Our certification lapsed. How bad is it and how do we recover?
A lapsed ISO 27001 or SOC 2 certification immediately invalidates previous assurances, potentially breaching contractual obligations and eroding stakeholder trust. Recovery typically necessitates undergoing a full initial certification audit again, demonstrating continuous adherence to control requirements and the Information Security Management System (ISMS) for ISO 27001, or the Trust Services Criteria for SOC 2. This process is often more costly and time consuming than maintaining continuous certification.
A lapsed certification means the organisation can no longer claim compliance or provide the assurance that the certification previously offered. For ISO 27001, this implies the Information Security Management System (ISMS) is no longer formally recognised as conforming to the standard, potentially impacting client contracts that mandate certification. For SOC 2, which is often a contractual requirement, a lapse can lead to immediate non-compliance with client agreements, triggering breach clauses, financial penalties, or loss of business. Both scenarios result in a significant loss of market credibility and trust, as the independent validation of security controls is no longer current.
Recovering from a lapsed certification generally requires initiating a new "initial" certification process, rather than a re-certification. This involves a full scope definition, readiness assessment, and a Stage 1 and Stage 2 audit for ISO 27001, or a new Type 2 audit period for SOC 2. While the underlying controls and ISMS should ideally have been maintained, the lapse means the certification body or auditor must re-evaluate the entire system from scratch. Organisations should immediately engage with their previous certification body or an accredited auditor to understand the specific requirements and timelines for re-establishing certification, which will likely incur similar costs and effort to the original process.
Sources
- ISO/IEC 27001:2022 (Information security, cybersecurity and privacy protection — Information security management systems — Requirements)
- AICPA, Trust Services Criteria (TSC) for SOC 2