Current statusThe 2013-to-2022 transition is historical; the 2022 ISMS is the operating baseline.
ISO published ISO/IEC 27001:2022 on October 25, 2022 and now marks ISO/IEC 27001:2013 as withdrawn. IAF MD 26 established a 36-month client transition period ending October 31, 2025. That deadline matters when interpreting old transition articles, audit plans, supplier questionnaires, procurement language, and certificates that still refer to the 2013 edition.
Do not treat an old “transition plan” as evidence that the transition was completed. For an organization claiming accredited certification today, check the current certificate, certification scope, edition named on the certificate, status, certification body, and accreditation chain. Procurement records that still ask only for “ISO 27001:2013” should be corrected so buyers are not collecting obsolete evidence.
The standard is a management-system standard, not a claim that every system is secure or every Annex A control is implemented identically. A useful current-state review looks at how the organization identifies information-security risks, decides treatment, assigns accountability, measures performance, audits the ISMS, performs management review, corrects nonconformities, and improves the system over time.