ISO 27001: What Changed in 2026? 

ISO 27001 “What Changed in 2026?” graphic showing a central gateway surrounded by flying document and system icons, symbolizing updates, transitions, and evolving ISMS requirements.

Updated:

August 30, 2026

Table of Contents

    ISO 27001 has changed in recent years, but there is no new ISO 27001:2026 edition. Organizations pursuing or maintaining certification in 2026 must follow ISO 27001:2022 and its 2024 climate action amendment.

    The latest available data shows continued global interest in the standard. The ISO Survey 2024 reported 96,709 valid ISO 27001 certificates covering 179,877 sites.

    However, ISO changed its survey method and used aggregated IAF CertSearch data instead of voluntary submissions from certification bodies.

    The increase from 47,291 certificates in the 2023 survey therefore reflects broader reporting coverage as well as actual certification growth.

    This guide explains the ISO 27001 requirements that apply in 2026, the recent changes organizations need to address, and the practical steps required to maintain or pursue certification.

    What Are the Key ISO 27001 Takeaways for 2026?

    ISO 27001 work in 2026 centers on the 2022 edition, Amendment 1:2024, the completed 2013 transition, and current certification arrangements. Annex A contains 93 controls across four themes, Clause 6.3 governs planned ISMS changes, and accredited certification now sits within the Global ACI mutual recognition system after the January 2026 accreditation merger.

    • ISO 27001:2022 remains the current requirements standard for certification in 2026.
    • ISO 27001:2022/Amd 1:2024 adds climate-related text to Clauses 4.1 and 4.2.
    • The ISO 27001:2013 transition period ended on October 31, 2025.
    • Annex A contains 93 controls across four themes, compared with 114 controls across 14 groups in the 2013 edition.
    • The 2022 control set contains 11 new controls, 24 controls formed through mergers, and 58 updated controls.
    • Clause 6.3 requires changes to the ISMS to be carried out in a planned manner.
    • The ISO 27006-1:2024 transition for accreditation bodies and certification bodies ended on March 31, 2026.
    • Global ACI began full operations on January 1, 2026 and replaced IAF and ILAC at the international accreditation-cooperation level.
    • ISO 27000:2026 was published on July 3, 2026 as an overview standard and does not replace ISO 27001.

    What Is the Difference Between ISO 27001:2013 and ISO 27001:2022?

    ISO 27001:2022 retains the risk-based ISMS model while revising Annex A and several management-system requirements. The largest visible change is the move from 114 controls in 14 groups to 93 controls in four themes. The edition adds Clause 6.3, revises Clause 6.1.3 wording, and updates the harmonized management-system structure.

    Comparison of ISO 27001:2013 and 2022, showing 114 vs. 93 Annex A controls, new four-theme grouping, control updates, Clause 6.3 planning, structure changes, and the 2025 transition.
    ISO 270012013 vs. ISO 270012022

    The 2022 edition was published on October 25, 2022. Historical transition requirements gave certified organizations until October 31, 2025 to move from the 2013 edition to the 2022 edition. Accredited ISO 27001:2013 certifications were required to expire or be withdrawn at the end of that transition period.

    How Did Annex A Change in ISO 27001:2022?

    Annex A changed from 114 controls in 14 groups to 93 controls organized under four themes. The revision consolidates related controls and adds distinct controls for current security needs such as threat intelligence, cloud services, data masking, data leakage prevention, monitoring, configuration management, ICT continuity, web filtering, and secure coding.

    ISO 27001 Annex A has four control themes: Organizational with 37 controls, People with 8, Physical with 14, and Technological with 34.
    The Four ISO 27001 Annex A Control Themes

    The 2022 set contains 11 new controls, 24 controls created through mergers of earlier controls, and 58 updated controls. The lower total results from consolidation and restructuring of the reference control set.

    Are All 93 Annex A Controls Mandatory?

    No. The certifiable requirements sit in Clauses 4 through 10. Clause 6.1.3 requires the organization to determine necessary information security controls for risk treatment, compare those controls with Annex A so necessary controls are not omitted, and produce a Statement of Applicability that records the necessary controls and their implementation status.

