Getting ISO 27001 certified is the project most companies plan for. ISO 27001 maintenance is the part almost nobody plans for well enough.
The Most Common Mistake After Certification
Most companies treat the certificate as a finish line.
The audit is done. The project is complete. The team moves on.
That’s a reasonable conclusion if ISO 27001 were a one-time audit. It isn’t.
The certification is valid for three years, but it requires annual surveillance audits to stay active. Year one and year two each need a surveillance audit. Year three requires a full recertification. The system you built during the initial project has to keep running, continuously, not just when an audit is approaching.
What the Surveillance Audit Actually Checks (ISO 27001 maintenance)
The surveillance audit is not a full re-audit. It’s a review of whether you are still operating the controls you documented.
Your auditor will look for:
- New risks you have identified and assessed
- Evidence that your management review took place
- Records from your internal audit
- Whether any significant changes to your environment have been reviewed and addressed
Companies that pass their initial audit and then let the system coast often fail their first surveillance audit. Not because they did anything wrong. Because the evidence collection stopped.
Evidence Collection Has to Become Routine for ISO 27001 Maintenance
During the initial project, collecting evidence is a focused, temporary effort. Everyone is paying attention. The deadline is clear.
After certification, that focus disappears. The project team disbands. Ownership of the system becomes unclear. And the evidence stops.
For ISO 27001 maintenance to actually work, these activities need to happen on a fixed schedule without anyone chasing them:
- Access reviews are completed on time
- Security incidents logged, even minor ones
- Training completion tracked
- Vendor assessments run before renewing contracts
None of this is technically hard. All of it stops when no one owns it.
The Infrastructure Costs Nobody Budgets For
ISO 27001 requires compliant log retention. Security logs, access logs, and event logs all need to be retained. The period depends on your auditor’s requirements and any applicable regulations.
For a 50-person SaaS company, this typically means centralised log management. The cost varies depending on your log volume and retention period, but it is a real monthly line item. It does not appear in most certification project budgets.
On top of that, add the ongoing cost of:
- Vulnerability scanning
- Endpoint protection
- Access management tooling required by your controls
These costs don’t go away after the certificate arrives. They are the price of keeping it.
The Internal Audit Requirement
This is the one that surprises people most.
The ISO/IEC 27001:2022 standard requires at least one internal audit per year. This is separate from the external surveillance audit. It also has to be conducted by someone independent of the area being audited.
For companies without a dedicated compliance team, that usually means using an external consultant for the internal audit function. It is a legitimate approach, and many companies use it. But it adds to the annual cost. Plan for it in advance, not in a hurry, when the surveillance audit date appears on the calendar.
ISO 27001 Maintenance: How to Build a System That Actually Runs
Companies that handle surveillance audits without drama have three things in place:
1. A clear owner
One person is responsible for the ISMS. Not a committee, not “the team”. One named person who knows what needs to happen and when.
2. A compliance calendar
Every recurring activity has a date: internal audits, management reviews, access reviews, vendor assessments, and training cycles. The calendar runs automatically. The owner doesn’t have to remember any of it.
3. A simple evidence repository
Somewhere to store evidence that the owner can update without specialist knowledge. It does not have to be sophisticated. It has to be used.
Companies that build this in the first six months after certification handle surveillance audits without significant preparation. Companies that don’t find themselves running a mini-project every time an audit approaches.
What ISO 27001 Maintenance Costs in Practice
The annual cost varies by company size and setup. For a typical B2B SaaS company at the 20 to 100 person stage, expect to account for:
- Internal time for the ISMS owner (often a part-time responsibility at this stage)
- External consultant fees if you outsource the internal audit function
- Log management and security tooling (ongoing monthly cost)
- Surveillance audit fees from your certification body
None of these is a surprise if you plan for them before the certificate arrives.
Before You Commit, Know What You’re Committing To
If you want to understand what maintaining your specific ISO 27001 setup will cost and require, contact us at support@riskora.io or book a call on the website. We will walk you through it before you commit.