Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Preparing for an ISO 27001 Surveillance Audit Without Rebuilding the ISMS

Direct answer: An ISO 27001 certificate runs three years, with a shorter surveillance audit in each of the two intervening years and a recertification at the end. Surveillance audits are narrower than the Stage 2 that got you certified, but they concentrate on the parts of the management system that only exist if you kept running them: internal audit, management review, corrective actions, risk treatment, and any nonconformities from last time. The teams that get findings are almost never failing controls. They are failing to show the ISMS operated.

What a surveillance audit covers

The certification body samples. It will not walk all 93 Annex A controls again, and it will not re-examine everything in your Statement of Applicability. It will look at the management system clauses, a rotating subset of controls, anything that changed, and everything it raised last time.

That sampling is why surveillance audits feel deceptively small and then produce findings. The narrow scope concentrates on exactly the areas that decay when a programme goes quiet.

The four things that get checked every time

Internal audit. Clause 9.2 requires it, on a programme, by someone sufficiently independent of what they are auditing. The common failure is not skipping it, it is running it as a formality: an audit with no findings, no evidence of testing, and a report written by the person who owns the controls. An internal audit that finds nothing is itself a finding.

Management review. Clause 9.3, with a specific list of inputs including performance, nonconformities, risk status and improvement opportunities. Minutes that say leadership met and agreed the ISMS was working will not survive a competent auditor. The review has to show decisions.

Corrective actions. Anything raised at Stage 2 or the last surveillance visit needs a root cause, an action, evidence the action happened, and a check that it worked. A closed nonconformity with no evidence of effectiveness gets reopened.

Risk treatment. The register should have moved. Treatments progressed, new risks from incidents and changes added, owners still employed. A register identical to last year is evidence that nobody looked at it.

Scope and the Statement of Applicability

The SoA is a live document and it is the first thing a surveillance auditor compares against reality. If you added a product line, a cloud region, an office, or a significant subprocessor, the scope statement and the SoA need to reflect it, with justifications updated for any control you excluded.

An exclusion that made sense at certification and no longer does is a straightforward nonconformity, and it is entirely avoidable. Reviewing the SoA when the business changes takes an hour. Explaining a stale one during an audit takes considerably longer.

Keeping it true is the hard part. Continuous compliance on a monthly retainer: the reviews, the evidence and the calendar operated for you, so the next audit is a review rather than a rebuild. See how a retainer works

What to have ready

Assemble these before the visit rather than during it. The internal audit programme and reports for the period. Management review minutes with the clause 9.3 inputs visible. The corrective action log with evidence of closure. The current risk register with a change history. The SoA and scope statement, current. Evidence of the recurring controls: access reviews, training completion, supplier reviews, incident records, change records, backup and recovery testing. Any incidents in the period, with what you did and what changed afterwards.

Have the metrics too. Clause 9.1 asks you to monitor and measure, and most companies pick indicators at certification and then never produce them. Three real numbers you actually track beat a dashboard nobody looks at.

The recertification year is different

Year three is a fuller audit, closer to a Stage 2 in breadth, and it is where an ISMS that has been coasting gets found out. Two quiet surveillance visits followed by a recertification is the pattern that produces major nonconformities, because the gaps have had three years to accumulate.

The 2022 revision of the standard is also worth checking against if you certified earlier. Annex A restructured to 93 controls in four themes, and transition deadlines have passed for most certificate holders, so the SoA and mappings should already reflect the current version.

Running SOC 2 alongside it

If you hold both, the evidence overlaps substantially and the calendars do not. A SOC 2 observation window and an ISO surveillance visit are separate obligations with separate dates, and the practical answer is one calendar covering both, with evidence collected once and mapped to both control sets. Access review records satisfy CC6.2 and A.5.18 at the same time, provided they are filed somewhere both can reach.

The management system requirements are what ISO adds and SOC 2 has no equivalent for, which is why teams who came to ISO from SOC 2 are usually strong on controls and weak on clauses 4 through 10. That is where the surveillance findings land.

