What an ISO 27001 surveillance audit covers, how often it happens, how many audit days it takes and what a small organisation should budget for it.
An ISO 27001 surveillance audit is a shorter audit your certification body runs in each of the two years between your initial certification audit and your three yearly recertification. It checks that the ISMS is still running, not that it was once built. The first ISO 27001 surveillance audit must happen within 12 months of the certification decision, it usually takes about a third of the time your initial audit took, and commonly reported 2026 US figures put it at roughly US$6,000 to US$7,500 a year for a small organisation.
An ISO 27001 surveillance audit is a partial audit carried out by your accredited certification body during the three year life of your certificate, to confirm the information security management system is still operating and still conforms to ISO/IEC 27001:2022. It is not a full re-examination of every Annex A control. The auditor samples the parts of the ISMS that prove the system is alive: your internal audit programme, your management review, the nonconformities raised last time, and any changes to scope, risk or personnel.
The rules that govern an ISO 27001 surveillance audit sit in ISO/IEC 17021-1, the standard accredited certification bodies work to, rather than in ISO 27001 itself. That is why the requirement is the same whether your certificate covers ISO 27001, ISO 9001 or ISO 14001.
An ISO 27001 surveillance audit happens once a year, in each of the two years that contain neither an initial certification nor a recertification audit. Under ISO/IEC 17021-1 the first one must be conducted no later than 12 months after the certification decision date, which is the date the certificate was granted and not the date the Stage 2 audit finished. Those two dates can be six weeks apart, and diarising the wrong one is the most common reason a surveillance audit gets booked late.
| Year of the cycle | Audit | What the certification body is deciding |
|---|---|---|
| Year 1 | Stage 1 and Stage 2 initial audit | Whether to grant a certificate at all |
| Year 2 | First surveillance audit, within 12 months of the certification decision | Whether to maintain the certificate |
| Year 3 | Second surveillance audit | Whether to maintain the certificate |
| Year 4 | Recertification audit, before expiry | Whether to issue a new three year certificate |
Certification bodies often schedule at nine month intervals rather than twelve, so a slipped date does not breach the rule. Some split the year into two half day visits for larger scopes. Both are normal.
An ISO 27001 surveillance audit takes roughly one third of the time your initial Stage 1 plus Stage 2 audit took, and a recertification audit takes roughly two thirds. Those ratios come from IAF MD 5:2023, the mandatory document accredited bodies use to calculate audit duration, which also states that a surveillance audit is unlikely to be less than one full auditor day. That floor is why a five person company does not get a proportionally tiny renewal bill.
Your own audit days are set by the certification body under ISO/IEC 27006-1, based on the effective number of people doing work inside your scope. Once you have that number from your original quote, the rest is arithmetic.
| Initial audit, Stage 1 + Stage 2 | Each surveillance audit, about 1/3 | Recertification, about 2/3 |
|---|---|---|
| 3 days | 1 day (the minimum) | 2 days |
| 5 days | 1.5 days | 3.5 days |
| 7 days | 2.5 days | 4.5 days |
| 9 days | 3 days | 6 days |
| 12 days | 4 days | 8 days |
Elapsed time is longer than audit time. A one day ISO 27001 surveillance audit still needs an audit plan a few weeks ahead and a report that normally lands within two weeks, and any nonconformity then carries its own clock.
An ISO 27001 surveillance audit costs about a third of what your initial certification audit cost, because certification bodies price both the same way: audit days multiplied by a day rate. Konfirmity's published 2026 breakdown puts surveillance audits at US$6,000 to US$7,500 a year for a lean, single location organisation under 100 people, against US$14,000 to US$16,000 for the initial Stage 1 and Stage 2 audit. Smaller scopes come in lower. Quotes vary widely by body and region, so treat any single figure as a starting point.
| Cost line in a surveillance year | Typical range, USD | Who you pay |
|---|---|---|
| Surveillance audit | US$2,000 to US$7,500 | Your certification body |
| Certificate maintenance fee, where charged | US$500 to US$1,500 | Your certification body |
| Internal audit | US$0 in-house, US$5,000 to US$10,000 outsourced | An independent internal auditor |
| Compliance platform | US$225 per month with CertAssist | Your software vendor |
| Your team's time | Roughly 5 to 15 days a year, not invoiced | Nobody, which is why it gets forgotten |
Certification bodies do not publish day rates, so the only reliable way to price an ISO 27001 surveillance audit is to ask three accredited bodies and divide each quote by the audit days in the table above. A quote well below the calculated audit time is a warning rather than a bargain, because an audit shorter than the required duration can put the accreditation of your certificate at risk. The CertAssist figure above was verified against the live pricing page in September 2026. For the first year picture, see the ISO 27001 certification cost breakdown.