    ISO 27001 Annex A graphic explaining that all 93 controls are not mandatory; organizations select controls based on risk and document applicability, exclusions, and status in the SoA.
    Are All 93 Annex A Controls Mandatory

    Annex A therefore functions as a reference control set. An organization can use controls outside Annex A when its risk treatment requires them. Controls from Annex A can be excluded when they are not necessary, with the Statement of Applicability recording the relevant justification and status.

    What Are the 11 New Controls in ISO 27001:2022?

    ISO 27001:2022 introduced 11 distinct Annex A controls for security areas that received new or expanded attention in the revised reference set. They cover threat intelligence, cloud services, ICT continuity, physical monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

    The following are the 11 new Annex A controls in ISO 27001:2022: 

    • A.5.7 Threat Intelligence: Collects and analyzes information about relevant current and emerging threats. Evidence may include threat advisories, threat-feed review records, risk updates, and related security actions.
    • A.5.23 Information Security for Use of Cloud Services: Covers security governance across the acquisition, use, management, and termination of cloud services. Evidence may include cloud security policies, shared-responsibility records, supplier terms, configuration standards, and offboarding procedures.
    • A.5.30 ICT Readiness for Business Continuity: Supports business continuity and recovery through ICT preparedness. Evidence may include business impact analyses, recovery procedures, recovery objectives, test results, and dependency records.
    • A.7.4 Physical Security Monitoring: Monitors premises and sensitive physical areas for unauthorized activity. Evidence may include CCTV procedures, alarm procedures, access-monitoring records, retention settings, and incident follow-up records.
    • A.8.9 Configuration Management: Covers secure configurations for hardware, software, services, and networks throughout their life cycles. Evidence may include configuration baselines, hardening standards, change records, configuration scans, and exception approvals.
    • A.8.10 Information Deletion: Requires information to be deleted when retention is no longer necessary. Evidence may include retention schedules, deletion procedures, disposal records, platform settings, and deletion verification.
    • A.8.11 Data Masking: Protects sensitive data through masking, tokenization, redaction, or similar methods. Evidence may include masking rules, test-data procedures, access restrictions, tokenization settings, and application configurations.
    • A.8.12 Data Leakage Prevention: Reduces unauthorized disclosure or extraction of sensitive information. Evidence may include DLP policies, email or endpoint rules, cloud DLP settings, alert records, and incident tickets.
    • A.8.16 Monitoring Activities: Monitors networks, systems, and applications for anomalous or suspicious activity. Evidence may include SIEM configurations, alert rules, review records, monitoring procedures, and incident escalation records.
    • A.8.23 Web Filtering: Restricts access to malicious or prohibited web resources. Evidence may include DNS filtering, secure web gateway policies, category rules, block logs, and exception approvals.
    • A.8.28 Secure Coding: Applies security practices throughout software coding and development activities. Evidence may include secure coding standards, code-review records, SAST results, dependency-scan results, developer training, and remediation tickets.

    Organizations should assess each control against current information security risks and the controls needed for treatment. Applicability belongs in the Statement of Applicability, while implementation evidence should match the organization’s selected controls, operating model, technology, suppliers, and risk treatment decisions.

    What Changed in the Core ISMS Requirements?

    ISO 27001:2022 kept the risk-based ISMS model while adding Clause 6.3 and revising Clause 6.1.3. It also added Clause 4.2(c), updated wording for documented information and externally provided processes, products, and services, and reorganized parts of Clauses 9 and 10.

    ISO 27001 core ISMS changes: Clause 6.3 adds planned changes, 6.1.3 revises risk treatment, 4.2(c) adds interested-party requirements, with documentation and Clauses 9–10 reorganized.
    What Changed in the Core ISMS Requirements

    Clause 6.3: Planning of Changes

    Clause 6.3 requires changes to the ISMS to be carried out in a planned manner. Organizations should apply this requirement when material changes affect the ISMS, including changes to scope, technology, suppliers, organizational structure, risk treatment, security processes, or other elements that can affect information security management.

