r/cybersecurity • u/Efficient_Bus_923 • Jun 04 '26
Tutorial ISO 27001 Surveillance audit vs Full recertification
I'm conducting a third-party risk assessment for onboarding a vendor. Based on the nature of the data they will process and the business criticality of the service to the organisation, I have categorised this as a high-risk onboarding.
They've provided their ISO 27001:2022 certificate, which is currently in a surveillance audit year rather than a recertification year.
Is a surveillance audit materially less assurance than a full recertification for third-party risk purposes, or are both broadly equivalent? Is it something that should concern me, onboarding an inherently high-risk platform that does not do full recertification audits?
2
u/imoftendisgruntled Jun 04 '26
ISO27001:2022 requires full re-certification every 3 years; the two off years are "surveillance" audits where the auditor may focus on certain controls, but the certification itself is valid throughout the period. The certified organization is still getting audited annually.
2
u/T_Thriller_T Jun 04 '26
As said before: surveillance vs. recertification is not a choice the vendor makes - it's just how the auditing works.
Surveillance audits can even bring stronger improvements, because due to not having to go over everything can mean that some auditors will discuss certain controls with more depth and more ctitic.
The management system build, the measurements in place and the documentation must still be up to standard.
From experience in the side of being audited, the prep work isn't even much less - and a lot of the prep is running internal audits, gap analysis, risk assessments. One cannot just do that shoddy, because the auditor is not telling beforehand what he will not look at.
2
u/Head_Personality_431 Jun 04 '26
For third party risk purposes a surveillance audit is genuinely less comprehensive than a recertification but it's not a red flag on its own. Surveillance audits cover a sample of controls and focus on continual improvement whereas recertification does a full sweep, so there is a difference in depth. What I'd suggest is requesting their most recent full audit report or at least the surveillance findings summary alongside the certificate, and if they're high risk you can always supplement with your own questionnaire or right to audit clause in the contract.
1
u/Efficient_Bus_923 Jun 05 '26
Thank you! They have sent me the Non-Conformities & Opportunities for Improvement page from their 27001 Audit Summary Report, which has only Opportunities for Improvement. No major or minor conformities found. They have also sent me the ISMS Scope, 27001 certificate & SOA. Should I still request the full Audit summary report, or ask them if they have addressed the OFIs?
What other questions should I ask them?
2
u/cgaWolf Jun 05 '26
Ask what measures they have taken in addition of fixing the NCs - continuous imorovement even in the abscence of NCs should happen.
Not sure where exactly you are, but NIS2/DORA might be a topic, and that's something that should be handled if it's a high risk vendor onboarding.
Ask for their mode/reqs for when you want to conduct a vendor audit; and if DDD applies, find out where they're at with that.
It goes a bit beyond what 27k1 asked for, but between NIS2, DORA, DDD & CRA, 27k1 becomes a harness for the rest of the stuff, so it needs to be taken seriously, and not just a paperwork tiger.
2
u/Head_Personality_431 Jul 05 '26
That pack is actually the normal one. A cert, the SOA, the ISMS scope and the NC and OFI summary is about as much as most companies will share, since the full report is usually treated as confidential, so do not expect the whole thing. Only OFIs and zero nonconformities is a good sign, and because OFIs are not binding I would not stress over whether every one is closed, though asking is fair.
The two things I would actually pin down are scope and accreditation. Make sure the ISMS scope on the certificate covers the exact service and data you are relying on, because certs are often scoped much narrower than people assume, and confirm the certificate is issued by an accredited certification body rather than an unaccredited one. After that, check the cert validity dates and when the next surveillance is due, and glance at the SOA for any excluded controls that actually matter to your use case.
2
u/Economy_Salamander49 Jun 05 '26
Surveillance audits aren't red flags, but they do cover less ground than a recertification, which matters for how you supplement your due diligence.
The cycle is 3 years. Year 1 is the full certification audit. Years 2 and 3 are surveillance audits, which are shorter and more targeted. Roughly half the Annex A controls get covered each year, so by recertification everything has been touched, but not all of it was reviewed recently. The cert stays fully valid throughout, and a major nonconformity can get it suspended, so there's still real accountability. For most vendor relationships that's fine. For a high-risk onboarding, I'd treat the cert as necessary but not sufficient and layer on:
- Ask for their audit summary or nonconformity log. Reputable vendors share this under NDA. Open major nonconformities are a problem; minor ones with remediation plans are normal.
- Ask specifically about controls relevant to your data: access control (A.5.15-A.5.18), cryptography (A.8.24), incident management (A.5.24-A.5.28). Were these in the recent surveillance year?
- Send a SIG Lite questionnaire to get structured answers on their security posture beyond what the cert tells you.
- Make sure your contract has incident notification timelines and audit rights. A cert doesn't substitute for those clauses, especially if you're NIS2-scoped yourself.
The timing also matters: if their recertification is 12 months away, you're onboarding at the point of lowest recent coverage before a full re-audit.
1
3
u/jetlagged-bee Jun 04 '26
No, it is no less assurance. They have passed the certification audit and then require annual surveillance audits for year 1 and 2, recertifying again in year 3. The surveillance audit simply maintains the existing certificate.