In short: The three-year transition period from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 ends on 31 October 2025. After this date, certificates issued against the 2013 edition are no longer valid.
What happens after the deadline?
Organizations that have not transitioned will no longer hold valid ISO/IEC 27001 certification and may need a new certification audit.
What did the transition involve?
- Updating the Statement of Applicability to the new Annex A
- Implementing new controls where applicable
- Minor changes to management system clauses
Key takeaways
- The transition ended on 31 October 2025.
- 2013 certificates are no longer valid.
- Late organizations may need a new certification audit.
Frequently asked questions
Can certification be restored quickly?
This depends on the certification body; a full audit is often required.
What were the biggest changes?
The Annex A control set aligned with ISO/IEC 27002:2022.
Does this affect ISO/IEC 27701?
ISO/IEC 27701 certification depends on a valid ISO/IEC 27001 certification.