Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What is ISO 27001 recertification?
Last verifiedRecertification is the full reassessment of your ISMS before the typical three-year ISO/IEC 27001 certificate expires. It is broader than surveillance. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Explainer, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. ISO/IEC 17021-1 and ISO/IEC 27006 set how accredited bodies recertify. Plan before expiry; a lapse is not repaired by this page.
What this page is, and what it is not
Audience: a CISO approaching the end of a certificate cycle.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file a recertification application. Last verified 10 September 2026.
The certificate remains a relationship with an IAF-MLA accredited certification body. This product does not renew it.
Milestones relative to expiry
Timing is typical accredited practice. Your contract and the body confirm the window. Last verified 10 September 2026. Not legal advice.
| Milestone | Timing relative to expiry | How it differs from surveillance | Kind of text |
|---|---|---|---|
| Confirm expiry date and body | When the certificate is issued — record it immediately | Surveillance does not change the printed expiry by itself. | Contract / certificate fact. |
| Plan recertification audit days | Typically several months before expiry so findings can close | Surveillance days are fewer and partial; recertification is a full reassessment. | ISO/IEC 17021-1 recertification practice; IAF MD 5 influences days. |
| Perform recertification audit | Before expiry — not after, if you want continuity | Looks again at Clauses 4–10 and the SoA/Annex A selection as a system, not a thin sample. | Accreditation practice. |
| Close nonconformities | Inside the body’s window, still aiming to finish before expiry | Surveillance findings also need closure; a recertification major finding can block renewal. | CB grading practice. |
| New cycle begins | On successful recertification, typically another three years with year-1 and year-2 surveillance | Surveillance continues a live certificate; recertification is the gate between cycles. | Typical cycle — not a law. |
| Lapse | After expiry without a successful recertification decision | Missed surveillance can also suspend; a lapse usually means you are no longer certified. | Accreditation outcome. This page does not restore it. |
Legal requirement, regulatory guidance, best practice, or our recommendation
Renewal is not automatic. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| A typical accredited certificate lasts three years subject to surveillance and recertification. | ISO/IEC 17021-1 cycle norms. | Does not make ISO 27001 a legal duty. |
| Clauses 4–10 must still be fulfilled at recertification, with a current SoA for Annex A. | Certification standard. | Does not mean you implement all 93 Annex A controls. |
| Book the recertification visit early enough to close findings before expiry. | Industry best practice. | Does not guarantee the body has calendar availability. |
| IAF transition ended accredited 2013-edition certificates by 31 October 2025. | IAF arrangement. | Does not recertify a 2013 system as 2013. |
| Keep a standing evidence base so recertification is not a rebuild. | ShipReady Metrics recommendation. | Does not issue the new certificate. |
How recertification differs from the first audit
The first cycle includes Stage 1 as a documentation/readiness gate. Recertification assumes an ISMS already exists and tests whether it still works. You should still expect a full look at scope, risk, SoA, internal audit, management review, and a sample of implemented controls. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for a renewal. Last verified 10 September 2026. Not legal advice.
- Is the printed expiry date on a shared calendar with a three-month warning?
- Has the body confirmed recertification dates in writing?
- Is the SoA 2022 (93 / four themes), not a leftover 2013 domain list?
- Have we distinguished this visit from year-1/year-2 surveillance in the board pack?
- Are open nonconformities closed or owned?
- Do we know this page does not file the recertification request?
What to do now
These steps do not start a statutory clock.
- Write the expiry date at the top of the ISMS risk register.
- Read the surveillance and certification-process pages so the whole cycle is visible.
- If this is a first certificate, read how to get certified instead.
- Verify the body on IAF CertSearch before you pay the recertification invoice.
- Re-verify sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance evidence collection and the obligation map maintain a standing evidence base across the cycle. Policies library and cyber risk register hold YOUR artefacts. Annex A crosswalk density is coverage, not a pass.
The recertification decision remains the accredited body’s.
Primary sources (last verified 10 September 2026)
ISO/IEC 17021-1; ISO/IEC 27006; IAF. ISO/IEC 27001:2022 remains the standard you are recertified against. Not legal advice.