Back to Columns
ISMS & Certification12 min read

Preparing for Recertification in Year Three

September 14, 2026

Preparing for Recertification in Year Three
Share this article

ISMS certificates expire. Certification is valid for three years, and a recertification audit before that expiry renews it for the next three.

Organisations that have sailed through two surveillance audits tend to treat recertification as "the third surveillance." That misdirects the preparation. Where surveillance samples parts of the system to check operation, recertification re-evaluates whether the ISMS as a whole is effective for the organisation. Both the auditor-days and the examined scope step up.

There is also a constraint unique to recertification: the deadline. The audit, any corrective action, and the certification decision must all complete before the certificate expires. Surveillance can absorb some schedule slippage; recertification cannot.

This article covers how it differs from surveillance, how to present three years of improvement, when to revisit scope, and how to plan backwards. For the annual audits see Preparing for the Surveillance Audit; for the whole picture see What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. Timing, auditor-days, examined scope, and the treatment of expiry vary by certification body. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Confirm your own dates and requirements with your body.

Where It Sits in the Cycle

Year-counting conventions differ — you will hear both "the year-three audit" and "the year-four audit" — but in substance it is the audit taken after two surveillance audits, before the certificate expires.

StageAuditWhat it examines
Initial certificationStage 1 + Stage 2Whether the ISMS is established
First maintenanceSurveillanceWhether it has been operated for a year
Second maintenanceSurveillanceAs above, allocated so as not to repeat the previous year
RenewalRecertification auditWhether the ISMS as a whole is effective, and whether to renew for another three years

In breadth of examination, recertification approaches the initial audit, so it helps to recall what that looked at (What Stage 1 Looks At, What Stage 2 Looks At). The axis differs, though: not whether the documents are in place, but how you have operated for three years.

Certification bodies plan across the full three-year cycle so that the requirements and the scope are covered in aggregate. Recertification is the settlement of that account, so areas that surveillance passed over lightly often get concentrated attention. Lay out three years of audit reports and identify which requirements and which departments have only been examined thinly — that ordering decides your preparation priorities.

How It Differs from Surveillance

AspectSurveillanceRecertification
PurposeConfirm continued operationRe-evaluate the effectiveness of the whole ISMS and decide on renewal
ScopeNarrowed (a share of the three-year coverage)The full set of requirements and the whole scope, re-examined
Auditor-daysFewer than the initial auditMore than surveillance, approaching the initial audit
Period examinedThe last twelve monthsThree years of trajectory
Central questionIs it running as decided?Are the decisions themselves still right for this organisation — and has it improved?
Scope statementReport and reflect changesThe soundness of any revision is itself evaluated
Effect of findingsBears on maintaining certificationUnresolved before expiry risks lapse of the certificate

Put differently: surveillance asks whether you kept your promises; recertification asks whether the promises are still the right ones.

Take the risk assessment. Surveillance mostly asks whether there is evidence of review. Recertification asks whether the criteria set three years ago still fit the business, and whether the distribution of risk reflects how the business has changed. The same goes for security objectives: three years of identical targets, met every year, becomes material for a finding that the targets are set too low.

Presenting Three Years of Improvement

This is where preparation separates organisations. Arriving with three years of records in a box earns nothing. The real work is to build, yourself, the material that explains how the ISMS got better over three years.

Five axes make that explanation constructible.

AxisWhat it showsMaterial
① Trend in findingsWhether findings decreased, or changed in characterThree years of nonconformities and observations with their corrective outcomes
② Change in riskHow the risk assessment has been updatedWhat changed each year and why; new services and systems reflected
③ Objectives metKPI trajectory and what happened when targets were missedAnnual measurement results, history of target revision
④ IncidentsWhat occurred, the response, and what it changedIncident list linked to the procedures it altered
⑤ Structure and competenceWhether the ISMS survives people changingHandover records for role changes, updated training, internal auditors developed

Under ①, "zero findings" is not automatically good. Three years without a single finding invites the suspicion that the internal audit is not working. A sequence of findings raised, corrected, and not recurring is far stronger evidence that the management system functions.

Under ③, the revision history is what counts. Raising the bar after hitting a target, or replacing an indicator when the business changed, demonstrates that continual improvement is real. See Setting Security Objectives and KPIs.

Axis ⑤ is easy to overlook but close to what recertification is really asking. An ISMS running on one person's memory always fails across a three-year horizon. Aim to be able to show, through handover and training records, that operation holds at the same level when the manager changes.

