ISMS certificates expire. Certification is valid for three years, and a recertification audit before that expiry renews it for the next three.
Organisations that have sailed through two surveillance audits tend to treat recertification as "the third surveillance." That misdirects the preparation. Where surveillance samples parts of the system to check operation, recertification re-evaluates whether the ISMS as a whole is effective for the organisation. Both the auditor-days and the examined scope step up.
There is also a constraint unique to recertification: the deadline. The audit, any corrective action, and the certification decision must all complete before the certificate expires. Surveillance can absorb some schedule slippage; recertification cannot.
This article covers how it differs from surveillance, how to present three years of improvement, when to revisit scope, and how to plan backwards. For the annual audits see Preparing for the Surveillance Audit; for the whole picture see What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. Timing, auditor-days, examined scope, and the treatment of expiry vary by certification body. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Confirm your own dates and requirements with your body.
Where It Sits in the Cycle
Year-counting conventions differ — you will hear both "the year-three audit" and "the year-four audit" — but in substance it is the audit taken after two surveillance audits, before the certificate expires.
| Stage | Audit | What it examines |
|---|---|---|
| Initial certification | Stage 1 + Stage 2 | Whether the ISMS is established |
| First maintenance | Surveillance | Whether it has been operated for a year |
| Second maintenance | Surveillance | As above, allocated so as not to repeat the previous year |
| Renewal | Recertification audit | Whether the ISMS as a whole is effective, and whether to renew for another three years |
In breadth of examination, recertification approaches the initial audit, so it helps to recall what that looked at (What Stage 1 Looks At, What Stage 2 Looks At). The axis differs, though: not whether the documents are in place, but how you have operated for three years.
Certification bodies plan across the full three-year cycle so that the requirements and the scope are covered in aggregate. Recertification is the settlement of that account, so areas that surveillance passed over lightly often get concentrated attention. Lay out three years of audit reports and identify which requirements and which departments have only been examined thinly — that ordering decides your preparation priorities.
How It Differs from Surveillance
| Aspect | Surveillance | Recertification |
|---|---|---|
| Purpose | Confirm continued operation | Re-evaluate the effectiveness of the whole ISMS and decide on renewal |
| Scope | Narrowed (a share of the three-year coverage) | The full set of requirements and the whole scope, re-examined |
| Auditor-days | Fewer than the initial audit | More than surveillance, approaching the initial audit |
| Period examined | The last twelve months | Three years of trajectory |
| Central question | Is it running as decided? | Are the decisions themselves still right for this organisation — and has it improved? |
| Scope statement | Report and reflect changes | The soundness of any revision is itself evaluated |
| Effect of findings | Bears on maintaining certification | Unresolved before expiry risks lapse of the certificate |
Put differently: surveillance asks whether you kept your promises; recertification asks whether the promises are still the right ones.
Take the risk assessment. Surveillance mostly asks whether there is evidence of review. Recertification asks whether the criteria set three years ago still fit the business, and whether the distribution of risk reflects how the business has changed. The same goes for security objectives: three years of identical targets, met every year, becomes material for a finding that the targets are set too low.
Presenting Three Years of Improvement
This is where preparation separates organisations. Arriving with three years of records in a box earns nothing. The real work is to build, yourself, the material that explains how the ISMS got better over three years.
Five axes make that explanation constructible.
| Axis | What it shows | Material |
|---|---|---|
| ① Trend in findings | Whether findings decreased, or changed in character | Three years of nonconformities and observations with their corrective outcomes |
| ② Change in risk | How the risk assessment has been updated | What changed each year and why; new services and systems reflected |
| ③ Objectives met | KPI trajectory and what happened when targets were missed | Annual measurement results, history of target revision |
| ④ Incidents | What occurred, the response, and what it changed | Incident list linked to the procedures it altered |
| ⑤ Structure and competence | Whether the ISMS survives people changing | Handover records for role changes, updated training, internal auditors developed |
Under ①, "zero findings" is not automatically good. Three years without a single finding invites the suspicion that the internal audit is not working. A sequence of findings raised, corrected, and not recurring is far stronger evidence that the management system functions.
Under ③, the revision history is what counts. Raising the bar after hitting a target, or replacing an indicator when the business changed, demonstrates that continual improvement is real. See Setting Security Objectives and KPIs.
Axis ⑤ is easy to overlook but close to what recertification is really asking. An ISMS running on one person's memory always fails across a three-year horizon. Aim to be able to show, through handover and training records, that operation holds at the same level when the manager changes.
