Skip to main content
Category: Audit Process

Recertification Audit

Also known as: Recertification, Renewal Audit
Simply put

A recertification audit is a comprehensive reassessment that an accredited certification body performs to renew an organization's ISO/IEC 27001 certification before the existing certificate expires. It typically takes place at the end of the certification cycle and is similar in depth and rigor to the original certification audit. Passing it allows the organization to continue holding a valid ISO 27001 certificate.

Formal definition

A recertification audit is the periodic, full-scope reassessment conducted by an accredited certification body to renew ISO/IEC 27001 certification at the close of a certification cycle, commonly structured over three years with interim surveillance audits. In most engagements it is comparable in detail and intensity to the initial Stage 2 certification audit, evaluating the ongoing conformity, effectiveness, and continual improvement of the information security management system (ISMS) against the certifiable requirements in clauses 4 through 10, with Annex A controls assessed as selected through the Statement of Applicability. Unlike surveillance audits, which are narrower interim checks between certification events, the recertification audit reassesses the ISMS as a whole. Its outcome is a renewed certificate covering only the defined scope of the ISMS; it does not constitute a SOC 2 report or attestation, and cycle length and specific procedures may vary by certification body and scope.

Why it matters

ISO/IEC 27001 certification is not a one-time achievement. Certification is issued for a defined cycle, commonly structured over three years, after which the certificate expires. The recertification audit is the mechanism that allows an organization to demonstrate that its information security management system (ISMS) remains conforming, effective, and subject to continual improvement, so that it can continue holding a valid certificate. Without a successful recertification audit, an organization risks a lapse in certification, which can affect customer trust, contractual obligations, and eligibility for engagements that require current ISO 27001 status.

Because the recertification audit is comparable in detail and intensity to the initial Stage 2 certification audit, it carries more weight than the narrower surveillance audits conducted between certification events. Surveillance audits are interim checks that sample portions of the ISMS, whereas recertification reassesses the ISMS as a whole against the certifiable requirements in clauses 4 through 10, with Annex A controls evaluated as selected through the Statement of Applicability. Treating recertification as a routine formality rather than a full reassessment can expose gaps that have accumulated over the cycle.

It is important to keep the boundaries of the outcome clear. A renewed certificate covers only the defined scope of the ISMS and does not guarantee the absence of security incidents. It is also distinct from a SOC 2 report or attestation, which is produced by a licensed CPA firm under a different standard; holding a renewed ISO 27001 certificate does not automatically satisfy SOC 2 requirements.

Who it's relevant to

Compliance and GRC Managers
Those responsible for maintaining ISO 27001 status need to plan for recertification well before the certificate expires, ensuring the ISMS has been maintained and improved across the full cycle rather than only in the periods sampled by surveillance audits. They also coordinate scheduling with the accredited certification body and manage evidence for the full-scope reassessment.
Information Security Teams
Security engineers and ISMS owners must demonstrate that controls selected through the Statement of Applicability remain implemented and effective, and that the requirements in clauses 4 through 10 continue to be met. Because recertification is comparable in intensity to the initial Stage 2 audit, these teams should treat it as a comprehensive reassessment rather than a lighter surveillance check.
Executive and Risk Leadership
Leadership relies on continued certification to meet customer and contractual expectations. They should understand that a renewed certificate covers only the defined scope of the ISMS, does not guarantee freedom from breaches, and is not equivalent to a SOC 2 report or other attestations.
Auditors and Certification Body Personnel
Auditors conducting recertification evaluate the ongoing conformity, effectiveness, and continual improvement of the ISMS as a whole, distinguishing the full-scope recertification assessment from the narrower surveillance audits performed between certification events.

Inside Recertification Audit

Certification Cycle Context
A recertification audit occurs at the end of an ISO/IEC 27001 certification cycle, which typically spans three years in most engagements. It is conducted by an accredited certification body to determine whether the ISMS should be re-certified for a subsequent cycle.
Full ISMS Re-Evaluation
Unlike the interim surveillance audits conducted between certifications, a recertification audit typically involves a more comprehensive review of the management system requirements in clauses 4 through 10, rather than a limited sample of activities.
Statement of Applicability Review
The audit reassesses the Statement of Applicability and the selection of Annex A reference controls, confirming that the risk assessment and control selection remain appropriate for the defined scope of the ISMS.
Scope Confirmation
The certification body confirms that the certified scope of the ISMS remains accurate and reflects any organizational, technological, or contextual changes that occurred during the certification cycle.
Continual Improvement Evidence
The audit examines evidence of ongoing operation and improvement of the ISMS, such as management reviews, internal audits, corrective actions, and treatment of previously identified nonconformities.
Certification Outcome
A successful recertification audit results in the issuance of a renewed certificate covering only the defined scope of the ISMS for the next cycle. It is a certification outcome, not a report or attestation.

