An ISO 27001 certificate sitting in a procurement portal looks identical whether the underlying ISMS is actively managed or undergoing deterioration. Understanding ISO 27001 validity means knowing every audit milestone, suspension trigger, and rule that governs how accredited certification bodies must manage a certificate between issuance and expiry.

This article sets out the three-year certification cycle in precise terms, what happens when audit windows are missed, and what drives early recertification, so that security leaders, compliance managers, and procurement teams have a technically accurate reference against which to hold a certification claim.

Schedule a Meeting with CertPro
TL;DR

Concern

Organizations achieve ISO 27001 certification and then mismanage the lifecycle that follows it: missed surveillance audit windows, and a misunderstanding of what triggers early recertification. An expired or suspended certificate can cost contracts.

Overview

ISO 27001 certification validity is three years from the date of issue, governed by accredited certification bodies under ISO/IEC 17021-1. Two annual surveillance audits occur within that window, and a full recertification audit resets the cycle at year three.

Solution

Track surveillance audits, corrective actions, scope changes, and recertification timing against the certificate expiry date. Keep the ISMS operating throughout the certification cycle and maintain evidence of continued conformity. When changes affect the certified scope or the ISMS, engage the certification body early to determine whether additional audit activity is required.

ISO 27001 Validity: What the Three-Year Cycle Actually Means

ISO 27001 certification validity is three years from the certificate issue date. That figure comes from ISO/IEC 17021-1:2015, the accreditation standard governing certification bodies that conduct management system audits. Every accredited certification body, whether ANAB-accredited or operating under another Global ACI MRA (formerly the IAF MLA) member, must follow these rules.

The three-year period contains the following mandatory audit events:

  • The initial certification audit in year one
  • A first surveillance audit approximately 12 months after initial certification
  • A second surveillance audit approximately 24 months after initial certification

The certificate expiry date is fixed at issuance. Late surveillance audits do not extend that date — they reduce the time remaining for the recertification audit and can trigger suspension. Conducting surveillance at month 15 instead of month 12 does not push the certificate anniversary; it compresses the recertification window that follows.

The ISO 27001 certification validity period resets only upon successful recertification. Certification bodies are required by ISO/IEC 17021-1 to confirm continued conformity before issuing that new certificate, meaning recertification is a genuine re-evaluation and not a renewal.

Certification Cycle Milestones

  • Initial Certification (Stage 1 + Stage 2) — Year 1

    A full ISMS audit against applicable ISO/IEC 27001 requirements and the organization's defined scope. Output: certificate issued and the three-year validity clock starts.

  • Surveillance Audit 1 — ~Month 12

    A focused review covering selected clauses, corrective actions, and objectives. Output: continued certification confirmed or suspended.

  • Surveillance Audit 2 — ~Month 24

    A focused review broader than Surveillance Audit 1, including recertification-preparation elements. Output: continued certification confirmed or suspended.

  • Recertification Audit — Before Month 36

    A full ISMS re-evaluation, typically shorter than the initial audit because the certification body already holds ISMS history. Output: a new certificate is issued and a fresh three-year cycle begins.

Initial Certification: Stage 1 and Stage 2

Initial certification uses two audit stages. Stage 1 evaluates the ISMS documentation, scope, readiness, and other requirements relevant to planning Stage 2.

Stage 2 evaluates implementation of the ISMS against ISO/IEC 27001 requirements. The audit team may examine records, interview personnel, observe activities, and sample relevant evidence.

That evidence establishes the baseline for the certification decision. The certificate is issued when the applicable requirements support that decision.

Surveillance Audits: What Gets Reviewed and What Can Lead to a Suspension

Across the certification cycle, the certification body plans surveillance and recertification activities to provide sufficient coverage of the management system and applicable certification requirements. Certification bodies plan which clauses and Annex A controls to sample at each surveillance event, ensuring full coverage across the cycle.

Surveillance audits typically assess:

  • Internal audit and management review results
  • Progress on corrective actions from prior audits
  • Complaints and their handling
  • Effectiveness of the ISMS in achieving information security objectives
  • Status of planned activities
  • Any significant changes to the ISMS or the organization's context
Surveillance Audits: What Gets Reviewed
Surveillance Audits: What Gets Reviewed

A merger, major technology migration, or significant headcount change must be disclosed and assessed as part of that review.

