Track ISO 9001 & 27001 Expiry and Surveillance Audit Dates
Track ISO 9001 and ISO 27001 surveillance, recertification and booking deadlines in one place, with a practical tracker that prevents a missed audit early.

Your ISO certificate can show years left while a surveillance-audit booking deadline is only weeks away. Track ISO 9001 and ISO 27001 surveillance, recertification and book-by dates together so the team acts before a missed audit puts certification at risk.
Letting one lapse is not a minor admin slip. It can mean losing the right to claim certification, removing the badge from your website and bid documents, and explaining to customers why you're no longer certified.
This guide shows which ISO dates to track, how to build a free system that catches every deadline, and where a dedicated tracker fills the gaps a spreadsheet can't.
How ISO management system certifications actually work
Most certificate tracking guides treat every cert the same way: one expiry date, one reminder. ISO management system certs work differently.
ISO 9001 and ISO 27001 both run on a 3-year certification cycle:
- Year 0 - Initial certification audit. You pass, you get certified. The clock starts.
- Year 1 - Surveillance audit 1. A shorter audit confirming your system is still compliant.
- Year 2 - Surveillance audit 2. Same check, one year later.
- Year 3 - Recertification audit. Full audit again. Pass and the 3-year clock resets. Fail or skip, and your certification lapses.
The surveillance audits are not optional. Missing one can result in suspension or withdrawal of your certificate, even if the 3-year expiry date on the document hasn't arrived yet.
So there isn't just one date to track. There are at minimum four: the surveillance-1 window, the surveillance-2 window, the recertification date, and the "book by" date for each audit. Most trackers miss that last one.
The free method: build a working tracker in a spreadsheet
You don't need software to do this properly. Here's a concrete setup.
Step 1: List every ISO certification you hold
One row per standard per site. If you have multiple locations, each site gets its own row. Record: the standard (ISO 9001, ISO 27001, ISO 14001, ISO 45001, etc.), the certification body name, and the certificate number.
Step 2: Record all key milestone dates
For each row, add these columns:
- Issue date - When the current 3-year cycle started.
- Surveillance 1 due - Typically 9-15 months after the issue date. Check your certification body's schedule for the exact window.
- Surveillance 1 book-by - 60-90 days before that audit date. This is when you need to contact the body to confirm the slot, not when the audit happens.
- Surveillance 2 due - Typically 21-27 months after the issue date.
- Surveillance 2 book-by - Again, 60-90 days before.
- Recertification due - Issue date plus 3 years.
- Recertification book-by - At least 90 days before. For larger scopes, 6 months.
Step 3: Set reminders on a shared calendar
Create calendar events for each book-by date and each audit due date. Put them on a shared team calendar, not a personal one. At least two people should see every reminder.
Recommended schedule per milestone:
- 90 days before: confirm the audit slot is booked
- 30 days before: internal readiness review
- 7 days before: document check and final preparation
Step 4: Attach the certificate PDF
Keep the actual certificate file with the record. Auditors, customers, and procurement teams ask for proof regularly. Hunting through email when someone asks is avoidable with a named file stored somewhere the team can find it.
Step 5: Record your certification body contact
Add a contact column with the name, email and phone number of your account manager at the cert body. When a book-by date arrives, you know exactly who to contact, not just where to start searching.
Here's what a working spreadsheet layout looks like:
| Column | Example |
|---|---|
| Standard | ISO 9001:2015 |
| Cert body | Bureau Veritas |
| Cert number | UK12345 |
| Issue date | 2024-03-15 |
| Surv 1 due | 2025-03-15 |
| Surv 1 book-by | 2024-12-15 |
| Surv 2 due | 2026-03-15 |
| Surv 2 book-by | 2025-12-15 |
| Recert due | 2027-03-15 |
| Recert book-by | 2026-12-15 |
| Owner | J. Williams (QM) |
| Cert body contact | sarah@bureauveritas.com |
Common mistakes that cause ISO certifications to lapse
Most lapses are predictable. These are the ones that come up repeatedly.
Tracking only the certificate expiry, not the surveillance dates. Your certificate might say "expires 2027" while your surveillance audit is due in three months. Miss the surveillance window and the cert can be suspended before it formally expires. In most years, the surveillance calendar matters more than the expiry date.
Booking the auditor too late. Accredited certification bodies have limited auditor capacity. Popular slots in Q4 and Q1 fill early. A 60-90 day booking window is the minimum for most bodies. Leave it later and you risk a date that doesn't fit your internal schedule, which pushes the audit even later.
Single-owner dependency. The quality manager carries all the dates in their head, or in their own calendar. When they leave or take extended leave, the visibility disappears. It's a fragile arrangement even when it works for years without incident.
