Short answer: Certification lasts a three-year cycle. Surveillance audits take place at least once each calendar year (the first within 12 months of the certification decision) and confirm the system is maintained. A recertification audit, planned so the decision is taken before expiry, renews the certificate for a new cycle.
What surveillance covers
- Internal audits and management review since the last audit.
- Complaints and how they were handled.
- Effectiveness of corrective actions from previous findings.
- Changes to the organisation, sites or scope.
- Use of the certificate and certification mark.
- A rotating sample of processes and requirements, so the whole system is covered over the cycle.
Surveillance audit time is typically about one third of the initial audit time, calculated under IAF MD 5.
Recertification
Recertification reviews performance over the whole cycle and audits the system again. Its time is normally around two thirds of what an initial audit would need at that point, so changes in headcount or risk change the duration.
If deadlines are missed
- Surveillance not possible in time: certification may be suspended.
- Recertification not completed before expiry: the certificate expires. Restoration may be possible within six months if outstanding activities are completed; otherwise a full Stage 2 is needed.
Status changes should be visible through the certification body's verification service.
Next step
What happens after the certificate is issued: annual surveillance, what auditors check, recertification before expiry, and what happens if deadlines are missed.
View the three-year cycle