Keeping pace with ISO standards changes is a genuine challenge for businesses managing multiple certifications. New editions introduce transition deadlines, updated requirements, and in some cases significantly revised control frameworks. Missing a deadline can put certification at risk and create real business consequences: particularly for organisations where certification is a supply chain or tendering requirement.
This article focuses on the most time-sensitive updates and what UK businesses should be doing right now.
The ISO 27001:2022 transition is complete: what if you missed it?
The transition deadline from ISO 27001:2013 to ISO 27001:2022 was 31 October 2025. Certification bodies were required to withdraw certificates issued against the 2013 edition by that date.
If your organisation was certified to ISO 27001:2013 and did not complete the transition:
- Your certificate is now considered lapsed or withdrawn by your certification body
- You will need to go through a fresh certification audit against the 2022 edition: you cannot simply resume a suspended certificate
- Any contracts, frameworks, or supply chain requirements that specify ISO 27001 certification may be affected
If this applies to you, the first step is to contact your certification body to confirm the status of your certificate and to begin planning a fresh certification audit. Elmar can help you prepare: get in touch via the contact page.
ISO 27001:2022: what changed?
For organisations that completed the transition or are beginning certification for the first time, here is a brief summary of the key changes from the 2013 edition.
Restructured Annex A. The 114 controls in the 2013 edition have been reorganised into 93 controls across four themes: Organisational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls). Eleven controls are entirely new.
New controls to implement. The 11 new controls include:
- Threat intelligence (5.7)
- Information security for use of cloud services (5.23)
- ICT readiness for business continuity (5.30)
- Physical security monitoring (7.4)
- Configuration management (8.9)
- Information deletion (8.10)
- Data masking (8.11)
- Data leakage prevention (8.12)
- Monitoring activities (8.16)
- Web filtering (8.23)
- Secure coding (8.28)
Attributes. Each control now has attributes (cybersecurity concept, operational capability, etc.) to support flexible categorisation. These attributes do not change what you need to implement but do change how you document and evidence controls.
Updated Statement of Applicability. Your SoA needs to reference the 2022 Annex A controls. This is not a trivial update: it requires mapping existing 2013 controls to the new structure and documenting the 11 new controls.
ISO 14001: preparing for the 2026 revision
The ISO 14001 revision is progressing, with the new edition expected for publication in 2026. The current committee draft strengthens requirements around climate change, expanding the existing requirement to consider climate as an external issue when determining organisational context.
Organisations currently certified to ISO 14001:2015 should:
-
Familiarise yourself with the draft requirements. ISO publishes committee drafts for public comment periods. Engaging with these early means you will not be surprised when the final edition is published.
-
Assess your current climate-related inputs. The revision is expected to require a more structured assessment of how climate change affects your organisation’s environmental aspects and impacts. If your environmental review does not currently address climate change explicitly, begin building that in now.
-
Plan for the transition period. ISO typically allows a transition period of three years from the date of publication. If ISO 14001:2026 is published in mid-2026, the transition deadline would fall around mid-2029: but organisations that leave it until the last year consistently report higher transition costs and more disruption.
ISO 9001: revision on the horizon
ISO 9001 is also under revision. While no firm publication date has been confirmed, the revision is expected to add explicit climate change considerations and to tighten requirements around organisational knowledge and documented information.
For businesses currently certified, the most important action is to ensure you maintain a well-functioning QMS and do not let complacency set in between surveillance audits. A QMS that is genuinely embedded and actively maintained will require far less effort to transition to a new edition than one that exists largely on paper.
Practical steps for certified organisations
Regardless of which standards you hold, the following practices will keep you well prepared for updates:
Stay connected with your certification body. Certification bodies are required to communicate transition timelines to their clients. Make sure your contact details are current and that you are reading their communications.
Review your management review cadence. ISO management system standards require management review at planned intervals. If yours has slipped, re-establish a regular schedule. Management reviews are the primary mechanism for identifying whether your system needs to evolve in response to external changes: including standards revisions.
Keep your gap analysis current. A gap analysis against the current edition of your standard, conducted every 12 to 18 months, is a low-cost way to catch drift before it becomes a nonconformity at audit.
Invest in staff awareness. Standards changes rarely succeed without staff understanding why things are changing. Brief communications to relevant teams about what is changing and why are worthwhile.
If you would like support with any ISO standards transition or certification programme, contact Elmar Risk Management.
Share:
LinkedIn