Assuming the cert body will chase you. Some send reminders. Many don't, or the reminder goes to an email address that's changed since the last audit cycle. Don't build your compliance around an email you might never receive.
Holding multiple standards with offset cycles. Many organisations hold ISO 9001 as a base and add ISO 14001 or ISO 45001 later. Each runs its own 3-year cycle, often starting at different times. Combined audit programmes help but the dates can still be offset by months. A single tracker with one row per standard keeps it clear.
Track your ISO certifications in Lapsewise. Free to start, no card. Add the cert once, set the surveillance and recertification dates, and get reminded automatically before each deadline.
Start tracking freeWhere a dedicated tracker adds real value
A purpose-built tool handles the things a spreadsheet can't.
Multiple dates per record. You don't have to split surveillance-1, surveillance-2, and recertification across three rows or three tabs. One certification record holds all the dates, each with its own reminder, so the whole picture stays in one place.
Automatic email reminders fire at 8am in the owner's timezone, at the lead time you configure. Both the cert owner and any team members you add get warned, so one person's absence doesn't mean the reminder is missed.
Document storage on the record. The certificate PDF, the last audit report, and the booking confirmation all live with the certification rather than scattered across email threads and shared drives.
A status view shows every cert as green, amber, or action-needed at a glance. A compliance check takes seconds rather than requiring someone to open, scan, and interpret a spreadsheet.
Shared team visibility means anyone who needs to see the status can.
For the broader approach to certificate tracking across your whole compliance stack, use this certificate expiry tracking method to build the full register. If you're also tracking contracts, licenses, and insurance alongside your ISO certs, our comparison of spreadsheets vs renewal trackers covers when to make the move. The same expiry calendar should include membership renewal tracking for subscriptions with cancellation windows and insurance renewal reminders for policies that need review before cover ends. And if you're thinking about this across all the dates your business needs to watch, 9 business dates you should never miss is a useful starting point.
For certificate-specific tracking, see the Lapsewise certificate management system, which holds the certificate, the audit dates and the proof in one record. If you track contracts, insurance or licenses alongside ISO certs, expiration reminder software covers all of it in one dashboard.
Frequently asked questions
How long is an ISO 9001 or ISO 27001 certificate valid? The certification cycle is three years. Within that cycle, you must pass annual surveillance audits in years 1 and 2. If a surveillance audit is missed or failed, the certification body can suspend or withdraw the certificate before the 3-year term ends.
What is the difference between a surveillance audit and a recertification audit? A surveillance audit is a shorter check confirming that your management system is still functioning and compliant. A recertification audit is a full review at the end of the 3-year cycle that resets the clock for another three years. Surveillance audits are less intensive but no less mandatory.
How early should I start the recertification process? Contact your certification body at least 3 months before your recertification date to confirm the audit slot. For larger organisations or multi-site scopes, 6 months is safer. Auditor availability and document preparation both take time.
How often are ISO surveillance audits carried out? Most ISO 9001 and ISO 27001 certification cycles include a surveillance audit in each of the first two years, followed by recertification in year three. Your certification body sets the exact audit window, so record its confirmed dates rather than relying on a generic anniversary reminder.
What happens if my ISO certification lapses? You lose the right to claim certification and must remove the badge from marketing materials, bid documents, and supply-chain registries that require it. Customers and procurement platforms that have listed the cert as a requirement may disqualify you. Re-entering the cycle means a new initial certification audit.
Can I track ISO 9001 and ISO 27001 together in one system? Yes, and it's the cleaner approach. Both run on 3-year cycles but often start at different times. A tracker that holds each standard as a separate record with its own surveillance and recertification dates and its own reminder schedule is much cleaner than juggling separate spreadsheet tabs.
Can an ISO certificate be extended after its expiry date? Usually not as a simple extension. Under ISO/IEC 17021-1, recertification should be completed before expiry. A certification body may be able to restore certification within a limited period if the outstanding recertification work is completed, but the exact route depends on the body and the circumstances. Contact your certification body as soon as a delay appears.
The cost of a lapse, initial recertification typically runs $3,000-$7,000 before internal costs, according to Qualio's analysis, plus the commercial impact on bids and contracts, makes tracking worth doing properly. The spreadsheet method above is enough to start. When the list of standards or sites grows, or when one person carrying all the dates starts to feel like a risk, a tracker removes the manual work and the single-owner dependency at the same time.
Track every certificate, contract, grant, and license in one place. Lapsewise warns you before any renewal or expiry slips. Free to start, no card.
Related guides
Never let it lapse
Track every certificate, contract, grant, and license in one place. Lapsewise warns you before any renewal or expiry slips. Free to start, no card.