The eleven months your certificate isn't watching
An audit is a sample taken on a single day; the certificate hangs on the wall for a year. Here is what happens in the gap between the two — and why "compliant at the time" is a breach pattern, not a defence.
An ISO 27001 certificate is a photograph, and everyone in the room treats it as a livestream.
The photograph is a fair one. A competent auditor came in, sampled your controls, read your evidence, and formed a defensible opinion about the state of your information security management system on the days they were looking. Then they left, the certificate went up on the wall, and the sales team started attaching it to proposals. From that moment the document and the organisation begin to diverge, quietly and continuously, and nothing in the process is designed to notice.
The audit is a sample, and the sample is a day
Start with what a certification audit actually is, because the marketing has sanded the edges off it. An ISO 27001 assessment runs on a three-year cycle: an initial audit, then a surveillance audit roughly once a year, then recertification. On each visit the auditor does not inspect every control operating on every system on every day. They cannot. They take a sample — a handful of controls, a slice of evidence, a set of interviews — and reason from it to a conclusion about the whole. That is not a flaw in the method; it is the method. Sampling is how assurance has always worked.
The trouble is not the sample. The trouble is what everyone downstream does with it. The auditor draws a careful, bounded conclusion about a population, on a date, from a sample. The certificate compresses all of that into a logo. And the reader of the logo — the customer, the board, the procurement team — hears a claim the auditor never made: this organisation is secure, now.
A certificate certifies the past
This is not unique to ISO. SOC 2 Type II is often sold as the stronger report because it covers a period rather than a single instant — six months, or twelve. True, and it changes less than it sounds. A Type II describes how controls operated across a window that has already closed by the time you read the report. You are holding a well-evidenced account of a period in the past and using it to make a decision about the present. The observation period ended; the world kept going.
So the honest description of every point-in-time attestation is the same. It tells you, with real rigour, something that was true. It does not tell you whether it is true now, and it was never built to. The rigour is real and the currency is assumed.
A certificate is evidence of an audit. It is not evidence of a state. The gap between those two sentences is where the breaches live.
The eleven months
Put the cycle on a calendar and the problem names itself. The auditor visits, forms the photograph, and leaves. The next scheduled look is a year away. Between those two points there is a stretch — call it the eleven months — during which the certificate keeps making its claim and no one is checking whether the claim still holds.
Nobody is idle in the eleven months. That is the point. A cloud configuration is changed to ship a feature. A key engineer leaves and their access is never fully unwound. A supplier alters an offering the whole control depended on. An exception is accepted “just for this quarter” and never revisited. None of these is misconduct; each is an ordinary Tuesday. And each one moves the organisation a little further from the photograph on the wall, with nothing on the page updating to say so. The certificate does not decay in appearance as it decays in truth. That is precisely the problem — the confidence stays green while the evidence underneath it goes stale.
“Compliant at the time” is a breach pattern
You can see the shape of the failure in the incident reports. An organisation holds a valid, current certificate. It is breached anyway, through a control that was in scope — and the post-mortem finds the control had drifted months earlier, well inside the certification window. The certificate was not fraudulent. It was accurate on the day it was issued and stale by the day it mattered. “We were compliant at the time” is offered as a defence and lands as an admission, because everyone in the room can now see the difference between holding the certificate and being in the state the certificate described.
In our reading of these reports, the pattern is common enough to be unremarkable. The occasional well-publicised case — a certified vendor breached inside its own audited window — is not the anomaly worth staring at; it is the most visible instance of the ordinary thing. The scandal dates; the structure doesn’t. Point-in- time assurance produces a document whose truth is highest on the day it is least needed and lowest on the day it is needed most, and no amount of auditor diligence changes that, because the diligence is aimed at the photograph, not at the eleven months after it.
What standing readiness looks like
The fix is not a better audit. A better audit still produces a photograph — a sharper one, on a different day, followed by the same eleven months. The fix is to stop treating assurance as an event and start treating it as a state you can read at any moment.
That is the corner Frank stands in. Instead of a certificate that asserts a posture and lets it
quietly age, every posture Frank publishes carries an expiry — Holds until YYYY-MM-DD — and
a basis you can inspect: the evidence that earned it, the exceptions holding it down, and the date
it stops being defensible unless something is renewed. Confidence is treated as a quantity that
decays, because it does, and the interface is built to show the decay rather than hide it.
When fresh evidence lands, the date moves out. When an acceptance lapses or a dependency changes,
the date moves in. There is no path to indefinite green, because indefinite green is the lie the
certificate tells for eleven months at a stretch.
This does not replace your auditor, and it is not trying to. The audit is the deep, independent, point-in-time examination it has always been. Frank is the thing that keeps watching after the auditor goes home — the record of whether the state they certified is still the state you are in.
The test
There is one question worth putting to any assurance artefact you rely on: if this stopped being true tomorrow, would the document change? A certificate answers no — it will say exactly the same thing the day after a control fails as the day before, for as long as eleven months. That is not a reason to distrust the audit. It is a reason to stop asking the audit to do a job it was never shaped for, and to keep an honest, current account of the eleven months it cannot see.
You can read that account for your own scope. Start with obligation visibility — it will not certify you or reassure you. It will tell you what your evidence still supports today, and the date that stops being true.