ISO 27001:2022 Certified SECP Registered PEC Licensed PSEB Registered
+92 312 5463398  ·  support@cyberedgetechs.com
Home / Insights / ISO 27001:2022 after the transition deadline: where organisations stand
GRC & ISO Compliance

ISO 27001:2022 after the transition deadline: where organisations stand

The transition window for the 2013 edition closed on 31 October 2025. If your certificate still references the old edition, it is no longer valid — and auditors have changed what they look for.

GRC & ISO Compliance8 July 20266 min read

The transition period from ISO/IEC 27001:2013 to the 2022 edition ended on 31 October 2025. Certificates issued against the 2013 edition ceased to be valid at that point rather than quietly continuing until their printed expiry date. Organisations discovering this in a tender response are discovering it late.

What actually changed in the 2022 edition

The control set was restructured from fourteen clauses into four themes and reduced in number, but the reduction is a consolidation rather than a relaxation. Several genuinely new controls were introduced, and they reflect where incidents were actually occurring: threat intelligence, information security for cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, monitoring activities, web filtering and secure coding.

If your Statement of Applicability was mapped across mechanically from the old edition, those new controls are where an auditor will start.

The audit emphasis has moved to evidence of effect

The clearest shift reported through 2026 is that auditors are less interested in whether a policy exists and more interested in whether a control demonstrably reduces risk. Expect to be asked for measurements rather than documents: time to patch, frequency of access reviews, detection and containment times for incidents, and evidence that management reviewed those numbers and acted.

A policy nobody measures is a document. A control with a metric attached is a management system.

If you have let certification lapse

  • You cannot transition a lapsed certificate. Recertification is a fresh Stage 1 and Stage 2 audit.
  • Plan for the internal audit and management review cycle to be complete before Stage 2 — auditors will ask for the records, and they cannot be produced retrospectively.
  • Check your contracts. Many public and enterprise contracts name certification as a continuing obligation, not a one-off qualification.

Building a system you can actually operate

The most common failure we are called in to fix is an ISMS built by a consultant for an audit rather than for the organisation. It passes, then decays, because nobody internally understands why any of it exists. A management system that survives its second surveillance audit is one where the risk register is owned by people with the authority to act on it, and where the documentation set is small enough to be read.

Sources and further reading

External links, provided for verification. CyberEdge is not responsible for third-party content.