The transition period for ISO/IEC 27001:2022 ends today. From tomorrow, certificates issued against ISO/IEC 27001:2013 are no longer valid.
Organisations that transitioned will have:
- Updated their Statement of Applicability to the 93 controls in the new Annex A.
- Implemented the 11 new controls where applicable, such as threat intelligence, cloud security, data leakage prevention and secure coding.
- Addressed the new requirement for planning changes to the ISMS (clause 6.3).
- Considered climate change in their context analysis, following the 2024 amendment.
If your certificate has lapsed, or you are considering certification for the first time, talk to us about the fastest practical route to ISO/IEC 27001:2022.
Source: ISO/IEC 27001:2022 (ISO)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.