Common questions

Answers to the questions practitioners most commonly ask about Recertification Audit.

Does a recertification audit result in a report like a SOC 2 examination?
No. A recertification audit relates to ISO/IEC 27001, which results in a certification issued by an accredited certification body, not a report. A SOC 2 examination is a separate attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard and produces a report. The two outcomes are distinct, and satisfying one does not automatically satisfy the other. Do not expect a recertification audit to produce a SOC 2-style attestation report.
Is a recertification audit just a repeat of the original certification audit covering everything again?
Not necessarily. A recertification audit reassesses whether the ISMS continues to meet the ISO/IEC 27001 requirements in clauses 4 through 10 and whether the controls selected via the Statement of Applicability remain appropriate, but its depth and emphasis depend on the certification body, the defined scope of the ISMS, and prior audit findings. It typically considers changes since the previous cycle rather than treating the ISMS as entirely new. The specifics vary by engagement.
How should we prepare for a recertification audit?
Preparation typically involves reviewing the ISMS scope, the Statement of Applicability, and the results of the risk assessment to confirm they remain current, along with evidence from internal audits and management reviews conducted during the certification cycle. In most engagements, organizations also address any nonconformities raised during earlier surveillance activity. The exact expectations depend on the certification body and the defined scope of your ISMS.
What areas does a recertification audit usually focus on?
A recertification audit generally revisits the certifiable ISMS requirements in clauses 4 through 10 and the operation of the reference controls selected through the Statement of Applicability, which for the 2022 revision are drawn from the 93 Annex A controls organized into four themes (the 2013 version listed 114). Emphasis often falls on continual improvement, changes to scope or risk, and how prior findings were handled, though the precise focus depends on the auditor and scope.
What happens if nonconformities are identified during a recertification audit?
When nonconformities are identified, certification bodies typically require corrective action, and the handling depends on their severity and the certification body's own procedures. The outcome and timelines vary by certification body and scope, so organizations should confirm expectations directly with their certification body rather than assuming a fixed process applies.
Does a successful recertification audit guarantee our organization is free from security breaches?
No. An ISO/IEC 27001 certificate, whether initial or renewed, covers only the defined scope of the ISMS and attests that the management system meets the standard's requirements at the time of assessment. It does not guarantee freedom from breaches. This limitation is similar in spirit to how a SOC 2 report attests only to the controls and period covered rather than guaranteeing security outcomes.

Common misconceptions

A recertification audit is the same as an annual surveillance audit, just at the end of the cycle.
Surveillance audits between certifications typically review a limited sample of the ISMS, whereas a recertification audit generally involves a more comprehensive re-evaluation of the management system requirements before a renewed certificate can be issued. The exact depth depends on the certification body and scope.
Passing a recertification audit produces a SOC 2 report or attestation-style outcome.
Recertification is an ISO/IEC 27001 activity that results in a renewed certificate issued by an accredited certification body. It is not an attestation examination and does not produce a report. SOC 2 attestation under SSAE 18 is a separate framework performed by a licensed CPA firm.
A renewed certificate guarantees the organization is secure and free from breaches.
An ISO 27001 certificate covers only the defined scope of the ISMS and confirms conformity with the standard's requirements at the time of assessment. It does not guarantee freedom from security incidents or breaches.

Best practices

Begin recertification planning well before the current certificate expires, coordinating timing and scope with the certification body to avoid a lapse in certification.
Maintain continuous evidence of ISMS operation throughout the cycle, management reviews, internal audits, and corrective actions, rather than assembling documentation only ahead of the audit.
Reassess and update the risk assessment, Statement of Applicability, and Annex A control selection to reflect changes in the organization, technology, and threat landscape, noting the applicable ISO 27001/27002 version.
Confirm that the certified scope still accurately describes the ISMS and revise it where organizational or system changes have occurred.
Close out any nonconformities from prior surveillance or interim audits and retain evidence of their effective remediation.
Where the organization also pursues SOC 2, treat the two frameworks as distinct efforts, since satisfying ISO 27001 recertification does not automatically satisfy SOC 2 criteria and any mapping between them is partial.