    A planned change process should define the change, responsibility, timing, dependencies, expected effects, required resources, related risk decisions, documentation updates, and follow-up activities that are appropriate for the organization.

    What Does the 2024 ISO 27001 Climate Amendment Require?

    ISO 27001:2022/Amd 1:2024 adds climate action text to Clauses 4.1 and 4.2. Clause 4.1 requires the organization to determine whether climate change is a relevant issue. Clause 4.2 adds a note that relevant interested parties can have requirements related to climate change. The amendment was published on February 23, 2024.

    ISO 27001 climate amendment requirements: Clause 4.1 assesses whether climate change affects the ISMS, while Clause 4.2 considers climate requirements from interested parties.
    ISO 27001 Climate Amendment Requirements
    • Clause 4.1: Determine whether climate change is a relevant issue for the organization and its ISMS context.
    • Clause 4.2: Consider climate-related requirements from relevant interested parties where those requirements apply.

    The organization should reflect climate-related effects in the relevant ISMS context, risk, objective, continuity, supplier, facility, or other management processes when climate change is relevant to the ISMS. A documented rationale can support consistency during internal review and certification audits.

    The amendment did not create a new ISO 27001 edition. ISO 27001:2022 remains the requirements standard, with Amendment 1:2024 applied to it.

    What Does the End of the ISO 27001:2013 Transition Mean in 2026?

    The ISO 27001:2013 transition ended on October 31, 2025. Historical IAF Mandatory Document 26 required certification bodies to complete certified-client transitions by that date and required all certifications based on ISO 27001:2013 to expire or be withdrawn at the end of the transition period.

    ISO 27001:2013 transition ended October 31, 2025. In 2026, ISO 27001:2013 certificates are expired or withdrawn, and accredited certification must use ISO 27001:2022.
    What Does the End of the ISO 270012013 Transition Mean in 2026

    Organizations holding accredited certification in 2026 should therefore have certification against ISO 27001:2022. Public certificate references, procurement records, customer security portals, trust-center content, and contract materials should use the current edition where they describe active accredited certification.

    An organization that did not complete the transition should discuss current certification options with an accredited certification body. A withdrawn or expired 2013 certificate should not be represented as current accredited ISO 27001 certification.

    What Did ISO 27006-1:2024 Change for Certification Bodies?

    ISO 27006-1:2024 updates requirements for bodies that audit and certify information security management systems. The historical IAF MD 29 transition required accreditation bodies and certification bodies to complete their transition by March 31, 2026. These requirements govern certification delivery rather than adding new ISO 27001 requirements for certified organizations.

    ISO 27006-1:2024 changes covering remote audits, audit-time calculations, Annex D references, certification documents, auditor requirements, and the March 31, 2026 transition deadline.
    ISOIEC 27006-12024 Changes

    The transition document listed changes concerning remote audits, audit-time calculation, Annex D references to ISO 27001:2022 controls, references to other standards in certification documents, removal of duplicated ISO 17021-1 content, and removal of quantitative work-experience and training requirements for ISMS auditors.

    Organizations may notice differences in audit planning, audit-time calculations, certification documentation, or certification-body procedures. The March 31, 2026 deadline applied to accreditation bodies and certification bodies, not to a new client transition between editions of ISO 27001.

    What Changed When Global ACI Replaced IAF and ILAC?

    Global Accreditation Cooperation Incorporated, known as Global ACI, began full operations on January 1, 2026 and replaced IAF and ILAC as the single international accreditation-cooperation organization. The former IAF MLA and ILAC MRA scopes moved into one Global ACI MRA, while continuity of existing accreditation recognition was maintained through the transition.

    IAF ceased operations on January 1, 2026, and its website now operates as a legacy reference site. Global ACI carries forward the international mutual-recognition function for accreditation activities previously covered through the IAF MLA and ILAC MRA.