The honest summary

Surveillance preparation is not a project if the ISMS has been running. It is a week of assembly. It becomes a project when internal audit has not happened, the management review is a calendar invite nobody accepted, and the risk register was last touched during certification.

Keeping those three alive across a year is a small, unglamorous amount of work with an unforgiving deadline attached. If nobody internally owns it, an ongoing retainer covers exactly this: the internal audit programme run, the management review prepared with real inputs, the register maintained, and the certification body handled when it arrives.

The dates are not negotiable in the way people assume

Surveillance visits are anchored to your certification decision date, not to whenever the calendar suits you. The first surveillance audit generally has to be conducted within twelve months of that decision, and certification bodies apply the rule strictly because their own accreditation depends on it. Slipping a visit by a month because a product launch landed badly is usually possible with notice. Slipping it past the anniversary risks suspension of the certificate, and a suspended certificate is worse commercially than a delayed one, because it shows up on the certification body's public register where your prospects can see it.

The duration is not arbitrary either. Audit days are calculated from accredited tables driven mainly by headcount within the scope, adjusted for complexity, number of sites and the nature of what you do. A surveillance visit is typically about a third of the initial certification effort, which for a company of forty people in a single scope often means one to two auditor days. That number is why surveillance audits feel compressed: the auditor has a fixed budget of hours and will spend it on the areas most likely to produce findings, which is exactly the management system material.

Tell your certification body about material changes when they happen rather than at the visit. A merger, a new office in scope, moving your production workload to a different cloud region or provider, a change of the person holding overall ISMS accountability, or a significant expansion of headcount can all change the audit day calculation and occasionally the scope statement. Surfacing that on the morning of the audit turns a routine visit into a scoping argument.

Major, minor, and the paperwork each one triggers

Findings come in grades, and the grade determines your obligations. An observation or opportunity for improvement carries no formal requirement, though ignoring one for two cycles has a way of maturing it into a nonconformity. A minor nonconformity is a single lapse against a requirement that does not undermine the management system as a whole, and it typically needs a documented root cause and corrective action plan submitted within a set period, often around thirty days, with evidence of implementation reviewed at the next visit.

A major nonconformity is a different situation. It means a requirement is absent, or a systemic failure has been demonstrated, and the certification body will normally require evidence of correction within a defined window, commonly sixty to ninety days, before it will confirm the certificate. A special visit may be needed to verify closure, at your cost. If it is not closed, suspension follows.

The distinction between one missed access review and no access review process at all is the distinction between minor and major, and auditors decide it partly on how you respond. A team that produces the missed artefact, explains why it was missed, and shows the control that would catch a recurrence is describing an isolated lapse. A team that cannot say whether the review happened is describing a system that does not operate.

Write root causes that will survive the next visit

The most common weakness in corrective action work is a root cause that is really a restatement of the finding. "The access review was not performed because it was missed" is not a cause. "The review sat on a shared team calendar with no named owner, and the person who habitually did it was on parental leave in Q2 with no deputy nominated" is a cause, and it points at an action that is not simply resolving to try harder.

The auditor will come back to this. At the next surveillance visit they will look at your corrective action log, pick the actions closed since last time, and ask for evidence that each one worked. Two things satisfy that: proof the action was implemented, and proof the failure has not recurred in the period since. If the corrective action for a missed quarterly review was to assign a named owner and set a calendar reminder, the effectiveness evidence is three subsequent quarterly reviews with that owner's name on them. Assemble that before the visit, because reconstructing it live is how a closed minor gets reopened as a repeat finding, and repeat findings escalate in grade.

Auditors interview the people who operate the controls

Companies prepare the ISMS manager and forget that the auditor will ask to speak to an engineer, someone from HR, and whoever handles supplier onboarding. Those conversations are where the picture either holds together or does not.

