Ask a security lead when their ISO 27001 certificate expires and they will read you the date on the PDF. It is on the trust page, it is in the sales deck, it is pasted into the answer field of every vendor security questionnaire the company fills in. It is also, of the dates that actually govern that certificate, the one with the least control over what happens next.
Three different parties set ISO 27001 dates, and only one of them prints anything. Your certification body schedules the surveillance audits — but counts them from the day the certification decision was made, which is not the date on the certificate and is frequently weeks or months earlier. The accreditation system sets the rules that certification body has to follow, and those rules can reach in and change your expiry date: when a new edition of the standard is published, every certificate issued against the old edition stops being valid on a shared deadline that nobody's certificate has ever carried. And underneath both of those, your own information security management system generates obligations with no dates on them at all — a Statement of Applicability that has to be current every time anybody looks at it, internal audits and management reviews on a cadence you set yourself.
The result is a set of clocks that behave in ways experienced compliance people find genuinely counterintuitive. Recertify six months early and you do not get six extra months. Pass a real audit against a new edition of the standard and your expiry date does not move at all. Schedule the same piece of work onto the wrong visit and it costs twice the auditor time. None of that is written on the certificate, because the certificate is an output of the process, not a description of it.
Here is where each ISO 27001 date actually comes from, which of them can be changed by somebody other than you, and how to hold the set of them together.
General information, not certification or security advice. Your certificate is issued by an accredited certification body, and the specifics of your cycle belong to them — confirm your own dates with your certification body and the official sources in section 11.
1. What is ISO/IEC 27001 certification?
ISO/IEC 27001 is the international standard for an information security management system — an ISMS. The standard does not hand you a list of controls to install and call it done; it specifies the requirements for establishing, implementing, maintaining and continually improving a management system, including how information security risks are assessed and treated. Certification means an accredited certification body has audited that system and attested that it conforms. It is the certificate that enterprise buyers ask for by name in vendor security reviews, and increasingly the one written into customer contracts. Remindax helps you hold the dates attached to it and reminds the people responsible; it doesn't audit, certify, run your ISMS, write your documentation, or provide security or certification advice.
The certification body is not free to invent its own schedule. It works under ISO/IEC 17021-1, the conformity assessment standard that sets requirements for bodies providing audit and certification of management systems, and under the mandatory documents of the accreditation system its own accreditation comes from. That is why the rhythm of an ISO 27001 certificate looks broadly the same wherever it was issued — and also why some of your dates are decided several layers away from anybody you have ever spoken to.
1.1 Who sets which date
The single most useful thing to understand about an ISO 27001 calendar is that it has three authors. Separate them and most of the surprises stop being surprising.
- →Your certification body sets the audit dates — from the decision, not the paper. ISO/IEC 17021-1 requires surveillance audits at least once a calendar year except in recertification years, and requires that the first surveillance audit following initial certification be no more than 12 months from the certification decision date. The decision is the moment the body concluded you conformed. The certificate is a document produced afterwards.
- →The accreditation system sets deadlines that override your certificate. When a new edition of ISO/IEC 27001 is published, the International Accreditation Forum issues a mandatory transition document that binds accreditation bodies and the certification bodies they accredit. It fixes one date by which every certificate against the old edition must be transitioned — and states plainly that certifications based on the superseded edition expire or are withdrawn at the end of that period.
- →Your own ISMS generates obligations with no dates printed anywhere. The Statement of Applicability required by clause 6.1.3 d) has no expiry. Neither does your risk assessment, your internal audit program or your management review. They have to be current, which is a different and harder property than not being expired, and it is the property every audit tests.
- →And the cycle length itself is a convention, not a universal law. Three years is the ordinary pattern, and ISO/IEC 17021-1 notes that where an industry-specific certification scheme specifies it, the certification cycle can be different from three years. The annual audit obligation is the harder rule; the three-year framing around it is the softer one.
Read that list and notice what the certificate itself contributes. It carries one date, set by the third-least consequential of these mechanisms, and it is the date every downstream system in the company — the CRM field, the security questionnaire, the reminder somebody set in a shared calendar — ends up keyed to.