Certificate suspension may be required when a certified organization fails to meet surveillance audit requirements, voluntarily requests suspension, or has not resolved major nonconformities within the agreed timeframe. Suspension is typically signaled with a defined correction window, after which withdrawal (revocation) follows if the issues remain unresolved. A suspended certificate cannot be presented as evidence of current certification.

Certification bodies are required to publicize suspension and withdrawal status through their certificate directories, so waiting out a suspension rather than resolving nonconformities is not a viable option — a withdrawn certificate can disqualify a vendor from active contracts.

Recertification: Re-examination Before Expiry

Recertification provides the basis for a new certification cycle. The audit team evaluates the ISMS across the applicable requirements and considers the performance of the ISMS during the current cycle.

The certification body needs sufficient time to complete the recertification audit, address applicable findings, conduct the required review, and make the certification decision before the existing certificate expires.

Out-of-Cycle Changes and How ISO 27001 Certificate Expiry Works in Practice

Standard recertification happens before the 36-month expiry. Several scenarios, however, can trigger an out-of-cycle recertification or significantly alter the ISO 27001 certification validity period, and understanding them protects organizations from being caught with an invalid certificate mid-contract.

Major scope changes — adding a new business unit, a new geographic location, or an entirely new product line to the ISMS scope — typically require the certification body to conduct a special audit before the scope extension is reflected on the certificate. If the change is substantial enough that the existing audit basis no longer represents the organization, the certification body may initiate early recertification rather than waiting for the scheduled event.

Standard transitions are another trigger. The ISO 27001:2013 to ISO 27001:2022 transition deadline was October 31, 2025 (Source: IAF). Organizations that held a 2013-edition certificate had their certificates invalidated after that date.

Ownership or organizational structure changes — such as acquisitions — may prompt a certification body to review whether the legal entity on the certificate still exists. Some certification bodies require a new application and fresh Stage 1 and Stage 2 audits when the certified legal entity changes materially. Others allow transfer with a targeted audit, but this is certification-body-specific and must be confirmed in writing.

ISO 27001 certificate expiry on the stated date is fixed. Organizations commonly schedule their recertification audit 60 to 90 days before expiry to allow time for major nonconformity resolution without letting the certificate lapse.

Verifying a Certificate

Management can verify an ISO 27001 certificate through five checks:

  • Dates

    Confirm the issue and expiry dates.

  • Scope

    Compare the certificate scope with the services and locations in operation.

  • Accreditation

    Review the accreditation mark and the certification body's accreditation status.

  • Register

    Check the certification body's register or IAF CertSearch where available.

  • Edition

    Confirm the applicable ISO/IEC 27001 edition.

The transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 ended on 31 October 2025 under IAF MD 26. Current certification claims should therefore identify the applicable edition.

IAF CertSearch provides a database for validating accredited management system certifications and identifying status such as active, suspended, or withdrawn.

Conclusion

ISO 27001 validity is not a passive countdown. The three-year ISO 27001 certification validity period is an active management obligation. Organizations that treat ISO 27001 validity as a box already checked are the ones who discover a suspended certificate when a major contract is at stake.

The distinctions that matter most:

  • The certificate expiry date is fixed at issuance
  • Late surveillance audits compress the recertification window
  • Major scope or ownership changes can trigger out-of-cycle events
  • The ISO 27001:2013 edition is no longer recognized

CertPro is an independent CPA firm that conducts certification audits and provides independent assurance to technology organizations requiring ISO 27001 and related assessments. CertPro performs initial certification audits and surveillance audits with the objectivity that genuine third-party assurance requires.

Frequently Asked Questions
ISO 27001 certification validity is three years from the date of certificate issuance, as required by ISO/IEC 17021-1.
Missing a surveillance audit can lead to certificate suspension by the certification body. If the certificate expires during suspension, or major nonconformities remain unresolved within the suspension window, typically six months, the certificate is withdrawn.
Yes. A successful ISO 27001 recertification audit results in a new certificate with a new three-year expiry date. The recertification audit is a full ISMS re-evaluation, though it is typically shorter than the initial audit because the certification body already has audit history for the organization's ISMS.
Yes. October 31, 2025 was set as the mandatory transition deadline. Certificates referencing ISO 27001:2013 were invalidated after that date regardless of where they stood in their three-year cycle. Organizations that had not completed transition to ISO 27001:2022 by that date no longer held a recognized certificate under the framework.