Your security and compliance glossary

All the terms you need to know when you’re trying to get compliance audit ready, fast.

Show filters

What is an ISO 27001 nonconformity?

An ISO 27001 nonconformity is an organization’s non-fulfillment of a requirement of the ISO standard. Both major and minor nonconformities may be recorded in the process of a company’s certification audit. The presence of a major nonconformity means that a company cannot get certified. 

An organization is at risk of nonconformity if they have not fulfilled the standard requirements of the ISO 27001; if an organization’s documentation specified a process the organization is not following; or if an organization is not upholding contractual requirements in its dealings with third parties.  

A company’s ISO auditor will utilize nonconformities to judge the compliance of that company’s Information Security Management System (ISMS) against the ISO standard. An auditor will describe the nonconformity, provide evidence of the issue, reference by clause the requirement that is not being adequately addressed, and summarize what must be done to meet the stated requirement.

Examples of major nonconformities include:

  • Failure to fulfill a certain requirement of the standard
  • Absence of mandatory documentation
  • Breakdown of a process or procedure
  • Accumulation of minor nonconformities about one process or element of an organization’s management system, illuminating a larger problem 
  • Misuse of a certification mark, thus misleading customers 
  • Unresolved minor nonconformities

{{cta_withimage2="/cta-modules"}}

Additional resources you might like:

Compliance
Blog
How do you perform quarterly access reviews?

Without periodic access reviews, former employees may retain access to sensitive data after termination. Learn how to perform effective quarterly access reviews.

Product updates
Events
Turn Every Promise into Predictable Trust: Customer Commitments in Action

Join us for a live demo of Customer Commitments and see how Vanta turns contracts into structured, actionable intelligence.

SOC 2
Events
SOC 2 Basics: A 30 Minute Guide for Startups

Register to get a clear, founder-friendly intro to SOC 2 in just 30 minutes.

Additional resources you might like:

Compliance
Blog
How do you perform quarterly access reviews?

Without periodic access reviews, former employees may retain access to sensitive data after termination. Learn how to perform effective quarterly access reviews.

Product updates
Events
Turn Every Promise into Predictable Trust: Customer Commitments in Action

Join us for a live demo of Customer Commitments and see how Vanta turns contracts into structured, actionable intelligence.

SOC 2
Events
SOC 2 Basics: A 30 Minute Guide for Startups

Register to get a clear, founder-friendly intro to SOC 2 in just 30 minutes.

Compliance
Blog
Government contracting compliance 101: Everything you should know

Understand the regulations and standards government contractors must meet—and the challenges involved.

SOC 2
Events
Learn How to Automate Compliance for SOC 2, ISO 27001, and More

Register to see how Vanta helps fast-moving startups and security teams get audit-ready fast and stay continuously compliant, turning compliance into a deal accelerator, not a blocker.

Compliance
Events
Beyond the Checkbox: Scaling Compliance Across European Regulations

Watch to learn how to scale your compliance program across NIS2, DORA, and the EU AI Act — without duplicating controls or overwhelming your team.

GDPR
Blog
How to make your website GDPR compliant in 8 steps

Learn the essential steps to achieve GDPR compliance for your website. Click here to learn the requirements and organizational benefits of GDPR compliance.

Compliance
Blog
Compliance risk: A guide to assess and manage it effectively

A guide to help you navigate the growing complexity of managing compliance risk.

Product updates
Events
Goodbye, Audit Chaos. Hello, Calm-pliance.

Watch this edition of Vanta Delivers to see how we’re putting audit chaos behind us and moving forward into Calm-pliance.