ISO/IEC 27001:2022 replaced the 2013 edition on 25 October 2022. The International Accreditation Forum gave certified organisations three years to transition, and the window closed on 31 October 2025. Any certificate that still cites ISO/IEC 27001:2013 has expired or been withdrawn under accredited certification, whatever printed expiry date it carries. The index applies that rule automatically, and it is one of the most common reasons an ISO row shows as expired. This note is about what the index sees on live vendor pages nearly a year later.
- 68
- Vendors with public ISO 27001 evidence in the index
- 18 September 2026
- 24
- ISO rows shown as expired
- 2013 edition or printed expiry passed
- 96,709
- Valid ISO 27001 certificates worldwide
- ISO Survey 2024
All certificates based on ISO/IEC 27001:2013 shall expire or be withdrawn by the end of the transition period.
Three ways a 2013 certificate stays online
Trust centres are often edited by marketing rather than by the ISMS owner, so a certificate PDF uploaded in 2023 stays where it was put. Badge widgets from compliance platforms say "ISO 27001 certified" with no edition at all, which is technically never wrong and never useful. And some vendors did transition but published only the new expiry date, leaving the old document as the linked evidence. The index sees all three, and in each case the captured page is what a buyer would find.
| Pattern on the page | What the index records | What a buyer sees |
|---|---|---|
| 2013 certificate PDF still linked | Vendor-stated, edition 2013, state expired | A certificate that is no longer accredited |
| Badge with no edition | Vendor-stated, edition unknown | A claim; ask for the certificate |
| New expiry, old document | Vendor-stated, edition 2013, state expired | A mismatch worth one question |
| 2022 certificate with scope and sites | Vendor-stated, edition 2022, current | Everything needed except the surveillance date |
What changed in the 2022 edition
| 2013 | 2022 | |
|---|---|---|
| Annex A controls | 114 in 14 domains | 93 in 4 themes |
| New controls | 11, including threat intelligence, cloud services security, data leakage prevention and secure coding | |
| Transition deadline | 31 October 2025 (IAF MD 26) | |
| What a buyer should see | Nothing; expired | Certificate citing 27001:2022 with scope, sites, CB and accreditation mark |
The new controls are the ones buyers of cloud software care about most: information security for use of cloud services, threat intelligence, monitoring activities, data leakage prevention, web filtering and secure coding. A 2013 certificate never tested them. That is the practical reason the edition matters, beyond the accreditation rule.
How the index states ISO 27001
- Vendor-stated: a certificate or badge published by the vendor, captured with a snapshot, edition recorded when visible.
- Verified by auditor: the certification body confirms the certificate, its scope and its status.
- Expired: the printed expiry has passed, the certificate cites the 2013 edition, or a registry reports withdrawal.
- No public evidence: nothing captured. Not a judgement, and fixable by publishing the certificate.
- Vendor-stated, current26
- Expired (2013 edition or past printed expiry)24
- Vendor-stated, edition unknown18
There is no crawlable global registry of ISO certificates, so most rows in the index are vendor-stated. That is exactly why the edition rule matters: it is the one check a buyer can apply to a vendor-published certificate without calling anyone. Browse every vendor with public ISO 27001 evidence on the ISO 27001 hub; the transition explainer covers how to read a certificate line by line.
The wider market
The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates worldwide, nearly double the 48,671 reported for 2023, partly because the 2024 survey draws directly on the IAF CertSearch database. Most certified organisations do not publish their certificate; the 68 vendors with public ISO evidence in the index are the ones that do. For a buyer, that is an argument for asking, and for vendors it is an argument for publishing, since a published 2022 certificate with scope and sites turns a "no public evidence" row into a dated one.
What to ask for
- 1
The certificate PDF
With the edition (must be 27001:2022), the scope statement and the covered sites.
- 2
The certification body and its accreditation
UKAS, ANAB, DAkkS and peers. An unaccredited certificate is a consultancy letter.
- 3
The last surveillance audit date
A certificate depends on annual surveillance; a lapsed one invalidates it without changing the printed expiry.
- 4
Optionally, the Statement of Applicability
It shows which of the 93 controls the vendor applies and why.
Reminder
CertReports never writes "ISO certified" as a state. It records certificate, edition, scope, body and date, each with a source, and flags the 2013 edition as expired.
People also ask
Is an ISO 27001:2013 certificate still valid in 2026?
No. Under IAF MD 26 every 2013-edition certificate had to transition or be withdrawn by 31 October 2025. A 2013 certificate is expired for accredited purposes regardless of its printed date.
Why do vendors still show 2013 certificates?
Trust centres are updated by marketing, badge widgets omit the edition, and some vendors publish a new expiry date without replacing the linked document. None of it is evidence of a current certificate.
How can I tell which edition a certificate is?
The standard is printed on the certificate, for example "ISO/IEC 27001:2022". Badges rarely show it; ask for the PDF.
What happens if a vendor missed the transition?
Its certificate is withdrawn or expired and it must be audited against the 2022 edition to be certified again. Ask for the transition audit date and the new certificate.
How does CertReports know a certificate is expired?
From the printed expiry date, the edition on the captured certificate, or a withdrawal reported by a registry or certification body. Each row shows which applied.
CertReports Research · Index and methodology
Notes from the team that runs the nightly registry syncs, the snapshot pipeline and the state resolver. Every figure quoted is reproducible from the index on the date given.
Read next on CertReports
You might also like
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read
ISO 27001:2013 to 2022: what the transition deadline means for vendor certificates
Solomon Amos · 1 Sep 2026 · 10 min read
Three quarters of the Visa registry is not a PCI DSS validation
CertReports Research · 17 Sep 2026 · 10 min read