IAF MD 26:2023 required every ISO/IEC 27001:2013 certificate to transition to the 2022 edition, expire or be withdrawn by 31 October 2025. A vendor page still showing a 2013 certificate in 2026 is showing a lapsed one, whatever the printed expiry says.
Surveillance audits
Certificates run on a three-year cycle with annual surveillance. A missed surveillance audit can suspend or withdraw a certificate without changing the printed expiry, which is why CertReports reads status and withdrawal separately from expiry where a registry provides them.
Scope statements
A certificate covers the scope written on it: named products, sites and processes. Ask for the certificate and check the scope includes the service you are buying.
Verifying a certificate
IAF CertSearch and UKAS CertCheck are lookup-only. Certification bodies such as Coalfire, Schellman and A-LIGN publish client directories or certificate lookups. CertReports upgrades a vendor-stated ISO row to Verified when one of those confirms it.