Surveillance audits: what year two and year three actually involve

Certification is a three year contract, not a one off exam. Year one proves you built a system. Year two asks whether anyone ran it, which is a harder question and the one more companies fail.

Daniel Grigorovich
Daniel Grigorovich
Founder · 15 Sept 2026 · 6 min read
ISO 27001AuditEvidence
Surveillance audits: what year two and year three actually involve

Who should read this: a company that has just been certified to ISO 27001 and is approaching its first surveillance visit, or one deciding whether to certify and wanting to know what it is committing to beyond the first audit.

Most of what is written about ISO 27001 stops at the certificate. That is where the marketing stops, and it is also where the recurring obligation starts. The certificate runs for three years, and the certification body will be back twice before it expires.

The three year cycle

The shape is fixed by the accreditation rules the certification body works under, not by the body itself, so it is broadly the same wherever you certify.

  • Year zero. Stage 1, then Stage 2, then the certification decision. The certificate carries the decision date. What happens in those two visits is covered in Stage 1 and Stage 2: what the auditor asks for.
  • Around twelve months later. Surveillance audit one.
  • Around twenty four months. Surveillance audit two.
  • Before thirty six months. Recertification, which has to be completed and decided before the certificate expires, not after.

The word “around” carries weight. The first surveillance has to take place within twelve months of the certification decision, and if you let it slip the body can suspend the certificate. Companies that treat the anniversary as a soft target are the ones who end up explaining a suspension to a customer.

How long it takes

Considerably less than certification, which is the good news.

For an organisation of up to roughly fifty people, a surveillance visit typically runs half a day to a day. Stage 2 for the same company would have been one to three days, and recertification one to two. Surveillance is roughly a third of the initial audit effort, which is also broadly how the fees behave. The arithmetic for the full three years sits in what ISO 27001 really costs an SME.

Shorter does not mean lighter. The auditor arrives with a fixed list and less time to be charmed.

The five things checked every single visit

Whatever else is sampled, these are covered at every surveillance audit without exception.

  1. Nonconformities from the previous audit. Closed, with evidence, not just marked closed in a spreadsheet. If Stage 2 raised a minor about access reviews, the auditor wants the access reviews.
  2. The internal audit programme. At least one internal audit must have run since the last visit, covering an appropriate part of the system, with findings and follow-up.
  3. The management review. Real minutes, addressing the Clause 9.3 inputs, producing decisions. Not a calendar entry.
  4. Risk assessment currency. Has the risk assessment been revisited since the organisation changed? New office, new cloud platform, forty new staff, a new product line, an acquisition. If the business moved and the risk assessment did not, that is a finding.
  5. Corrective action in general. Evidence that issues get raised, investigated and closed as a matter of routine, not only when an auditor is due.

Items two and three are the ones companies miss most often, and they are the two that cannot be produced retrospectively with any credibility. The practical detail on running both properly is in internal audit and management review.

Annex A sampling rotates, deliberately

This is the part that catches people who prepared narrowly.

The certification body does not re-audit all ninety three applicable controls every year. It samples. And the sample rotates specifically so that across the three year cycle the whole Statement of Applicability gets covered.

The practical consequence: whatever the auditor examined last time is the least likely thing they will examine next time. A company that fixed exactly what was sampled at Stage 2 and left the rest has arranged to fail surveillance one. The grouping of controls that makes full coverage manageable is in the 93 Annex A controls grouped for real work.

Auditors also pay particular attention to proportionality when you have grown. Controls that were reasonable for a company of twenty five are often not reasonable at eighty, and headcount growth is visible to the auditor before they walk in.

Why year two fails more than year one

The pattern is consistent enough to be predictable.

Certification is a project. It has a deadline, a budget, someone assigned, and visible pressure. The system gets built and the audit gets passed. Then the project ends, the person who ran it returns to their real job, and the system has no owner.

Eleven months later somebody notices the surveillance date. The internal audit that should have happened in month four did not happen. The management review was a fifteen minute item in a leadership meeting with no minutes. The risk assessment still describes the company as it was before the new platform. Three months of access reviews are missing.

None of that can be fabricated convincingly, because all of it is dated. This is the same principle that makes evidence that assembles itself worth more than evidence prepared for the occasion: the dates are the part that cannot be back-filled.

It is also the argument for the system having a named owner with actual time, rather than being everyone’s occasional responsibility. That question is the subject of who owns security when nobody owns it.

What happens when it goes wrong

A minor nonconformity is normal. Most surveillance audits produce one or two. You agree a corrective action plan, you implement it, you provide evidence, it closes at or before the next visit. No drama.

A major nonconformity is different. The certification body sets a resolution window, commonly around ninety days, and may require a follow-up audit to verify closure rather than accepting documents. If it is not resolved in that window the certificate is suspended, which means you cannot use it or the mark while suspension lasts. That is the phase where a customer asks for your certificate and you have to explain. Prolonged suspension leads to withdrawal, which in practice is rare, because the prospect of losing a certificate concentrates attention.

The realistic risk for most SMEs is not withdrawal. It is a suspension that happens to overlap with a tender.

What to do in the twelve months between visits

Four commitments, and they are small if they are scheduled rather than remembered.

Put the internal audit in the calendar for month four or five, not month eleven. Hold the management review as its own meeting, twice a year, with minutes that record decisions. Revisit the risk assessment whenever something material changes, and record that you did even when nothing needed to change. Keep the routine evidence, the access reviews, the supplier checks, the training records, generating as it goes rather than being collected before the visit.

That is a handful of hours a quarter. It is also the difference between a surveillance audit that is an administrative morning and one that is a crisis.

The technical reality: surveillance tests whether the system ran, not whether it worked

Worth being precise about what these audits do and do not establish.

A surveillance audit verifies that your management system operated: that reviews happened, that audits ran, that findings closed, that a sample of controls is in place. It is a test of process continuity. It is not a test of whether your estate is actually defensible on the day of the visit, and it is not designed to be.

The auditor samples a subset of controls once a year. An attacker does not sample. The interval between surveillance visits is twelve months, and the interval between a misconfiguration appearing and it being exploited is usually shorter than that. A company can pass three consecutive surveillance audits while running an internet-facing service that has been unpatched for most of the cycle, because nothing in the audit programme is designed to find it.

Closing that gap means the things the audit samples annually are measured continuously instead: asset inventory built from what is actually running, patch and exposure state visible rather than declared, access reconciled against leavers and contracts, backup restores verified rather than scheduled. Do that and surveillance stops being an event you prepare for, because the evidence is already there and current. The broader version of this argument is in certified is not secure.

If you want the interval between audits covered rather than assumed, that is what the CloudSoul platform is for, and an independent security audit will tell you what the last sample missed.

Daniel Grigorovich

Daniel Grigorovich · Founder

I believe that no business should suffer from "compliance checklists" or navigating vague regulatory text. While I still stand by the principle that all software products should be reliable and secure, I want to give companies a way to overcome the challenges faced when implementing these requirements.