# ISO 27001 Recertification After 3 Years

> ISO 27001 recertification after three years: how it differs from a surveillance audit, management review, internal audit, SoA and preparation.

- Source: https://www.sidd.swiss/en/insights/iso-27001-recertification/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Oliver Stutz
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

An ISO/IEC 27001 certificate is valid for three years. Stage 1 and Stage 2 in year 0 are followed by two surveillance audits in years 1 and 2, and in year 3 by the recertification audit, which re-examines the entire scope of the Information Security Management System (ISMS). Organisations that approach recertification as a "big surveillance audit" systematically underestimate the effort and risk Major Nonconformities that can block the renewal of the certificate.

This article summarises what matters in an ISO 27001:2022 recertification:

- The formal difference between surveillance and recertification audits under IAF MD 5
- Minimum requirements for sampling, audit person-days and topic coverage
- The role of management review and internal audit as gate-openers
- Statement of Applicability (SoA): maintenance, versioning, transition from 2013 to 2022
- Typical findings after three years of ISMS operation and how to avoid them
- An ideal preparation timeline starting at T-9 months

The legal framework consists of ISO/IEC 27001:2022, ISO/IEC 27006:2021 (requirements for certification bodies) and IAF Mandatory Document 5, which governs the calculation of audit person-days. In Switzerland, accredited bodies such as SQS, SGS, Bureau Veritas and TÜV operate under the supervision of the Swiss Accreditation Service (SAS).

## Surveillance versus recertification

Surveillance audits sample on a risk basis: typically all core processes (risk management, internal audit, management review, corrective actions) but only a subset of Annex A controls. Audit duration under IAF MD 5 is one third of the initial audit time. A recertification audit, by contrast, must demonstrate the full effectiveness of the ISMS across the entire three-year cycle and has a scope of roughly two thirds of the initial audit duration. For an organisation with 150 employees, this means in practice: if the initial audit took 8 person-days, surveillances were 2.5–3 each, and recertification will be 5–6 person-days.

In terms of substance, ISO/IEC 27006 section 9.6.4 requires the auditor to address three topics explicitly: (1) the continued suitability and effectiveness of the ISMS in light of internal and external changes, (2) demonstrated contribution to achieving the information security objectives and (3) the suitability of the chosen Annex A controls for treating identified risks. The auditor will therefore ask specifically what has changed in the organisational context over the past three years, cloud migration, M&A, new product lines, Brexit fallout, regulatory shifts such as NIS2 or DORA, and how the ISMS has responded.

## What management review must cover

In the recertification year, the management review under clause 9.3 of ISO 27001 is the single most important document besides the SoA. It must demonstrably process all inputs listed in 9.3.2: status of previous reviews, changes in external and internal issues (linked to the context analysis under 4.1/4.2), findings from audits and reviews, fulfilment of information security objectives, trends in nonconformities and corrective actions, results of risk assessment and risk treatment, feedback from interested parties, and opportunities for continual improvement.

The outputs under 9.3.3 are fewer but decisive: decisions on improvement opportunities, any changes to the ISMS, and resource needs. The weakness auditors most commonly document as a Minor Nonconformity is the missing linkage between these outputs and concrete actions and owners. A management review minute that records only "the executive board takes note of the report" does not satisfy the standard. What is required are documented decisions with owner, deadline and budget allocation, ideally linked to the action pool in the ISMS tooling.

## Internal audit as gate-opener

Clause 9.2 requires an internal audit programme that defines frequency, methods, responsibilities, planning requirements and reporting. Across the three-year cycle, all ISMS clauses (4–10) and all applicable Annex A controls must have been audited at least once in full. Producing the multi-year programme plan only in the recertification year signals to the auditor that internal audits were ad hoc rather than systematic.

