To maintain ISO 27001 compliance after certification, you need to run your Information Security Management System (ISMS) as a living process, not treat it as a one-time project. That means conducting regular internal audits, reviewing and updating your risk assessment, tracking security incidents, and passing annual surveillance audits. The sections below walk through each of these requirements in practical detail.

What happens to your ISO 27001 certification after it’s issued?

Once you receive your ISO 27001 certificate, it is valid for three years, but it does not stay active automatically. Your certification body will schedule annual surveillance audits in years one and two, and a full recertification audit in year three. If you fail a surveillance audit or let your ISMS lapse, your certificate can be suspended or withdrawn.

Think of the three-year cycle as a continuous loop rather than a finish line. The certificate you hold on day one is a snapshot of your ISMS at that moment. From that point forward, your job is to keep the system accurate, effective, and up to date so that every audit confirms the same level of control.

What are the ongoing requirements for ISO 27001 compliance?

Ongoing ISO 27001 compliance requires you to maintain a set of core activities throughout the year: internal audits, management reviews, risk treatment updates, incident tracking, and continual improvement actions. These are not optional add-ons but formal requirements written into the standard itself under Clause 9 (Performance Evaluation) and Clause 10 (Improvement).

In practical terms, this means you need to:

  • Run at least one full internal audit cycle per year covering all relevant ISMS processes
  • Hold a management review meeting where leadership evaluates ISMS performance and signs off on decisions
  • Keep your Statement of Applicability and risk treatment plan current whenever your business or threat environment changes
  • Log and investigate information security incidents and near misses
  • Track corrective actions to completion and document the outcomes

Documentation is what makes all of this auditable. If an activity is not recorded, it effectively did not happen from an auditor’s perspective. Maintaining clean, up-to-date records for each of these areas is what keeps your ISO 27001 certification standing on solid ground between audits.

How often should you review your ISO 27001 risk assessment?

You should review your ISO 27001 risk assessment at least once a year, and additionally whenever a significant change occurs in your business or technical environment. The standard does not specify a fixed frequency, but industry practice and audit expectations treat an annual review as the baseline minimum.

Significant changes that should trigger an immediate review include:

  • Launching a new digital product or service
  • Onboarding a new cloud provider or critical supplier
  • A staff restructuring that affects who has access to sensitive systems
  • A security incident that reveals a gap in your current controls
  • Changes in regulatory requirements relevant to your sector

For digital companies in particular, the threat landscape shifts quickly. A risk assessment that was accurate twelve months ago may already be out of date if you have adopted new tools, expanded your customer data processing, or moved infrastructure. Reviewing risk proactively is far less costly than discovering a gap during a surveillance audit.

What causes companies to lose their ISO 27001 certification?

Companies most commonly lose their ISO 27001 certification because they stop treating the ISMS as an active system after the initial audit. The three most frequent causes are failing a surveillance audit due to undocumented processes, missing the surveillance audit window entirely, and accumulating unclosed major nonconformities.

More specifically, the patterns that lead to certificate suspension or withdrawal include:

  • Letting documentation drift: Policies and procedures that no longer reflect how the business actually operates are a red flag for auditors.
  • Skipping internal audits: No evidence of internal auditing is a major nonconformity on its own.
  • Not closing corrective actions: Identifying a problem and then failing to fix it and document the fix is worse than not finding the problem at all.
  • Missing the surveillance audit: If you are unavailable or unprepared when your certification body schedules the annual audit, the certificate can be placed on hold.
  • Ignoring scope changes: Growing your business without updating your ISMS scope means your certificate may no longer accurately represent your operations.

How do you prepare for an ISO 27001 surveillance audit?

To prepare for an ISO 27001 surveillance audit, you should start by reviewing all documentation updated since your last audit, confirming that internal audits and management reviews have been completed and recorded, and checking that all corrective actions from the previous audit are closed with documented evidence.

A practical preparation checklist looks like this:

  1. Pull together the internal audit reports from the past year and confirm full ISMS coverage
  2. Review the management review minutes and confirm decisions and actions are documented
  3. Check that your risk assessment and risk treatment plan reflect the current state of the business
  4. Verify that all corrective actions from the last audit cycle have been completed and signed off
  5. Confirm that your Statement of Applicability is current and that control owners can speak to their areas
  6. Brief the relevant team members on what the auditor is likely to ask and where to find supporting records

Surveillance audits are narrower in scope than the initial certification audit, but auditors will probe the areas flagged in previous cycles. Going in with complete, organised records is the most reliable way to get through the process smoothly.

Can a small company realistically maintain ISO 27001 compliance in-house?

Yes, a small company can realistically maintain ISO 27001 compliance in-house, provided the right processes and tools are in place from the start. The challenge is not the size of the company but the consistency of the effort. Small teams often lack a dedicated compliance function, which means compliance tasks need to be embedded into existing roles rather than treated as a separate workstream.

What makes in-house maintenance feasible for small businesses:

  • Using structured templates for internal audits, risk assessments, and management reviews reduces the time each cycle takes
  • Assigning clear ownership for each ISMS process so nothing falls through the gaps
  • Setting calendar reminders for recurring tasks like annual reviews and corrective action follow-ups
  • Keeping documentation lightweight but complete, since auditors care about substance, not volume

Where small companies typically struggle is in keeping up with the administrative side while also running the business. Digital tools that automate document management and audit trails can remove a significant portion of that overhead. The compliance work itself is manageable; the risk is letting it slip during busy periods.

How DICIS AG helps you stay ISO 27001 compliant

We built our platform specifically for small digital companies that want to hold a credible ISO 27001 certification without dedicating a full-time resource to maintaining it. Here is what working with us looks like in practice:

  • AI-assisted documentation: Our platform helps you keep policies, risk assessments, and control records up to date with significantly less manual effort
  • Fully online audits: Surveillance audits and recertification are conducted entirely online, which means no travel, no scheduling complexity, and no disruption to your operations
  • Structured annual cycle support: We guide you through the internal audit, management review, and corrective action steps so nothing gets missed between audit years
  • Scope-appropriate approach: Our process is designed for companies with up to 50 employees, so you are not working through requirements built for enterprise organisations

If you are a digital company looking to certify or stay certified without the traditional overhead, explore our ISO 27001 certification process and see how quickly you can get started.

Related Posts

There is no related posts