← Back to Insights Information Security

ISO/IEC 27001:2022 Transition: What Certified Organisations Must Know Before October 2025

Share
LinkedIn X
ISO/IEC 27001:2022 Transition: What Certified Organisations Must Know Before October 2025

At a Glance

The publication of ISO/IEC 27001:2022 marked the first major revision to the information security management standard in nearly a decade. For the approximately 70,000 organisations worldwide holding current 27001 certification, the transition is not optional. It is a regulatory imperative.

Understanding the Structural Changes

The most visible change is the restructuring of Annex A. The previous 114 controls organised across 14 clauses have been consolidated into 93 controls within four thematic categories. This is not merely a cosmetic reorganisation. It reflects a fundamental shift in how the standard addresses modern security landscapes.

Organisations that have built their Statement of Applicability around the 2013 structure will need to map their existing controls to the new framework. This mapping exercise, while methodical, often reveals gaps in areas such as threat intelligence gathering, information security for cloud services, and ICT readiness for business continuity.

The Transition Timeline

Certification bodies have been conducting transition audits since the revision's publication. However, the pace of adoption has varied considerably across sectors and geographies. Financial services and technology firms have generally moved quickly, driven by regulatory pressure and supply chain requirements. Manufacturing and construction sectors have been slower to engage.

The International Accreditation Forum has established a clear deadline: all existing 2013 certificates will become invalid after 31 October 2025. Organisations that have not completed their transition by this date will effectively lose their certification status.

Practical Recommendations

Based on our experience auditing transitions across multiple sectors, we recommend the following approach: