Press TechRound interviews Secure.com CEO on the future of AI security
Read

The Real Cost of an ISO 27001 Surveillance Audit, and How to Make the Next One Boring

ISO 27001 surveillance audits, made simple. What auditors check, what it costs, and how to stay ready all year.

TL;DR

A surveillance audit is a yearly spot check your certification body runs in Years 1 and 2 of your three year cycle. It is narrower than your first audit. The auditor samples a few Annex A controls, reviews past findings, and confirms your ISMS still runs. It usually takes one to two days and costs roughly 3,000 to 10,000 dollars per year. The teams that dread it are the ones collecting evidence by hand. The teams that find it boring keep evidence live all year.

Introduction

Most teams treat the surveillance audit like a pop quiz. It is not. You already know the date. You already know roughly what gets checked. The stress comes from one thing: evidence that lives in twelve places instead of one.

Here is the part nobody tells you. Auditors report the same failure over and over. Teams hit a “mad scramble in the days leading up to your audit,” hunting for control evidence that feels like “looking for a needle in a haystack.” Most audit failures start with documents that cannot be found or trusted. That is a filing problem wearing a compliance costume.

This guide covers what a surveillance audit really is, what it costs, what gets checked, and how to turn it from a fire drill into a fifteen minute formality.

What an ISO 27001 surveillance audit actually is

A surveillance audit is a periodic check by your certification body to confirm your information security management system still meets the standard. Think health check, not full physical.

It is targeted on purpose. Your first certification looked at everything. Surveillance audits zoom in on the areas most likely to slip: past non conformities, anything that changed, and the controls tied to your biggest risks. You do not have to prove all 93 Annex A controls. You have to prove the system is working.

Where it fits in the three year cycle (H2)

Your certificate lasts three years, but it is not set and forget. Here is the rhythm.

  • Year 1: First surveillance audit, about twelve months after you certify.
  • Year 2: Second surveillance audit, same narrow scope.
  • Year 3: Full recertification audit, which looks a lot like your first audit and renews the certificate for another three years.

Surveillance audits happen at least once a year. Skip one and your certificate is at risk.

What a surveillance audit really costs

The sticker price is smaller than people fear. Surveillance audits usually run about one third of your initial certification fee.

Rough 2026 numbers for small to mid sized teams:

Surveillance audit: 3,000 to 10,000 dollars per year, most teams land near 6,000 to 7,500.
Recertification audit: 7,000 to 16,000 dollars in Year 3.
Full three year cycle including recertification: often 20,000 to 23,000 dollars in audit fees alone.

Your real cost driver is headcount, scope, and your certification body day rate, which averaged around 1,250 pounds or 1,500 dollars a day in 2026. But the fee is rarely what hurts. The hidden cost is the internal time your team burns gathering evidence by hand. That bill never shows up on the invoice.

What gets checked

Surveillance audits follow a pattern. Knowing it turns prep from guesswork into a checklist.

Common review areas:

  • Management review meetings and proof leadership is engaged.
  • Internal audit program and recent findings.
  • Risk treatment plan updates and fresh risk assessments.
  • Corrective actions from your last audit, this one is mandatory.
  • Incident logs and how you handled anything since the last visit.

The auditor leans harder on:

  • Anything that changed in your scope, tech, or processes.
  • Controls that were non conforming before.
  • High risk areas from your own risk register.
  • New locations or services added since last time.

The five most common non conformities

Surveillance audits fail in predictable ways. Watch these four traps, plus one that catches almost everyone.

Missed risk reviews. Teams treat risk as a once a year task. New systems and vendors add risk that never makes it into the register. Fix it with quarterly reviews and a risk check whenever something new goes live.

Controls that exist on paper but not in practice. A policy sits in a folder while the actual setting drifts. Fix it with regular control testing and an evidence trail that proves controls run.

Stale documentation. Procedures that do not match how the team actually works signal the ISMS is not part of daily life. Fix it with a document review cycle.

Unclosed findings from the last audit. This is the number one failure. Auditors will check every past corrective action. Fix it by tracking each one with proof it worked before you call it closed.

Evidence you cannot find. When a document is missing, it triggers back and forth that drags the audit out and shakes auditor confidence. Fix it with one central, current source of truth.

How to prepare so the audit is boring

Name one owner

Pick someone who has been through an audit before and knows your ISMS. Scattered ownership across five departments is where prep goes to die. One person routes evidence and answers.

Close every past finding first

This is non negotiable. For each old finding, document what you did, how you checked it worked, and what you changed so it does not come back.

Keep evidence in one place, version controlled

Evidence spread across drives and tickets stretches the audit and raises stress. Organize by clause or process area and keep every document current.

Run a mock audit four to six weeks out

A dry run gives you room to fix gaps without panic. Focus on management review, internal audit, and risk updates, the areas auditors always probe.

Brief your people

Tell key staff what to expect. Coach them to answer honestly from live records, not from a script. Auditors can tell the difference in one question.

Where Secure.com fits

Most surveillance audit pain is an evidence problem, not a security problem. Secure.com’s Compliance Teammate keeps evidence live all year, so prep drops from weeks to minutes.

  • Real time compliance dashboards show your ISO 27001 status by control, so you see gaps the day they appear, not the week of the audit.
  • Evidence is pulled automatically from your assets, vulnerabilities, incidents, and access reviews, then mapped to Annex A controls.
  • Audit ready reports export in minutes as PDF, CSV, or JSON, with a drilldown behind every control.
  • Drift detection flags a control the moment it slips out of line and routes the fix to an owner.
  • Past findings and corrective actions are tracked to closure, so nothing quietly reopens before the auditor arrives.

More from Secure.com