ISO27K

ISO 27001 surveillance audits

The certificate lasts three years and the audits do not stop. Years two and three each carry a surveillance audit, year three carries a recertification on top, and the second year is where certificates quietly go wrong.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

An ISO 27001 surveillance audit costs $5,000 to $16,000 CAD a year for a Canadian company under 250 staff, runs roughly a third of the days of your stage 2, and happens in each of years two and three of the three-year certificate. At the end of year three a recertification audit replaces it and costs $15,000 to $25,000 CAD, which is most of the way back to the original audit fee. Nobody is quoted this number when they buy the first certificate, and it is the reason a project that looked like a one-off purchase turns into a line item that never goes away.

The three-year cycle, in days and dollars

Certification bodies price from audit day tables, so the comparable number between two quotes is days rather than the total. A surveillance visit is normally about a third of the initial certification audit, and recertification about two-thirds.

ISO 27001 certification cycle for a Canadian company of 25 to 100 staff, CAD
YearWhat happensTypical audit daysCertification body fee
1Stage 1 and stage 2 initial certification6 to 9$20,000 to $30,000
2First surveillance audit2 to 3$7,000 to $12,000
3Second surveillance audit2 to 3$7,000 to $12,000
3, lateRecertification, before the certificate expires4 to 6$15,000 to $25,000
Full cycle, certification body onlyFour audits over three years14 to 21$49,000 to $79,000

Add the internal audit, the annual penetration test and whatever platform you run, and the recurring cost of holding a certificate lands between $25,000 and $60,000 CAD a year. The full picture across every line is on the cost page, and the cost calculator gives you the three-year total for your own headcount rather than this band.

Ask for the three-year total before you sign year one

Two certification bodies quoting a similar stage 2 fee can differ by $20,000 CAD across the cycle, because one has loaded the cost into surveillance and recertification. Ask both for the day count per visit for all four audits, and ask what happens to the fee if your headcount grows past the next band. This is a three-year purchase priced as though it were one, and it is the easiest negotiation on the whole project because it happens before you are locked in.

What the surveillance auditor actually looks at

Not everything. A surveillance audit is a sample, and the sample is not random. Certain things are checked every single visit because the standard and the accreditation rules require it.

Always on the agenda
Internal audit and its findings, management review, use of the certification mark and logo, complaints and incidents since the last visit, changes to scope or to the organization, and progress on nonconformities raised last time.
Sampled across the cycle
Annex A controls and clause requirements, chosen so the whole system is covered by the end of the three years rather than at every visit.
Triggered by change
A new product, a new cloud region, an acquisition, a move to a new office or a significant headcount jump. Tell the body in advance. A change discovered during the audit becomes a finding about your change process rather than about the change.

The first item on that list is the one that catches people. A surveillance auditor opens with last year's nonconformities and this year's internal audit report. If the internal audit did not happen, the visit has already failed before anyone looks at a control, which is why the internal audit is an annual purchase rather than a project cost.

Why year two is where it goes wrong

The pattern is consistent and it is not about security. The certificate arrives, the deal that funded it closes, the consultant leaves, the person who ran the project moves to something else, and for eleven months nothing operates. Then a surveillance audit is booked and the honest position is that the management system stopped.

  • Access reviews that were quarterly happened once.
  • The risk register has the same dates on it as it did at stage 2.
  • No management review was held, because the executive who chaired it left.
  • Supplier reviews were not repeated, and three new suppliers were onboarded without one.
  • Nobody raised a nonconformity all year, which tells the auditor the improvement process is not running.
  • Training was done at onboarding for the original staff and not for the eleven people hired since.

None of that is expensive to prevent. It is roughly one day a month of somebody's attention, and the alternative is a surveillance audit that raises majors. The realistic fix is to name an owner in the management review minutes and to put the recurring activities in a calendar with the same seriousness as a payroll run.

Can a certificate be suspended

Yes, and this is the part buyers do not know. A major nonconformity that is not closed inside the timeframe the certification body sets, normally 30 to 90 days, leads to suspension of the certificate, and continued failure leads to withdrawal. A suspended certificate is not a private matter: the body's own rules require it to be reflected on its public register, which is exactly where a procurement team checking your certificate will look.

Missing a surveillance audit entirely has the same effect. The visits have scheduled windows tied to the original certification date, and a body that cannot audit you inside the window will suspend rather than reschedule indefinitely. Book the visit early, and if a genuine business reason means you need to move it, ask before the window closes rather than after.

Preparing for a surveillance audit in a fortnight

  1. Pull last year's nonconformities and assemble the closure evidence for each one. This is the first thing asked for.
  2. Confirm the internal audit for this cycle is complete, reported and signed.
  3. Confirm a management review was held with the clause 9.3 inputs, and that it is minuted.
  4. Refresh the risk register and the Statement of Applicability so the version dates are from this year, and record what changed.
  5. Collect the recurring records: access reviews, supplier reviews, training completion, backup restore tests, incident log.
  6. Write down every change since the last visit, including new systems, new suppliers, scope changes and headcount, and send it to the auditor in advance.

If that list produces more gaps than evidence, say so to the certification body before the visit rather than during it. Bodies deal with this constantly and a declared problem with a plan attached is treated very differently from one discovered in an interview.

Get help before the surveillance audit, not after

Tell us where the management system has drifted and we will match you with Canadian firms that can get the records back in order.

Get matched

Common questions

How much does an ISO 27001 surveillance audit cost in Canada?

$5,000 to $16,000 CAD a year depending on headcount and scope, which is roughly a third of the initial certification audit. The recertification in year three is separate and runs $15,000 to $25,000 CAD. Every figure here is Canadian dollars, and quotes from bodies headquartered elsewhere are frequently issued in another currency.

What is the difference between surveillance and recertification?

A surveillance audit is a partial check during the life of the certificate, sampling part of the system and always covering internal audit, management review and open nonconformities. Recertification happens before the three years expire, covers the whole management system, and issues a new certificate. Recertification is longer and more expensive, though still shorter than the original stage 1 and stage 2 combined.

What happens if we fail a surveillance audit?

You do not fail it in the pass-or-fail sense. The auditor raises nonconformities and sets a timeframe to close them, typically 30 to 90 days for a major. Closing them ends the matter. Not closing them leads to suspension of the certificate, and continued failure to withdrawal, both of which appear on the certification body's public register.

Can we change certification body mid-cycle?

Yes. It is called a transfer and accredited bodies have a defined process for it, which normally involves reviewing your current certificate, the last audit reports and any open nonconformities. It is easiest immediately after a successful surveillance audit and hardest while a major is open, which is also when people most want to move.

Does the scope have to stay the same for three years?

No, and widening it at recertification is the normal way to grow a certificate. Tell the body about any scope change as it happens rather than at the next visit. An extension inside the cycle is possible and is priced as extra days, while an undeclared change is a finding about your management of change.