Certification Withdrawal
Certification withdrawal is the formal process by which a certification body revokes a previously issued certificate, typically because the certified organization has failed to maintain compliance with the standard's requirements. In an ISO/IEC 27001 context, this means the organization can no longer claim that its information security management system (ISMS) is certified for the withdrawn scope. Withdrawal often follows a period of suspension and generally requires a written or formal decision by the certification body.
In the ISO/IEC 27001 certification lifecycle, certification withdrawal is a formal action taken by an accredited certification body to revoke a certificate against the ISMS requirements (clauses 4 through 10), typically as a consequence of unresolved nonconformities, failure to satisfy corrective actions, non-compliance with certification conditions, or non-payment of fees. Withdrawal is commonly preceded by a defined suspension period, after which the certification body's designated authority decides on extension, reinstatement, or withdrawal; the specific durations and procedures vary by certification body. Because an ISO 27001 certificate covers only the defined scope of the ISMS, withdrawal removes the organization's right to claim certified status for that scope and requires ceasing use of the associated certification marks. This concept is distinct from a SOC 2 engagement, which is an attestation examination performed by a licensed CPA firm under AICPA SSAE 18 and results in a report rather than a certificate; a SOC 2 report is not subject to 'certification withdrawal' because no certification is issued in the first place.
Why it matters
Certification withdrawal represents the most serious outcome in the ISO/IEC 27001 certification lifecycle, because it removes an organization's right to claim that its information security management system is certified for the affected scope. For many organizations, an ISO 27001 certificate functions as a market signal to customers, partners, and regulators; losing it can undermine contractual commitments, procurement eligibility, and trust that was built on the certified status. Because the certificate covers only the defined scope of the ISMS, withdrawal specifically affects the ability to assert certified status for that scope, and the organization must cease using the associated certification marks.
Withdrawal typically does not happen abruptly. It generally follows a period of suspension during which the organization has an opportunity to resolve outstanding issues, such as unresolved nonconformities, failure to complete corrective actions, non-compliance with certification conditions, or non-payment of fees. If those matters remain unaddressed by the end of the suspension period, the certification body's designated authority may decide on withdrawal rather than reinstatement. The specific durations and procedures vary by certification body, so organizations should consult the terms of their own certification agreement.
It is important to distinguish this concept from SOC 2. A SOC 2 engagement is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report rather than a certificate. Because no certification is issued in a SOC 2 engagement, the notion of 'certification withdrawal' does not apply to it; concerns about a SOC 2 report instead relate to its scope, the period covered, and whether a subsequent report is issued.
Who it's relevant to
Inside Certification Withdrawal
Common questions
Answers to the questions practitioners most commonly ask about Certification Withdrawal.