    Global ACI replaced IAF and ILAC on January 1, 2026, merged the IAF MLA and ILAC MRA, and kept existing accreditation recognition and legacy documents valid.
    What Changed When Global ACI Replaced IAF and ILAC

    Existing accreditation recognition carries forward through the Global ACI MRA, and legacy accreditation documents may remain valid. Use of the IAF MLA and ILAC MRA marks follows economy-specific transition rules. Once the Global ACI MRA Mark becomes legally available in an economy and the Secretariat issues notice, new, renewed, reissued, or amended accreditation documents must use the Global ACI MRA Mark.

    The merger changed the international accreditation-cooperation structure. It did not amend ISO 27001, ISO 27006-1, or another ISO standard. Organizations should expect accreditation references and marks to move toward Global ACI terminology as transition guidance is applied.

    Does ISO 27000:2026 Replace ISO 27001?

    No. ISO 27000:2026 is an overview standard for information security management systems, while ISO 27001:2022 contains the certifiable ISMS requirements. ISO 27000:2026 was published on July 3, 2026 as the sixth edition. ISO 27000:2018 was withdrawn on the same date and no longer serves as the current overview edition.

    ISO 27000:2026 does not replace ISO 27001. It provides an ISMS overview, while ISO 27001:2022 contains the certifiable requirements.
    Does ISO 270002026 Replace ISO 27001

    The sixth edition changed the title from “Information security management systems – Overview and vocabulary” to “Information security management systems – Overview.” The revision focuses on ISMS concepts, principles, and relationships rather than serving as a terminology document.

    Clause 3 now contains 12 defined terms, compared with 77 defined terms in the 2018 edition. The revised structure places related control standards under candidate necessary information security controls. That structure supports the reference-set model used in ISO 27001 Clause 6.1.3 and the Statement of Applicability process.

    ISO 27000:2026 provides context for the ISO 27000 family. It does not contain the requirements used to certify an ISMS, and it does not create an ISO 27001:2026 certification standard.

    What Should Organizations Review for ISO 27001 in 2026?

    Organizations should review the ISMS against ISO 27001:2022, Amendment 1:2024, current risks, the 93-control Annex A reference set, and current certification information. 

    The review should connect risk treatment, the Statement of Applicability, policies, technical evidence, internal audit, management review, and public certificate references before a surveillance, recertification, or initial certification audit.

    1. Confirm that the ISMS scope, context, interested parties, and climate-change relevance decision remain current.

    2. Review the risk assessment method and current risk results for material business, technology, supplier, and threat changes.

    3. Compare necessary information security controls with the 93-control Annex A reference set and assess the 11 new controls based on current risk.

    4. Update the Statement of Applicability so that control selection, exclusions, implementation status, and supporting rationale match the current ISMS.

    5. Update the risk treatment plan where new or changed controls are necessary, and verify that assigned actions have owners and evidence.

    6. Check policies, procedures, technical configurations, supplier records, training records, continuity evidence, and monitoring evidence affected by the revised controls.

    7. Complete the internal audit and management review with enough time to correct nonconformities before the certification-body audit.

    8. Review public and customer-facing certification references so they point to ISO 27001:2022 rather than the withdrawn 2013 edition.

    What Common ISO 27001 Gaps Should Organizations Avoid in 2026?

    Common 2026 gaps usually come from incomplete transition cleanup, weak links between risk treatment and the Statement of Applicability, missing evidence for selected controls, outdated certificate references, or an undocumented climate relevance decision. Organizations should treat the ISMS as an operating management system and keep risk, control, audit, and management records consistent with current conditions.

    • Using an old 2013 control numbering scheme without mapping it to the 2022 Annex A structure.
    • Treating all 93 Annex A controls as automatically mandatory without applying the Clause 6.1.3 risk-treatment process.
    • Leaving the Statement of Applicability inconsistent with current controls, exclusions, risk decisions, or implementation status.
    • Failing to assess the 11 new controls where current risks make them relevant.
    • Recording a climate relevance decision without reflecting relevant effects elsewhere in the ISMS.
    • Making material ISMS changes without a planned change process under Clause 6.3.
    • Keeping public references to an ISO 27001:2013 certificate after the transition deadline.
    • Treating ISO 27000:2026 as a replacement for the certifiable ISO 27001 requirements.

