ISO/IEC 27001:2022 – Information Security, Cybersecurity and Privacy Protection – Information Security Management Systems – has replaced ISO/IEC 27001:2013.
The new standard was published on October 25, 2022. After a three-year transition period, ending October 31, 2025, all ISO/IEC 27001:2013 certifications will expire or should be withdrawn. We will not conduct initial or recertification audits to the old standard after April 30, 2024.
Certificates issued or reissued against ISO/IEC 27001:2013 during the transition period (November 1, 2022, to October 31, 2025) will have October 31, 2025, as their expiration date and not the usual three-year validity. After the transition period, an organization with an expired ISO/IEC 27001:2013 certification will be treated as a new client, subject to a full initial audit.
The transition may be conducted in one of three ways: via special audit, routine surveillance or recertification audit.
ISO/IEC 27001:2022 is not a fully revised edition. Its main changes include, but are not limited to:
Note 1: The first two items come from ISO/IEC 27001:2013/DAmd1 and the third item from ISO/IEC 27001:2013/COR 2:2015. The other changes result from the harmonized structure for MSS.
Note 2: Compared with the old edition, the number of information security controls in ISO/IEC 27002:2022 decreases from 114 controls in 14 clauses to 93 controls in 4 clauses. For the controls in ISO/IEC 27002:2022, 11 controls are new, 24 controls are merged from the existing controls, and 58 controls are updated. Moreover, the control structure is revised, which introduces “attribute” and “purpose” for each control and no longer uses “objective” for a group of controls.
Download our white paper on the key changes.
For further information, please contact:
Paula Costa
Global Technical Product Manager
Information Security Assurance
t: +44 7918 740604
We are SGS – the world’s leading testing, inspection and certification company. We are recognized as the global benchmark for sustainability, quality and integrity. Our 99,600 employees operate a network of 2,600 offices and laboratories around the world.