How Long Should You Keep Calibration Records? A UK Guide
By Brian Crocker · Published 15 August 2026
"How long do we have to keep these?" is a question every quality manager asks about calibration records eventually, usually while deciding whether to delete a folder of old certificates. The answer surprises people: the standards do not give you a number. What they give you is a duty to decide, document, and justify a retention period of your own — which is more useful than a fixed rule, and more defensible at audit. This guide explains what is actually required and how to set a retention period you can stand behind.
The Standards Do Not Set a Number
It is worth being precise here, because retention is an area where it is tempting to invent a figure. Neither calibration standard prescribes a retention period.
ISO 9001:2015 requires that documented information is retained and controlled — kept legible, identifiable, and retrievable, and protected from loss of integrity. Clause 7.1.5 requires calibration records as evidence that monitoring and measuring resources are fit for purpose. But the standard leaves the retention period to the organisation. It asks you to determine your own, based on your requirements.
ISO/IEC 17025:2017 takes the same approach for accredited laboratories: the laboratory must retain records and define a retention period for them, taking account of its obligations. Again, no fixed figure — a defined, justified period.
So anyone who tells you "ISO requires seven years" is overstating it. The requirement is to set a period and justify it, not to use a particular one.
How to Set a Defensible Period
If the standard does not give you a number, you have to derive one. A defensible retention period for calibration records is the longest of the obligations that apply to you:
- The life of the instrument, plus a margin. At minimum, you want an instrument's full calibration history for as long as it is in use, plus a period after it is retired — because measurements made with it may be questioned after it has gone.
- Product liability and traceability windows. If your product can be subject to a claim or recall years after manufacture, you need to show the instruments that measured it were in calibration at the time. The retention period should cover that window.
- Contractual and customer requirements. Customers, particularly in aerospace, automotive, and medical device supply chains, frequently specify record retention periods in their contracts. These can be long, and they override a shorter internal default.
- Sector-specific regulatory requirements. Some regulated sectors set their own record-keeping durations. Where one applies to you, it is a floor.
The right period is whichever of these is longest. Document the reasoning — "we retain calibration records for the life of the instrument plus N years, to satisfy [customer contract / liability window / sector requirement]" — and you have an answer that holds up at audit far better than a round number with no basis.
Keep the History, Not Just the Latest
A specific point that catches teams out: retention applies to the history, not just the current certificate. The value of a calibration record is that it shows an instrument was in calibration at a specific past time. If a measurement from eighteen months ago is later disputed, the relevant evidence is that instrument's certificate from eighteen months ago — superseded though it now is. Discarding old certificates the moment a new one arrives destroys exactly the evidence retention exists to preserve. This is the same reason the metrological traceability chain has to be documented over time, not just at the present moment.
Electronic Retention Is Fine — With Controls
Both standards are media-neutral. Calibration records can be electronic, and usually should be — electronic records are more legible, more retrievable, and less prone to loss than a filing cabinet. The condition is control. For everyone, records must stay legible, retrievable, and protected. For accredited laboratories, ISO/IEC 17025 §7.11 adds that the system holding them must be validated for functionality, protected from unauthorised access, and safeguarded against tampering and loss — the same data-control points covered in the ISO 17025 software guide.
The practical risk with electronic retention is not the standard — it is the shared drive where files get moved, overwritten, or deleted with no record. A controlled system that holds the full history, with an audit trail and a backup, satisfies retention far more reliably than a folder anyone can edit.
How CalProof Fits
CalProof retains each instrument's full calibration history — every certificate, not just the latest — against its record, with an audit trail of changes and a backup, so the history is preserved for whatever retention period you set. When you need to produce an instrument's certificate from three years ago, it is on the record, not lost in a reorganised folder. And because you can export the whole record set as CSV plus the underlying PDFs at any time, your retained evidence is never locked in.
GBP pricing from £29 a month. No per-user fees on Pro and above. UK data hosting. No long-term contract.
To see the shape of the retained record, the sample audit pack is ungated and downloads as a single PDF.
Sources
- ISO 9001:2015 — Quality management systems — Requirements (Clause 7.1.5; control of documented information)
- ISO/IEC 17025:2017 — General requirements for the competence of testing and calibration laboratories (control of records; §7.11 control of data and information management)
This guide applies to UK manufacturers and laboratories under ISO 9001 or ISO/IEC 17025. It is general guidance based on the published standards; the retention period that applies to your organisation depends on your products, contracts, sector, and your auditor's interpretation. Verify against your certification body, customer contracts, and any sector regulator. This is not legal or compliance advice.