2. How long is ISO 27001 certification valid?
A certification cycle normally runs three years, with surveillance audits conducted at least once a calendar year, except in recertification years. Where an industry-specific scheme says otherwise, the cycle can differ.
The first surveillance audit after initial certification shall be no more than 12 months from the certification decision date — a date that is usually earlier than the one printed on your certificate, and is rarely the one anybody diarized.
Where recertification is completed before the existing certificate expires, the expiry date of the new certification can be based on the expiry date of the existing certification. Finishing in March instead of September moves the work, not the deadline.
For any major nonconformity at recertification, time limits for correction and corrective action are defined and completed prior to the expiration of certification — so a finding raised late has less room to be closed than the same finding raised early.
When a new edition is published, the accreditation system sets a transition period, and all certifications against the superseded edition expire or are withdrawn at the end of it — regardless of what your own certificate says.
Following expiration, a certification body can restore certification within 6 months, provided the outstanding recertification activities are completed. Past that, you are looking at starting again.
The phrase worth pausing on is certification decision date. Every organization that has been through initial certification remembers the Stage 2 audit, because it was disruptive and everyone was in it. Fewer remember the decision, because it happened inside the certification body afterwards, in a review by people the client never met. Fewer still remember the certificate issue date as distinct from either. Those three dates can sit weeks apart, and the one your surveillance obligation is measured from is the middle one.
Nobody is being deliberately misleading when they say a certificate lasts three years. For a well-run certification body with a client that answers its emails, three years is what the cycle looks like from the outside, and the surveillance audits arrive on schedule because the body schedules them. The framing only fails in the cases where it matters: an organization whose audit slipped a quarter and is now uncertain whether it is inside the calendar-year rule, one that assumed an early recertification bought runway, one holding a certificate issued during a transition period that carries a shortened validity it never asked for, and one that has changed certification bodies and inherited a cycle whose original decision date is in someone else's file.
There is a second, quieter consequence of the annual-audit rule that organizations tend to discover at an awkward moment. The requirement is expressed as at least one audit per calendar year, not as one audit per twelve-month period. A surveillance audit performed in January of one year and December of the next satisfies both years on paper while leaving a gap of nearly two years between visits — and an audit program drifting in the other direction, later and later each year, will eventually skip a calendar year entirely while every individual interval still looks reasonable. Tracking the audit against the year it belongs to, rather than against the last one, is the only way to see that coming.
3. Why tracking ISO 27001 dates matters
Security teams are not bad at deadlines. They are bad at deadlines that arrive from a direction they were not watching, and ISO 27001 has four of those:
The clock starts on a date that isn't on the certificate
Surveillance is counted from the certification decision, and the reminder everyone sets is keyed to the certificate. The two drift apart by however long the decision review took — and the drift always runs in the direction of being later than you think.
Passing an audit doesn't always move the expiry
Recertify early and the new expiry can be based on the old one. Complete a transition audit and the current cycle's expiration is not changed at all. Real work, a new certificate document, and the same end date.
Somebody else can rewrite the expiry date
A new edition of the standard starts a transition clock set by the accreditation system, not your certifier. At the end of it, certificates against the old edition expire or are withdrawn — on a date shared by every certified organization in the world.
The document with no date is the one every audit opens
The Statement of Applicability has no expiry to miss, which is exactly why it goes stale. It is also the first thing an auditor reads, and the document a transition audit is explicitly required to see updated.
Property 3.1 is the cheapest to fix and the most commonly wrong. When an organization is certified, three artefacts arrive in short order: the audit report, the certification decision, and the certificate. The certificate is the one that gets circulated, filed, and attached to the sales team's questionnaire responses, so it is the one that becomes the company's memory of the event. But the obligation runs from the decision. If the decision was made in early March and the certificate was issued in late April after the body's document production caught up, an organization diarizing “surveillance audit — April” has quietly given itself a deadline six weeks after the real one. That is comfortably enough to slide a booking into the following month, and comfortably enough to end up outside twelve months from the decision.
Property 3.2 is the one that produces genuine disbelief, and it has two separate mechanisms behind it. The first is early recertification: where recertification activities are successfully completed before the existing certificate expires, the new certification's expiry can be based on the existing expiry date — and the issue date on a new certificate has to be on or after the recertification decision. So an organization that heroically pulls its recertification forward by five months receives a new certificate, correctly dated, that ends when the old one would have. The second mechanism is the transition audit, and it is stated even more flatly: when a certification document is updated because the client successfully completed only the transition audit, the expiration of its current certification cycle is not changed. You did the work, you are certified against the new edition, and your renewal date is exactly where it was.
