Guides
Surveillance audits and recertification, explained
The certificate lasts three years — but only if you pass the audits in between. What surveillance covers, what it costs, and what recertification demands.
The three-year cycle
| Year | Audit | Typical duration | Published cost range |
|---|---|---|---|
| 1 | Stage 1 + Stage 2 (initial certification) | Full audit days per ISO 27006 | ~$8K–$25K (small-to-mid, published) |
| 2 | Surveillance audit | ~⅓–½ of Stage 2 | $4K–$10K/yr (published) |
| 3 | Surveillance audit | ~⅓–½ of Stage 2 | $4K–$10K/yr (published) |
| 4 | Recertification (new 3-year cycle) | Stage 2 scale | Comparable to initial audit |
What surveillance actually checks
- Continual improvement. Are internal audits, management reviews, and corrective actions still happening?
- Control sampling. A rotating subset of Annex A controls — over the cycle, everything gets sampled.
- Changes. New systems, new sites, new risks since the last audit.
- Complaints and incidents. How security events were handled and whether the ISMS learned from them.
What gets companies in trouble
- Treating the certificate as done. Evidence collection that stops after Stage 2 makes surveillance painful.
- Skipping the internal audit. Required every year — surveillance checks it happened.
- Unreported scope changes. New sites or systems the CB doesn't know about are findings waiting to happen.
Budget the cycle, not the audit. A useful planning number is the 3-year total: initial certification + two surveillance audits. Our quote worksheet has a row for exactly this — and our estimator shows the first year.
Get the full cycle quoted
Ask CBs for 3-year pricing — initial, surveillance, and recertification — in one comparable quote. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.