A transition audit checks only the move from ISO 27001:2013 to ISO 27001:2022. A recertification audit is a broader reassessment of the ISMS that typically occurs every three years. Organisations can often combine them, but the transition review still needs clear evidence that the 2022 requirements and control structure have been adopted.
Why This Matters for Security Teams
A transition audit and a recertification audit look similar on the surface, but they answer different assurance questions. The transition audit is narrowly focused on whether the organisation has moved its ISMS to the 2022 version of the standard and can show that the revised control set, Annex A structure, and related processes are in use. A recertification audit is broader and tests whether the ISMS still operates effectively as a management system over the full certification cycle, which is why it typically covers governance, internal audit, management review, corrective action, and operational evidence.
That distinction matters because teams sometimes treat the transition as a paperwork exercise, when auditors are looking for evidence of implementation, not only mapping. The same discipline is reflected in broader control frameworks such as the NIST Cybersecurity Framework 2.0, where governance and continuous improvement are integral rather than optional. For iso 27001 programmes, the practical question is whether the organisation has merely renamed controls or actually updated risk treatment, applicability statements, and supporting evidence. In practice, many security teams encounter this gap only after the audit schedule is set, rather than through intentional readiness planning.
How It Works in Practice
A transition audit is usually time-bound and scope-specific. The auditor checks whether the organisation has identified the 2022 changes, updated the Statement of Applicability, revised risk treatment where needed, and implemented any control changes that affect the ISMS. Evidence often includes updated policies, control owners, internal audit records, training, asset and access governance updates, and proof that the new control structure is reflected in day-to-day operations. By contrast, a recertification audit revisits the whole ISMS and tests whether the management system still supports the organisation’s stated security objectives.
In practical terms, the transition review is more like a targeted confirmation exercise, while recertification is a full cycle reassessment. Many organisations combine the two when the certification calendar aligns, but the evidence burden is not identical. Auditors will still expect the organisation to demonstrate that the 2022 requirements are adopted, not only planned. Where helpful, teams often benchmark their ISMS operating model against the control discipline in NIST SP 800-53 Rev 5 Security and Privacy Controls and the implementation guidance in ISO/IEC 27002:2022 Information Security Controls, because both emphasise documented, auditable control operation rather than intent alone.
- Transition audit: confirm adoption of ISO 27001:2022 changes and supporting evidence.
- Recertification audit: confirm the ISMS still operates effectively across the full scope.
- Combined audit: satisfy both objectives, but prepare distinct evidence for each.
- Key documents: risk assessment, SoA, internal audits, management review, corrective actions.
These controls tend to break down when the ISMS is fragmented across business units because evidence is inconsistent, ownership is unclear, and the updated control set cannot be demonstrated end to end.
Common Variations and Edge Cases
Tighter audit planning often increases documentation overhead, requiring organisations to balance assurance value against operational disruption. That tradeoff is especially visible in multi-site or fast-changing environments, where the transition may be completed technically but the broader recertification still exposes weak governance or stale evidence.
One common edge case is a combined audit with a short remaining certification window. In that situation, the organisation may pass the transition element but still receive findings on general ISMS maturity if internal audit coverage is thin or management review is outdated. Another issue appears when teams assume that control inheritance from group-level policies is enough; current guidance suggests auditors still want local evidence of implementation. Where the organisation operates in a heavily regulated context, alignment with ISO/IEC 27001:2022 Information Security Management should be shown through actual operating evidence, not just cross-references to policy text. Best practice is evolving on how much automation evidence is sufficient, but there is no universal standard for this yet. The safest approach is to prepare a clear audit trail from risk assessment through control operation to corrective action closure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while EU Cyber Resilience Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC, GV.RM, GV.OV | Transition and recertification both depend on governance, risk, and oversight evidence. |
| NIST SP 800-53 Rev 5 | CA-2, CA-5, PM-14 | Audit cycles map well to assessment, remediation, and program governance controls. |
| EU Cyber Resilience Act | Product and control evidence discipline supports broader assurance and compliance expectations. |
Maintain traceable control evidence that can support certification and external assurance reviews.
Related resources from NHI Mgmt Group
- What is the difference between passing an ISO 27001 audit and maintaining certification?
- How should security teams govern non-human identities for ISO 27001?
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org