Neither of those is a trap so much as an accounting rule, but both defeat the assumption baked into almost every other renewable document a business holds. A business license renewed early gets a new term. A certificate of insurance reissued mid-policy carries the new period. The intuition that doing the work early buys time is correct nearly everywhere else, which is precisely why nobody thinks to check it here.
Property 3.3 is the structural one, and it is worth being precise about how unusual it is. Almost every date a compliance function tracks is bilateral: it exists between your organization and one authority, and if it changes, that authority tells you. A transition deadline is not bilateral. It is published by the International Accreditation Forum as a mandatory document binding accreditation bodies and, through them, certification bodies. Your certification body is required to communicate the transition program to you, and good ones do so relentlessly — but the deadline was not negotiated with you, does not appear on your certificate, and applies identically to a two-person startup and a bank. When ISO/IEC 27001:2022 replaced the 2013 edition, the transition period ran 36 months from the end of the publication month, to 31 October 2025, and IAF MD 26 states that all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of it. Certificates issued against the old edition during that window did not get their usual three years; they got whatever was left of the transition.
That mechanism is not a one-off. ISO standards are reviewed and revised on a continuing basis, and amendments arrive between editions: ISO/IEC 27001:2022 was itself amended in 2024 to add climate action changes, requiring organizations to determine whether climate change is a relevant issue in their context. An amendment of that size is absorbed into normal audit activity rather than triggering a full transition program, but it is the same machinery, and the next full edition will start the same clock again. An organization that treats the last transition as a completed project rather than a recurring category of date will be surprised by the next one in exactly the way it was surprised by the last.
Property 3.4 is the one that quietly decides how an audit goes. The Statement of Applicability, required by clause 6.1.3 d), records which information security controls are necessary, why each one is included, whether it is implemented, and the justification for excluding any control from the standard's reference set in Annex A. It is the bridge between your risk assessment and everything you actually do, and it is where an auditor starts. It also has no renewal date, no reminder attached to it and no external party who will ask about it, so it decays at the speed of your organizational change: an acquisition, a cloud migration, a new product line or a doubling of headcount all make it less accurate, none of them make it look out of date. When the 2022 edition reorganized the reference control set — from 114 controls in 14 clauses down to 93 in 4, with 11 new controls, 24 merged and 58 updated — the transition audit was required to include the updating of the Statement of Applicability and, where applicable, the risk treatment plan, for exactly this reason.
4. Who needs to track ISO 27001 dates
A large enterprise with a dedicated ISMS manager and a certification body account manager is generally fine. The interesting list is the organizations where the certificate is business-critical and the calendar behind it belongs to nobody in particular:
SaaS & cloud companies
The certificate customers ask for by name, pasted into every security questionnaire the sales team answers. The company that most needs it current is usually the one whose security function is two people and a shared inbox.
Learn MoreSecurity & compliance teams
The people holding all three calendars at once — the certification body's audits, the accreditation system's transition deadlines, and the internal reviews the auditor will ask to see evidence of.
Learn MoreMSPs & IT service providers
Certification held as a condition of holding client data, where a suspension is not an internal problem but a conversation with every client at once — and where the ISMS scope keeps moving as the client base does.
Learn MoreFintech & healthtech
Selling into buyers whose own regulators care what their suppliers hold. The certificate sits inside a stack of other recurring assurances, and the whole stack is only as current as its least-watched date.
Learn MoreMulti-scope & multi-entity groups
Several certificates, several scopes, sometimes several certification bodies — each with its own decision date and its own cycle. Being current in four entities tells you nothing whatsoever about the fifth.
Learn MoreAnyone who has changed certifier
A transferred certification arrives with a cycle already running and an original decision date recorded in a file you no longer hold. It is the single most common way an organization loses track of which year of the cycle it is actually in.
Learn More5. What happens when an ISO 27001 date is missed
An ISO 27001 problem arrives in one of four shapes. Only the first looks like a missed deadline, and it is the one organizations are already braced for.
