Convert ISO 27001:2022 now: migration path until October 2026
The deadline for switching to ISO/IEC 27001:2022 is October 31, 2026. If you plan now, you will avoid re-audit stress, duplicate documentation and certificate gaps. This guide shows operational migration in five steps.
The International Accreditation Forum Resolution 2024-12 sets the final expiry date for ISO/IEC 27001:2013 certificates as October 31, 2026. From this date, all certificates issued under the old standard will no longer be valid, regardless of the original issue date. Anyone who has not migrated by then will be left without valid proof before customers, insurers and supervisory authorities.
The changeover is not just a paper act. Appendix A of the 2022 version reduces the controls from 114 to 93, introduces eleven new controls, and organises the entire set into four themes instead of fourteen categories. This article shows how you can plan the migration in five operational steps, which templates you need and when an external representative will solve the bottleneck.
Key Takeaways
- The deadline of October 31, 2026 is absolute: from this date, ISO 27001:2013 certificates are invalid and an extension has been ruled out by the IAF.
- The new standard requires eleven new controls such as Threat Intelligence, ICT Readiness for Business Continuity and Secure Coding, which must be documented in the Statement of Applicability.
- A structured migration takes four to six months; Plan the transition audit with your certification body at least three months before the certificate expires.
What the switch to ISO 27001:2022 specifically requires
ISO/IEC 27001:2022 was published on October 25, 2022 and replaces the 2013 version, which has been in force for nine years. The main part of the standard, clauses 4 to 10, remains largely structurally stable. The operationally relevant changes are in Appendix A, which defines the security controls and is the most intensively checked by auditors in practice.
The 93 controls in the 2022 version replace the 114 from 2013. Eleven controls are new, 24 have been merged, 58 have just been revised. The four-topic structure (organisational, personnel, physical, technological) replaces the old fourteen categories and makes it easier to assign to modern IT landscapes, in particular cloud, remote work and supply chain security.
A transition phase of three years applies to existing certificates from the publication of the new standard. This ends on October 31, 2026. Within this period, you must have completed either a re-audit or a transition audit, depending on the cycle of your regular surveillance audits.
In the NIS 2 context, the Federal Network Agency only recognises certificates according to the current standard. Many insurers, cyber underwriters and major customers in regulated sectors will also explicitly require ISO 27001:2022 as a minimum standard for suppliers and service providers from 2026.
You can find the complete background on the standard and the transition logic in the CIVAC contribution to the ISO 27001:2022 transition. This article focuses on operational implementation in your own company.
The eleven new controls and their practical significance
The eleven new controls in Appendix A of the 2022 version address technological developments that did not yet play a systematic role in the 2013 standard. They concern Threat Intelligence, Cloud Services, ICT Readiness for Business Continuity, Physical Security Monitoring, Configuration Management, Information Deletion, Data Masking, Data Leakage Prevention, Monitoring Activities, Web Filtering and Secure Coding.
A.5.7 Threat Intelligence requires a documented process for collecting, assessing and disseminating threat information. In practice, this means a connection to CERT sources such as BSI CERT-Bund, an internal triage routine and a link to the incident response plan. A pure RSS feed collection is not sufficient in the audit.
A.5.23 Information Security for Use of Cloud Services defines responsibilities towards cloud providers. You must document shared responsibility models, set minimum contractual requirements and enable provider audits. This also applies to SaaS tools such as Microsoft 365, Salesforce or GitHub.
A.8.28 Secure Coding requires coding standards, code reviews and automated security tests in the development cycle. Even without your own software development, the control can be relevant if you use scripts, automation or low-code platforms.
A.8.16 Monitoring Activities and A.8.23 Web Filtering require technical measures with documented threshold values, escalation rules and retention periods. Many migrations fail here due to a lack of proof of evaluation. It is not enough to run a SIEM; You must provide evidence that alarms are actually being processed.
Migration steps 1 to 3: Gap analysis, SoA update, action plan
The first operational step is a structured gap analysis. You take your existing Statement of Applicability (SoA) to the 2013 standard and map each of the 114 old controls to the 93 new ones. The ISO itself provides an official transition table in Appendix B of 27002:2022 that makes this assignment easier.
In the second step, you create the new SoA against the 93 controls. You decide for each control: applicable or not, with reasons. The eleven new controls require special attention because there is no inventory documentation available. Experience has shown that seven to nine of these are applicable to every company.
Step three is the action plan. For each unfulfilled requirement, document: person responsible, due date, resources, success indicator. A realistic schedule includes two months for conception, two months for implementation and one month for internal effectiveness testing.
