{"id":851,"date":"2026-10-09T13:00:36","date_gmt":"2026-10-09T11:00:36","guid":{"rendered":"https:\/\/mergenorth.com\/start\/?page_id=851"},"modified":"2026-10-09T13:18:59","modified_gmt":"2026-10-09T11:18:59","slug":"keeping-iso-27001-alive-three-years-on-and-recertified","status":"publish","type":"page","link":"https:\/\/mergenorth.com\/start\/?page_id=851","title":{"rendered":"ISO 27001: Three Years of learnings"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Three years later<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Extenda Retail has just completed its first three-year ISO 27001 recertification. Our certificate now runs through December 2029. In my previous post I described how we built our information security management system and passed the initial audit in 2023. This one is about everything that happened in between, which turned out to be the real test.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anyone who has been through a first certification knows the feeling afterwards: relief, then a quiet risk that the organisation exhales and lets the system drift. A certificate is a snapshot. The renewal audit asks a harder question: did the system keep working when nobody was preparing for an auditor?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The annual rhythm<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">What kept us on track was not heroics but a calendar. Every year, the same cycle repeats:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Annual policy review.<\/strong> The Information Security Policy is reviewed and approved by the Board each spring. This year it reached version 2.4.<\/li>\n\n\n\n<li><strong>Annual procedure review.<\/strong> Every ISMS document has an owner and a review date. Obsolete documents are retired, not left to confuse people.<\/li>\n\n\n\n<li><strong>Internal audits.<\/strong> We audit ourselves before anyone else does, across sites and functions.<\/li>\n\n\n\n<li><strong>External surveillance audit.<\/strong> The certification body returns each year to check that the system still works.<\/li>\n\n\n\n<li><strong>Management review.<\/strong> The Executive Management Team reviews audit results, incidents, risks and objectives, and sets the security objectives for the year ahead.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The management review is the step most companies underestimate. It is where findings turn into budget, priorities and named owners. Without it, audit reports become reading material.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Moving to the 2022 standard and growing the scope<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We certified against ISO\/IEC 27001:2013. In November 2024 we transitioned to the 2022 version of the standard, well ahead of the deadline for retiring the old one. That meant updating our ISMS procedure, adding a formal process for planning changes, and mapping our controls to the restructured Annex A.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The transition was less painful than we feared, because the system was alive. The work was translation, not reconstruction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the same time, the business kept changing around the certificate. Our India team grew into a significant part of how we deliver and support our products, so we brought the Bangalore office inside the certification boundary. A scope that does not follow the business stops meaning anything to customers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What the audits told us<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Our surveillance audits did their job: they found things. In 2025 the auditor raised six minor nonconformities. None threatened the certificate, but together they told an honest story about where a growing software company tends to cut corners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The themes were familiar ones:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Plans we had written but not tested<\/strong>, including business continuity scenarios and backup restores<\/li>\n\n\n\n<li><strong>Training completion<\/strong> that was mandatory on paper but not fully enforced<\/li>\n\n\n\n<li><strong>Incident records<\/strong> that were hard to filter and follow up<\/li>\n\n\n\n<li><strong>Supplier due diligence<\/strong> for new vendors that was not consistently documented<\/li>\n\n\n\n<li><strong>Vulnerability management<\/strong> that engineering teams had not all been onboarded to<\/li>\n\n\n\n<li><strong>Management follow-up<\/strong> of audit results that needed to be more explicit<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">We did not treat these as paperwork to close. They shaped our security objectives. Business continuity and the human factor became the two priorities, the latter reinforced by phishing exercises that showed click rates higher than we wanted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability finding led to something bigger. Responsibility had been spread across engineering, product and IT with no consolidated view. We are now building a centralised vulnerability management capability, and we updated our business continuity framework with a proper testing plan.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The 2026 recertification<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A recertification audit is closer to an initial audit than to a surveillance visit. The auditor looks at the full three-year cycle, not just the last twelve months. Have objectives been met? Were findings closed? Does the system improve, or does it just repeat?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This year&#8217;s audit ran across our sites. Stockholm and Gothenburg were audited in August, as was Bangalore for the first time, and our office in T\u00f8nsberg followed on site in September. We also met a new lead auditor, which was healthy: fresh eyes test whether your system makes sense to someone who has not seen it before.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The preparation felt different from 2023. The first time, we prepared for the audit. This time, we mostly demonstrated what we already do. We even used AI to support parts of our internal audit work this year, which freed time for the conversations that actually matter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result: our certificate is renewed, valid through December 2029.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What comes next<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The next three years will stretch the system in new directions, and that is exactly what it is for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>AI governance.<\/strong> We are building an AI management system aligned to ISO 42001 alongside our ISMS. Roughly 60 to 70 percent of the controls overlap with ISO 27001, so we are extending what works rather than starting over. AI-related risks now sit in our corporate risk register, and new AI tools go through a formal approval process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Cyber Resilience Act.<\/strong> The EU&#8217;s product security regulation adds obligations at the product level. Our CRA workstream has confirmed which products are in scope and is now assessing them, building on the same risk and vulnerability processes our ISMS already runs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Customer trust at scale.<\/strong> Our certificate lets retailers rely on an independent assessment instead of sending us custom questionnaires. The next step is making that evidence even easier to consume.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lessons on keeping it alive<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The calendar is the system.<\/strong> Fixed review dates beat good intentions.<\/li>\n\n\n\n<li><strong>Welcome the findings.<\/strong> Minor nonconformities are cheap lessons. Use them to set objectives.<\/li>\n\n\n\n<li><strong>Let the scope follow the business.<\/strong> New offices, products and regulations belong inside the boundary.<\/li>\n\n\n\n<li><strong>Build new frameworks on the old one.<\/strong> ISO 42001 and the CRA are far easier with a working ISMS underneath.<\/li>\n\n\n\n<li><strong>Measure culture, not just controls.<\/strong> The human factor remains our biggest risk, and the hardest to certify.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Three years ago, certification was our finish line. Today it is simply how we run the company.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Three years later Extenda Retail has just completed its first three-year ISO 27001 recertification. Our certificate now runs through December 2029. In my previous post I described how we built our information security management system and passed the initial audit in 2023. This one is about everything that happened in between, which turned out to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-851","page","type-page","status-publish","hentry","entry"],"_links":{"self":[{"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=\/wp\/v2\/pages\/851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=851"}],"version-history":[{"count":2,"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=\/wp\/v2\/pages\/851\/revisions"}],"predecessor-version":[{"id":865,"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=\/wp\/v2\/pages\/851\/revisions\/865"}],"wp:attachment":[{"href":"https:\/\/mergenorth.com\/start\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}