An ISO 27001 certificate runs on a three-year rhythm: stage 2 earns it, surveillance audits in years one and two keep it, and a recertification audit at year three renews it. Surveillance visits are shorter and sample-based — the auditor won’t retest everything, but will always look at the mandatory machinery: internal audits, management reviews, corrective actions from prior findings, and how the ISMS absorbed changes like new products or new infrastructure.
Certification is a sprint with a deadline and an owner; the year after is neither. Risk reviews slip, the control owner changes jobs, evidence automation quietly breaks, and nobody notices until the surveillance notice lands. That decay pattern — not new threats — is the most common source of nonconformities at surveillance, and a certificate can be suspended if findings show the management system simply stopped running.
The fix is structural: give every recurring ISMS task a named owner and a calendar, and check evidence health monthly instead of annually. Teams without spare security headcount hand that operating layer to a managed compliance service, which keeps internal audits, reviews, and evidence current so surveillance becomes a half-day of confirmation rather than a scramble.