Certification Maintenance
Certification maintenance is the ongoing process of keeping a credential or certification active after it is first earned. Rather than being a one-time event, a certification typically requires continued effort, such as periodic reviews, updated exams, or evidence of continued competence, to remain valid. The specific requirements vary depending on the certifying body and the type of certification involved.
Certification maintenance refers to the recurring activities required to keep a professional credential or organizational certification in an active, valid state after initial award. For individual professional credentials, the evidence indicates this commonly involves demonstrating continued competence, completing periodic maintenance exams, or meeting other renewal requirements set by the certifying organization. Note that the evidence provided addresses certification maintenance in general and professional-credential contexts rather than the specific mechanics of ISO/IEC 27001 certification maintenance; for an ISO/IEC 27001 certificate, maintenance is typically administered by the accredited certification body over the certification cycle and applies only to the defined scope of the ISMS, though the precise cadence and requirements depend on the certification body and are not detailed in the sources cited here. This term should not be conflated with a SOC 2 attestation, which is a report covering a defined period rather than a certification subject to maintenance.
Why it matters
Certification maintenance matters because a certification is rarely a permanent, one-time achievement. In most contexts, a credential or certification must be actively kept in a valid state through recurring effort, periodic reviews, updated or maintenance exams, or ongoing evidence of continued competence. Without this ongoing attention, a certification can lapse, undermining the assurance it was intended to provide to employers, clients, or other stakeholders who rely on it.
For professional credentials, maintenance ensures that the holder's knowledge stays current as practices evolve. The evidence describes maintenance certifications in fields such as reliability, asset management, and maintenance practice, where credentials like the CMRT test competency across defined domains, and platforms such as Salesforce require maintenance exams to keep certifications valid. In each case, the underlying principle is the same: the value of a certification depends on it reflecting present, not merely past, competence.
In an organizational compliance context, the same logic applies to certifications such as ISO/IEC 27001, though the specific mechanics differ and are not detailed in the sources cited here. An ISO/IEC 27001 certificate covers only the defined scope of the information security management system, and maintaining it typically involves ongoing oversight by the accredited certification body over the certification cycle. This is distinct from a SOC 2 attestation, which is a report covering a defined period rather than a certification subject to maintenance, so certification maintenance concepts should not be applied to SOC 2 outcomes.
Who it's relevant to
Inside Certification Maintenance
Common questions
Answers to the questions practitioners most commonly ask about Certification Maintenance.