Revisit Scope at Recertification
Scope can be changed at any time, but recertification is the most natural moment to revisit it, for three reasons:
- The soundness of your scope is being evaluated as a whole anyway
- Audit planning and auditor-day recalculation happen for this audit regardless
- Three years of operation have produced the evidence for whether the scope was too narrow or too broad
| Situation | What to consider |
|---|---|
| A customer asks for certification covering a business or site outside the current scope | Expanding scope. First establish exactly what the contract requires |
| New services or products launched since certification | Whether to bring them in — and if not, whether the boundary is explicable in documents |
| New sites, or remote work changing what a "site" means | Redefining the physical boundary and how remote environments are treated |
| Scope drawn too broadly, and operation is heavy | Narrowing — but confirm the effect on customers first, since it requires explanation |
| M&A or restructuring changed the legal entity or business mix | Re-examining the certified entity itself; consult the body early |
Scope changes flow straight into auditor-days and fees. Change the number of sites or the headcount in scope and the effort is recalculated. Tell your certification body of any intended change before you fix the audit date. See Audit Fees: Ranges and What Moves Them and Defining ISMS Scope.
For healthcare companies, how much medical information handling to include is the distinctive question, and it must line up with what hospital contracts require, with your coverage of the three-ministry guidelines, and with your definition of the responsibility boundary (Demarcating Responsibility, The Three-Ministry Guidelines).
Planning Backwards, and Not Letting It Lapse
The outcome to avoid is expiry. Audit, corrective action, and the certification decision must all complete before the expiry date. Allowing for corrective action if a finding is raised, sitting the audit three to four months ahead of expiry is the realistic target.
| Timing (relative to expiry) | Work |
|---|---|
| 12 months | Read three years of audit and internal audit reports; identify thinly covered areas |
| 9–10 months | Decide whether scope needs revising; raise any intended change with the body |
| 8 months | Provisionally book the audit; confirm auditor-days and fees |
| 6 months | Substantive review of the risk assessment, including the criteria themselves |
| 5 months | Stocktake of procedures and the SoA; find what has drifted from reality since |
| 4 months | Deliver training — with content that is not three years old either |
| 3 months | Perform the internal audit, planned to cover all departments and requirements |
| 2 months | Correct internal audit findings; build the three-year improvement summary |
| 1–2 months | Hold the management review; resolve direction and resources for the next three years |
| 1 month | Self-check; confirm attendees, location, and whether remote audit is available |
| 3–4 months before expiry | Recertification audit |
| After | Corrective action, reporting, certification decision |
The management review before recertification matters more than in an ordinary year. A record of top management resolving direction, objectives, and resources for the next three years is the most direct evidence that the ISMS is integrated into the organisation. Do not settle for pro-forma minutes.
The gap between certification periods is also the point at which changing certification body is practicable — though transfer has its own procedure and lead time. If you are considering it, gather information early (Choosing a Certification Body).
Preparation Checklist
For the whole-system re-evaluation
- Three years of audit and internal audit reports re-read; thin areas identified
- Three years of nonconformities and observations, with outcomes, summarised on one page
- The risk assessment criteria themselves reviewed against the current business
- Objective trajectories and revision history organised
- Three years of incidents linked to the procedures they changed
Document freshness
- Last-revised dates checked; anything untouched for three years examined
- SoA inclusions and exclusions consistent with the current risk assessment
- Scope statement matches the current organisation chart, sites, and services
- Training material updated to reflect the threat landscape and your own changes
Operating records
- Internal audit and management review completed since the last surveillance
- Previous surveillance findings closed, with evidence of effectiveness
- Supplier register, asset register, and access rights match reality
- Where the ISMS manager or internal auditors changed, handover and competence records exist
Schedule and procedure
- A backward schedule from the expiry date, including time for corrective action
- Intended scope changes raised with the body, with the effect on effort and fees confirmed
- Audit date fixed
Conclusion
- Certification is valid for three years; audit, correction, and the decision must all complete before expiry
- The difference from surveillance is the unit of evaluation — not a sample of operation but the effectiveness of the whole ISMS
- The criteria, objectives, and procedures set three years ago are themselves questioned against the organisation you are now
- What to present is not volume of records but accumulated improvement, along five axes: findings trend, change in risk, KPI revision history, what incidents changed, and continuity of the structure
- Zero findings is not automatically good — raised, corrected, not recurring is stronger
- Recertification is the natural moment to revisit scope, but it drives effort and fees, so raise it before fixing the date
- To avoid lapse, work backwards to sit the audit three to four months before expiry
Pottech provides post-certification operational support: reviewing roles and scope, updating the risk assessment, performing internal audits, and handling surveillance and recertification. ISMS operational support starts at ¥800,000 per year (excluding tax, assuming an organisation of up to around 50 people). Payments to the certification body (audit fees) are not included.
See ISMS Certification Support, or contact us if you want to revisit scope before recertification, or if pulling three years together is more than your team can absorb.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- ISO/IEC 17021-1 Conformity assessment — Requirements for bodies providing audit and certification of management systems | ISO
- Guidelines for the Safe Management of Medical Information Systems | MHLW
Note: recertification timing, auditor-days, examined scope, and the handling of expiry and of transfer between certification bodies vary by body. Interpretation of requirements and controls, and the handling of accreditation and certification, are governed by the standard itself and the publications of the accreditation and certification bodies. Guidelines are revised; always check the current edition.