Major Nonconformity
A major nonconformity is a serious failure to meet a requirement of a standard, identified during an audit, that raises significant doubt about whether the organization's management system is working as intended. In an ISO 27001 context, it typically indicates a substantial gap that could negatively affect the organization's operations or objectives and generally must be resolved before certification can be granted or maintained. It is distinct from a minor nonconformity, which reflects a smaller, more isolated lapse.
In the context of an ISO/IEC 27001 certification audit conducted by an accredited certification body, a major nonconformity is typically a finding that represents a total failure to fulfil, or an absence of, a requirement of the standard or the organization's Information Security Management System (ISMS), or a situation that casts significant doubt on the ISMS's capability to achieve its intended outcomes. Such findings are generally addressed under the ISO/IEC 27001 requirement for nonconformity and corrective action (Clause 10, ISMS requirements), which calls for evaluating the need for action to eliminate causes so the nonconformity does not recur. Depending on the certification body's process and the audit stage, a major nonconformity typically requires documented corrective action and, in most cases, verification of effective resolution before a certificate is issued or maintained. This term applies to management system certification and should not be conflated with SOC 2 examination findings, which are reported by a CPA firm under a different attestation model rather than as certification nonconformities.
Why it matters
A major nonconformity is one of the most consequential outcomes an organization can receive during an ISO/IEC 27001 certification audit, because it typically must be resolved before a certificate can be issued or maintained. Unlike a minor nonconformity, which reflects a smaller or more isolated lapse, a major nonconformity signals a total failure to fulfil a requirement, the absence of a required element of the ISMS, or a situation that casts significant doubt on whether the management system can achieve its intended outcomes. For organizations pursuing certification on a deadline, this distinction can directly determine whether the certification timeline slips.
The practical stakes are significant because a major nonconformity can negatively affect an organization's operations and its ability to meet its objectives. A finding such as a misconfigured firewall permitting unauthorized network access is the kind of substantial gap that can rise to the level of a major nonconformity, since it undermines confidence in the effectiveness of the information security controls the ISMS is meant to govern. In most engagements, the certification body will require documented corrective action and verification of effective resolution before proceeding.
It is important to keep the framework boundaries clear. A major nonconformity is a concept specific to management system certification against ISO/IEC 27001 and is handled by an accredited certification body. It should not be conflated with findings in a SOC 2 examination, which is an attestation performed by a CPA firm under a different model and reported rather than certified. The precise thresholds and processes for classifying and closing a major nonconformity depend on the certification body and the audit stage.
Who it's relevant to
Inside Major Nonconformity
Common questions
Answers to the questions practitioners most commonly ask about Major Nonconformity.