ISO 27001:2013 to 2022 Transition Deadline
The three-year transition period for migrating from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 ended on this date under IAF MD 26:2023, which required certification bodies to complete all client transitions within 36 months of the 2022 edition's October 2022 publication. Per the IAF mandatory document, all certifications based on ISO/IEC 27001:2013 expired or were withdrawn at the end of the transition period regardless of their stated expiry date. Any organization that did not complete a transition audit by the deadline no longer holds a valid ISO 27001 certification and must pursue a new initial certification to the 2022 edition.
Key Analytics
Impact Analysis
Organizations that missed the deadline now have a gap in certification, which can trigger contractual non-compliance with customers requiring ISO 27001, insurance policy issues, and regulatory concerns in jurisdictions where ISO 27001 certification is a prerequisite for data processing. Because the transition window is closed, the only remediation path is a full initial certification audit against ISO/IEC 27001:2022 (Stage 1 and Stage 2), which is significantly more expensive and time-consuming than the transition audit would have been. Organizations that transitioned on time should confirm their new certificate correctly references the 2022 edition and that customer-facing compliance documentation has been updated.
Recommended Actions
- If your organization missed the deadline, engage a certification body immediately to scope a new initial certification audit against ISO/IEC 27001:2022; the transition pathway is no longer available
- Verify your current certificate references ISO/IEC 27001:2022 and update trust pages, security questionnaire responses, and customer contracts that cite the certification
- Ensure your ISMS documentation reflects the 2022 control set (93 controls in 4 themes), including an updated Statement of Applicability and risk assessment mapped to Annex A of the 2022 edition
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Initial certification scoping with a certification body, since the transition pathway is closed
- ›ISMS documentation rebuild to the 93-control, four-theme structure
- ›Evidence backfill for controls with no operating history
- ›Customer and contract communication plan covering the certification gap
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 210 to 500 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.