Skip to main content

Analysis

ISO 27001:2013 lapsed on 31 October 2025. Vendor pages have not caught up.

The IAF transition deadline passed nearly a year ago. Certificates still citing the 2013 edition are expired for accredited purposes, and the index still finds them on trust centres. Why, and what to ask.

CertReports ResearchPublished 16 Sep 2026Updated 18 Sep 20269 min read

ISO 27001:2013 lapsed on 31 October 2025. Vendor pages have not caught up.

ISO/IEC 27001:2022 replaced the 2013 edition on 25 October 2022. The International Accreditation Forum gave certified organisations three years to transition, and the window closed on 31 October 2025. Any certificate that still cites ISO/IEC 27001:2013 has expired or been withdrawn under accredited certification, whatever printed expiry date it carries. The index applies that rule automatically, and it is one of the most common reasons an ISO row shows as expired. This note is about what the index sees on live vendor pages nearly a year later.

68
Vendors with public ISO 27001 evidence in the index
18 September 2026
24
ISO rows shown as expired
2013 edition or printed expiry passed
96,709
Valid ISO 27001 certificates worldwide
ISO Survey 2024
All certificates based on ISO/IEC 27001:2013 shall expire or be withdrawn by the end of the transition period.

Three ways a 2013 certificate stays online

Trust centres are often edited by marketing rather than by the ISMS owner, so a certificate PDF uploaded in 2023 stays where it was put. Badge widgets from compliance platforms say "ISO 27001 certified" with no edition at all, which is technically never wrong and never useful. And some vendors did transition but published only the new expiry date, leaving the old document as the linked evidence. The index sees all three, and in each case the captured page is what a buyer would find.

Pattern on the pageWhat the index recordsWhat a buyer sees
2013 certificate PDF still linkedVendor-stated, edition 2013, state expiredA certificate that is no longer accredited
Badge with no editionVendor-stated, edition unknownA claim; ask for the certificate
New expiry, old documentVendor-stated, edition 2013, state expiredA mismatch worth one question
2022 certificate with scope and sitesVendor-stated, edition 2022, currentEverything needed except the surveillance date
Printed reports on a desk
The certificate PDF is the evidence. The badge above it is a label. · Photo by Helloquence on Unsplash

What changed in the 2022 edition

20132022
Annex A controls114 in 14 domains93 in 4 themes
New controls11, including threat intelligence, cloud services security, data leakage prevention and secure coding
Transition deadline31 October 2025 (IAF MD 26)
What a buyer should seeNothing; expiredCertificate citing 27001:2022 with scope, sites, CB and accreditation mark

The new controls are the ones buyers of cloud software care about most: information security for use of cloud services, threat intelligence, monitoring activities, data leakage prevention, web filtering and secure coding. A 2013 certificate never tested them. That is the practical reason the edition matters, beyond the accreditation rule.

How the index states ISO 27001

  • Vendor-stated: a certificate or badge published by the vendor, captured with a snapshot, edition recorded when visible.
  • Verified by auditor: the certification body confirms the certificate, its scope and its status.
  • Expired: the printed expiry has passed, the certificate cites the 2013 edition, or a registry reports withdrawal.
  • No public evidence: nothing captured. Not a judgement, and fixable by publishing the certificate.
ISO 27001 rows in the index by state, September 2026
  • Vendor-stated, current26
  • Expired (2013 edition or past printed expiry)24
  • Vendor-stated, edition unknown18

There is no crawlable global registry of ISO certificates, so most rows in the index are vendor-stated. That is exactly why the edition rule matters: it is the one check a buyer can apply to a vendor-published certificate without calling anyone. Browse every vendor with public ISO 27001 evidence on the ISO 27001 hub; the transition explainer covers how to read a certificate line by line.

A padlock on a keyboard
Eleven controls are new in 2022, including cloud services security and data leakage prevention. · Photo by FLY:D on Unsplash

The wider market

The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates worldwide, nearly double the 48,671 reported for 2023, partly because the 2024 survey draws directly on the IAF CertSearch database. Most certified organisations do not publish their certificate; the 68 vendors with public ISO evidence in the index are the ones that do. For a buyer, that is an argument for asking, and for vendors it is an argument for publishing, since a published 2022 certificate with scope and sites turns a "no public evidence" row into a dated one.

What to ask for

  1. 1

    The certificate PDF

    With the edition (must be 27001:2022), the scope statement and the covered sites.

  2. 2

    The certification body and its accreditation

    UKAS, ANAB, DAkkS and peers. An unaccredited certificate is a consultancy letter.

  3. 3

    The last surveillance audit date

    A certificate depends on annual surveillance; a lapsed one invalidates it without changing the printed expiry.

  4. 4

    Optionally, the Statement of Applicability

    It shows which of the 93 controls the vendor applies and why.

Reminder

CertReports never writes "ISO certified" as a state. It records certificate, edition, scope, body and date, each with a source, and flags the 2013 edition as expired.

People also ask

Is an ISO 27001:2013 certificate still valid in 2026?

No. Under IAF MD 26 every 2013-edition certificate had to transition or be withdrawn by 31 October 2025. A 2013 certificate is expired for accredited purposes regardless of its printed date.

Why do vendors still show 2013 certificates?

Trust centres are updated by marketing, badge widgets omit the edition, and some vendors publish a new expiry date without replacing the linked document. None of it is evidence of a current certificate.

How can I tell which edition a certificate is?

The standard is printed on the certificate, for example "ISO/IEC 27001:2022". Badges rarely show it; ask for the PDF.

What happens if a vendor missed the transition?

Its certificate is withdrawn or expired and it must be audited against the 2022 edition to be certified again. Ask for the transition audit date and the new certificate.

How does CertReports know a certificate is expired?

From the printed expiry date, the edition on the captured certificate, or a withdrawal reported by a registry or certification body. Each row shows which applied.

ISO 27001certificatesindexexpirytrust centres
C

CertReports Research · Index and methodology

Notes from the team that runs the nightly registry syncs, the snapshot pipeline and the state resolver. Every figure quoted is reproducible from the index on the date given.

You might also like