A surveillance audit is the shorter annual check that keeps an ISO 27001 certificate valid between full recertification audits.
The short answer
An ISO 27001 certificate runs for three years. In years one and two the certification body carries out a surveillance audit, a partial review confirming the management system is still operating. In year three there is a full recertification audit. Surveillance audits are shorter than the original Stage 2, but they are not a formality: a major nonconformity can suspend the certificate.
The shift in emphasis matters. The first audit asked whether you built a system. Surveillance asks whether you have been running it since.
On this page
The three-year cycle
What a surveillance audit covers
Not everything. The certification body works to a plan that guarantees the whole system is covered across the three-year cycle, with certain items examined every single time.
| Examined every year | Sampled across the cycle |
|---|---|
| Internal audit programme and its results | A rotating selection of Annex A controls |
| Management review records | Specific departments, sites or systems |
| Corrective actions from the last audit | Supplier and third-party arrangements |
| Complaints and security incidents | Business continuity testing |
| Changes to scope, systems or the organisation | Awareness and training coverage |
| Use of the certification mark and logo | Physical and environmental controls |
Change is the trigger
New product, new cloud region, new office, an acquisition or a big headcount jump all get scrutiny. Tell the certification body in advance. Discovering an unreported scope change during the audit is worse than declaring it.
What happens if something fails
| Outcome | Consequence |
|---|---|
| Minor nonconformity | Corrective action plan submitted, usually verified at the next audit. Certificate unaffected |
| Major nonconformity | Must be resolved within a set window, often 90 days, with evidence. Certificate at risk |
| Unresolved major | Certificate suspended, and withdrawn if it stays unresolved |
| Audit not scheduled in time | Suspension on process grounds, independent of how the controls are performing |
Staying ready between audits
Run the programme
Internal audits and management reviews on schedule. Their absence is the fastest route to a major.
Keep the register live
A risk register untouched since certification tells the auditor the system stopped operating.
Log evidence as it happens
Access reviews, patching and incidents recorded continuously, the way evidence collection should work.
How Osto keeps evidence continuous
The hard part of surveillance is not the audit day, it is the eleven months before it. Osto runs the controls that generate the evidence, access and MFA, cloud posture, endpoint control, vulnerability testing and monitoring, and records the output as it happens. When drift appears, in a misconfigured cloud account or a device out of policy, it shows up in the dashboard rather than in an auditor’s finding a year later.
Free security assessment
Stay audit-ready for the eleven months in between
Osto catches drift as it happens, in cloud configuration, device state and access, rather than leaving it for next year’s auditor.
Get a free security assessment Book a platform walkthroughContinuous evidence · Drift caught early · One platform, everything
Frequently asked questions
What is a surveillance audit?
A shorter annual audit carried out by your certification body in years one and two of the three-year ISO 27001 cycle. It confirms the management system is still operating, examining a subset of controls plus the internal audit and management review records.
How often does a surveillance audit happen?
Once a year, in years one and two after certification. Year three is a full recertification audit. Each audit must fall within twelve months of the previous one, measured from the audit date rather than the certificate date.
How long does a surveillance audit take?
Typically about a third of the original Stage 2 duration. For a small organisation with a narrow scope that often means one auditor day, though scope changes or open findings extend it.
Can you lose certification at a surveillance audit?
Yes. A major nonconformity that is not resolved within the agreed window leads to suspension, and continued failure leads to withdrawal. Missing the audit window entirely can also trigger suspension.
What is the difference between a surveillance audit and recertification?
Surveillance is partial and confirms ongoing operation. Recertification in year three re-examines the entire management system, closer in depth to the original Stage 2, and results in a new three-year certificate.

