Guide

What happens after ISO 27001 certification? ISMS maintenance explained

Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.

Summary

After certification, the ISMS must be operated and improved: risks reviewed, controls monitored, documents updated, evidence collected, internal audits and management reviews repeated, corrective actions closed. Annual surveillance audits check this; after three years a recertification follows. A fixed annual rhythm with clear owners is the most effective way to avoid last-minute stress.

An ISO/IEC 27001 certificate confirms that your ISMS met the requirements at the time of the audit. From then on, the question is whether it keeps working.

The recurring activities

A living ISMS has a rhythm. Typical recurring activities:

Activity Typical frequency
Review of risks and treatment plans at least annually and on significant change
Review of the Statement of Applicability annually
Monitoring of controls and KPIs continuously / quarterly
Review of policies and procedures annually or on change
Supplier reviews for critical suppliers annually or by risk
Awareness activities and training continuously, at least annually
Access right reviews periodically, by risk
Internal audit annually (program can be spread over the year)
Management review at least annually
Follow-up of corrective actions continuously

The exact frequencies are your decision — they should follow your risks, not a template.

Why ISMS operation becomes painful

Most organizations do not struggle with the design of their ISMS, but with operating it:

  • Documentation diverges from reality. New systems, new suppliers, reorganizations — the documents stay the same.
  • Evidence is scattered. Screenshots in mailboxes, records on personal drives.
  • Responsibilities blur. The person who built the ISMS has moved on.
  • Audits drive the calendar. Everything happens in the four weeks before the auditor arrives.
  • Management reviews become a formality. Slides are presented, nothing is decided.

How to keep an ISMS alive

  1. Create an ISMS calendar — recurring activities, owners and deadlines, ideally in the tools people already use.
  2. Collect evidence continuously — define where evidence lives and make capturing it part of the normal process.
  3. Link changes to the ISMS — new systems, suppliers or incidents automatically trigger a risk check.
  4. Keep documents short and useful — easier to maintain, more likely to be read.
  5. Make the management review a decision meeting — with clear inputs, a few KPIs and concrete decisions.
  6. Close the loop — findings and incidents lead to corrective actions, and corrective actions are verified.

When outside support makes sense

Many organizations do not need a full-time information security team, but they need continuity. Ongoing support can mean coordinating the ISMS calendar, preparing audits and reviews, following up on actions, or helping implement measures that come out of the ISMS — while your team keeps ownership and grows its own capability.

Frequently asked questions

How often are surveillance audits?

Typically once a year in the two years after certification, followed by a recertification audit in the third year.

What is the most common problem after certification?

Loss of momentum. The project team disbands, responsibilities blur and activities are postponed until shortly before the next audit. A clear annual plan and someone who coordinates prevent this.

Talk to us

Want to tackle this in your organization? We help — together with your team.

contact@feldmanncyber.com · +49 (0)151 6275 6121