Skip to main content
Category: Audit Process

Major Nonconformity

Also known as: Major Non-Conformance, Major NC
Simply put

A major nonconformity is a serious failure to meet a requirement of a standard, identified during an audit, that raises significant doubt about whether the organization's management system is working as intended. In an ISO 27001 context, it typically indicates a substantial gap that could negatively affect the organization's operations or objectives and generally must be resolved before certification can be granted or maintained. It is distinct from a minor nonconformity, which reflects a smaller, more isolated lapse.

Formal definition

In the context of an ISO/IEC 27001 certification audit conducted by an accredited certification body, a major nonconformity is typically a finding that represents a total failure to fulfil, or an absence of, a requirement of the standard or the organization's Information Security Management System (ISMS), or a situation that casts significant doubt on the ISMS's capability to achieve its intended outcomes. Such findings are generally addressed under the ISO/IEC 27001 requirement for nonconformity and corrective action (Clause 10, ISMS requirements), which calls for evaluating the need for action to eliminate causes so the nonconformity does not recur. Depending on the certification body's process and the audit stage, a major nonconformity typically requires documented corrective action and, in most cases, verification of effective resolution before a certificate is issued or maintained. This term applies to management system certification and should not be conflated with SOC 2 examination findings, which are reported by a CPA firm under a different attestation model rather than as certification nonconformities.

Why it matters

A major nonconformity is one of the most consequential outcomes an organization can receive during an ISO/IEC 27001 certification audit, because it typically must be resolved before a certificate can be issued or maintained. Unlike a minor nonconformity, which reflects a smaller or more isolated lapse, a major nonconformity signals a total failure to fulfil a requirement, the absence of a required element of the ISMS, or a situation that casts significant doubt on whether the management system can achieve its intended outcomes. For organizations pursuing certification on a deadline, this distinction can directly determine whether the certification timeline slips.

The practical stakes are significant because a major nonconformity can negatively affect an organization's operations and its ability to meet its objectives. A finding such as a misconfigured firewall permitting unauthorized network access is the kind of substantial gap that can rise to the level of a major nonconformity, since it undermines confidence in the effectiveness of the information security controls the ISMS is meant to govern. In most engagements, the certification body will require documented corrective action and verification of effective resolution before proceeding.

It is important to keep the framework boundaries clear. A major nonconformity is a concept specific to management system certification against ISO/IEC 27001 and is handled by an accredited certification body. It should not be conflated with findings in a SOC 2 examination, which is an attestation performed by a CPA firm under a different model and reported rather than certified. The precise thresholds and processes for classifying and closing a major nonconformity depend on the certification body and the audit stage.

Who it's relevant to

Compliance and GRC managers
Those responsible for achieving or maintaining ISO 27001 certification need to understand that a major nonconformity generally blocks certification until it is resolved. They coordinate corrective action and evidence of resolution with the certification body, and should plan certification timelines with the possibility of such findings in mind.
Security engineers and ISMS owners
Technical staff who implement and operate controls are often the ones addressing the underlying gaps, such as a misconfigured firewall allowing unauthorized network access. They are responsible for the corrective actions that eliminate the causes of a nonconformity so it does not recur, as called for under Clause 10.
Internal auditors and ISMS reviewers
Personnel conducting internal audits benefit from understanding how certification bodies distinguish major from minor nonconformities, so they can surface substantial gaps before an external audit and reduce the risk of a certification-blocking finding.
Executive sponsors and leadership
Because a major nonconformity can negatively affect operations and the organization's ability to meet its objectives, leaders accountable for certification outcomes should recognize its impact on certification status and allocate resources to timely, verifiable resolution.

Inside Major Nonconformity

Definition in the ISO 27001 context
A major nonconformity is a finding raised during an ISO/IEC 27001 audit indicating that a requirement of the standard (typically within clauses 4 through 10, or a selected Annex A control) is not met in a way that represents a significant failure. In most certification schemes it reflects either the absence of a required part of the ISMS or a systemic breakdown that raises doubt about the ISMS's ability to achieve its intended outcomes.
Distinction from a minor nonconformity
A major nonconformity typically denotes a substantial or systemic failure, whereas a minor nonconformity generally represents an isolated lapse or a limited deviation that does not undermine the overall ISMS. The precise classification depends on the certification body and auditor judgment rather than a fixed universal rule.
Impact on certification
During an initial certification audit, an outstanding major nonconformity usually prevents the certification body from recommending certification until it is resolved. During surveillance or recertification audits, a major nonconformity can place an existing certificate at risk, depending on the certification body's procedures.
Corrective action and resolution
Resolution typically requires the organization to perform root cause analysis, define and implement corrective action, and provide evidence to the certification body, often within a defined timeframe. The certification body may require verification, which can involve additional review before the nonconformity is closed.
Framework scope
The concept of a major nonconformity is native to the ISO/IEC 27001 certification process conducted by an accredited certification body. It does not apply in the same form to a SOC 2 examination, which is an attestation engagement under AICPA SSAE 18 that results in a report describing exceptions or deviations rather than issuing nonconformities.

