+91 98804 42758

How Long Does ISO 27001 Certification Last

Three years, but not unconditionally, here's what keeps it valid and what breaks it

Sudhakar Varma Delivery Head, Avantcert
August 13, 2026 8 min read

An ISO 27001 certificate is valid for three years. That is the answer most sources stop at, and it is the least useful part of the story, because validity is conditional, not automatic. Miss a required audit along the way and the certificate can be suspended long before the three years are up.

This page covers what actually keeps a certificate valid, what breaks it, and how reinstatement works. For how long it takes to get certified in the first place, a different question, see how long ISO 27001 certification takes.


The Three-Year Cycle, and What Sits Inside It

The three years are not one unbroken block of validity. They are structured around two checkpoints:

  • Year 1: Initial certification, following the Stage 1 and Stage 2 audits.
  • Year 2: A surveillance audit, a shorter check confirming the management system is still operating as certified.
  • Year 3: A second surveillance audit.
  • Before year 3 ends: A full recertification audit, which restarts the three-year cycle if passed.

Skip a surveillance audit, and the certificate does not just quietly stay valid until year three. It gets suspended.

What "Valid" Actually Means Day to Day

Validity is a status the certification body actively maintains, not a fixed expiry date you can ignore until it arrives. Two things have to hold true simultaneously for a certificate to remain valid:

  • The certificate has not passed its three-year expiry date, and
  • All required surveillance audits up to that point have been completed and passed.

A company that stops maintaining its ISMS after certification, then skips the year-two surveillance audit, does not have a certificate that quietly stays valid until year three. It has a suspended certificate almost immediately.

What Happens If You Miss a Surveillance Audit

Certification bodies typically allow a short grace period, often around 30 days past the due date, before moving to suspension. A suspended certificate cannot be referenced in sales material, security questionnaires, or your website while suspended. Completing the overdue audit and closing any findings usually lifts the suspension without restarting the three-year clock.

Extended non-response, well past the grace period with no audit scheduled, typically escalates to withdrawal. Withdrawal is a harder reset: most certification bodies require a fresh initial certification audit rather than a simple catch-up, which means Stage 1 and Stage 2 again.

Can a Lapsed Certificate Be Reinstated?

Suspended, generally yes. Withdrawn, generally no, not without starting over. The distinction matters enough that if you know a surveillance audit is going to be late, contacting the certification body proactively, rather than letting the deadline pass silently, meaningfully changes which of those two outcomes you end up in.

Coming up on a surveillance or recertification deadline?

We help clients stay ahead of the three-year cycle so a missed date never turns into a full re-audit.

Get a Free Quote

Does the Certificate Survive an Acquisition or Rename?

A straightforward legal name change usually just requires notifying the certification body, who reissues the certificate under the new name without a fresh audit, provided the underlying entity and management system are unchanged. A genuine acquisition that folds the certified entity into a different legal structure, or changes what's in scope, is treated differently: the certification body typically needs to reassess whether the certificate still accurately describes what's being certified.

Reading the Expiry Date on Your Certificate

The expiry date is printed directly on the physical or digital certificate document issued by your certification body, alongside the original certification date. It is the authoritative source, not a reminder email or an internal spreadsheet. Most certification bodies do send renewal reminders several months ahead, but treat the certificate itself as ground truth if there is ever a discrepancy.

Starting Recertification Early Avoids a Gap Entirely

If the recertification audit is completed and passed before the existing certificate's expiry date, the new three-year period begins exactly where the old one ended, with no gap. A gap only happens if recertification isn't finished in time, which is why certification bodies generally recommend starting the recertification audit process several months before the deadline, not the week of.

Not sure where you sit in your certification cycle?

We track surveillance and recertification timing for 3,000+ organisations across 40+ markets so nothing lapses unexpectedly.

Talk to an Avantcert Expert

Frequently asked questions about ISO 27001 certificate validity

What happens if we miss a surveillance audit deadline?

Certification bodies typically allow a short grace window, often around 30 days, before formally suspending the certificate. A suspended certificate cannot be referenced in sales or marketing material until the surveillance audit is completed and passed. Missing the window entirely for an extended period usually leads to withdrawal rather than suspension.

Can a suspended ISO 27001 certificate be reinstated?

Yes, in most cases. Completing the overdue surveillance audit and closing any findings typically reinstates a suspended certificate without restarting the three-year cycle. A fully withdrawn certificate is a harder case, and often requires a new initial certification audit rather than a simple reinstatement.

Does our ISO 27001 certificate stay valid if the company is acquired or renamed?

A legal name change or restructuring typically requires notifying the certification body, who will usually reissue the certificate under the new name without a fresh audit if the underlying entity and management system are unchanged. An acquisition that merges the certified entity into a different legal structure or changes its scope usually does require the certification body to reassess.

Is the three-year validity period the same across all certification bodies?

Yes. The three-year certification cycle with annual surveillance audits is set by ISO/IEC 17021-1, the standard accreditation bodies use to govern certification bodies, not by any individual certifier. Every accredited ISO 27001 certificate anywhere in the world follows the same three-year structure.

What's the difference between certificate validity and the ISMS staying operational?

The certificate is a point-in-time attestation that gets re-validated at each surveillance audit; the ISMS is the ongoing management system that has to keep operating every day in between. A certificate can technically still be valid on paper while the underlying ISMS has quietly stopped functioning, which is exactly what a surveillance audit is designed to catch before it reaches recertification.

Can we extend our ISO 27001 certificate validity beyond three years?

No. The three-year limit is fixed by the accreditation framework and cannot be extended by request, regardless of how clean your surveillance audits have been. The only way to remain certified past year three is a full recertification audit.

How do we know exactly when our certificate expires?

The expiry date is printed directly on the certificate document issued by your certification body, alongside the initial certification date. Most certification bodies also send renewal reminders several months in advance, but the certificate itself is the authoritative source.

Does certification lapse while the recertification audit is in progress?

If the recertification audit is scheduled and completed before the three-year expiry date, there is no gap, the new certificate's validity period begins where the old one ended. A lapse only occurs if the recertification audit is not completed before the expiry date, which is why certification bodies recommend starting the process several months ahead of the deadline.

About Avantcert. Avantcert is an ISO and compliance certification consultancy that has guided 3,000+ organisations across 40+ markets to certification, including surveillance and recertification support. See our ISO 27001 service or request a free quote.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.