The CIVAC FAQ documents the most common stumbling blocks in this phase. Particularly critical: Companies underestimate the effort required for A.5.7 Threat Intelligence and A.8.28 Secure Coding, because completely new processes often have to be set up instead of adapting existing ones.
The 490 ready-to-use audit templates from the CIVAC Workspace cover all 93 controls. Get sample SoA, action plans, threat intelligence procedures, and secure coding policies as editable templates that you tailor to your context. The appointment certificate, signed, filed, verifiable.
Migration steps 4 and 5: Internal audit and transition audit
Step four is the internal audit against the new standard. It must be completed before the external transition audit and documented that all 93 controls have been evaluated, all applicable ones have been implemented and are effective. Auditors require samples over at least three months of observation period, ideally six.
The internal audit typically uncovers two to five findings that need to be corrected before the transition audit. If you don't plan buffer time for this, you will come under pressure. Experience: Reserve eight weeks between the internal audit and the external transition audit.
Step five is the transition audit by the certification body. It can be carried out as a stand-alone audit, combined with the regular surveillance audit or as part of the re-certification audit. The combined variant is the most efficient, but requires that your recertification falls within the migration window.
The duration of the transition audit is one to three days, depending on the size of the company and scope. The auditor focuses on the eleven new controls and the consistency between SoA, risk assessment and implementation of measures. Gaps in the documentation lead to major nonconformities and delays.
Book the transition audit with your certification body at least three months in advance. Capacity bottlenecks are to be expected in the summer of 2026 because many companies are putting off migration until the very end. Anyone who has not yet booked in Q3 2026 risks a certificate gap.
Typical pitfalls and how to avoid them
The most common mistake in migration projects is processing Appendix A in isolation without linking back to risk assessment and SoA. Auditors check the consistency of these three high priority artifacts. If a risk is classified as high in the assessment, but the associated control is marked as not applicable in the SoA, this is an automatic major finding.
The second stumbling block is the underestimated complexity of new controls such as A.5.7 Threat Intelligence. Many companies think that a subscription to a CERT newsletter is enough. In fact, control requires a documented process with sources, evaluation criteria, distribution list, escalation and verifiable response to specific threats.
Stumbling block three is supplier control against A.5.19 to A.5.22. The new standard requires more differentiated treatment of ICT suppliers than in 2013. You must identify critical ICT suppliers, secure them contractually and regularly check them. This affects all cloud and SaaS providers with access to confidential information.
Fourth stumbling block: The documentation of A.8.16 Monitoring Activities. A list of tools is not enough here. Auditors require use cases with threshold values, escalation rules, documented processing of alarms and effectiveness testing over a defined observation period.
The fifth stumbling block is resource planning. An internal ISB requires four to six months of focus time for a clean migration. Anyone who lets the project run alongside day-to-day business will miss the deadline. The reporting line to management must be clear from the start, otherwise any escalation will stall.
When external support solves the bottleneck
An internal information security officer with several years of experience can manage an ISO migration independently. In reality, such profiles are scarce and expensive in Germany. The average vacancy duration for an ISB in medium-sized companies was 5.2 months in 2025, and over seven months in regulated sectors.
External support clearly pays for itself in two scenarios. Firstly, if your internal capacity is lacking: an experienced external force will complete the migration in four to five months instead of eight to twelve months of internal development. Secondly, if your migration runs parallel to NIS 2 implementation or DORA implementation and internal conflicts about priorities arise.
CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. Both models provide the same migration path with the same documentation, but differ in terms of staff utilization.
The CIVAC SLA for appointing an external information security officer is two working days instead of the classic two to six weeks. The appointment certificate, reporting line to management and initial action plan are available in the workspace after 72 hours.
In the workspace you will find 93 control templates, 490 audit templates and the EU data residency, which is required for NIS 2-relevant industries. Others run compliance like a filing cabinet. We run it like software. The auditor calls, the evidence is ready.
Costs, schedule and negotiation with the certification body
The direct costs of the changeover are divided into four items: consulting or external ISB, tooling, training of internal employees and audit costs of the certification body. For a medium-sized company with 100 to 500 employees, experience shows that the range is 45,000 to 120,000 euros, depending on the scope and level of maturity.
The transition audit itself costs between 8,000 and 18,000 euros net for the major certifiers such as TÜV, DEKRA or DQS. If it is combined with the regular surveillance audit, the surcharge is reduced to 30 to 50 percent of the audit fee. This combination is the most economical option.
The schedule should be calculated backwards from October 31, 2026. Three months of audit booking lead time, two months of internal audit and correction loop, four months of implementation of measures, one month of gap analysis and SoA update. Those who start at the beginning of 2026 still have reserves. Anyone who starts in the second quarter of 2026 is running at the limit.
