Key Information on Certifications and Audits

Revision of ISO/IEC 27019

ISO/IEC 27019 has been revised and has been available in an updated version since 18 October 2024. This standard provides specific security controls for the energy supply industry and is closely interlinked with ISO/IEC 27001 and 27002. Thanks to the adjustments, the need for a mapping to ensure certifications under the IT Security Catalogues will no longer apply in future. Organisations should review the changes in the new standard early and integrate them into existing ISMS.

Revision of ISO 9001 – what it means and the timeline

ISO 9001 is being revised ahead of schedule, with a new version planned for autumn 2026. The aim is to further advance harmonisation with other management systems and to give more concrete form to topics such as quality culture, risk management, and ethics and integrity. The revision process is currently in full swing and initial drafts are already available. ISO 9000 is being adapted in parallel. Organisations should keep an eye on developments in order to be prepared early.

Benefits of certification by an accredited certification body

Certification by an accredited body such as ours offers numerous benefits: from international recognition and increased trust through to meeting regulatory requirements. Our independent, standardised audit processes deliver reliable results and encourage continual improvement. Organisations benefit from greater credibility, market access and a clear competitive advantage.

IAF MD 11 – Audits of integrated management systems to ISO/IEC 17021-1

How can organisations with several management systems – for example for quality and information security – make their audit processes more efficient? The IAF MD 11:2023 guidance provides answers to the key questions on auditing integrated management systems. In our article you will learn exactly what the "degree of integration" is, how it affects audit time, and why a high level of integration can save real money. We show you which requirements conformity assessment bodies must meet, how the audit effort is calculated, and give a concrete worked example for practice. A must for anyone looking to optimise audits and avoid unnecessary duplicate assessments.

Accreditation – IAF, ILAC and DAkkS

Albert Barillé might well have opened with: "Once upon a time …" In this article we look at the background to accreditation, the legal framework in Europe and the major international accreditation organisations IAF and ILAC. What makes an accreditation body independent and impartial? Why is there no competition between the national bodies? We explain the requirements and give you an overview of the most important IAF documents that have a direct influence on audits and certifications. Dive into the world of accreditation and find out how international standards strengthen quality assurance.

IAF MD 1 – Auditing and certification of management systems in multi-site organisations

How does certification work for organisations with multiple sites – and what needs to be considered in multi-site audits? The IAF MD 1:2023 guidance sets out clear requirements, which we examine more closely in this article. From the definition of key terms such as "head office" and "sites", through the requirements for matrix certifications, to the question of when a sampling procedure makes sense and when it does not: we provide a comprehensive overview of the factors that influence audit effort and audit duration. Discover the key prerequisites and find out how best to prepare the certification process for your multi-site organisation. An indispensable guide for organisations looking to structure their certification effort clearly.

IAF MD 2 – Certificate transfers

Would you like to transfer your certification to a new certification body? The IAF MD 2 document governs the prerequisites and requirements to be met when transferring certificates – for example for ISO 9001 or ISO/IEC 27001. In this article you will learn under which conditions a certificate transfer is possible, how the assessment process works, and what to do if certificates cannot be transferred due to particular circumstances. We also examine the role of the issuing and the accepting certification body in the transfer process and what to bear in mind after a successful transfer. An indispensable guide for organisations aiming for a smooth change of certificate.

IAF MD 4 – Use of information and communication technology (ICT) in audits

Digital technologies in audits – yes or no? IAF MD 4:2023 sets out clear rules on how information and communication technology (ICT) can be used for audit purposes and when remote delivery is possible. This article gives you an overview of the fundamental requirements a certification body must meet when audits are carried out using ICT. Find out how virtual sites are defined, which conditions apply to the use of ICT, and how factors such as security, confidentiality and procedural requirements are taken into account. A must for organisations considering ICT for more efficient audits.

IAF MD 26 – Transition from DIN EN ISO/IEC 27001:2017 to ISO/IEC 27001:2022

The transition to the new ISO/IEC 27001:2022 is unavoidable for certified organisations. The IAF MD 26:2023 document defines clear requirements and deadlines to ensure the transition from DIN EN ISO/IEC 27001:2017 to the new standard. Certified organisations have a transition period until 31 October 2025 to maintain their certification. This article summarises the key points of the transition – from the requirements for updating the ISMS and the Statement of Applicability through to the minimum effort involved in the audit. An essential guide for anyone looking to master the changeover successfully.

IAF MD 29 – Transition to ISO/IEC 27006:2024

With the publication of ISO/IEC 27006:2024, certification bodies face an important transition. IAF MD 29 governs the changeover to this new standard for information security management systems and primarily affects certification and accreditation bodies, with no direct impact on certified organisations. Certification bodies such as RSM Certification GmbH have two years to complete the transition, from the gap analysis through to the final audit by DAkkS. Find out here which steps are needed for a successful transition to ISO/IEC 27006:2024.