Revisit Scope at Recertification

Scope can be changed at any time, but recertification is the most natural moment to revisit it, for three reasons:

  1. The soundness of your scope is being evaluated as a whole anyway
  2. Audit planning and auditor-day recalculation happen for this audit regardless
  3. Three years of operation have produced the evidence for whether the scope was too narrow or too broad
SituationWhat to consider
A customer asks for certification covering a business or site outside the current scopeExpanding scope. First establish exactly what the contract requires
New services or products launched since certificationWhether to bring them in — and if not, whether the boundary is explicable in documents
New sites, or remote work changing what a "site" meansRedefining the physical boundary and how remote environments are treated
Scope drawn too broadly, and operation is heavyNarrowing — but confirm the effect on customers first, since it requires explanation
M&A or restructuring changed the legal entity or business mixRe-examining the certified entity itself; consult the body early

Scope changes flow straight into auditor-days and fees. Change the number of sites or the headcount in scope and the effort is recalculated. Tell your certification body of any intended change before you fix the audit date. See Audit Fees: Ranges and What Moves Them and Defining ISMS Scope.

For healthcare companies, how much medical information handling to include is the distinctive question, and it must line up with what hospital contracts require, with your coverage of the three-ministry guidelines, and with your definition of the responsibility boundary (Demarcating Responsibility, The Three-Ministry Guidelines).

Planning Backwards, and Not Letting It Lapse

The outcome to avoid is expiry. Audit, corrective action, and the certification decision must all complete before the expiry date. Allowing for corrective action if a finding is raised, sitting the audit three to four months ahead of expiry is the realistic target.

Timing (relative to expiry)Work
12 monthsRead three years of audit and internal audit reports; identify thinly covered areas
9–10 monthsDecide whether scope needs revising; raise any intended change with the body
8 monthsProvisionally book the audit; confirm auditor-days and fees
6 monthsSubstantive review of the risk assessment, including the criteria themselves
5 monthsStocktake of procedures and the SoA; find what has drifted from reality since
4 monthsDeliver training — with content that is not three years old either
3 monthsPerform the internal audit, planned to cover all departments and requirements
2 monthsCorrect internal audit findings; build the three-year improvement summary
1–2 monthsHold the management review; resolve direction and resources for the next three years
1 monthSelf-check; confirm attendees, location, and whether remote audit is available
3–4 months before expiryRecertification audit
AfterCorrective action, reporting, certification decision

The management review before recertification matters more than in an ordinary year. A record of top management resolving direction, objectives, and resources for the next three years is the most direct evidence that the ISMS is integrated into the organisation. Do not settle for pro-forma minutes.

The gap between certification periods is also the point at which changing certification body is practicable — though transfer has its own procedure and lead time. If you are considering it, gather information early (Choosing a Certification Body).

Preparation Checklist

For the whole-system re-evaluation

  • Three years of audit and internal audit reports re-read; thin areas identified
  • Three years of nonconformities and observations, with outcomes, summarised on one page
  • The risk assessment criteria themselves reviewed against the current business
  • Objective trajectories and revision history organised
  • Three years of incidents linked to the procedures they changed

Document freshness

  • Last-revised dates checked; anything untouched for three years examined
  • SoA inclusions and exclusions consistent with the current risk assessment
  • Scope statement matches the current organisation chart, sites, and services
  • Training material updated to reflect the threat landscape and your own changes

Operating records

  • Internal audit and management review completed since the last surveillance
  • Previous surveillance findings closed, with evidence of effectiveness
  • Supplier register, asset register, and access rights match reality
  • Where the ISMS manager or internal auditors changed, handover and competence records exist

Schedule and procedure

  • A backward schedule from the expiry date, including time for corrective action
  • Intended scope changes raised with the body, with the effect on effort and fees confirmed
  • Audit date fixed

Conclusion

  1. Certification is valid for three years; audit, correction, and the decision must all complete before expiry
  2. The difference from surveillance is the unit of evaluation — not a sample of operation but the effectiveness of the whole ISMS
  3. The criteria, objectives, and procedures set three years ago are themselves questioned against the organisation you are now
  4. What to present is not volume of records but accumulated improvement, along five axes: findings trend, change in risk, KPI revision history, what incidents changed, and continuity of the structure
  5. Zero findings is not automatically good — raised, corrected, not recurring is stronger
  6. Recertification is the natural moment to revisit scope, but it drives effort and fees, so raise it before fixing the date
  7. To avoid lapse, work backwards to sit the audit three to four months before expiry

Pottech provides post-certification operational support: reviewing roles and scope, updating the risk assessment, performing internal audits, and handling surveillance and recertification. ISMS operational support starts at ¥800,000 per year (excluding tax, assuming an organisation of up to around 50 people). Payments to the certification body (audit fees) are not included.

See ISMS Certification Support, or contact us if you want to revisit scope before recertification, or if pulling three years together is more than your team can absorb.

References and Sources

Note: recertification timing, auditor-days, examined scope, and the handling of expiry and of transfer between certification bodies vary by body. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Guidelines are revised; always check the current edition.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.