The cost of preparing for a surveillance audit
Surveillance is far lighter than certification - unless you let the ISMS go quiet. What drives the cost of surveillance prep, and the drift that makes it expensive.
By Kellwick Team · July 19, 2026 · 2 min read
Preparing for an ISO 27001 surveillance audit is usually far lighter than the original certification. Surveillance auditors do not re-audit everything; they check that your prior findings stayed closed and that the ISMS did not drift since certification.
So the real variable is not the audit. It is how much drift there is to fix first - and that is something you can assess yourself before anyone quotes you.
What decides whether this is cheap or expensive
| Where you are | What the work looks like |
|---|---|
| ISMS kept running, evidence current across the year | A confirmation exercise: check the findings stayed closed, spot the few things that slipped |
| Quiet since certification week | A rebuild before the confirmation - the drift has to be closed first, against a date |
The gap between those two is much larger than any difference in company size, which is why a published figure would be misleading either way.
The drift that makes it expensive
The cost climbs when an auditor finds the ISMS was maintained on paper but not in practice. The signals they look for:
- Prior nonconformities closed on paper, but the underlying issue quietly returned.
- A risk register untouched since the certification audit.
- No internal audit or management review run this cycle.
- Access reviews that stopped once the certificate was in hand.
- Evidence all dated to certification week, rather than spread across the year.
Every one of those is fixable. Fixing them close to the audit costs more than never letting them slip.
Check yourself in five minutes
Open your risk register and look at the date of the last change. Then find the minutes of your most recent management review. If both are inside the last six months, your surveillance prep is a confirmation exercise. If either is dated to certification week, plan for remediation as well.
The cheaper path: do not let it drift
That is the whole reason ISMS Maintenance exists. Steady upkeep - a monthly evidence check, risk register upkeep, a management-review cadence - is dramatically cheaper than an annual scramble, and it means surveillance prep stays a light confirmation rather than a rescue.
Before you book the auditor
Run a readiness check first, so you walk in knowing you will pass. The five-question guide will point you at the right starting point, or book a call and we will size it against your certification date.
Certification and surveillance decisions are made by your accredited certification body. We prepare you, and never guarantee the outcome.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.