Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations plan the transition from ISO…
Governance, Ownership & Risk

How should organisations plan the transition from ISO 27001:2013 to ISO 27001:2022 without disrupting certification work already in progress?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

Organisations should map the transition to their existing audit calendar, confirm that their certification body can assess ISO 27001:2022, and avoid restarting work that is already advancing under 2013 unless timing makes a switch practical. The safest approach is to preserve current progress while building a controlled migration plan toward the updated clauses and Annex A controls.

How to migrate the certification effort without losing current momentum

The transition works best when it is treated as a controlled update to an existing certification programme, not as a restart. Keep the current audit work moving, identify which clauses and Annex A controls change under 2022, and decide early whether the certification body can assess the new version on your planned timeline. That keeps effort aligned to one path instead of splitting the team across two.

A practical migration plan usually starts with a gap review against the 2022 control set, then a schedule decision: finish the current 2013 cycle, or fold the migration into the next audit event if the timing and assessor availability make that cleaner. The key judgement is whether the remaining 2013 work is close enough to completion to justify preserving it, or whether the delta to 2022 is large enough that a deliberate pivot will save rework.

For most organisations, the safest sequencing is to protect work already completed, document the differences that must be closed for 2022, and coordinate the change with the certification body rather than making an internal assumption about audit timing. A transition plan that ignores the audit calendar often creates avoidable duplication, especially where evidence, statement-of-applicability updates, and control mapping all need to be refreshed together.

What usually changes in the control picture

iso 27001:2022 is not a wholesale reinvention of the management system, but it does change the control landscape enough that teams should not treat it as a simple date update. The main impact is in Annex A, where the control set was streamlined and reorganised, so existing mappings, evidence packs, and internal assurance work need to be revalidated against the new structure.

That matters because certification work is often built around a live statement of applicability, internal audit findings, treatment plans, and management review outputs. If those artefacts were prepared for 2013, they may still be useful, but they need to be checked for whether the control references, titles, and implementation evidence still line up with the 2022 wording and structure. Reuse is usually possible, but only after explicit mapping.

Organisations also need to be careful about scope and timing. If the certification body will assess 2022 during the same period that 2013 work is being closed out, you need a single source of truth for which version governs which deliverable. Otherwise, teams can end up remediating a finding against one version while preparing attestations against another.

How to keep the transition controlled and audit-ready

The most effective approach is to run a migration register that links each affected 2013 control, policy, or evidence item to its 2022 counterpart and assigns an owner, target date, and audit dependency. That lets the organisation continue normal certification work while making the transition visible as a managed workstream rather than an informal side project.

At the same time, confirm whether the certification body will accept a mixed evidence period and how it wants the transition evidenced. Some bodies will tolerate a phased approach if the management system is clearly controlled; others will expect a tighter cutover. The sooner that expectation is confirmed, the less chance there is of producing evidence that satisfies the wrong version.

This is also the point where internal audit and governance teams should agree on what “done” means. If the team can no longer answer quickly which controls are still inherited from 2013 and which have been updated for 2022, the transition is already becoming opaque. Clear control traceability is more valuable here than trying to accelerate every update at once.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access ControlThe transition hinges on updating Annex A mappings across the revised control set.
A.5.1 — Policies for information securityMigration planning depends on keeping governance documents aligned during the version change.
A.8.8 — Management of technical vulnerabilitiesEvidence and remediation work already underway must stay traceable through the transition.
Recommendation — Remap existing controls to Annex A 2022 before updating the statement of applicability. Update policies and governance artefacts to reference the new standard version. Preserve remediation evidence and link it to the new control mapping without restarting work.

Practitioner Guidance

What to prioritise: Protect certification continuity first. Preserve in-flight work, then update the minimum set of clauses, Annex A mappings, and evidence references needed to make the transition credible to the assessor.

Decision rule: If your current 2013 certification work is close to completion, finish it and schedule the 2022 transition deliberately; if not, switch early enough to avoid building duplicate evidence sets.

What to verify: Confirm the certification body’s transition window, assessment method, and expectations for reusing existing artefacts before you commit to a timeline. That decision should drive the migration plan, not the other way around.

Practitioner takeaway: The goal is continuity with controlled change, not parallel programmes competing for the same audit evidence.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org