Skip to content

ISO 27001 surveillance audits and recertification

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

The certificate lasts three years, but the auditor comes back every year. Surveillance audits are how the certification stays honest.

The three-year cycle

ISO 27001 certification is not a single pass — it is a three-year relationship with the certification body. After the initial certification audit, the body returns for surveillance audits (typically annually) and then a recertification audit at the end of the cycle. The certificate is valid for three years contingent on passing those checks.

What surveillance checks

A surveillance audit is narrower than the full Stage 2 but confirms the ISMS is alive: that internal audits and management reviews happened, that corrective actions closed, that the controls still operate, and that any changes (new products, new risks) are reflected. It samples rather than covering everything.

Keep operating between audits

The implication is that the ISMS must keep running all year, not get dusted off before the auditor visits. A management review that only ever happens the month before surveillance, or controls that lapse between audits, are exactly what surveillance is designed to catch.

Recertification

At year three, recertification is a fuller audit — closer to the original — that renews the certificate for another cycle. Continuous operation makes both surveillance and recertification routine. SentinelPanda keeps the audit cadence, evidence, and corrective actions flowing year-round so each surveillance visit is a confirmation, not a scramble.

The ISO 27001 certification process SOC 2 bridge letters Continual improvement in an ISMS

Run your compliance program in one workspace.