Don’t do SECURITY. Do business SECURELY.

ISO/IEC 27001:2013 certificates expire today

The three-year transition to ISO/IEC 27001:2022 has ended; certificates against the 2013 edition are no longer valid.

The transition period for ISO/IEC 27001:2022 ends today. From tomorrow, certificates issued against ISO/IEC 27001:2013 are no longer valid.

Organisations that transitioned will have:

  • Updated their Statement of Applicability to the 93 controls in the new Annex A.
  • Implemented the 11 new controls where applicable, such as threat intelligence, cloud security, data leakage prevention and secure coding.
  • Addressed the new requirement for planning changes to the ISMS (clause 6.3).
  • Considered climate change in their context analysis, following the 2024 amendment.

If your certificate has lapsed, or you are considering certification for the first time, talk to us about the fastest practical route to ISO/IEC 27001:2022.

Source: ISO/IEC 27001:2022 (ISO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights