IAF MD 29 – Transition to ISO/IEC 27006:2024
IAF MD 29 is the most recent IAF publication with implications for certification services in the field of information security to ISO/IEC 27001.
Background: ISO 27006
ISO/IEC 27006:2024 is the central standard defining requirements for bodies that audit and certify information security management systems. Accreditations – such as ours – are granted exclusively in conjunction with the requirements of DIN EN ISO/IEC 27006.
DIN EN ISO/IEC 27006 defines in particular:
- General requirements (e.g. legal and contractual matters)
- Requirements for resources (e.g. the competencies of auditors)
- Requirements for information (e.g. confidentiality)
- Requirements for processes (e.g. audit planning, certification decisions)
- Management system requirements for certification bodies
In addition, corresponding requirements are defined, for example regarding the calculation of audit time, which must be complied with.
IAF MD 29 and DIN EN ISO/IEC 27006
IAF MD 29 now defines requirements for accredited certification bodies as well as for the accreditation bodies (such as DAkkS) governing the changeover from DIN EN ISO/IEC 27006:2021 to ISO/IEC 27006:2024. ISO/IEC 27006:2024 was published in spring 2024. IAF MD 29 defines a transition period of two years, within which all accredited certification bodies must be transitioned to ISO/IEC 27006:2024 by their respective accreditation authority.
What the transition means
The transition to ISO/IEC 27006:2024 initially has no direct effects on certified organisations, as the standard defines requirements for certification and accreditation bodies. Certification bodies must analyse the changes arising from ISO/IEC 27006:2024 and implement them internally. In our case, the compliant implementation of these changes is audited by DAkkS and, if successful, confirmed. Without a transition to ISO/IEC 27006:2024, we would lose our accreditation status at the end of the transition period.
The transition process
The process for such a transition to a new version of a standard is as follows:
- Submission of an application for change to DAkkS for the changeover to ISO/IEC 27006:2024; analysis of the changes (gap analysis) between ISO/IEC 27006:2024 and the previous version of the standard.
- Transition plan with specific deadlines.
- Evidence of the changes to documents made necessary by the transition.
- Technical assessment by a DAkkS auditor, generally by means of a document review.
- Where applicable, an on-site assessment by DAkkS auditors at our offices, if the documentation submitted is not sufficient to demonstrate the transition successfully.
- If the DAkkS assessment is successful, the results are presented to the accreditation committee, which decides on accreditation.
- If the decision is positive, the accreditation certificate is amended. From that point onwards, audits to ISO/IEC 27001 in conjunction with ISO/IEC 27006:2024 may be carried out.
This entry does not claim to cover all individual requirements of IAF MD 29 in full. Rather, it is intended as a summary of the key requirements – particularly from a customer perspective.