ISO27K

ISO 27001 major and minor nonconformities

A finding is not a failure. It is a deadline with your name on it, and the difference between a major and a minor is how short that deadline is and whether a certification decision waits for you.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A major nonconformity at stage 2 does not usually cost you the certificate. It costs you the timetable. The certification decision is held until you close it, and ISO/IEC 17021-1 gives you six months from the last day of stage 2 to do that before the audit has to be repeated rather than resumed. In practice certification bodies set a much shorter clock than the outside limit: a correction plan inside 30 days and verified closure inside 60 to 90 days. A minor nonconformity does not hold the certificate at all. You submit a plan, and the evidence is checked at the next audit.

What is the difference between a major and a minor nonconformity

The grade is not a measure of how serious the security problem is. It is a measure of how much of the management system is broken, which is why a missing signature can be a major and an unpatched server can be a minor.

Major nonconformity
A required element of the management system is absent, or has broken down entirely, or a set of minor findings adds up to a systemic failure of the same requirement. No internal audit was carried out. No management review was held. The Statement of Applicability excludes controls with no justification at all. Access is never reviewed anywhere. The test the auditor applies is whether the requirement is being met in any meaningful sense, not whether it is being met well.
Minor nonconformity
A single lapse against a requirement that is otherwise working. Eleven of twelve joiners have a screening record and one does not. The quarterly access review ran in three quarters out of four. The risk register has an owner recorded for every risk except two. The system exists, and it slipped.
Observation
Something the auditor noticed that is not a breach of a requirement. It carries no deadline and no obligation. It frequently reappears as a nonconformity next year if you ignore it, which is why it was written down.
Opportunity for improvement
Advice, offered within the limits of what an accredited auditor is permitted to say. You do not have to act on it and you should not create a corrective action record for it, because a corrective action against something that was not a nonconformity confuses your own improvement process.

What actually raises a major

Four patterns account for most majors raised at a first certification, and all four are visible before the auditor arrives.

  • A required activity has never happened. Clause 9.2 internal audit and clause 9.3 management review are the two that catch first certifications, because they are the only requirements that cannot be produced on the day. There is no way to hold a management review retroactively.
  • A control marked implemented is not running. The Statement of Applicability says a control is in place, the auditor asks the person who operates it, and it was approved and never turned on. This is a nonconformity against your own management system rather than against the control, and it is graded harshly for that reason.
  • The same minor in five places. One missing training record is minor. Training records missing across every department is a breakdown of the requirement, and the auditor is required to grade it as one.
  • A finding raised last year and not fixed. A repeat nonconformity says the corrective action process does not work, which is itself a clause 10 requirement. Repeats are escalated on principle.

How long do we have to close a nonconformity

Two clocks run at once. The certification body sets the working deadlines in your contract, and the accreditation rules set the outside limit that neither of you can move.

Nonconformity closure deadlines after an ISO 27001 stage 2 audit A correction plan is normally due between day 14 and day 30 after the closing meeting, root cause and corrective action are accepted between day 30 and day 45, closure evidence is verified between day 60 and day 90, and ISO/IEC 17021-1 sets an outside limit of 180 days after which stage 2 has to be repeated. Correction plan due day 14 to 30 Root cause accepted day 30 to 45 Closure verified day 60 to 90 Outside limit day 180, then stage 2 repeats 0 30 60 90 120 150 180 Days after the last day of stage 2
Typical certification body deadlines for a major raised at stage 2, against the accreditation limit. The same days are in the table below.
Closure timetable for a major nonconformity raised at stage 2
StepDays after stage 2What you submit
Correction plan14 to 30The immediate fix, the root cause statement, the corrective action and a date
Plan accepted by the body30 to 45Nothing. The auditor either accepts the root cause or sends it back, and a rejected root cause restarts this line
Closure evidence verified60 to 90Records showing the corrective action is running, by desk review or a follow-up visit
Certification decision70 to 120Made by a reviewer inside the body who was not on the audit team
Accreditation outside limit180ISO/IEC 17021-1 requires a new stage 2 rather than a resumption once six months have passed

Minors follow a shorter path and a longer one at the same time. The plan is usually due inside 30 days like a major, but the evidence is verified at the next scheduled visit rather than by a special one, which means a minor raised at stage 2 is closed at the first surveillance audit a year later. It does not delay your certificate.

What a certification body wants in the response

Most rejected responses fail on the same thing: the company sent a correction and called it a corrective action. They are different words in clause 10.1 and the auditor is reading for both.