Common questions

Answers to the questions practitioners most commonly ask about Major Nonconformity.

Does a major nonconformity mean my organization automatically fails and loses certification?
Not necessarily. A major nonconformity identified during an audit typically means the certification body will not recommend certification (in an initial audit) or may suspend or place certification at risk (in a surveillance or recertification audit) until the issue is resolved. However, in most cases the organization is given an opportunity to address the finding through corrective action, and outcomes depend on the certification body's procedures and the timing and adequacy of the response. It is not an immediate, irreversible loss of certification.
Is a major nonconformity in ISO 27001 the same as a qualified opinion or exception in a SOC 2 report?
No. A major nonconformity is a concept specific to ISO/IEC 27001 certification audits performed by an accredited certification body against the ISMS requirements. A SOC 2 report is an attestation examination performed by a CPA firm, where control deficiencies may lead to exceptions or a qualified opinion. The two frameworks use different terminology, methodologies, and outcomes, and the concepts are not directly interchangeable, even though both signal a shortcoming in controls.
What is the typical difference between a major and a minor nonconformity?
A major nonconformity generally reflects a significant failure, such as the absence of a required part of the ISMS, a systemic breakdown, or a control that fails to meet a requirement in a way that raises doubt about the ISMS's ability to achieve its intended outcomes. A minor nonconformity typically indicates an isolated or less severe lapse that does not undermine the overall effectiveness of the management system. The precise classification depends on the auditor's judgment and the certification body's criteria, so the same finding may be weighed differently across engagements.
What is usually expected in response to a major nonconformity?
In most engagements, the organization is expected to perform root cause analysis, define and implement corrective action, and provide evidence of remediation within a timeframe set by the certification body. The certification body may require verification of the correction, sometimes through additional review or a follow-up visit, before certification can proceed or be maintained. The specific evidence and timeline vary by certification body and the nature of the finding.
Which parts of ISO/IEC 27001 can a major nonconformity be raised against?
A major nonconformity can be raised against the certifiable ISMS requirements in clauses 4 through 10, or against the reference controls in Annex A that the organization has determined applicable through its Statement of Applicability and risk assessment. Because Annex A controls are selected based on scope and risk rather than applied universally, a nonconformity relating to Annex A is generally assessed against the controls the organization has declared applicable.
How can an organization reduce the risk of receiving a major nonconformity?
Common approaches include conducting internal audits and management reviews before the certification audit, maintaining current documentation aligned to the Statement of Applicability, ensuring risk assessment and treatment activities are evidenced, and confirming that selected controls are both designed and operating as intended. Because outcomes depend on the auditor, certification body, and defined scope, these measures reduce but do not eliminate the possibility of a finding.

Common misconceptions

A major nonconformity is the same as a SOC 2 exception, so the two frameworks handle findings identically.
A major nonconformity is a formal finding within the ISO 27001 certification process against the management system standard. A SOC 2 report, by contrast, is an attestation under SSAE 18 that describes control deviations or exceptions identified by a CPA firm. The mechanisms, terminology, and consequences differ and should not be treated as equivalent.
A single major nonconformity automatically and permanently means certification is lost.
In most cases a major nonconformity delays or suspends a certification recommendation rather than causing permanent loss. Organizations are typically given an opportunity to perform corrective action and provide evidence, and the specific outcome depends on the certification body's procedures and whether the audit is an initial, surveillance, or recertification audit.
Major nonconformities relate only to missing Annex A controls.
A major nonconformity can arise from failing to meet any applicable requirement, including the ISMS requirements in clauses 4 through 10, not solely from Annex A reference controls. Annex A controls are selected via the Statement of Applicability, while the certifiable requirements sit in the main clauses.

Best practices

Treat a major nonconformity as requiring documented root cause analysis rather than a surface-level fix, since certification bodies typically expect evidence that the underlying cause has been addressed.
Clarify the certification body's required timeframe and verification expectations for closing the nonconformity early, as these vary by body and by audit type (initial, surveillance, or recertification).
Distinguish clearly between whether a finding relates to an ISMS requirement in clauses 4 through 10 or to a selected Annex A control, and confirm the applicable version of the standard when referencing controls.
Maintain evidence of corrective action, including the changes implemented and their effectiveness, so it can be presented for the certification body's verification.
Avoid assuming that resolving a nonconformity in one framework satisfies another; because mapping between ISO 27001 and SOC 2 is only partial, address findings within the framework in which they were raised.
Use internal audits and management reviews proactively to detect systemic issues before an external audit, reducing the likelihood that a lapse escalates to a major nonconformity.