Recertification
Recertification is the act or process of certifying, or being certified, again. In practice it means periodically reviewing and confirming that a person, credential, or requirement still meets the necessary standards, rather than assuming an initial certification remains valid indefinitely. The process is often repeated on a set schedule and may require submitting an application or having a certifying official confirm continued eligibility.
Recertification is a recurring verification process in which a certifying authority or official reviews and reaffirms that a subject (such as an individual, credential, or enrolled party) continues to meet defined eligibility or qualification requirements after an initial certification. It is typically time-bound and procedurally driven, often involving a formal application (online or paper-based), review by a certifying official, and confirmation or attestation that requirements are still satisfied. In some contexts recertification is conducted on a fixed cycle, such as annually, and completion of the process is generally required to maintain the validity of the original certification. The specific methods, evidence, and cadence vary by the certifying body and the applicable program or standard.
Why it matters
Recertification addresses a governance risk that many organizations underestimate: the assumption that an initial certification remains valid indefinitely. Standards, eligibility conditions, personnel qualifications, and organizational circumstances change over time, and a credential or approval granted at one point may no longer reflect current reality. By requiring periodic review and reaffirmation, recertification helps ensure that what was once true is still true, and it forces a deliberate checkpoint rather than allowing lapsed or outdated status to go unnoticed.
For security leadership, recertification is a recurring control that supports the integrity of governance and compliance programs. Whether the subject is an individual's professional credential, an employee's continued eligibility for a program, or a party's ongoing qualification under a standard, the recurring nature of the process is what gives it value. A vCISO advising on such programs typically emphasizes that the cadence, evidence, and review responsibilities should be clearly defined so that recertification is treated as an ongoing obligation rather than a one-time event.
The value of recertification depends heavily on the cooperation of the subject and the diligence of the certifying official or authority. If the process is treated as a formality, or if applications and attestations are submitted without genuine review, the confirmation it provides can be hollow. Accountability for confirming continued eligibility generally rests with the certifying body and the organization operating the program, not with any single advisor, and the specific requirements vary by the certifying authority and applicable program.
Who it's relevant to
Inside Recertification
Common questions
Answers to the questions practitioners most commonly ask about Recertification.