ISO 27001 surveillance audits and recertification
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
The certificate lasts three years, but the auditor comes back every year. Surveillance audits are how the certification stays honest.
The three-year cycle
ISO 27001 certification is not a single pass — it is a three-year relationship with the certification body. After the initial certification audit, the body returns for surveillance audits (typically annually) and then a recertification audit at the end of the cycle. The certificate is valid for three years contingent on passing those checks.
What surveillance checks
A surveillance audit is narrower than the full Stage 2 but confirms the ISMS is alive: that internal audits and management reviews happened, that corrective actions closed, that the controls still operate, and that any changes (new products, new risks) are reflected. It samples rather than covering everything.
Keep operating between audits
The implication is that the ISMS must keep running all year, not get dusted off before the auditor visits. A management review that only ever happens the month before surveillance, or controls that lapse between audits, are exactly what surveillance is designed to catch.
Recertification
At year three, recertification is a fuller audit — closer to the original — that renews the certificate for another cycle. Continuous operation makes both surveillance and recertification routine. SentinelPanda keeps the audit cadence, evidence, and corrective actions flowing year-round so each surveillance visit is a confirmation, not a scramble.