    How Can Bright Defense Support ISO 27001 Work?

    Bright Defense’s ISO 27001 services support organizations preparing for certification, surveillance, or recertification through readiness work, risk and control reviews, Statement of Applicability support, and policy and evidence review.

    Bright Defense’s security assessment and remediation services can address control implementation gaps, vulnerability management, cloud and supplier security, secure development, monitoring, and continuity evidence.

    Human-led penetration testing can validate selected technical controls and produce remediation evidence for audit preparation.

    A virtual CISO can provide security leadership, risk oversight, and coordination across certification work when an organization lacks full-time internal leadership.

    Bright Defense’s continuous compliance services can support ongoing evidence collection, internal governance, and control monitoring after certification.

    What Are the Most Common ISO 27001 Questions in 2026?

    These frequently asked questions summarize the current edition, transition status, climate amendment, certificate expectations, and documented information requirements for 2026.

    What Is the Newest Version of ISO 27001?

    ISO 27001:2022 is the current edition. Amendment 1:2024 applies climate action changes to Clauses 4.1 and 4.2 without creating a new edition.

    Is There an ISO 27001:2026 Standard?

    No. There is no ISO 27001:2026 edition as of August 2026. ISO 27001:2022 remains the requirements standard used for certification.

    Is ISO 27001 Outdated?

    No. ISO 27001:2022 is the current published requirements edition, with Amendment 1:2024 applied to it.

    When Was ISO 27001:2022 Released?

    ISO 27001:2022 was published on October 25, 2022 as the third edition of the standard.

    What Is the Difference Between ISO 27001:2013 and ISO 27001:2022?

    The 2022 edition changes Annex A from 114 controls in 14 groups to 93 controls in four themes, adds Clause 6.3 for planned ISMS changes, and updates several core requirement clauses and management-system wording.

    What Is the 2024 ISO 27001 Climate Amendment?

    ISO 27001:2022/Amd 1:2024 requires an organization to determine whether climate change is a relevant issue under Clause 4.1 and adds a Clause 4.2 note concerning climate-related requirements from relevant interested parties.

    Do ISO 27001:2013 Certificates Remain Valid in 2026?

    Accredited ISO 27001:2013 certifications were required to expire or be withdrawn at the end of the transition period on October 31, 2025. Current accredited certification in 2026 should reference ISO 27001:2022.

    What Should Organizations Do for ISO 27001 in 2026?

    Organizations should maintain the ISMS against ISO 27001:2022 with Amendment 1:2024, keep risk treatment and the Statement of Applicability current, maintain evidence for selected controls, complete internal audit and management review, and use current certification references.

    Do Enterprise Clients Require Updated Certificates Immediately?

    Customer requirements depend on contracts, procurement rules, and vendor security programs. The formal 2013 transition has ended, so an ISO 27001:2013 certificate should not be presented as current accredited certification in 2026.

    How Do Changes to Documented Information Affect an ISMS?

    Organizations do not need to rewrite every ISMS document. They should update documented information affected by changed requirements, controls, risk decisions, or operating practices, with particular attention to the Statement of Applicability, risk treatment plan, and evidence for new or changed controls.

    What Is the Final ISO 27001 Status for 2026?

    ISO 27001:2022 with Amendment 1:2024 is the current certifiable standard in 2026. The 2013 certification transition is complete, Global ACI now operates the international accreditation MRA, ISO 27006-1:2024 governs certification-body requirements after its transition, and ISO 27000:2026 provides the current family overview without replacing ISO 27001.

    For organizations, the practical priority is maintaining a current, risk-based ISMS with a defensible Statement of Applicability, planned changes, current control evidence, climate relevance consideration, completed internal governance activities, and accurate certification references.

    Tamzid brings 5+ years of writing experience across SaaS, cybersecurity, compliance, and blockchain. He holds a foundational Cisco cybersecurity certification and turns complex topics into clear, practical insights.

    Get In Touch

      Group 1298 (1)-min