Don’t do SECURITY. Do business SECURELY.

Transition to ISO/IEC 27001:2013 closes

Certificates issued against ISO/IEC 27001:2005 are no longer valid; all certified organisations must now hold certification to the 2013 edition.

The two-year transition period for moving from ISO/IEC 27001:2005 to ISO/IEC 27001:2013 has now ended. Certificates issued against the 2005 edition are no longer valid.

If your organisation has transitioned, congratulations. The move typically involved:

  • Reviewing the context of the organisation and the needs of interested parties
  • Updating the risk assessment method and risk treatment plan
  • Re-mapping controls to the restructured Annex A (114 controls in 14 domains) and updating the Statement of Applicability
  • Defining measurable information security objectives and monitoring ISMS performance

If you missed the deadline, or are considering certification for the first time, the 2013 edition is now the only route to certification.

Source: ISO/IEC 27001:2013 (ISO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights