Key Takeaways
- The ISO 27001:2022 transition deadline was 31 October 2025, set by IAF MD 26:2023. Every 2013-edition certificate not transitioned by then has expired or been withdrawn.
- A lapsed 2013 certificate cannot be rescued with a transition audit. Certification bodies treat the holder as a new client, which means a full Stage 1 and Stage 2 initial audit.
- Annex A went from 114 controls in 14 clauses to 93 controls in four themes. Of the 93, 11 are new, 24 were merged and 58 were updated.
- No regulator fines a lapsed certificate. The cost lands in tenders and contracts that depend on a valid one.
- ISO 27001 does not by itself meet NIS2. The Article 23 reporting clock of 24 hours, 72 hours and one month has no counterpart in the standard.
The Certificate in Your Tender Pack Stopped Counting on 31 October 2025
Somewhere in your tender library there is probably a certificate that still says ISO/IEC 27001:2013. If it was not transitioned to the 2022 edition before 31 October 2025, it no longer certifies anything. That date ended a 36-month transition set by the International Accreditation Forum (IAF) and the ISO 27001:2022 transition deadline did not move. It matters to whoever owns the certificate and just as much to the sales and procurement teams who rely on it.
The reason is a mismatch between how certificates are read and how they are governed. For years an ISO 27001 certificate was a three-year document renewed through a recertification audit so most people check only the printed expiry date. The 2022 revision overrode that habit. Under IAF MD 26:2023 every certification based on the 2013 edition had to expire or be withdrawn when the transition ended, whatever its cycle said. The question is no longer when your certificate expires but which edition it names.
What is the ISO 27001:2022 Transition Deadline?
The ISO 27001:2022 transition deadline is 31 October 2025, the date by which every organisation certified to ISO/IEC 27001:2013 had to complete a transition to the 2022 edition. It was set by IAF MD 26:2023, the mandatory transition document for accredited certification bodies. Certificates not transitioned by then expired or were withdrawn.
ISO published the 2022 edition on 25 October 2022. From 30 April 2024 certification bodies could run initial and recertification audits against the 2022 edition only. Organisations already certified to 2013 could transition during a surveillance audit, a recertification audit or a separate audit, provided it finished in time.
A worked example shows how this caught people out. A company recertified to the 2013 edition in March 2024 would normally have held its certificate until March 2027. Certification bodies instead issued such certificates with a 31 October 2025 expiry. Skip the transition audit and the certificate lapsed with 17 months of its usual cycle unused.
The Dates That Bound the Transition
| 25 October 2022 | ISO publishes ISO/IEC 27001:2022 and the 36-month transition period begins. |
| 23 February 2024 | Amendment 1 adds climate change to clauses 4.1 and 4.2 of the 2022 edition. |
| 30 April 2024 | Initial and recertification audits must be against the 2022 edition only. |
| 31 October 2025 | The transition period ends. All 2013-edition certifications expire or are withdrawn. |
Is Your ISO 27001 Certificate Still Valid?
Start with the edition named on the certificate. Then confirm the status with the certification body because a withdrawn certificate can keep circulating as a PDF long after the body’s records have changed. MD 26 binds accredited certification bodies only. For accredited certificates three positions cover almost everyone.
Where Your Certificate Stands Today
- Transitioned in Time : A certificate moved to ISO/IEC 27001:2022 before 31 October 2025 is valid with its original expiry date.
- Certified After April 2024 : Every initial certification or recertification from 30 April 2024 was against the 2022 edition, so it is current.
- Still Naming 2013 : Expired or withdrawn, whatever date is printed on it. You are not certified until you pass a new initial audit.
ISO 27001 2013 vs 2022: What Actually Changed
The management system clauses changed less than many expected. Clause 4.2 now requires you to determine which requirements of interested parties the ISMS will address. A new clause 6.3 requires changes to the ISMS to be planned. Clause 8.1 now refers to externally provided processes, products or services. Clauses 9.2 and 9.3 were reorganised into named subclauses.
Annex A is where the work is. The 2013 edition held 114 controls in 14 clauses. The 2022 edition holds 93 controls in four themes which are organisational (37), people (8), physical (14) and technological (34). Of the 93, 11 are new, 24 were merged from older controls and 58 were updated.
Amendment 1, published on 23 February 2024, adds a requirement to clause 4.1 to determine whether climate change is a relevant issue plus a matching note in clause 4.2. Expect an auditor to ask how you reached that determination.
The 11 New Annex A Controls and the Risks Behind Them
Each new control answers a way organisations have been hurt since 2013. They are also where a lapsed certificate holder is most likely to have gaps because nothing in the 2013 Annex A asked for them by name.
One detail is often misstated. The new development control is 8.28 secure coding. A secure development life cycle control already existed in 2013 and carried over as 8.25.
The 11 New Controls in Annex A
- 5.7 Threat Intelligence : Collect and analyse threat information so defences track real attacker behaviour.
- 5.23 Cloud Services : Set security requirements for acquiring, using, managing and exiting cloud services.
- 5.30 ICT Readiness : Plan and test ICT continuity against business continuity objectives.
- 7.4 Physical Monitoring : Monitor premises continuously for unauthorised physical access.
- 8.9 Configuration Management : Define, document and monitor secure configurations.
- 8.10 Information Deletion : Delete information once it is no longer needed.
- 8.11 Data Masking : Mask sensitive data where full values are not needed.
- 8.12 Data Leakage Prevention : Detect and stop unauthorised disclosure of sensitive information.