The failure mode is not that the engineer says something incriminating. It is that they cannot describe a process they genuinely follow, because nobody told them the thing they do every day is a control. An engineer who says "we just get a second approval on the pull request and it will not merge without it" has given a better answer than one who recites a policy clause. Awareness under clause 7.3 is about people understanding their contribution to the ISMS, not about reciting document numbers.

Brief your people on what to expect, who will be there, roughly how long, and the honest instruction to describe what they actually do. Do not coach answers. Auditors interview for a living, and a rehearsed answer that contradicts the evidence in front of them turns a routine question into a thread they will pull for the next hour. If a process is not being followed, it is far better for your own team to raise it as a known nonconformity you identified internally, with an action already open, than for the auditor to find it. Self-identified findings with open corrective actions are evidence the system works.

The requests that catch people out

Beyond the obvious four areas, a handful of specific requests come up repeatedly and are awkward to satisfy on the day.

Documented information control under clause 7.5: the auditor asks how you know the policy in front of them is the current approved version, and who approved it. Documents with a version number that has not moved since certification, or a review date that has passed, answer that question badly.

Competence under clause 7.2: evidence that the people performing security-relevant roles are competent to do so. Job descriptions, training records, certifications, or documented experience all work. Nothing at all does not, and this is a common minor for companies who treat training as the annual awareness module and nothing else.

Clause 8.1 operational planning: evidence that the processes needed for the ISMS are planned and controlled, and that changes were considered before they were made rather than documented after. Change records tie into this more than people expect.

Supplier records under the Annex A supplier controls: not just the list, but evidence you assessed the ones that matter, and that you reviewed them within the frequency your own procedure commits you to. Every organisation adds subprocessors between visits and very few update the register at the time.

Interested parties and requirements under clause 4.2: usually written once at certification and never revisited, despite the customer base, regulatory exposure and contractual commitments having changed considerably since.

Changing certification body, and why it is rarely worth it mid-cycle

If you are unhappy with your certification body, you can transfer, but the mechanics matter. A transfer generally requires the existing certificate to be current and free of open major nonconformities, and the receiving body will review your last audit reports and may conduct its own review before accepting the transfer. The new body starts by understanding your ISMS from documents, which means a heavier visit than a routine surveillance.

Legitimate reasons to move: your body is not accredited by a recognised accreditation body, which affects whether your customers' procurement teams accept the certificate at all; or your customers work in a region where your body's mark carries no recognition. Being irritated by a fair finding is not a reason, and shopping for an easier auditor produces a certificate that a competent buyer will discount.

When you should not spend money on this

There is a group of companies holding ISO 27001 who did not need it and would be better served letting it lapse at the end of the cycle. The signal is straightforward: look at your closed deals over the past two years and count how many asked for the certificate rather than for a SOC 2 report. If your market is North American SaaS buyers and every request has been for SOC 2, you are paying certification body fees and carrying management system overhead for a document nobody asks to see. That decision deserves a deliberate discussion at recertification, not a renewal invoice paid on autopilot.

Equally, if your ISMS has been running properly for two cycles, your internal audit is genuine, and the last visit produced one observation, you do not need a consultant to prepare you for a surveillance audit. A week of assembly by your own owner is the correct answer, and a firm that tells you otherwise is selling reassurance. Our ISO 27001 work is worth buying when the management system was never really built, when the internal audit has been performed by the person who owns the controls, or when a major nonconformity is open and the clock is running.

The one case where outside help pays for itself reliably is the independent internal audit. Clause 9.2 requires objectivity and impartiality, and in a company of thirty people there is often nobody genuinely independent of the controls in question. Buying that single piece, rather than a full preparation engagement, is frequently the whole answer, and it is a much smaller purchase than the one people arrive expecting to make. If you would rather have the whole cycle operated for you, our retainers cover it, and if you are weighing ISO against the rest of your obligations, the compliance overview lays out how the frameworks overlap.

Keeping it true is the hard part. Continuous compliance on a monthly retainer: the reviews, the evidence and the calendar operated for you, so the next audit is a review rather than a rebuild.

See how a retainer worksOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.