Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is an ISO 27001 surveillance audit?

Last verified

A surveillance audit is the usual year-1 and year-2 sample that keeps an ISO/IEC 27001 certificate valid inside a typical three-year cycle. It is partial, not a full recertification. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Explainer, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. ISO/IEC 17021-1 and ISO/IEC 27006 govern how accredited bodies perform surveillance. Clauses 4–10 must keep operating; Annex A controls marked implemented still need records.

What this page is, and what it is not

Audience: an ISMS owner who has the certificate and needs to keep it.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.

Only the issuing IAF-MLA accredited certification body (or a successor it agrees) performs recognised surveillance.

What is sampled in each year of the cycle

Cadence below is the typical accredited pattern. Your contract may state exact windows. Last verified 10 September 2026. Not legal advice.

Surveillance compared with the rest of the cycle (typical; not legal advice; last verified 10 September 2026)
Year in the cycleWhat is sampledWhat stays continuousKind of text
Year 0 — initial Stage 1 and Stage 2Documentation/readiness, then implementation/effectiveness of the ISMS.The ISMS itself — Clauses 4–10 do not pause after the certificate.Certification process (see that page). Not surveillance.
Year 1 — first surveillance (typical)A partial sample: some processes, some sites, some Annex A controls marked implemented, progress on prior findings.Internal audit, management review, corrective actions, risk and SoA currency.ISO/IEC 17021-1 surveillance practice.
Year 2 — second surveillance (typical)Another partial sample, usually covering areas not seen in year 1 so the cycle as a whole is representative.The same continuous machinery. Scope changes should already have been notified.ISO/IEC 17021-1 surveillance practice.
Year 3 — recertification (not surveillance)Full reassessment before expiry.Still the ongoing ISMS; recertification is a milestone, not a substitute for years 1–2.Recertification — see that page.
After a major change (new site, merger, new processing)Possible special audit or expanded sample, depending on the body.Revised scope, risk assessment, and SoA.Accreditation practice — ask your body; this page does not decide.
Lapsed or suspended certificateSurveillance does not restart a dead certificate by itself.Nothing on this page restores recognition.Accreditation outcome. Not a law.

What to keep continuously

Surveillance goes badly when the ISMS was rebuilt for Stage 2 and then left idle. Keep: a current SoA, risk assessment that reflects new systems, internal-audit results, management review, corrective-action status, and operating records for implemented Annex A controls. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for staying ready. Last verified 10 September 2026. Not legal advice.

  • Do we know the contracted surveillance window for year 1 and year 2?
  • Have internal audit and management review run since Stage 2?
  • Is the SoA still true after the last product or vendor change?
  • Are prior nonconformities closed with records?
  • Have we told the body about scope changes?
  • Do we treat this as partial sampling, not as “the easy year”?

What to do now

These steps do not file and do not start a statutory clock.

  • Put surveillance dates on the same calendar as recertification expiry.
  • Read the recertification and certification-process pages.
  • Refresh the auditor-evidence index before the visit.
  • Confirm the body is still IAF-MLA accredited in CertSearch.
  • Re-verify sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance evidence collection and evidence review keep rows current between visits. The obligation map, policies library, and cyber risk register support continuous operation. Annex A crosswalk density is coverage, not a pass.

Surveillance remains the accredited body’s sample.

Primary sources (last verified 10 September 2026)

ISO/IEC 17021-1 surveillance requirements; ISO/IEC 27006; IAF. ISO/IEC 27001:2022 still describes the ISMS you must keep running. Not legal advice.

Frequently asked questions