A surveillance audit was not held in time. The familiar one. The audit slipped past the calendar-year requirement or past twelve months from the decision, and the certification body has to act — the outcome is a suspension while the situation is resolved, and a withdrawal if it is not. The commercial consequence is disproportionate to the administrative one, because the certificate is doing work everywhere: it is on the trust page, in the sales deck, and in the security questionnaire answers a dozen prospects are currently reading. A suspended certificate does not just create an audit to reschedule; it creates a set of statements the company is now making that are no longer true, in places nobody thinks to go and update.
Recertification was left too late, and a major nonconformity ran out of room. The one that punishes optimism about scheduling. At recertification, time limits for correcting a major nonconformity are set so that correction and corrective action are completed prior to the expiration of certification — so the window to fix a serious finding is not a fixed period, it is however much of your certificate is left. Book the recertification audit comfortably ahead and a major finding is an inconvenience. Book it four weeks before expiry and the same finding, discovered by the same auditor, may be unfixable in the time available for reasons that have nothing to do with how hard your team works. This is the clearest example on the page of a date whose real cost depends entirely on how early it was scheduled.
A transition deadline arrived while the certificate still looked fine. The one that catches organizations doing everything else right. During the move from the 2013 edition to the 2022 edition, certificates issued against the old edition ceased to be valid at the end of the transition period regardless of the date printed on them, because all certifications based on the superseded edition expire or are withdrawn at that point. Nothing about the certificate warned anyone: it had a perfectly ordinary expiry date, in a perfectly ordinary format, sitting comfortably in the future. The same mechanism applies to certification bodies themselves — where a certification body did not complete its own transition assessment in time, the expiry of its accreditation for the old edition was capped at the end of the transition period too.
Nothing was missed at all, and the audit still went badly. The most common shape, and the one no date alone will catch. The audits happened on schedule; the ISMS underneath them stopped operating. Internal audits were not run, management reviews were skipped for a quarter and then a year, the risk assessment still describes a company half the current size, and the Statement of Applicability justifies a control set chosen before the migration to a different cloud provider. Every one of those is a finding waiting to be written up, and none of them has an expiry date to miss. This is what a surveillance audit is for, and it is why an audit-date reminder without a cadence reminder underneath it only solves half the problem.
One piece of genuinely good news, worth knowing before panic sets in. Following expiration of certification, the certification body can restore certification within 6 months, provided the outstanding recertification activities are completed. That is a real second chance and it is written into the conformity assessment standard rather than left to a certifier's discretion. But it is a window, not a state of affairs: during it the organization is not certified, which is exactly the answer it has to give a customer who asks, and after it the route back is a new certification rather than a restoration. Treating the six months as breathing room rather than an emergency is how organizations turn a recoverable lapse into starting over.
The through-line across all four shapes is that the certificate itself never changes appearance. It does not grey out when a surveillance audit is overdue, gain a warning when a transition deadline passes, or annotate itself when the ISMS it attests to stopped being described accurately two years ago. It is a PDF with a date on it, and it looks exactly as reassuring on the day everything is fine as on the day it has been suspended. Whatever system tells you the truth about your certification status, it will not be the certificate.
6. How Remindax keeps your certificate valid
Remindax holds the dates and reminds the people who have to act on them. It does not audit or certify anything, run your ISMS, write or review your Statement of Applicability, or advise you on information security. What it does is make sure the date to act never passes unnoticed — including the ones your certificate does not show you.
Tracked from the decision date
Record the certification decision date alongside the certificate date, and count the surveillance obligation from the one that governs it — so the reminder is set against the real twelve months, not the reassuring one.
Long-lead reminders, sized to the audit
Staged alerts by Email, SMS and WhatsApp, timed backwards from each audit — with the recertification set earliest, because that is the one where a major finding needs room to be closed before the certificate expires.
The ISMS cadence underneath
Recurring dates for internal audits, management reviews and risk-assessment updates — plus a review prompt on the Statement of Applicability, the one mandatory document with no expiry date to remind you about itself.
Transition deadlines as their own date
A published transition deadline is a date like any other, and it belongs in the register next to the certificate it can override — held separately, with its own lead time, rather than assumed to be someone else's problem.
