home / frameworks / iso-27001 / transition-from-2013

// ISO 27001 hub

ISO 27001 transition from 2013 to 2022

The transition to ISO/IEC 27001:2022 closed on October 31, 2025, so certificates to the 2013 edition are no longer valid.

The transition timeline

When ISO published ISO/IEC 27001:2022 on October 25, 2022, the International Accreditation Forum issued a mandatory transition document, IAF MD 26. It set a 36-month transition period counted from the end of the publication month. It bound everyone accredited.

  • April 30, 2023, accreditation bodies ready to assess certification bodies to the 2022 edition
  • October 31, 2023, accreditation bodies finish moving certification bodies to the 2022 edition
  • April 30, 2024, initial certification and recertification audits only to the 2022 edition
  • October 31, 2025, all certified organizations moved to the 2022 edition

What it means now

The transition period is over. Under IAF MD 26, every certificate based on ISO/IEC 27001:2013 had to expire or be withdrawn at the end of October 31, 2025. As of October 2026, an accredited ISO 27001 certificate must refer to the 2022 edition, and any document still showing 2013 isn't a valid accredited certificate, whatever expiry date it prints.

For buyers, the check is simple. Ask for the current certificate, confirm it names ISO/IEC 27001:2022, and look it up in IAF CertSearch before relying on it in a contract or risk review. Updating supplier records and contract clauses that still cite the 2013 edition also helps avoid confusion in later audits.

For an organization whose 2013 certificate lapsed without a transition audit, there's no certificate left to update. It starts again. In most cases it will need to go through certification against the 2022 edition, and its certification body can explain whether any earlier audit work can be taken into account.

What the transition audit covered

IAF MD 26 told certification bodies that a transition audit could be held with a surveillance audit, with a recertification audit, or on its own, and could be remote if the objectives were met. It couldn't rely on document review alone, especially for technological controls. Testing was expected. A successful transition updated the certificate but didn't change the end date of the current 3-year cycle.

  • A gap analysis against the 2022 edition and any needed ISMS changes
  • An updated Statement of Applicability using the new Annex A
  • Updates to the risk treatment plan where needed
  • Evidence that new or changed controls were in place and working

Updating contracts and mappings

Contracts, supplier questionnaires, and internal policies written before 2022 often name ISO/IEC 27001:2013 or its 114 controls. Those references are now out of date. Replacing them with a reference to the current edition, or to the edition in force at the time of audit, avoids disputes about whether a supplier meets the clause. Control mappings built on the old Annex A numbering also need to be redone against the 2022 numbering, since the themes and control numbers changed.

Amendment 1 and later changes

Amendment 1:2024 added the climate change consideration to clauses 4.1 and 4.2 without creating a new edition or a separate transition. Auditors check it routinely. No newer edition of ISO/IEC 27001 has been published as of October 11, 2026, and ISO's catalogue lists the 2022 edition with its amendment as current. If a revision starts, the accreditation community would issue a new transition document, and that document would set any future deadlines.

Resources

All ISO 27001 resources

References

  1. IAF MD 26:2023 Transition requirements for ISO/IEC 27001:2022, International Accreditation Forum
  2. ISO/IEC 27001:2022 Information security management systems, ISO
  3. IAF CertSearch, International Accreditation Forum