Correction against corrective action, worked on a real finding
ElementWeak responseAccepted response
The findingTwo of the six joiners sampled had no completed security awareness training record.
CorrectionBoth employees have now completed the training.Both employees completed the training on 12 September, records attached, and the whole population was checked, which found one further gap now closed.
Root causeHuman error by the manager.Training assignment was a manual step in the onboarding checklist with no owner and no report, so nothing detected a missed assignment.
Corrective actionWe will be more careful.Training is now assigned automatically on account creation, and a monthly exception report of staff without a completion goes to the people lead. First two reports attached.
Evidence of effectivenessNone offered.Three onboarding cycles since the change, all with completions inside seven days.

The root cause is almost never the person

An auditor rejects "human error" as a root cause on sight, because it identifies no change you can make to the system. Keep asking why until the answer is about a process with no owner, no detection or no record. This is also the part that improves your company rather than your paperwork, and it is the reason clause 10.1 asks for it at all.

What happens if it is raised at a surveillance audit

The stakes change, because now you have a certificate to lose. A major raised at a surveillance visit that is not closed inside the body's timeframe, normally 30 to 90 days, leads to suspension of the certificate. Suspension is not private: accredited bodies are required to reflect certificate status on their public register, and that register is where a procurement team checks you. Continued failure leads to withdrawal, and getting back on afterwards means a new initial audit rather than a resumption.

The pattern that produces these findings is well documented and has nothing to do with security. It is the second year of the cycle, when the project that funded the certificate has closed and nobody has been given the running of the system. What goes wrong and how to catch it before the auditor does is set out on surveillance audits.

What a nonconformity costs in Canadian dollars

The finding itself is free. Closing it is not always.

  • Desk review of closure evidence. Usually included in the original audit fee, occasionally billed as a fraction of a day. Budget $0 to $1,500 CAD.
  • Follow-up or special visit. One to two audit days, $3,000 to $8,000 CAD plus travel, and it is required where the evidence cannot be judged remotely. Physical controls and anything requiring observation of people at work fall in this group.
  • A repeated stage 2. Only if you pass the six-month limit. This is the expensive outcome at $9,000 to $25,000 CAD and it is entirely avoidable.
  • The remediation itself. Unbounded, and usually the largest number. If the finding is that logging does not exist, the corrective action is a logging project rather than a document.

The case for wanting findings

The instinct is to aim for a clean audit, and on a first certification a clean audit is a mild warning sign rather than a triumph. A stage 2 that samples a management system built in the last nine months and raises nothing at all usually means the sample was shallow, and shallow samples are found by the accreditation body during its own witness audits of the certification body. Two or three minors on a first certification is the normal, healthy result.

The same logic applies harder to your own internal audit. An internal audit program that has never raised a nonconformity is evidence that it is not being run properly, and a surveillance auditor treats it that way. Raising and closing your own findings is the cheapest possible demonstration that clause 10 works, and it is the one piece of the standard where doing badly on purpose, early, is genuinely the right strategy.

Get help closing a finding properly

Tell us what was raised and when it is due, and we will match you with Canadian firms that write root cause responses auditors accept.

Get matched

Common questions

Can you fail an ISO 27001 audit?

Not in the way people expect. There is no fail grade. The auditor raises nonconformities and the certification decision waits until the majors are closed. What can happen is that you run out of time: once six months have passed since the last day of stage 2, ISO/IEC 17021-1 requires a fresh stage 2 rather than a resumption, and you pay for it again.

How many nonconformities are too many?

There is no threshold in the standard. What matters is the grade and the pattern. Half a dozen unrelated minors on a first certification is normal and closes without drama. Two majors in the same clause is a different conversation, because it suggests the management system was documented rather than operated.

Do minor nonconformities delay the certificate?

No. You submit a correction plan for a minor, typically within 30 days, and the certification decision proceeds. The evidence that the corrective action worked is checked at the next surveillance audit. A minor that is still open at that visit is normally escalated to a major, which is the point at which it starts to matter.

Can we argue with a nonconformity?

Yes, and accredited bodies are required to have an appeals process you can use. The productive version of the argument happens at the closing meeting, where you can ask the auditor to point at the clause or the control the finding is written against, and at the evidence they sampled. If the finding rests on a misunderstanding of your scope, that is usually where it gets resolved. Arguing after the report is written is slower and rarely works.

Does a nonconformity show up on our certificate?

No. Certificates carry the standard, the scope statement, dates and the accreditation mark, and nothing about findings. What is public is certificate status on the certification body register, which shows suspension or withdrawal. Customers who ask for your audit report are asking for something you are not obliged to provide, and most companies share the Statement of Applicability instead.

What is the difference between a nonconformity and an observation?

A nonconformity is a breach of a requirement in the standard or of your own management system, and it carries a mandatory response with a deadline. An observation is a note about something that is not yet a breach. There is no obligation attached to an observation, and no benefit in raising a formal corrective action for one, though it is worth tracking somewhere because ignored observations have a habit of returning as findings.