- 8.16 Monitoring Activities : Watch networks, systems and applications for anomalous behaviour.
- 8.23 Web Filtering : Manage access to external websites to cut exposure to malicious content.
- 8.28 Secure Coding : Apply secure coding principles to software development.
How to Get Back to a Valid Certificate
There is no late transition. Under IAF MD 26 a transition audit added as little as half an auditor day to a recertification audit. That option ended with the transition period. Certification bodies’ published policies now treat a holder whose 2013 certificate has lapsed as a new client which means a full initial audit in two stages.
Most of the time goes into the gap analysis. A well-run 2013 ISMS will already cover most of the 58 updated controls. The 11 new ones are where evidence is most likely to be missing.
The Route Back, Step by Step
| Gap Analysis | Compare your ISMS against the 2022 clauses and all 93 Annex A controls. |
| Statement of Applicability | Rebuild it against the 2022 Annex A with a justification for every inclusion and exclusion. |
| Risk Treatment | Update the risk assessment and treatment plan including the clause 4.1 climate determination. |
| Operate and Evidence | Run the new controls long enough to produce records since Stage 2 tests whether controls work. |
| Internal Audit and Review | Complete both against the 2022 edition before booking Stage 1. |
| Stage 1 and Stage 2 | Stage 1 reviews readiness and documentation. Stage 2 assesses implementation. A pass starts a new three-year cycle. |
What a Lapsed Certificate Actually Costs
No regulator fines an organisation for letting an ISO 27001 certificate lapse because certification is voluntary. The costs arrive through contracts. Tenders and supplier questionnaires that ask for a valid certificate become ones you cannot answer truthfully. A customer agreement that commits you to maintaining certification may already be in breach.
Continuing to present the old certificate is the larger risk. A withdrawn certificate still sitting in a sales deck or on a trust page reads as a misrepresentation that a customer’s due diligence can check in minutes.
Where Fines Do Apply
If you are in scope of NIS2, fines attach to the security measures, not to the certificate. Article 34 of the NIS2 Directive sets maximum fines of at least EUR 10 million or 2% of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4% for important entities, whichever is higher in each case.
Does ISO 27001 Cover NIS2?
Partly, and the part it misses is the part with a clock. NIS2 Article 21(2) lists ten risk-management measures and many correspond to ISO 27001 controls. ENISA’s Technical Implementation Guidance, published on 26 June 2025, maps the requirements of Implementing Regulation (EU) 2024/2690 to ISO/IEC 27001:2022 and other frameworks. A mapping shows where controls correspond. It does not say a certificate satisfies the law.
Two obligations sit outside the standard. Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours and a final report within one month. Article 20 requires management bodies to approve the measures, oversee them and take part in training. Percentage figures for how much of Article 21 ISO 27001 covers circulate widely but none we found traces to a published method.
ISO 27001 and Cybersäkerhetslagen
Sweden’s Cybersäkerhetslagen which implements NIS2, entered into force on 15 January 2026. For an in-scope Swedish organisation a valid ISO 27001:2022 certificate is useful evidence of systematic risk management while a lapsed 2013 certificate is evidence of nothing. The gap analysis you run to certify again is the natural place to add the NIS2 items the standard does not reach.
How to Keep the 2022 Certificate Valid
Once you are back, surveillance audits take place at least once a year between recertifications. Fix the habit that let a 2013 certificate lapse unnoticed by putting the edition and the certificate status on the management review agenda.
Control 8.8 deserves particular attention. It requires that information about technical vulnerabilities is obtained, your exposure evaluated and appropriate measures taken. No Annex A control names penetration testing, so the standard does not strictly require one. In practice an auditor will ask how you know your exposure. Periodic penetration testing alongside vulnerability scanning is the clearest answer. Control 8.29 adds security testing during development and acceptance.
Check the Edition Before the Next Tender Does
The transition period closed on 31 October 2025 and it will not reopen. If your certificate names the 2013 edition, stop presenting it and tell the customers whose contracts depend on it. Then book a gap analysis against the 2022 edition this quarter. The route back is a full initial audit, so start it before a customer asks.
Frequently Asked Questions
Is my ISO 27001 certificate still valid?
Only if it names ISO/IEC 27001:2022. Under IAF MD 26:2023 every certificate based on the 2013 edition had to expire or be withdrawn when the transition period ended on 31 October 2025. The printed expiry date does not override that rule. Check the edition first, then confirm the status with your certification body.
Can we still do a transition audit?
No. Transition audits were available only until 31 October 2025 and existed to move a valid 2013 certificate onto the 2022 edition. Once a 2013 certificate has lapsed, certification bodies treat the organisation as a new client. That means a full initial audit in two stages, Stage 1 for readiness and Stage 2 for implementation.
Does ISO 27001 cover NIS2?
Not fully. ISO 27001 controls correspond to many of the ten NIS2 Article 21 measures. ENISA maps its NIS2 guidance to ISO/IEC 27001:2022. The standard has no equivalent of the Article 23 reporting clock of 24 hours, 72 hours and one month. Nor does it match the management duties in Article 20.
Does ISO 27001 require penetration testing?
Not by name. No Annex A control mentions penetration testing. Control 8.8 requires you to obtain information about technical vulnerabilities, evaluate your exposure and act on it. Control 8.29 covers security testing in development. Auditors will ask how you evidence both. Penetration testing is the clearest way to answer.
eBuilder Security offers CISO-as-a-Service for ISO 27001 gap analysis and audit preparation. Its Penetration Testing service covers vulnerability evidence for control 8.8.
This post is also available in:


