Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is ISO 27001 recertification?

Last verified

Recertification is the full reassessment of your ISMS before the typical three-year ISO/IEC 27001 certificate expires. It is broader than surveillance. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Explainer, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. ISO/IEC 17021-1 and ISO/IEC 27006 set how accredited bodies recertify. Plan before expiry; a lapse is not repaired by this page.

What this page is, and what it is not

Audience: a CISO approaching the end of a certificate cycle.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file a recertification application. Last verified 10 September 2026.

The certificate remains a relationship with an IAF-MLA accredited certification body. This product does not renew it.

Milestones relative to expiry

Timing is typical accredited practice. Your contract and the body confirm the window. Last verified 10 September 2026. Not legal advice.

Recertification milestones compared with surveillance (typical; not legal advice; last verified 10 September 2026)
MilestoneTiming relative to expiryHow it differs from surveillanceKind of text
Confirm expiry date and bodyWhen the certificate is issued — record it immediatelySurveillance does not change the printed expiry by itself.Contract / certificate fact.
Plan recertification audit daysTypically several months before expiry so findings can closeSurveillance days are fewer and partial; recertification is a full reassessment.ISO/IEC 17021-1 recertification practice; IAF MD 5 influences days.
Perform recertification auditBefore expiry — not after, if you want continuityLooks again at Clauses 4–10 and the SoA/Annex A selection as a system, not a thin sample.Accreditation practice.
Close nonconformitiesInside the body’s window, still aiming to finish before expirySurveillance findings also need closure; a recertification major finding can block renewal.CB grading practice.
New cycle beginsOn successful recertification, typically another three years with year-1 and year-2 surveillanceSurveillance continues a live certificate; recertification is the gate between cycles.Typical cycle — not a law.
LapseAfter expiry without a successful recertification decisionMissed surveillance can also suspend; a lapse usually means you are no longer certified.Accreditation outcome. This page does not restore it.

How recertification differs from the first audit

The first cycle includes Stage 1 as a documentation/readiness gate. Recertification assumes an ISMS already exists and tests whether it still works. You should still expect a full look at scope, risk, SoA, internal audit, management review, and a sample of implemented controls. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for a renewal. Last verified 10 September 2026. Not legal advice.

  • Is the printed expiry date on a shared calendar with a three-month warning?
  • Has the body confirmed recertification dates in writing?
  • Is the SoA 2022 (93 / four themes), not a leftover 2013 domain list?
  • Have we distinguished this visit from year-1/year-2 surveillance in the board pack?
  • Are open nonconformities closed or owned?
  • Do we know this page does not file the recertification request?

What to do now

These steps do not start a statutory clock.

  • Write the expiry date at the top of the ISMS risk register.
  • Read the surveillance and certification-process pages so the whole cycle is visible.
  • If this is a first certificate, read how to get certified instead.
  • Verify the body on IAF CertSearch before you pay the recertification invoice.
  • Re-verify sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance evidence collection and the obligation map maintain a standing evidence base across the cycle. Policies library and cyber risk register hold YOUR artefacts. Annex A crosswalk density is coverage, not a pass.

The recertification decision remains the accredited body’s.

Primary sources (last verified 10 September 2026)

ISO/IEC 17021-1; ISO/IEC 27006; IAF. ISO/IEC 27001:2022 remains the standard you are recertified against. Not legal advice.

Frequently asked questions