All legacy ISO 27001:2013 certificates have fully expired, leaving ISO/IEC 27001:2022 as the active standard, alongside the mandatory Amendment 1 (Climate Action).
Current Compliance Status
- 2013 Expiration: All older 2013-version certifications are completely invalid, requiring total alignment with the 93-control Annex A framework of the 2022 revision.
- Climate Change Amendment (AMD 1:2024): Formally integrated into Clauses 4.1 and 4.2, forcing organizations to evaluate if climate factors impact their Information Security Management System (ISMS).
- Audit Enforcement: Certification bodies fully enforce 2022 standards and climate requirements during ongoing surveillance and recertification audits.
If you’d like, let me know:
- Is your organization currently undergoing an audit or planning a new certification?
- Do you need help addressing the climate change amendment requirements?