27001, the ISMS must continue to function, including risk assessment, monitoring, and management review activities under clauses 4-10.
Statement of Applicability and Risk Reassessment (ISO 27001)
Maintaining an ISO/IEC 27001 certification involves keeping the risk assessment and Statement of Applicability current, so that selected Annex A reference controls remain justified against the organization's risks. Control counts and structure differ by edition (for example, the 2022 revision restructured Annex A into 93 controls across four themes versus 114 in the 2013 version).
Scope Currency
Both frameworks require that the defined scope remain accurate as the organization changes. An ISO 27001 certificate covers only the defined ISMS scope, and a SOC 2 report attests only to the controls and system covered, so material changes typically need to be reflected in future assessments.

Common questions

Answers to the questions practitioners most commonly ask about Certification Maintenance.

Does an ISO 27001 certificate stay valid indefinitely once you earn it?
No. An ISO 27001 certificate is not a permanent status. It is typically issued for a limited certification cycle and remains valid only if the organization continues to satisfy the certification body through ongoing assessment activity. The certificate also covers only the defined scope of the ISMS, so maintenance depends on the ISMS remaining in operation and being subject to the certification body's continued review. Lapses in the required surveillance activity or significant unaddressed changes can put the certificate's validity at risk.
Is maintaining a SOC 2 report the same as renewing a certification?
No, and the terminology matters. SOC 2 produces an attestation report issued by a licensed CPA firm under the AICPA SSAE 18 standard, not a certificate that gets 'renewed.' To maintain continuous coverage, organizations typically commission successive examinations so that each new report's period follows the prior one. This is a repeated attestation engagement rather than a certification maintenance process, and each report attests only to the controls and period it covers.
How does surveillance activity fit into keeping an ISO 27001 certificate current?
Within an ISO 27001 certification cycle, the accredited certification body typically conducts periodic surveillance assessments to confirm the ISMS continues to meet the requirements in clauses 4 through 10 and that the controls selected via the Statement of Applicability remain appropriate. The exact frequency and depth are set by the certification body. The organization is generally expected to sustain its ISMS operations, including risk assessment, internal audit, and management review activity, between these assessments.
What should an organization do to keep SOC 2 coverage continuous across reporting periods?
For continuous SOC 2 Type II coverage, organizations typically plan successive examination periods so that one report's review period begins where the previous one ended, avoiding gaps. Because a Type II report assesses both design and operating effectiveness over a defined period whose length is set by scoping decisions, maintaining coverage means keeping the in-scope controls operating throughout and providing the CPA firm the evidence needed for each period. Consult the service auditor on timing and scope for each engagement.
How do changes to the environment or scope affect ongoing certification or reporting?
Significant changes, such as new systems, added services, or organizational shifts, can affect what is covered. For ISO 27001, changes may require updating the risk assessment, Statement of Applicability, and ISMS scope, and the certification body determines how such changes are addressed within the cycle. For SOC 2, scope changes may alter which Trust Services Criteria categories apply, since Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are selected based on scope. In both cases, discuss changes with the certification body or service auditor before the next assessment.
If we maintain one framework, do we automatically maintain the other?
No. Maintaining a SOC 2 report and maintaining an ISO 27001 certificate are separate processes governed by different standards and different bodies, and satisfying one does not automatically satisfy the other. Mapping between the two is possible but partial. Organizations pursuing both typically manage two distinct maintenance efforts, coordinating evidence where controls overlap while recognizing that the Trust Services Criteria and ISO 27001's ISMS requirements and Annex A reference controls are not equivalent.

Common misconceptions

Once you pass, you are certified indefinitely and no further work is required.
Neither outcome is permanent. ISO/IEC 27001 certification typically relies on periodic surveillance audits and recertification within the cycle, and SOC 2 provides no certificate at all, it is an attestation examination whose reports cover only a specific point in time (Type I) or a defined review period (Type II), so recurring examinations are typically needed for continuous coverage.
A SOC 2 report is renewed the same way an ISO 27001 certificate is.
They are maintained differently. SOC 2 is an attestation performed by a licensed CPA firm under SSAE 18 and is maintained by commissioning new reports; ISO/IEC 27001 is a certification issued by an accredited certification body and is maintained through surveillance and recertification audits. The two are distinct processes, not interchangeable.
Maintaining certification guarantees the organization will not experience a breach.
Maintenance confirms controls continue to be assessed against the applicable criteria or ISMS requirements within the defined scope and period. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined ISMS scope.

Best practices

Treat maintenance as continuous rather than event-based by operating controls consistently between assessments, since SOC 2 Type II requires evidence of operating effectiveness accumulated across the entire review period.
Plan recurring SOC 2 examinations so that successive reporting periods align and avoid coverage gaps for stakeholders relying on the reports.
For ISO 27001, keep the risk assessment and Statement of Applicability current so that selected Annex A reference controls remain justified as the organization changes.
Schedule and prepare for ISO 27001 surveillance and recertification audits according to the certification body's cycle, confirming clause 4-10 ISMS activities such as monitoring and management review are documented.
Review and update the defined scope regularly, as an ISO 27001 certificate and a SOC 2 report each cover only their defined boundaries.
Confirm which edition of ISO/IEC 27001 the ISMS is certified against and align documentation accordingly, since Annex A structure and control counts differ between the 2013 and 2022 versions.