Information and Cyber Security

Minor NC vs Major NC: What Organizations Must Know Before the Audit

Author: Tejaswi
Aug 25, 2026
13

Minor NC vs Major NC: What Organizations Must Know Before the Audit

For many companies preparing for ISO 27001 certification, the word “audit” creates anxiety. Teams spend many months implementing controls, policies, and documentation, and preparing the evidence, but one concern always remains:

“What happens if the auditor finds nonconformities?”

The good news is that nonconformities (NCs) are most common during ISO 27001 audits. Even mature companies receive audit findings. What is important is to understand the difference between a minor NC and a major NC, how they are affecting certification, and how faster corrective actions are conducted.

Companies that understand nonconformities before the audit are more prepared, less stressed, and significantly more likely to achieve certification smoothly.

Nonconformity in ISO 27001

A nonconformity (NC) in ISO 27001 is a situation where the company fails to meet a requirement of:

  • ISO 27001 standard
  • ISMS processes
  • Internal policies or procedures

In simple terms:

“Something required either does not exist, is not implemented properly, or is not working efficiently.”

Auditors identify nonconformities when they find gaps between:

  • Standard expectations
  • What the organization claims
  • What actually happens in practice

Not every finding is equally serious, which is why NCs are classified as either:

  • Minor nonconformities
  • Major nonconformities

Difference Between Minor NC and Major NC

The distinction is important because it directly affects certification outcomes and timelines.

Minor Nonconformity

A minor NC is an isolated issue that does not indicate a major failure of the Information Security Management System (ISMS).

It means:

  • Inconsistently followed a process that exists
  • Incomplete Evidence
  • Does the gap exist without a significant impact

The main aim is the functioning of the overall ISMS effectively

Examples of Minor NCs

  • A policy review date is missing
  • Missing security awareness training documentation by one employee
  • Evidence of Access review is incomplete for a specific system
  • Backup testing occurred, but was not fully documented
  • A risk treatment action is delayed slightly
Major Nonconformity

A major NC, a significant breakdown in the ISMS, or failure to meet critical ISO 27001 needs.

It means:

  • A required process that does not exist
  • Completely missed Controls
  • Unmanaged Risks
  • In a critical area, the ISMS is ineffective

The main aim of a major NC raises doubts about the effectiveness of the entire ISMS.

Examples

  • No formal risk assessment process exists
  • Not conducting Internal audits
  • Missing Management reviews
  • Non-existent Incident response procedures
  • Without justification, critical Annex A controls are absent
  • No evidence of corrective action management

Major NCs usually require more extensive remediation before certification can proceed.

How Minor and Major NCs Affect Certification Timelines

This is where the classification becomes especially important.

Impact of Minor NCs

Organizations can often still achieve certification with minor NCs, provided they:

  • Submit a corrective action plan
  • Address the issue within the agreed timeframe

Auditors generally expect:

  • Root cause analysis
  • Planned remediation actions
  • Evidence of future prevention

Minor NCs rarely delay certification significantly.

Impact of Major NCs

Major NCs have a much bigger impact.

In most instances:

  • Certification cannot proceed until the issue is resolved
  • Additional audit activities may be needed
  • Reassessment or follow-up audits might occur

This will delay certification by:

  • Weeks
  • Months
  • Or longer, depending on the severity

Major NCs often increase Audit costs, Internal workload, and Operational stress. This is why pre-audit readiness is important.

Why Companies Receive NCs

Many nonconformities will happen not because security is weak, but because:

  • Processes need to be undocumented
  • Inconsistent Teams
  • Missed Evidence
  • Controls exist, but are not maintained

Common causes include:

  • Ownership of Poor ISMS
  • Weak internal audits
  • Tracking of Incomplete risk treatment
  • Outdated policies
  • Lack of management involvement

In other words, the problem is often in governance, but not in technology.

Auditors’ Expectations on Corrective Action Planning

When an NC is identified, companies must respond with a corrective action plan.

A corrective action plan must include:

1. Root Cause Analysis

What caused this issue?

Not just:

“The document was missing.”

But:

“There was no formal process for periodic review of ownership.”

2. Immediate Correction

What needs to be fixed immediately?

For instance:

  • Missing evidence uploaded
  • Process completed
  • Access reviewed

3. Long-Term Preventive Action

How will recurrence be prevented?

For instance:

  • Adding Automated reminders
  • Assigning Ownership
  • Implementing the schedule of the internal review

Auditors look for sustainable improvements and not temporary fixes.

How to Reduce Nonconformities Before the Audit

Companies can significantly reduce audit findings by:

  • Conducting Internal Audits Properly
  • Reviewing Documentation Thoroughly
  • Validating Control Effectiveness
  • Performing Audit Readiness Assessments
  • Training Process Owners
Conclusion

Nonconformities are a normal part of ISO 27001 audits, but their severity makes the difference. Minor NCs are manageable gaps, while major NCs signal ISMS weaknesses that can delay certification.

Companies that prepare early, validate controls, and conduct strong internal audits are less likely to face major surprises during certification.

Finally, ISO 27001 audits are not just about perfection. They demonstrate that the companies understand risks, manage controls effectively, and continuously improves its security program over a period.

Why Azpirantz for ISO 27001 Audit Readiness?

ISO 27001 certification success depends on how well an organization identifies gaps, validates controls, maintains evidence, and responds to nonconformities before the external audit. Azpirantz helps organizations strengthen ISO 27001 audit readiness through ISMS gap assessments, internal audits, documentation reviews, control validation, evidence checks, risk treatment tracking, and corrective action planning. With expertise in ISO 27001 implementation, audit preparation, nonconformity management, root cause analysis, and certification support, Azpirantz helps organizations reduce the risk of major NCs, address minor findings effectively, improve governance maturity, and build confidence before the certification audit. By ensuring that processes are documented, implemented, and consistently maintained, Azpirantz enables companies to approach ISO 27001 audits with clarity, accountability, and stronger compliance readiness.

*This content has been created and published by the Azpirantz Marketing Team and should not be considered as professional advice. For expert consulting and professional advice, please reach out to [email protected].

Ready To Get Started?
We're Here To Help