ISO 27001 surveillance audits, explained: what happens after you certify, what the annual checks look at, and how to stay ready so they never become a scramble.
TL;DR
An ISO 27001 certificate is valid for three years, but it is not fire-and-forget. The certification body returns for lighter surveillance audits, usually annually, to confirm your ISMS is still operating. At the end of the three years, a full recertification audit renews the certificate.
Surveillance audits are smaller than the original Stage 2, but they can suspend or withdraw your certificate if your ISMS has decayed. Staying ready continuously is far easier than re-preparing each year.
On this page
ISO 27001 surveillance audits: what happens after you certify
Earning the certificate is a milestone, not a finish line. To keep it, you host surveillance audits, lighter checks conducted by the same certification body, typically once a year during the certificate’s three-year life. Their job is to confirm that the ISMS you certified is still running and improving, not quietly decaying now that the pressure is off.
The three-year cycle
Certification runs on a predictable rhythm. Understanding it removes the surprise and lets you plan.
What surveillance audits check
A surveillance audit does not re-examine everything. It samples, and it focuses on the areas most likely to reveal whether the ISMS is being maintained.
- That controls are still operating. The auditor samples evidence to confirm controls did not lapse after certification.
- Internal audits and management reviews. Proof the improvement loop kept running.
- Corrective actions. That findings, including any from the last audit, were genuinely closed.
- Changes since last time. New systems, new risks, and scope changes handled properly.
- Ongoing risk management. That your risk assessment and register are current, not frozen at certification.
What is at stake
Surveillance audits are lighter than the original Stage 2, but they carry real consequences. If the auditor finds that your ISMS has materially decayed, they can raise major nonconformities, and in serious cases the certificate can be suspended or withdrawn. For a company that won deals on the strength of the certificate, that is a commercial problem, not just a compliance one.
Staying ready between audits
Keep evidence flowing
- Collect continuously, not at audit time
Hold the cadence
- Internal audits and reviews on schedule
Close findings promptly
- Do not carry open items into the audit
Keep risk current
- Update the register as things change
The lean-team path to painless surveillance
Everything a surveillance audit checks comes down to one question: did the ISMS keep running after the certificate was issued? That is hard to guarantee when controls and evidence are spread across tools and depend on someone remembering to maintain each one.
Make every surveillance audit a non-event.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Keep controls running and evidence flowing continuously, so staying certified is the default rather than an annual scramble. No security team required.
Frequently asked questions
What is an ISO 27001 surveillance audit?
A lighter audit conducted by your certification body, usually annually, during the three-year life of your certificate. It confirms your ISMS is still operating and improving, sampling evidence rather than re-examining everything.
How often do surveillance audits happen?
Typically once a year in the two years after certification, with a full recertification audit at the end of the three-year cycle. Some bodies may adjust frequency based on your context.
Can I lose my ISO 27001 certificate at a surveillance audit?
Yes, if the audit finds that your ISMS has materially decayed. Major nonconformities can lead to suspension or, in serious cases, withdrawal of the certificate, which is why continuous maintenance matters.
How is a surveillance audit different from certification?
It is smaller and samples rather than assessing the entire ISMS. Certification, through Stage 1 and Stage 2, establishes the certificate; surveillance audits confirm it is still deserved between recertification cycles.
How do I prepare for a surveillance audit?
Stay ready continuously: keep evidence flowing, hold internal audits and management reviews on schedule, close findings promptly, and keep your risk assessment current. Continuity is far easier than re-preparing each year.

