Short answer
In ISO 27001 certification audits, a major nonconformity is one that affects the management system's ability to achieve its intended results, such as a required process missing or not working. A minor nonconformity is an isolated lapse that does not. Certification bodies define both in ISO/IEC 17021-1, and a major must be corrected before a certificate is issued or kept.
Key takeaways
- Major: a requirement not met in a way that undermines the ISMS, or doubt that it is effective.
- Minor: a lapse that does not affect the ISMS's ability to achieve its results.
- Several related minors in one area can be raised as a major.
- Every nonconformity needs a correction, a root cause and a corrective action.
Where the definitions come from
ISO 27001 itself does not grade nonconformities. The grading comes from ISO/IEC 17021-1, the standard certification bodies follow. A major nonconformity affects the capability of the management system to achieve its intended results. A minor nonconformity does not.
Worked examples
| Finding | Grade | Why |
|---|---|---|
| No internal audit has been carried out since the last certification audit | Major | Clause [[9.2|Internal audit]] is not being met at all |
| Management review has never considered ISMS performance | Major | A required input to [[9.3|Management review]] is missing, so the ISMS is not steered |
| One leaver's account was disabled five days late | Minor | An isolated lapse in [[5.18|Access rights]]; the process works |
| Access reviews missed in three of four quarters and never escalated | Major | The control has broken down, not lapsed |
| The Statement of Applicability omits the justification for one excluded control | Minor | Documentation gap; the risk treatment decision exists |
What each grade means for certification
- Major: the certification body will not issue or continue the certificate until the correction and corrective action are accepted, and it may need to verify them on site.
- Minor: you submit a correction and corrective action plan, and the auditor checks its effectiveness at the next audit.
- Opportunities for improvement are not nonconformities and do not need a response, though a good auditor will ask what you did with them.
Writing a nonconformity that can be closed
A good finding states three things: the requirement, the evidence and what is missing. For example: 'Clause 9.2 requires internal audits at planned intervals. The audit programme shows audits planned for Q1 and Q3; no Q3 audit record exists and no reschedule was approved.' Anyone can see what closes it.
Checklist
Responding to a nonconformity
0 of 6 done
Frequently asked questions
What is a major nonconformity in ISO 27001?
A nonconformity that affects the capability of the information security management system to achieve its intended results, as defined in ISO/IEC 17021-1, for example a required process such as internal audit not being performed.
Can minor nonconformities become a major?
Yes. Several minor nonconformities with the same cause or in the same area can show a systemic breakdown and be raised as a major.