ISO/IEC 27001:2013 certificates expired on October 31, 2025
On October 31, 2025, the transition period from ISO/IEC 27001:2013 to ISO/IEC 27001:2022 ended. Under the International Accreditation Forum’s mandatory document IAF MD 26, every accredited certificate issued against the 2013 edition expired or was withdrawn on that date regardless of the expiry printed on it. The 2022 edition, published October 25, 2022, is now the only edition of the information security management system (ISMS) standard that a certification body can certify against.
This item was added to the change feed when the ISO/IEC 27001 page launched on this site, so followers can see the kind of edition change a subscription covers. It is not a new announcement.
What changed
ISO/IEC 27001:2022 kept the management-system clauses (4 through 10) largely intact and reworked Annex A. The 2013 list of 114 controls in 14 domains became 93 controls in four themes (organizational, people, physical, technological), aligned to ISO/IEC 27002:2022, with 11 new controls covering topics such as threat intelligence, cloud services security, configuration management, data masking, data leakage prevention, monitoring, web filtering, and secure coding. Certified organizations had to update their risk treatment and Statement of Applicability to the new list and pass a transition audit.
A one-line Amendment 1, published February 23, 2024, added climate change to the issues an organization must consider in clauses 4.1 and 4.2. It applies to every 2022 certificate.
IAF MD 26 set the calendar: certification bodies had to begin auditing new and recertifying clients against the 2022 edition no later than April 30, 2024, and complete every transition by October 31, 2025.
What did not change
Certification still comes from an accredited certification body, still runs on a three-year cycle with annual surveillance audits, and still covers only the ISMS scope stated on the certificate. ISO itself still does not certify anyone. Organizations that missed the deadline cannot revive a 2013 certificate; they start a new initial certification (Stage 1 and Stage 2) against the 2022 edition.
What to do now
- If you hold a certificate, confirm it cites ISO/IEC 27001:2022 and check its status in IAF CertSearch. A certificate citing 2013 is no longer valid.
- If you rely on a vendor’s certificate, ask for the current one and read the scope statement and edition, not just the logo.
- Check that your Statement of Applicability uses the 2022 Annex A numbering and that the climate change consideration from Amendment 1 appears in your context review.
- See the ISO/IEC 27001 page for who pursues certification, how accredited certification works, and what to ask whoever is requesting your certificate.
- Follow ISO/IEC 27001 on this site for future amendments, companion-standard editions, and certification-rule changes.
Sources
- IAF MD 26, Transition requirements for ISO/IEC 27001:2022 (Issue 2) (January 15, 2023)
- ISO/IEC 27001:2022 (ISO catalogue) (October 25, 2022)
- ISO/IEC 27001:2022/Amd 1:2024, climate action changes (February 23, 2024)