Skip to main content
Category: Certification and Accreditation

Certification Withdrawal

Also known as: Certificate Withdrawal, Withdrawal of Certification, Certification Revocation
Simply put

Certification withdrawal is the formal process by which a certification body revokes a previously issued certificate, typically because the certified organization has failed to maintain compliance with the standard's requirements. In an ISO/IEC 27001 context, this means the organization can no longer claim that its information security management system (ISMS) is certified for the withdrawn scope. Withdrawal often follows a period of suspension and generally requires a written or formal decision by the certification body.

Formal definition

In the ISO/IEC 27001 certification lifecycle, certification withdrawal is a formal action taken by an accredited certification body to revoke a certificate against the ISMS requirements (clauses 4 through 10), typically as a consequence of unresolved nonconformities, failure to satisfy corrective actions, non-compliance with certification conditions, or non-payment of fees. Withdrawal is commonly preceded by a defined suspension period, after which the certification body's designated authority decides on extension, reinstatement, or withdrawal; the specific durations and procedures vary by certification body. Because an ISO 27001 certificate covers only the defined scope of the ISMS, withdrawal removes the organization's right to claim certified status for that scope and requires ceasing use of the associated certification marks. This concept is distinct from a SOC 2 engagement, which is an attestation examination performed by a licensed CPA firm under AICPA SSAE 18 and results in a report rather than a certificate; a SOC 2 report is not subject to 'certification withdrawal' because no certification is issued in the first place.

Why it matters

Certification withdrawal represents the most serious outcome in the ISO/IEC 27001 certification lifecycle, because it removes an organization's right to claim that its information security management system is certified for the affected scope. For many organizations, an ISO 27001 certificate functions as a market signal to customers, partners, and regulators; losing it can undermine contractual commitments, procurement eligibility, and trust that was built on the certified status. Because the certificate covers only the defined scope of the ISMS, withdrawal specifically affects the ability to assert certified status for that scope, and the organization must cease using the associated certification marks.

Withdrawal typically does not happen abruptly. It generally follows a period of suspension during which the organization has an opportunity to resolve outstanding issues, such as unresolved nonconformities, failure to complete corrective actions, non-compliance with certification conditions, or non-payment of fees. If those matters remain unaddressed by the end of the suspension period, the certification body's designated authority may decide on withdrawal rather than reinstatement. The specific durations and procedures vary by certification body, so organizations should consult the terms of their own certification agreement.

It is important to distinguish this concept from SOC 2. A SOC 2 engagement is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard and results in a report rather than a certificate. Because no certification is issued in a SOC 2 engagement, the notion of 'certification withdrawal' does not apply to it; concerns about a SOC 2 report instead relate to its scope, the period covered, and whether a subsequent report is issued.

Who it's relevant to

Compliance and GRC Managers
Compliance and GRC managers are typically responsible for maintaining the ISMS in a state that satisfies certification conditions and for tracking corrective actions to closure. Understanding the path from nonconformity to suspension to withdrawal helps them prioritize remediation before an issue escalates, and manage obligations such as settling fees and responding to certification body requirements within the applicable timelines.
Executive and Risk Owners
Executives and risk owners rely on the ISO 27001 certificate as evidence of a governed information security program to customers and partners. Because withdrawal removes the right to claim certified status for the affected scope and requires ceasing use of certification marks, leadership should understand the commercial and contractual exposure that a withdrawal could create and ensure the ISMS receives adequate resourcing.
Auditors and Certification Body Liaisons
Internal auditors and those who serve as the liaison to the certification body need to understand the body's documented suspension and withdrawal procedures, which vary by body. This knowledge helps them communicate accurately with the certification body's designated authority, understand the decision points around extension, reinstatement, or withdrawal, and prepare the organization for surveillance and reassessment activities.
Vendor Risk and Procurement Teams
Teams that evaluate third parties should recognize that a supplier's ISO 27001 certificate can be suspended or withdrawn, and that certification covers only the defined ISMS scope. Verifying the current status of a supplier's certificate, rather than relying on a past copy, is a prudent step, since a withdrawal would remove the supplier's right to claim certified status.

Inside Certification Withdrawal

Definition
Certification withdrawal is the action by which an accredited certification body revokes or cancels a previously issued ISO/IEC 27001 certificate, ending the certified organization's formal recognition of ISMS conformity for the defined scope.
Triggering Conditions
Withdrawal typically results from serious or unresolved nonconformities, failure to complete required surveillance or recertification audits, misuse of the certification mark, or the certified organization voluntarily requesting cancellation. The specific grounds depend on the certification body's rules and applicable accreditation requirements.
Distinction from Suspension
Suspension is typically a temporary hold on the validity of a certificate pending corrective action, whereas withdrawal is the full removal of certified status. In most schemes, unresolved suspension can escalate to withdrawal, though the sequence and timeframes vary by certification body.
Scope Boundary
Withdrawal applies to the ISMS scope that was certified. Because an ISO 27001 certificate covers only the defined scope of the management system, withdrawal likewise concerns only that certified scope and not necessarily the organization's broader security posture.
Consequences for the Organization
Following withdrawal, the organization typically loses the right to claim certification and to use the associated certification mark, and generally must remove related references from marketing and contractual materials. Recovery usually requires a new or repeat certification process rather than simple reinstatement, depending on the certification body's procedures.
Relationship to Framework Structure
Certification is issued against the ISMS requirements in clauses 4 through 10, with Annex A reference controls selected through the Statement of Applicability. Withdrawal reflects a determination that conformity with these certifiable requirements can no longer be maintained for the defined scope.

Common questions

Answers to the questions practitioners most commonly ask about Certification Withdrawal.

Does certification withdrawal mean my organization received a failed SOC 2 report?
No. Certification withdrawal applies to ISO/IEC 27001, which is a certification issued by an accredited certification body. SOC 2 is not a certification; it is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, resulting in a report rather than a certificate. There is no SOC 2 equivalent to certification withdrawal, though a CPA firm may issue a report with qualified or adverse conclusions. These are distinct outcomes under distinct frameworks, and they should not be conflated.
If our ISO 27001 certificate is withdrawn, does that automatically affect our SOC 2 report?
Not automatically. The two frameworks are separate, and satisfying or losing one does not directly determine the status of the other. An ISO 27001 certificate covers only the defined scope of the ISMS as assessed by the certification body, while a SOC 2 report attests only to the controls and period covered by the CPA firm's examination. Mapping between the frameworks is possible but partial, so a withdrawal in one program does not, by itself, invalidate an outcome in the other. In practice, however, the underlying issues that led to a withdrawal could also be relevant to a SOC 2 examination depending on scope.
What typically triggers withdrawal of an ISO 27001 certificate?
Withdrawal is generally a decision made by the accredited certification body and depends on their procedures and the applicable accreditation rules. Common circumstances include unresolved major nonconformities identified during surveillance or recertification audits, failure to maintain the ISMS requirements in clauses 4 through 10, or a client's failure to meet the certification body's contractual and audit obligations. Because triggers and thresholds vary by certification body, the specific conditions should be confirmed with your certifier rather than assumed.
Can we regain ISO 27001 certification after a withdrawal?
In most cases, an organization can pursue certification again, but the pathway depends on the certification body's policies and the reasons for withdrawal. Typically this involves remediating the issues that led to withdrawal, demonstrating that the ISMS requirements are met, and undergoing a further audit. Whether this is treated as a new certification cycle or a resumption depends on how much time has passed and the certifier's rules, so the process should be scoped directly with the certification body.
How can we reduce the risk of certification withdrawal during surveillance audits?
A practical approach is to maintain the ISMS as an ongoing operation rather than treating it as a point-in-time exercise. This typically includes keeping the risk assessment and Statement of Applicability current, promptly addressing nonconformities from prior audits, sustaining evidence for the selected Annex A reference controls, and demonstrating that management review and continual improvement activities in clauses 4 through 10 are active. The specific expectations depend on your certification body and the defined scope of your ISMS.
What should we communicate to stakeholders if a certificate is withdrawn?
Communication should be accurate and scoped carefully. Because an ISO 27001 certificate covers only the defined scope of the ISMS, any statement about a withdrawal should reflect that boundary and avoid implying broader claims about the organization's overall security. Stakeholders often distinguish between the certification status and the underlying security posture, so it is generally advisable to describe the remediation plan and the pathway back to certification. Any related SOC 2 reporting should be described separately, since it reflects a different framework, scope, and period.

Common misconceptions

Certification withdrawal is the ISO 27001 equivalent of a failed or withdrawn SOC 2 report.
The two frameworks produce different outcomes and are not directly equivalent. ISO/IEC 27001 results in a certification issued by an accredited certification body, and withdrawal revokes that certification. SOC 2 is an attestation examination performed by a licensed CPA firm under SSAE 18, resulting in a report rather than a certificate; there is no 'certificate' to withdraw in the SOC 2 model.
A withdrawn certificate can be reinstated simply by fixing the issue that caused withdrawal.
Withdrawal is generally the full removal of certified status, and regaining certification typically requires a new or repeat certification process rather than automatic reinstatement. Suspension, by contrast, is more commonly the temporary state that can be lifted after corrective action. The exact procedures depend on the certification body and applicable accreditation rules.
Withdrawal means the organization has no functioning security controls.
Withdrawal reflects that conformity with the certifiable ISMS requirements can no longer be maintained for the defined scope, not necessarily that all controls have failed. A certificate covers only the defined scope of the ISMS, so withdrawal does not by itself characterize the organization's entire security posture or guarantee the presence or absence of breaches.

Best practices

Monitor and complete all required surveillance and recertification audits on schedule, since missing them is a common path to suspension and eventual withdrawal.
Address nonconformities promptly and track corrective actions to closure, prioritizing serious or unresolved findings before they escalate to withdrawal.
Clarify with your certification body, in advance, its specific grounds, timeframes, and procedures for suspension versus withdrawal, as these vary by body and accreditation scheme.
Keep the certified ISMS scope and the Statement of Applicability accurate and current so that maintained conformity clearly matches what was certified.
Use the certification mark and any references only within the terms permitted by the certification body to avoid misuse-related grounds for withdrawal.
Maintain contingency plans for demonstrating security to customers through alternative means, recognizing that a withdrawn ISO 27001 certificate does not automatically satisfy other frameworks such as SOC 2, and that regaining certification typically requires repeating the certification process.