Every scope and entity separately
One certificate per scope, per entity, per certification body, each on its own cycle with its own owner — and an audit history you can hand to a customer, a prospect's security reviewer or an incoming compliance hire.
Dates and status only
Remindax records that an obligation exists, when it falls due and whether it has been met. It holds no ISMS documentation, no risk register, no audit findings and no security data. GDPR-ready, on AWS, with encrypted storage.
One scheduling note that pays for itself, because it is a pure date decision rather than a security one. Where a transition audit is carried out in conjunction with a recertification audit, the accreditation requirement is a minimum of half an auditor day for the transition element; carried out alongside a surveillance audit, or as a separate visit, the minimum is a full auditor day. Same work, same standard, twice the auditor time — decided entirely by which visit it was attached to. That is the sort of choice that gets made well when someone can see the whole cycle laid out, and made badly when the transition notice arrives in an inbox two months after the recertification has already been booked.
7. Why spreadsheets fail for ISO 27001 tracking
A spreadsheet is an excellent record of dates somebody has already decided to write down. Four things about this certificate sit outside that.
It records the date on the document, because that is the date on the document. Nobody building a compliance workbook types in a certification decision date, for the entirely reasonable reason that it is not printed on the artefact they are looking at while they build the row. So the workbook is keyed to the wrong date from the moment it is created, and it will stay wrong through every handover, because each new owner will validate it against the same certificate and conclude it is correct.
It assumes finishing work early moves a deadline. This is such a deep assumption that spreadsheets encode it structurally: a completed-on column, a next-due column, and a formula between them. Here the formula is wrong twice over — an early recertification can leave the expiry where it was, and a completed transition audit does not change the current cycle's expiration at all. A workbook that recalculates the next due date from the last completion date will confidently report a renewal that is months later than the real one.
It has no row for a deadline that hasn't been announced yet. Transition deadlines are published by the accreditation system when a new edition appears, which means the date does not exist when the workbook is built and arrives later, by email, to whoever the certification body has on file. There is no natural moment at which somebody opens the spreadsheet and adds a row for it, and no cell that turns red because a category of obligation has appeared that the sheet does not model.
And it cannot distinguish a document that is current from one that merely exists. The Statement of Applicability, the risk assessment, the internal audit program: a spreadsheet can hold a link to each, and a link is green forever. What the auditor is testing is whether the contents still describe the organization, which is a question no date field can answer and no formula can flag.
A system that counts from the decision date, treats each audit as its own obligation rather than a formula from the last one, holds transition deadlines as first-class dates, and prompts the recurring ISMS work underneath is what turns ISO 27001 from a certificate somebody hopes is still valid into a status the company can actually assert.
8. Key takeaways
- ✓An ISO/IEC 27001 certification cycle ordinarily runs three years, with surveillance audits conducted at least once a calendar year, except in recertification years — and where an industry-specific scheme requires it, the cycle can differ from three years.
- ✓The first surveillance audit must be no more than 12 months from the certification decision date — not from the date printed on the certificate, which is usually later and is the date most organizations diarize.
- ✓Finishing early does not buy time. Where recertification is completed before expiry, the new certification's expiry can be based on the existing expiry date, and a completed transition audit does not change the current cycle's expiration.
- ✓A new edition of the standard starts a transition period set by the accreditation system, at the end of which all certifications against the superseded edition expire or are withdrawn — a date that overrides the one on your certificate and is shared by everyone.
- ✓At recertification, correction of a major nonconformity must be completed before the certificate expires, so the room available to fix a serious finding is decided by how early the audit was booked.
- ✓The Statement of Applicability required by clause 6.1.3 d) has no expiry date, is the first document an auditor opens, and was explicitly required to be updated during the 2022 transition — it decays with organizational change, not with time.
- ✓After expiry, a certification body can restore certification within 6 months if the outstanding recertification activities are completed — but the organization is not certified during that window.
- ✓Tracking the decision date, each audit as its own obligation, the transition deadlines published above your certifier, and the ISMS cadence underneath is what keeps the certificate a company sells on from being suspended out from under it.
Never let a surveillance audit suspend your certificate
Track your surveillance audits, recertification and transition deadlines — automatically. Remindax holds each date from the one it is actually counted from, and reminds your security and compliance team while there is still time to prepare.
