Recertification Audit
A recertification audit is a comprehensive reassessment that an accredited certification body performs to renew an organization's ISO/IEC 27001 certification before the existing certificate expires. It typically takes place at the end of the certification cycle and is similar in depth and rigor to the original certification audit. Passing it allows the organization to continue holding a valid ISO 27001 certificate.
A recertification audit is the periodic, full-scope reassessment conducted by an accredited certification body to renew ISO/IEC 27001 certification at the close of a certification cycle, commonly structured over three years with interim surveillance audits. In most engagements it is comparable in detail and intensity to the initial Stage 2 certification audit, evaluating the ongoing conformity, effectiveness, and continual improvement of the information security management system (ISMS) against the certifiable requirements in clauses 4 through 10, with Annex A controls assessed as selected through the Statement of Applicability. Unlike surveillance audits, which are narrower interim checks between certification events, the recertification audit reassesses the ISMS as a whole. Its outcome is a renewed certificate covering only the defined scope of the ISMS; it does not constitute a SOC 2 report or attestation, and cycle length and specific procedures may vary by certification body and scope.
Why it matters
ISO/IEC 27001 certification is not a one-time achievement. Certification is issued for a defined cycle, commonly structured over three years, after which the certificate expires. The recertification audit is the mechanism that allows an organization to demonstrate that its information security management system (ISMS) remains conforming, effective, and subject to continual improvement, so that it can continue holding a valid certificate. Without a successful recertification audit, an organization risks a lapse in certification, which can affect customer trust, contractual obligations, and eligibility for engagements that require current ISO 27001 status.
Because the recertification audit is comparable in detail and intensity to the initial Stage 2 certification audit, it carries more weight than the narrower surveillance audits conducted between certification events. Surveillance audits are interim checks that sample portions of the ISMS, whereas recertification reassesses the ISMS as a whole against the certifiable requirements in clauses 4 through 10, with Annex A controls evaluated as selected through the Statement of Applicability. Treating recertification as a routine formality rather than a full reassessment can expose gaps that have accumulated over the cycle.
It is important to keep the boundaries of the outcome clear. A renewed certificate covers only the defined scope of the ISMS and does not guarantee the absence of security incidents. It is also distinct from a SOC 2 report or attestation, which is produced by a licensed CPA firm under a different standard; holding a renewed ISO 27001 certificate does not automatically satisfy SOC 2 requirements.
Who it's relevant to
Inside Recertification Audit
Common questions
Answers to the questions practitioners most commonly ask about Recertification Audit.