ISO/IEC 27001:2022 replaced the 2013 edition on 25 October 2022. The International Accreditation Forum gave certified organisations thirty-six months to transition under IAF MD 26, and the window closed on 31 October 2025. Any certificate that still cites ISO/IEC 27001:2013 has expired or been withdrawn under accredited certification, whatever printed expiry date it carries. This explainer covers what changed, how to read a certificate that claims the new edition, and where public evidence exists at all.
- 96,709
- valid ISO/IEC 27001 certificates worldwide
- ISO Survey 2024, covering 179,877 sites
- 31 Oct 2025
- End of the IAF transition period
- IAF MD 26; 2013-edition certificates expire or are withdrawn
- 93
- Annex A controls in the 2022 edition
- Down from 114 in the 2013 edition
All certificates based on ISO/IEC 27001:2013 shall expire or be withdrawn by the end of the transition period.
What changed in the 2022 edition
The management system clauses changed little: minor alignment with the harmonised structure and a new clause 6.3 on planning of changes. The visible change is Annex A, which follows ISO/IEC 27002:2022. The 114 controls in 14 domains became 93 controls in four themes: organisational, people, physical and technological. Eleven controls are new, including threat intelligence, information security for cloud services, data leakage prevention, monitoring activities, web filtering and secure coding. Twenty-four were merged and fifty-eight updated.
| ISO/IEC 27001:2013 | ISO/IEC 27001:2022 | |
|---|---|---|
| Annex A controls | 114 in 14 domains | 93 in 4 themes |
| New controls | 11, including threat intelligence, cloud services security, data leakage prevention, secure coding | |
| Clause changes | Clause 6.3 planning of changes; harmonised structure alignment | |
| Certification body | Accredited by a national body (UKAS, ANAB, DAkkS and others) | Same; the accreditation symbol on the certificate is the thing to check |
| Status after 31 October 2025 | Expired or withdrawn for accredited purposes | Current |
How to read the certificate
- 1
Edition
It must say ISO/IEC 27001:2022. A 2013 certificate is expired for accredited purposes since 31 October 2025.
- 2
Certification body and accreditation
The CB’s name and the accreditation body’s mark. An unaccredited "certificate" is a consultancy letter. CertReports links certification bodies to their auditor pages.
- 3
Scope statement
The ISMS scope names products, services, locations and sometimes teams. A scope that covers "the corporate IT function" says nothing about the product you buy.
- 4
Sites
Multi-site certificates list the covered locations. Check the one that processes your data.
- 5
Surveillance
A certificate is valid on paper for three years but depends on annual surveillance audits. A lapsed surveillance invalidates it without changing the printed expiry, which is why CertReports reads status and withdrawal separately from the expiry date where a registry provides them.
Why vendor pages lag
Trust centres are often edited by marketing, so a certificate PDF uploaded in 2023 stays online. Badge widgets say "ISO 27001 certified" with no edition, which is never wrong and never useful. Some vendors transitioned but published only the new expiry date and left the old document linked as the evidence. The index still finds 2013 certificates on live trust centres nearly a year after the deadline; the index note has the pattern.
The market behind the certificates
The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates covering 179,877 sites, nearly double the 48,671 reported for 2023. Part of the jump is methodological, since the 2024 survey draws on the IAF CertSearch database directly, but the direction is clear and consistent with a 20 percent compound growth rate across the decade. China holds the largest national count at 33,359. For a buyer the number matters less than the lookup: there is no crawlable global registry, and IAF CertSearch allows individual checks but not bulk access.
- 201936,362
- 202348,671
- 202496,709CertSearch-based count
Where public evidence exists
Because there is no bulk registry, most ISO 27001 evidence on CertReports is vendor-stated (a certificate or badge published by the vendor) or verified by auditor (the certification body confirms it). The edition rule is the one check a buyer can apply to a vendor-published certificate without calling anyone. Browse vendors with public ISO 27001 evidence on the ISO 27001 hub; rows still citing the 2013 edition are flagged expired, and expiring this month lists certificates approaching their printed date.
| What you see | What it means | Ask for |
|---|---|---|
| Badge, no edition | Vendor-stated, unknown edition | The certificate PDF |
| Certificate citing 27001:2013 | Expired for accredited purposes | The 2022 certificate or the transition audit date |
| Certificate citing 27001:2022, scope "corporate IT" | Current, wrong scope | Confirmation the product is in scope, or the product’s own certificate |
| Certificate with sites listed | Current | Confirm the site that processes your data is listed |
| CB confirmation on request | Verified by auditor | Nothing further; note the surveillance date |
What to ask for
The certificate PDF with the edition, scope statement and sites, plus the date of the last surveillance audit. A Statement of Applicability shows which of the 93 controls the vendor applies and why.
People also ask
Are ISO 27001:2013 certificates still valid?
Not under accredited certification. IAF MD 26 required every 2013-edition certificate to transition or be withdrawn by 31 October 2025, regardless of the printed expiry date.
What is the difference between ISO 27001:2013 and 2022?
The 2022 edition restructures Annex A from 114 controls in 14 domains to 93 controls in four themes, adds eleven controls including cloud services security and threat intelligence, and adds clause 6.3 on planning of changes.
How do I verify an ISO 27001 certificate?
Check the edition, the certification body and its accreditation mark, the scope statement and the sites. Confirm with the certification body or through IAF CertSearch, which supports individual lookups but not bulk access.
How long is an ISO 27001 certificate valid?
Three years on paper, with a surveillance audit each year in between. A missed surveillance can invalidate the certificate before its printed expiry.
How many companies are ISO 27001 certified?
The ISO Survey 2024 counted 96,709 valid certificates covering 179,877 sites worldwide, nearly double the prior year’s count partly because the survey now uses the IAF CertSearch database.
Does ISO 27001 certification cover a specific product?
Only if the scope statement says so. Many certificates cover a corporate function or a set of locations; ask for the scope and confirm the product and site that handle your data are in it.
Solomon Amos · Founder, CertReports
Solomon builds CertReports, the public evidence index for vendor security reviews. PhD in machine learning and cybersecurity, two years embedded at HMRC digital programmes, founder of TapTax. He writes about what registries, trust centres and auditors actually publish, and how buyers can use it before the questionnaire goes out.
Read next on CertReports
You might also like
ISO 27001:2013 lapsed on 31 October 2025. Vendor pages have not caught up.
CertReports Research · 16 Sep 2026 · 9 min read