GDPR-ready · AWS secure cloud · Encrypted storage · Setup in under 5 minutes
9. Frequently Asked Questions
A certification cycle ordinarily runs three years. What keeps it valid is the audit programme inside it: under ISO/IEC 17021-1 surveillance audits are conducted at least once a calendar year, except in recertification years. Where an industry-specific certification scheme requires it, the cycle can differ from three years.
At the certification decision, not the date printed on the certificate. The first surveillance audit following initial certification shall be no more than 12 months from the certification decision date - and that date is usually earlier than the certificate date most organizations diarise.
No. Where recertification activities are successfully completed before the existing certificate expires, the expiry date of the new certification can be based on the expiry date of the existing certification. Finishing early moves the work, not the deadline.
Yes. When a new edition is published, the accreditation system sets a transition period, and all certifications based on the superseded edition expire or are withdrawn at the end of it - regardless of the date on your own certificate. For ISO/IEC 27001:2022 that period ran 36 months, ending 31 October 2025.
No. Where a certification document is updated because the client successfully completed only the transition audit, the expiration of its current certification cycle is not changed. You get a certificate against the new edition and the same renewal date.
It is the document required by clause 6.1.3 d) recording which information security controls apply, why each is included or excluded from Annex A, and their implementation status. It has no expiry date, which is why it goes stale - it decays with organizational change rather than with time, and it is the first thing an auditor opens.
No. Remindax tracks the surveillance, recertification, transition and internal review dates and reminds the people responsible. Auditing and certification are done by your accredited certification body, and the ISMS is your organization's own. Nothing here implies Remindax itself is certified.
Yes - a forever-free plan, no credit card required.
ISO/IEC 27001 certificates are issued by accredited certification bodies working under ISO/IEC 17021-1 and the mandatory documents of their accreditation system. Audit scheduling, cycle length, transition arrangements and restoration after expiry are decided there, and can differ for industry-specific schemes. Remindax tracks the dates and reminds you; it doesn't audit, certify, run your ISMS or advise on information security. Confirm your own cycle with your certification body and the official sources below; this is general information, not certification or security advice. Nothing on this page states or implies that Remindax itself holds ISO/IEC 27001 certification.
11. Sources & references
This page summarizes how the ISO/IEC 27001 certification lifecycle works and isn't certification or security advice. Your certificate is issued by an accredited certification body, and audit scheduling, cycle length, transition arrangements and restoration after expiry are decided by that body under its accreditation. Confirm the specifics that apply to you with them and the official sources below.
- •ISO — ISO/IEC 27001:2022, Information security management systems — the standard itself: the requirements for establishing, implementing, maintaining and continually improving an ISMS, including clause 6.1.3 d) requiring the Statement of Applicability and Annex A's reference set of information security controls.
- •ISO — ISO/IEC 17021-1:2015, requirements for bodies providing audit and certification of management systems — the source of the audit cycle quoted throughout: surveillance audits at least once a calendar year except in recertification years, the first no more than 12 months from the certification decision date, the treatment of the expiry date when recertification is completed early, correction of major nonconformities before expiration, and restoration within 6 months after expiry.
- •IAF MD 26:2023 — Transition requirements for ISO/IEC 27001:2022 — the mandatory document setting the 36-month transition period ending 31 October 2025, stating that all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of it, that a transition audit does not change the expiration of the current certification cycle, that the transition audit must include updating the Statement of Applicability, and the minimum auditor days for a transition audit conducted alongside recertification versus surveillance.
- •IAF — International Accreditation Forum documents — where mandatory documents and transition requirements are published when a standard is revised, and the starting point for checking whether a new transition clock has begun.
- •ISO — ISO/IEC 27001:2022/Amd 1:2024, Climate action changes — the 2024 amendment referenced in section 3, adding the requirement to determine whether climate change is a relevant issue in the organization's context, and an example of how requirements change between full editions.
- •Your accredited certification body and its accreditation body — the only authority on your own certificate: your certification decision date, your audit program, your cycle length, the transition arrangements offered to you, and your current certification status. A certificate's accreditation can also be verified through the national accreditation body that accredited the certification body.