Skip to main content

ISO/IEC 27001

ISO 27001:2013 certificates lapsed on 31 October 2025

The IAF transition deadline, what it means for certificates still citing the 2013 edition, and how to check scope and surveillance.

Last updated 17 Sep 2026

IAF MD 26:2023 required every ISO/IEC 27001:2013 certificate to transition to the 2022 edition, expire or be withdrawn by 31 October 2025. A vendor page still showing a 2013 certificate in 2026 is showing a lapsed one, whatever the printed expiry says.

Surveillance audits

Certificates run on a three-year cycle with annual surveillance. A missed surveillance audit can suspend or withdraw a certificate without changing the printed expiry, which is why CertReports reads status and withdrawal separately from expiry where a registry provides them.

Scope statements

A certificate covers the scope written on it: named products, sites and processes. Ask for the certificate and check the scope includes the service you are buying.

Verifying a certificate

IAF CertSearch and UKAS CertCheck are lookup-only. Certification bodies such as Coalfire, Schellman and A-LIGN publish client directories or certificate lookups. CertReports upgrades a vendor-stated ISO row to Verified when one of those confirms it.