IAF MD 26 – Transition from DIN EN ISO/IEC 27001:2017 to ISO/IEC 27001:2022

The publication of ISO/IEC 27001:2022 has meant, and continues to mean, that organisations already certified have had to carry out a transition to ISO/IEC 27001:2022.

For the transition process to ISO/IEC 27001:2022, the IAF defined requirements in MD 26:2023 which both the accreditation bodies (such as the German Accreditation Body, DAkkS) and the certification bodies (such as RSM Certification GmbH) must follow.

The changeover took place in a two-stage procedure. In the first step, certification bodies accredited by DAkkS had to undergo an audit by DAkkS in order to obtain new or renewed accreditation for ISO/IEC 27001:2022. This process had to be completed by October 2023.

For the process of transitioning issued certificates to ISO/IEC 27001:2022, the timeframe for organisations already certified and those newly to be certified also derives from IAF MD 26:2023. In brief, the following was established:

  • The transition phase is three years from the publication of ISO/IEC 27001:2022 (i.e. 24 October 2025).
  • From November 2023, initial certifications and recertifications may be carried out exclusively to ISO/IEC 27001:2022.
  • Organisations already certified to DIN EN ISO/IEC 27001:2017-06 must complete the transition to ISO/IEC 27001:2022 by 31 October 2025 at the latest if the certificate is to be maintained.
  • The transition can take place in conjunction with a surveillance audit, a recertification audit, or in a separate audit (hereinafter only the word "audit" is used).
  • The audit must not rely solely on a document review, particularly for verifying the technical controls.
  • The audit covers, among other things:
    • the gap analysis against ISO/IEC 27001:2022 and the need for changes to the ISMS,
    • updating the Statement of Applicability (SoA),
    • where applicable, updating the risk treatment plan,
    • the implementation and effectiveness of the new or amended controls selected by the client.
  • The audit can be carried out remotely, provided it can be ensured that the objectives of the audit are achieved.
  • Regardless of the audit format (surveillance audit, recertification audit, separate audit), IAF MD 26:2023 gives rise to additional minimum effort incurred by RSM Certification GmbH, which must be charged.
  • On completion of the audit, the certification documents are updated. If the audit is carried out as a separate audit and therefore only the transition was assessed, the schedule of the current certification cycle is not changed.

Surveillance audits may still be carried out to DIN EN ISO/IEC 27001:2017 until 31 October 2025, and must be completed by then.

This entry does not claim to cover all individual requirements of IAF MD 26:2023 in full. Rather, it is intended as a summary of the key requirements – particularly from a customer perspective.

Go back