Current edition: ISO/IEC 27001:2022Reviewed September 30, 2026

ISO/IEC 27001:2022 after the transition deadline: manage the current ISMS, not the expired migration project.

The accredited transition from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 is over. ISO lists the 2013 edition as withdrawn, while ISO/IEC 27001:2022 remains the published edition. IAF MD 26 required certification bodies to complete transitions of certified clients by October 31, 2025.

For teams operating in 2026, the useful question is no longer “How do we meet the transition deadline?” It is whether the ISMS, Statement of Applicability, risk treatment, evidence, certification scope, and supplier-assurance processes actually reflect the current standard and remain effective.

Current status

The 2013-to-2022 transition is historical; the 2022 ISMS is the operating baseline.

ISO published ISO/IEC 27001:2022 on October 25, 2022 and now marks ISO/IEC 27001:2013 as withdrawn. IAF MD 26 established a 36-month client transition period ending October 31, 2025. That deadline matters when interpreting old transition articles, audit plans, supplier questionnaires, procurement language, and certificates that still refer to the 2013 edition.

Do not treat an old “transition plan” as evidence that the transition was completed. For an organization claiming accredited certification today, check the current certificate, certification scope, edition named on the certificate, status, certification body, and accreditation chain. Procurement records that still ask only for “ISO 27001:2013” should be corrected so buyers are not collecting obsolete evidence.

The standard is a management-system standard, not a claim that every system is secure or every Annex A control is implemented identically. A useful current-state review looks at how the organization identifies information-security risks, decides treatment, assigns accountability, measures performance, audits the ISMS, performs management review, corrects nonconformities, and improves the system over time.

Certification verification

Verify the certificate and the accreditation chain—not just the logo in a sales deck.

Check the document itself

Confirm the legal entity, sites, scope, standard edition, certificate identifier, issue and expiry information, and certification body. A certificate whose scope does not cover the product, service, location, or business unit you rely on may provide much less assurance than the badge suggests.

Check current status

Where available, use the issuing certification body, accreditation body, and an accredited-certification database such as IAF CertSearch to validate status rather than relying on a static PDF. Supplier evidence should record when verification occurred and what was actually checked.

Check what changed

Certification is a point in an ongoing surveillance and recertification cycle. Material acquisitions, cloud migrations, organizational changes, outsourcing, major incidents, or changes in scope can affect how much the certificate tells you about the environment today.

Keep certification in context

Use certification as one evidence source alongside architecture, penetration testing, vulnerability management, incident history, identity controls, resilience evidence, contractual protections, and product-specific security information. Certification should not replace technical due diligence.

Risk treatment and Annex A

Use Annex A as a reference set, not a universal checklist.

ISO/IEC 27001 requires organizations to determine the controls needed to treat information-security risk and compare those controls with Annex A so necessary controls are not inadvertently omitted. ISO/IEC JTC 1/SC 27 auditing guidance explicitly warns against treating Annex A as a comprehensive control list or assuming every Annex A control is automatically required for every organization.

That distinction matters operationally. A strong Statement of Applicability explains which controls are necessary, why controls are included or excluded, how they are implemented, and how those decisions trace to risk treatment. It should not be a spreadsheet that simply marks every row “implemented” to improve an audit score.

The 2022 control reference contains 93 controls grouped under organizational, people, physical, and technological headings. The organization may also need controls from contracts, laws, sector standards, cloud-security practices, NIST publications, CIS Controls, or its own engineering requirements. The ISMS should make those relationships visible instead of forcing every risk into one catalog.

Operating evidence

Make the ISMS observable between audits.

A certification audit is easier when the evidence comes from normal operations rather than a last-minute document collection project.

Risk and treatment

Keep risk criteria, assessments, treatment decisions, control mappings, acceptance decisions, owners, due dates, and residual-risk approvals current. Trigger reassessment when systems, suppliers, threats, or business processes materially change.

Control operation

Prefer evidence generated by operating systems: identity-provider logs, access reviews, configuration platforms, vulnerability scanners, backup results, change records, security monitoring, supplier reviews, and incident-management systems.

Assurance and review

Maintain internal-audit evidence, management-review inputs and decisions, nonconformity records, corrective actions, effectiveness checks, security objectives, and measurements that show whether the ISMS is improving rather than merely producing documents.

Evidence should answer five practical questions.

Amendment 1:2024

Do not freeze the ISMS at the October 2022 publication date.

ISO lists ISO/IEC 27001:2022/Amd 1:2024 — Climate action changes as a published amendment applying to ISO/IEC 27001:2022. Organizations maintaining an ISMS should ensure their controlled standards inventory and management-system interpretation reflect applicable amendments rather than treating the base publication as permanently unchanged.

The broader lesson is procedural: assign ownership for standards monitoring. Record the authoritative source, current edition, amendments, review date, and the decision made when a change appears. That keeps standards maintenance from depending on a person noticing an industry newsletter shortly before an audit.

Procurement and supplier assurance

Ask for scope and verification evidence, not “Are you ISO certified?”

Buyer questions

Evidence refresh

Record certificate status and scope during onboarding, then refresh the evidence on a defined cadence and on material changes. A supplier that was certified last year may have changed ownership, scope, infrastructure, subprocessors, or certification status.

Connect this evidence to the broader third-party risk process rather than storing certificates in an isolated folder that procurement never revisits.

90-day current-state review

Move from transition cleanup to a maintained 2022 operating model.

Days 1–30: establish truth

Inventory current certificates and standards references, remove obsolete 2013 requirements from procurement templates, validate scope and status, review the Statement of Applicability, and identify stale risk-treatment or control-ownership records.

Days 31–60: test operation

Sample high-risk controls from identity, vulnerability management, configuration, logging, backup, supplier management, incident response, and secure development. Trace each sample from risk to control to current operating evidence.

Days 61–90: close the loop

Run internal-audit or independent review work, resolve repeated evidence failures, update management-review inputs, confirm amendment monitoring, and create a recurring schedule for certificate, source, scope, and control-effectiveness reviews.

Quick answers

Common ISO 27001 transition questions in 2026.

Is ISO/IEC 27001:2013 still current?

No. ISO identifies the 2013 edition as withdrawn and the 2022 edition as current.

Did the transition deadline move beyond October 31, 2025?

IAF MD 26 set October 31, 2025 as the deadline for certification bodies to complete certified-client transitions. This guide treats that date as completed historical transition context.

Does certification mean every Annex A control is mandatory?

No. The organization determines necessary controls through risk treatment and compares them with Annex A to make sure necessary controls were not omitted. The Statement of Applicability records the resulting decisions.

What should a buyer verify?

Verify current certificate status, edition, legal entity, scope, sites, certification body, accreditation context, and whether the certified scope actually covers the service or operation being evaluated.

Primary sources

Verify current status at the source.

Standards, certification status, accreditation arrangements, and supplier scope can change. Verify current primary sources before making consequential certification, procurement, or compliance decisions.

Related implementation

Connect ISO evidence to the controls you actually operate.

Use the CIS Controls, configuration-management, third-party risk, and compliance-operations guides to turn assurance requirements into owned, testable evidence.

Continue learning

Related guides after ISO/IEC 27001:2022 Current Certification Guide

Follow the next implementation topic without returning to search.

Put this guide to work

Turn ISO 27001:2022 Current Certification Guide | Zeph Tech into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.