ISO/IEC 17021-1 fixes a mandatory core that every ISO 27001 surveillance audit must cover, and the auditor then samples Annex A controls on top of it. Have these ready before the auditor arrives:
The last one catches people out more than any technical control. A logo on a marketing page implying a wider scope than the certificate covers is a finding, and it is entirely avoidable.
Preparation for an ISO 27001 surveillance audit is mostly about having done the annual work on time rather than about revising for the day. Two items account for most of the findings raised at surveillance. The first is the internal audit, which has to be completed, documented and independent before the certification body arrives. The second is the management review, which has to cover every input the standard lists and record real decisions rather than a note saying the ISMS was discussed.
Beyond those two, work through the mandatory core above and check each item exists with a date inside the last twelve months. Evidence dated the week before the audit tells the auditor the control runs once a year for the auditor's benefit, which is itself a finding.
Failing an ISO 27001 surveillance audit does not normally cost you the certificate on the day. Minor nonconformities are cleared by submitting a correction and root cause analysis within the window your certification body sets, typically 30 to 90 days. A major nonconformity is more serious: the body will usually require evidence, and sometimes a follow up visit, and it can suspend the certificate while that runs.
Skipping the audit is the real risk. Under ISO/IEC 17021-1 a certification body must suspend certification when the surveillance programme is not completed at the required frequency, and suspension is followed by withdrawal if it is not resolved. A suspended certificate is publicly visible, and a withdrawn one means starting the certification cycle again from Stage 1. If a date is going to slip, tell the certification body before it slips rather than after.
An ISO 27001 surveillance audit asks whether the certificate should be maintained, and samples part of the ISMS to answer that. A recertification audit asks whether a new three year certificate should be issued, and re-examines the whole management system, including the effectiveness of the ISMS across the full cycle. Recertification takes roughly twice as long and must be completed before the current certificate expires, not after. Miss the expiry date and the certificate lapses, which means a new initial certification with Stage 1 and Stage 2.
CertAssist lays out every ISO 27001 control on one board, gives you editable policy and evidence templates, handles the Statement of Applicability, and keeps an activity history on every change, so when the surveillance auditor asks when a control last ran, the date is already recorded. Your certification body gets read only access and reviews the evidence where it sits. CertAssist costs US$225 per month on the current launch offer, normally US$375 per month, or US$2,475 per year.
CertAssist is not right for everyone. CertAssist is not a certification body and cannot audit or certify you, and no tool of any kind reduces the audit days set under ISO/IEC 27006-1. CertAssist also has no integrations by design, so there is no access to grant and nothing for an attacker to reach through, but it also means CertAssist does not collect evidence automatically. If you run a large estate and want continuous monitoring pulled from your systems, an integrated platform will suit you better and is worth paying for. CertAssist suits organisations of roughly 5 to 200 people.
What is an ISO 27001 surveillance audit?
An ISO 27001 surveillance audit is a partial audit run by your accredited certification body in each of the two years between initial certification and recertification. It confirms the ISMS is still operating by sampling your internal audits, management review, previous nonconformities, changes to scope and risk, and a selection of Annex A controls, rather than re-examining everything.
How often is an ISO 27001 surveillance audit?
An ISO 27001 surveillance audit happens once a year in years 2 and 3 of the three year cycle. ISO/IEC 17021-1 requires the first surveillance audit to be conducted within 12 months of the certification decision date, not the Stage 2 audit date. Many certification bodies schedule at nine month intervals so a slipped date does not breach that rule.
How much does an ISO 27001 surveillance audit cost?
Commonly reported 2026 US figures put an ISO 27001 surveillance audit at about US$6,000 to US$7,500 a year for a single location organisation under 100 people, with smaller scopes lower. Certification bodies price audit days multiplied by a day rate, and a surveillance audit is about one third of the initial Stage 1 and Stage 2 audit time.
What is the difference between ISO 27001 certification and a surveillance audit?
Certification is the initial Stage 1 and Stage 2 audit that decides whether a certificate is granted, and it examines the whole ISMS. An ISO 27001 surveillance audit is a shorter annual check that decides whether the existing certificate is maintained, and it samples rather than reviewing every control.
Do you lose ISO 27001 certification if the surveillance audit is not done?
Yes, eventually. Under ISO/IEC 17021-1 a certification body must suspend certification when the surveillance programme is not completed at the required frequency, and an unresolved suspension leads to withdrawal. A withdrawn certificate cannot be reinstated, so the organisation has to start the certification cycle again with a new Stage 1 and Stage 2 audit.
CertAssist lays out every ISO 27001 control, gives you editable policy and evidence templates, and lets your certification body review the evidence in one place, for a flat US$225 a month.
See pricing FrameworksFlat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.