Breakdown · ISO 27001
ISO 27001:2022 after the transition: what the auditor checks
The transition period to ISO/IEC 27001:2022 is closed. What changed compared with 2013, the 93 controls of Annex A, and what the auditor now looks at.
By Sentrix · Published 2026-09-20
The transition to ISO/IEC 27001:2022 has been over for almost a year. Certified organizations have updated their statement of applicability, certification bodies have redone their checklists, and auditors have stopped asking "where are you with the new version". What remains is a set of requirements that now apply without a grace period, and a practical question: what does the auditor check, concretely, in a surveillance or recertification audit in 2026.
What the IAF and accreditation bodies say
IAF MD 26:2023, which set the transition rules for accreditation and certification bodies, recalls that ISO published ISO/IEC 27001:2022 on 25 October 2022 and that the transition period was three years. Certification bodies had to audit only against the 2022 version for any initial certification and any recertification from 30 April 2024, and complete the transition of all their clients by 31 October 2025 at the latest. At the end of the period, all certifications based on ISO/IEC 27001:2013 expired or were withdrawn. The UKAS technical bulletin gives the same dates.
On substance, IAF MD 26 summarizes the changes. Annex A now refers to the controls of ISO/IEC 27002:2022: the number of controls goes from one hundred and fourteen in fourteen sections to ninety-three in four sections, with eleven new controls, twenty-four merged from existing controls and fifty-eight updated. The structure of the controls changes too: each control receives a purpose and attributes, and the objectives per group disappear. In the body of the standard, the IAF notes the addition of item 4.2 c) on the requirements of interested parties addressed through the management system, the new subclause 6.3 on planning of changes, the replacement of "outsourced processes" with "externally provided processes, products or services" in clause 8.1, and the reorganization of clauses 9.2 and 9.3.
The same document describes what the transition audit had to cover: the gap analysis, the update of the statement of applicability, the update of the risk treatment plan if applicable, and the implementation and effectiveness of the new or changed controls chosen by the client. It specifies that the audit cannot rely only on document review, especially for technological controls. Finally, in May 2024 the IAF published MD 29 for the transition of certification bodies to ISO/IEC 27006-1:2024, whose annex is aligned with Annex A of the 2022 version, with a full deadline of 31 March 2026.
Why it matters
The end of the transition changes the nature of nonconformities. During the period, a statement of applicability still numbered according to 2013 or a new control "being implemented" was treated as a transition item. Today, it is an ordinary nonconformity, with an action plan and a deadline.
The eleven new controls are the ones that cause the most trouble, because they require operating evidence rather than policies: threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28). An auditor trained on 27006-1:2024 knows it must see these controls working.
The other point is the supply chain. A 2013 certificate at a service provider has had no value since 31 October 2025. Supplier registers that have not been reread since then probably contain expired certificates.
What we think at Sentrix
An audit under the 2022 regime is prepared with operating evidence, not with a rereading of policies.
- Reread the statement of applicability control by control: for each of the 93, a justification, an owner and a dated piece of evidence. The 2013 to 2022 mergers often leave justifications that no longer match the control.
- Redo the clause 6.1.3 c) comparison between the necessary controls from the risk assessment and Annex A, then update the risk treatment plan if a necessary control is missing. This is exactly the process IAF MD 26 describes.
- Prepare a demonstration for each new technological control: threat intelligence log, baseline configuration, execution of a deletion, data leakage prevention rule, monitoring dashboard. A dated screenshot is worth more than a procedure.
- Document clause 6.3: the year's changes to the management system (new tool, new cloud region, reorganization) with their impact assessment.
- Purge 2013 certificates from the supplier register and ask for the 2022 version, noting the expiry date. The third-party risk module of the Sentrix platform tracks these deadlines.
- Use the compliance calendar to tie each piece of evidence to its frequency, so that the surveillance audit finds evidence from this year, not from the last audit.
The next step
Open your statement of applicability and look for the eleven new controls. For each, ask yourself which piece of evidence dated less than a year ago you would show tomorrow. Our ISO 27001 guide details each clause, and our ISO 27001 compliance service supports audit preparation. To talk about it, write to us.
Sources
Frequently asked questions
- What happened to ISO 27001:2013 certificates?
- According to IAF MD 26, the transition period lasted three years from the publication of the standard on 25 October 2022 and ended on 31 October 2025. On that date, all certifications based on ISO/IEC 27001:2013 expired or were withdrawn. A 2013 certificate still displayed on a supplier's website is therefore no longer valid, whatever expiry date is printed on it.
- How many controls does Annex A of the 2022 version contain?
- Ninety-three, grouped into four themes, against one hundred and fourteen controls in fourteen sections in the 2013 version, according to IAF MD 26. Among them, eleven controls are new, twenty-four result from merging existing controls and fifty-eight have been updated. Each control now carries a purpose and attributes, and the notion of an objective per group of controls disappears.
- What does the auditor look at now that the transition is over?
- The same things it had to verify during the transition audit, but as the permanent regime: the statement of applicability aligned with the 93 controls, the risk treatment plan, and above all the implementation and effectiveness of the new or changed controls. IAF MD 26 specifies that document review is not enough for technological controls. Expect demonstrations, not policies.
Let's talk about your compliance program.
Last updated: 2026-09-20