When negotiating with the certification body, it is worth asking about fixed audit slots. Many certifiers offer reservations against a deposit, which will be charged when booking later. This ensures capacity in the expected bottleneck phase in the third quarter of 2026.
For a reliable calculation of your own migration, we recommend starting with a structured maturity check. Depending on the initial situation, the effort varies between 30 person days and 120 person days. Deadline begins as soon as we become aware of it. Anyone who underestimates the deadline logic will end up paying twice as much.
Interfaces to NIS-2, DORA and data protection
The ISO 27001:2022 migration is not isolated. It operationally overlaps with the NIS 2 implementation, which has been in force since October 2024 and is substantiated in Germany by the NIS 2 Implementation Act. Around 29,500 companies are affected, many of which are planning to use ISO 27001 as a proof standard anyway.
NIS-2 requires risk-based security measures in accordance with Article 21 of EU Directive 2022/2555. An ISO 27001:2022 certificate substantially meets these requirements, but is not a licence. They must also operationally map the specific reporting requirements (24-hour early warning, 72-hour follow-up notification), which Annex A of the ISO does not cover.
DORA, the Digital Operational Resilience Act for the financial sector, requires its own requirements for ICT risk management, incident reporting and third-party risk from January 17, 2025. ISO 27001:2022 provides a strong basis here, supplemented by specific DORA artifacts such as the Register of Information.
On the data protection side, ISO 27001:2022 overlaps with Art. 32 GDPR (security of processing). The eleven new controls, in particular data masking, information deletion and data leakage prevention, are direct technical and organisational measures within the meaning of the regulation and can be referenced in the GDPR documentation.
A well-planned migration project uses these interfaces. It avoids double documentation by describing controls once and referencing them multiple times. The CIVAC Workspace systematically maps this multiple assignment and avoids inconsistent statements across different compliance domains.
Start migration: two ways at CIVAC
The ISO 27001:2022 migration can be planned if you start now. With twelve months' lead time to the deadline of October 31, 2026, you still have buffer time for gap analysis, implementation of measures and transition audit without pressure to escalate. From spring 2026 the air will be thin, from summer 2026 audit capacities will be scarce.
CIVAC is a compliance platform and officer-as-a-service with two clearly separated models. Licence the workspace for your internal representatives, or have our representatives order it. Both paths deliver the same migration structure with 93 control templates, 490 audit templates and EU data residency in the ISO/IEC 27001:2022 certified ISMS.
Model one, workspace licence: Your internal ISB or security team uses the platform for SoA, risk assessment, action plan, internal audit and transition audit preparation. The templates are customizable, the reporting line to management is mapped, the audit history is automatically documented.
Model two, officer-as-a-service: CIVAC appoints an external information security officer who is responsible for the migration end-to-end. Appointment certificate within two working days, reporting line to management established, first action plan in 72 hours, handover to your certification body coordinated.
Both models address the same bottleneck: tight internal capacity with a hard deadline. Which one is right depends on your personnel situation and internal maturity. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de for a structured initial discussion.
FAQ
By when does the transition to ISO 27001:2022 have to be completed?
The final deadline is October 31, 2026. From this date, all ISO 27001:2013 certificates will no longer be valid, regardless of the original date of issue. An extension of this deadline by the International Accreditation Forum was explicitly ruled out.
How many new controls are there in ISO 27001:2022?
Appendix A of the 2022 version contains 93 controls instead of 114 in the 2013 version. Eleven controls are completely new, including Threat Intelligence, Cloud Services Security, ICT Readiness for Business Continuity and Secure Coding. 24 controls were merged and the content of 58 was revised.
Can I combine the transition audit with the regular surveillance audit?
Yes, this is the most economical option. Most certification bodies such as TÜV, DEKRA or DQS offer the combination. The surcharge on the regular audit fee is 30 to 50 percent, instead of 8,000 to 18,000 euros for a stand-alone transition audit.
How long does a full migration to ISO 27001:2022 take?
A structured migration takes four to six months, depending on the initial maturity level. Gap analysis and SoA update take one month, implementation of measures around four months, internal audit and correction loop two months. Reserve an additional three months of audit booking lead time.
Do all eleven new controls have to be applicable to my company?
No. For each control, you decide in the Statement of Applicability whether it is applicable and justify the decision. Experience shows that seven to nine of the eleven new controls can be used by every company. Complete exclusions are rare and must be particularly carefully justified.
What happens if I miss the deadline?
Your certificate expires on October 31, 2026 with no extension option. Re-certification after expiry takes place as an initial certification with more effort and audit days. Customers, insurers and regulatory authorities that require ISO 27001 as a minimum standard will consider you as not certified at this stage.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.