In practice, a rolling plan works well: year 1 focuses on technological controls (A.8 Technological), year 2 on organisational (A.5) and people controls (A.6), year 3 on physical controls (A.7) and a fresh pass on all high-risk areas. Audit reports must classify findings by severity (Major/Minor Nonconformity, Observation, Opportunity for Improvement) and be tracked with owners, root-cause analysis and verification of effectiveness. In the recertification year, the external auditor will sample whether corrective actions marked as "closed" actually addressed root causes or only symptoms.

## Maintaining the Statement of Applicability across three years

The SoA is, under clause 6.1.3 d), the only mandatory document that lists all Annex A controls, including those excluded, with justification. For the 93 controls in the 2022 version, each SoA entry must contain at minimum: applicability (yes/no), justification for inclusion or exclusion, implementation status, reference to control documentation, and reference to the risks it treats. Versioning and change tracking are not optional, the auditor will compare the SoA from the initial audit, from each surveillance and the current state.

Organisations that have not yet migrated from ISO 27001:2013 to 2022 must have completed this by 31 October 2025, the transition period under IAF Resolution 2022-19 has ended. Anyone recertifying now necessarily works with the 2022 SoA (4 themes instead of 14 domains, 93 instead of 114 controls, 11 new controls including A.5.7 Threat Intelligence, A.5.23 Cloud Services, A.5.30 ICT Readiness, A.8.9 Configuration Management, A.8.23 Web Filtering, A.8.28 Secure Coding). A cross-reference table old/new makes traceability easier for the auditor.

## Typical findings after three years of operation

Based on experience from more than twenty recertification engagements, most findings do not stem from missing controls but from drift: processes that are no longer lived because the original owners have left; asset inventories (A.5.9) that have not been reconciled for two years; access rights (A.5.18) that have never been systematically re-certified; supplier assessments (A.5.19–A.5.22) that froze after initial onboarding; awareness training (A.6.3) without evidence of effectiveness; patch management (A.8.8) that produces reports but does not track SLA breaches.

A second pattern is unclear interfaces to new regimes: NIS2 supplier requirements from EU corporate customers, DORA Register of Information requests, AI Act conformity assessments for high-risk AI systems in use. If the ISMS has not captured these topics in the context analysis (4.1) and integrated them into the risk plan (6.1.2), the auditor will flag this as a systemic weakness. Referencing ongoing projects is not enough, a documented plan with owners and timeline is mandatory.

## Preparation roadmap from T-9 months

Realistic preparation begins nine months before the recertification date. T-9 to T-7: a complete internal audit of all ISMS clauses and Annex A controls that closes the three-year cycle. T-6: root-cause analysis of findings, corrective action plan with clear effectiveness-verification dates. T-5: updated risk assessment with the current threat picture (ransomware trends in 2026, supply-chain attacks, AI-driven phishing quality). T-4: SoA review and migration of any residual 2013 items. T-3: consolidated management review with all 9.3.2 inputs and documented outputs.

T-2 to T-1: documentation review by a second-opinion external partner, update of the mandatory documents (scope statement, ISMS policy, risk methodology, incident response plan, BCM plans per A.5.29/A.5.30), Stage 1 review simulation. T-0: audit execution. At this pace, there is buffer for the unavoidable last-minute issues, staff changes in the ISMS team, sudden shadow-IT discoveries, an open penetration test report without evidenced closures.

## How SIDD supports you

An ISO 27001 recertification is the stress test for an ISMS that has become routine over three years. We know the findings Swiss certification bodies typically write and where the workload concentrates: evidence of effectiveness, supplier lifecycle, 2022 transition residuals, integration of new EU regimes. SIDD accompanies recertifications with a 9-month sprint plan and delivers the documents auditors expect in the format they know. More on our offering at [ISMS & ISO 27001](https://www.sidd.swiss/en/services/iso-27001-isms) and on continuous operation at [External CISO / ISB](https://www.sidd.swiss/en/services/vciso). To request a quick gap assessment, use our [quote form](https://www.sidd.swiss/en/quote); for a confidential first conversation, reach us via the [contact form](https://www.sidd.swiss/en/contact). Anyone hoping to pass the recertification without a Major Nonconformity should not start in month T-2.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
