Recertification vs surveillance: what is different in year 3
Year 3 is a recertification audit, not another surveillance check. Understanding the fuller re-audit scope, how scope changes are handled, and what evidence resampling means in practice helps you prepare correctly.
By Kellwick Team · September 20, 2026 · 6 min read
Most organisations that have been through ISO 27001 certification understand the three-year cycle in broad terms: initial certification, then two surveillance audits, then recertification. What is less well understood is how different the year-three recertification audit is from the year-one and year-two surveillance visits. Treating recertification as a third surveillance audit is one of the most common preparation mistakes - and one of the most avoidable.
The difference in audit objectives
Surveillance audits have a specific and relatively narrow objective: to confirm that the certified ISMS is still operating and that the organisation is maintaining conformity with the standard. The auditor samples a subset of controls and focuses on whether the system continues to function as it was certified. They are not re-auditing from scratch.
Recertification is a fuller re-audit. The certification body must satisfy itself that the ISMS as a whole continues to conform to ISO 27001:2022 across the full scope and that the three-year cycle of planned audits, management reviews, and continual improvement has produced a functioning management system - not just a set of documents.
In practical terms, this means the auditor's sampling is broader and deeper in year three. They are not just checking that last month's management review happened; they are looking at the entire cycle's worth of evidence and asking whether the ISMS has genuinely been operated as a management system.
Scope changes accumulate over three years
In many organisations, the certified scope changes significantly between initial certification and recertification. Cloud infrastructure evolves. New services are launched. Staff locations change. Suppliers are added or replaced. Legal obligations shift.
Surveillance auditors note scope-relevant changes during their visits, but they are not conducting a full scope review. The recertification auditor will re-examine the scope statement, verify that it accurately reflects current operations, and check that controls have been applied across everything that should be within scope.
If your scope statement says "cloud infrastructure hosted in AWS eu-west-1" but you have been operating a secondary environment in eu-west-2 for eighteen months, the recertification audit will expose that. If your organisation has expanded into a new business area or acquired another company, the auditor will want to understand whether those activities and assets are appropriately in or out of scope.
The practical implication: review your scope statement formally before the recertification audit cycle begins - at least three to four months out - and update it to reflect current reality. If the scope has materially expanded, you may need to revisit the risk assessment and SoA for the new areas. Trying to work through scope changes during the audit itself is stressful and risks an adjournment.
Evidence resampling across the full cycle
Surveillance audits sample evidence from the period since the previous audit - roughly twelve months of records. Recertification audits will sample evidence across the full three-year cycle. This means records from year one, year two, and year three are all in scope for examination.
The practical consequence is that evidence retention matters. If your backup test records from twenty-four to thirty-six months ago have been deleted or cannot be retrieved, the auditor cannot verify that the control was operating in that period. If management review minutes from year one are missing, the auditor cannot confirm that the review cycle was maintained from the start.
Areas where three-year evidence resampling most often surfaces gaps:
Internal audit records. The auditor will want to see the complete audit programme - every internal audit that was planned and completed across the three years, the findings from each, and the corrective actions that were raised and closed. A programme that looks healthy in year three but has no records from year one will raise questions about whether the programme was genuinely operated throughout.
Risk register versioning. The auditor will look at how the risk register has evolved. A register that looks identical to the one presented at initial certification suggests it has not been actively maintained. Conversely, a register with dated version history that shows evolving risk assessments and treatment decisions demonstrates genuine operation.
Training and awareness records. Three years of security awareness training records, covering the in-scope population, should be available. If staff turnover has been significant, the records need to be comprehensive enough to show that new starters were trained as they joined.
Corrective action logs. Every nonconformity or corrective action raised by internal audits, surveillance audits, or management reviews over the three-year period should be documented with status and closure dates. A log that only covers the most recent six months will prompt questions about how earlier findings were managed.
How the audit days are structured differently
Recertification audits typically run for more days than surveillance audits. The exact duration depends on the size and complexity of your scope and is set by the certification body, but it is common for recertification to involve as many days as the original stage two - sometimes more if the scope has grown.
The audit will typically cover both a document review phase and an on-site or remote sampling phase. The document review in recertification is more thorough than in surveillance, looking at the full ISMS documentation set rather than updates since the last visit.
The sampling phase will revisit Clause-level conformity across all of the standard - not just the subset typically covered in surveillance. Auditors will check Clauses 4 through 10, not just the areas where previous surveillance findings were raised.
What continual improvement evidence looks like
A key question in recertification is whether the ISMS has improved over the three-year cycle. Clause 10.2 requires continual improvement, and recertification is where that requirement gets tested most rigorously.
Credible continual improvement evidence is not a bullet point on the management review saying "we will continue to improve." It is a trail of specific improvements: a control that was ineffective and was redesigned, a process that was streamlined after internal audit feedback, a supplier assurance programme that was tightened after an incident, a risk that was closed because a new technical control reduced likelihood to an acceptable level.
If the only improvements you can point to are ones made in the three months before recertification, auditors will question whether improvement has been a genuine management objective or a last-minute exercise.
Preparing for recertification without starting from scratch
Recertification does not require you to rebuild your ISMS. If surveillance audits have been clean and the ISMS has been genuinely maintained, recertification should feel like a thorough review rather than a new audit. The organisations that struggle in year three are those that let the ISMS drift during years two and three and then attempt to catch up in the final quarter.
The preparation that works best begins at month twenty to twenty-two of the cycle: a structured internal review of the full cycle's evidence, a scope statement refresh, a risk register review with documented conclusions, and a gap analysis against any changes to the operating environment since initial certification.
Where Kellwick fits
Whether you are approaching month eighteen of your certification cycle or closer to recertification, Kellwick's structured advisory helps you understand what the fuller year-three re-audit will examine and where your evidence is thin. See /surveillance-audit-readiness for details on how we support organisations through recertification preparation.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.