Author
International Accreditation Forum
1 reading card from 1 book · 2023.
1 card
IAF MD 26:2023 — Transition Requirements for ISO/IEC 27001:2022 · 2023
The 2013 edition no longer exists in audit: 93 controls, clause 6.3 and climate in the context are the starting point.
The transition is over. The mandatory document of the international accreditation forum, IAF MD 26:2023, set a three-year window from the publication of the 2022 edition and said without hedging that certifications on the 2013 edition expire or are withdrawn at its end — 31 October 2025. In 2026 the question is no longer how you transition but what you can show against the current edition. What changed concretely: clause 6.3 requires planning of changes to the system; clause 10 reversed its order, with continual improvement now ahead of nonconformity and corrective action; Annex A went from 114 to 93 controls, restructured into four themes, with eleven new controls, among them threat intelligence, cloud security, configuration management, data masking and secure coding. Amendment 1:2024 added to clauses 4.1 and 4.2 the duty to consider climate change as a relevant issue of the context.
“All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period.”