ISO/IEC 27001:2013 certificates are no longer valid
The transition period ended on 31 October 2025. Organisations still holding 2013-version certificates now require initial certification against ISO/IEC 27001:2022.
The transition period for ISO/IEC 27001:2013 ended on 31 October 2025. Certificates issued against the 2013 version are withdrawn and are no longer recognised under the IAF Multilateral Recognition Arrangement.
Organisations that completed transition before the deadline hold valid 2022-version certificates and are unaffected. Organisations that did not now require initial certification rather than a transition audit — the reduced-effort transition route is closed.