How to Prepare for ISO/IEC 27001:2022
Published 03/15/2023
Originally published by Schellman.
When it comes to ISO/IEC 27002:2022 recently, it felt a bit like a game of Red Light, Green Light—you know, the childhood game where everyone runs to the finish line upon Green Light being called, but you had to stop on a dime when you heard “Red Light!” and await the next, random declaration of Green so you could move forward again.
On the playground, it was a game of anticipation, and for those of us that were monitoring this standard, it was very similar, at least until recently—ISO/IEC 27002:2022 was released in February 2022, and on October 25, 25, 2022, ISO 27001:2022 was released as well.
Now that the “green light” on these new versions has officially been given, understanding the timeline for the related transition to ISO/IEC 27001:2022 is important for organizations undergoing ISO 27001 certification.
These major updates to standards can make things a bit complicated for you, and that’s why, in this article, we’ll discuss the key takeaways from relevant transition documents so that you know more of what to expect as things move forward with implementation.
What are the ISO/IEC 27001:2022 Transition Requirements?
Leading up to that publication of ISO/IEC 27001:2022, the International Accreditation Form (IAF), published a Mandatory Document (MD) in August 2022 outlining the transition requirements for migrating from ISO/IEC 27001:2013 to ISO/IEC 27001:2022. The document addressed both accreditation bodies (ABs) and accredited certification bodies (also referred to as conformity assessment bodies (CABs)) and was made publicly available on the IAF’s website here.
The following are the main takeaways, which have now been updated and are now based on the transition requirements outlined in IAF MD 26:2023 (issue 2):
Key Takeaways from IAF MD 26:2023 | Details |
New technical updates |
*The above bullets do not represent a comprehensive list of changes but rather those that Schellman believed to be most relevant. For a complete listing of changes from ISO/IEC 27001:2013 to ISO/IEC 27001:2022, please refer to clause 2.2 “key changes” of IAF MD 26:2023) |
Transition period for certified organizations |
So, you can do your recertification review against the ISO/IEC 27001:2013 version of the standard provided that your recertification review is started on or prior to April 29, 2024.You would then need to transition your ISO/IEC 27001:2013 certification to ISO/IEC 27001:2022 on or before October 31, 2025 (as noted below).
|
Transition period for organizations not yet certified |
|
Certification Expiration | All certifications based on ISO/IEC 27001:2013 will expire or be withdrawn at the end of each respective transition period. |
Transition period for accreditation bodies | Accreditation bodies will have 12 months from the last day of the publication month of ISO/IEC 27001:2022 (i.e., a deadline of October 31, 2025) to transition the accreditations of their change advisory boards (CABs), enabling them to perform certification audits of their ISO/IEC 27001:2013 certified clients. |
Transition Audits |
If the transition audit is successfully completed, the certificate document will be updated to reflect conformance with ISO/IEC 27001:2022; however, the expiration date of the current certification cycle will not be changed. |
Learning More About ISO/IEC 27001:2022
Though we’re not on the playground anymore, the green light has been given—now, organizations can and are streaking towards the “finish line” that is a successful transition to the new version of ISO 27001.
Thanks to IAF MD 26:2022 and subsequent updates in IAF MD 26:2023, some transition requirements have been outlined that can help you take any necessary internal steps to prepare.
As you get going in your preparation, make sure you’re all caught up there by reading our other content on the changes contained within the new standard:
Related Articles:
What Are the ISO 42001 Requirements?
Published: 11/25/2024
How Cloud-Native Architectures Reshape Security: SOC2 and Secrets Management
Published: 11/22/2024
It’s Time to Split the CISO Role if We Are to Save It
Published: 11/22/2024
Establishing an Always-Ready State with Continuous Controls Monitoring
Published: 11/21/2024