Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001:2013 to 2022: what IAF MD 26 actually requires

Unlike almost everything else in this market, the transition rules are public. IAF MD 26 is a free document, we read it, and it says precisely what had to happen and by when. What it does not contain is a price, because the transition audit is work your certification body quotes per engagement like any other. Here are the mechanics, verbatim where it matters, and the questions worth asking.

Updated July 2026

The instrument that governs the transition

IAF MD 26:2023

Transition Requirements for ISO/IEC 27001:2022

Transition period

3 Years (36 months)

Issue

Issue 2, issued 15 February 2023

Application date

15 February 2023

On what happens to a certificate that did not transition, the document is unambiguous:

"All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period."

Read IAF MD 26:2023 | IAF document register

The Key Timescale, as the document sets it out

Every date below is read directly from Clause 3 of IAF MD 26:2023. The document expresses each deadline as a number of months from the last day of the publication month of ISO/IEC 27001:2022 and then resolves it to a date itself. Both are shown.

ActorActivityDue date as expressedResolved
ABAccreditation body ready to assess to ISO/IEC 27001:2022no later than 6 months from the last day of the publication month30 April 2023
ABAccreditation body transitions of certification bodies completedby 12 months from the last day of the publication month31 October 2023
CABInitial certification and recertification by the certification body to ISO/IEC 27001:2022 only, to beginno later than 18 months from the last day of the publication month30 April 2024
CABCertification body transitions of certified clients completedby 36 months from the last day of the publication month31 October 2025

Two of these still matter in practice. The 30 April 2024 line means every initial certification and recertification has been against the 2022 revision for some time, so a fresh engagement today is a 2022 engagement by default. The 31 October 2025 line closed the transition period entirely.

There is also a useful detail about how a transition interacts with your cycle. IAF MD 26:2023 states: "When the certification document is updated because the client successfully completed only the transition audit, the expiration of its current certification cycle will not be changed." In other words, a transition performed alongside a surveillance visit moved you onto the 2022 standard without restarting or extending your three-year cycle.

Why this page carries no transition fee

IAF MD 26:2023 sets the mechanics and the deadlines. It sets no fee, and it was never going to: the IAF governs how accreditation and certification work, not what they cost. The transition audit is work your certification body performs and quotes per engagement, exactly like your initial audit and your surveillance visits.

So both inputs to a transition fee are unpublished. The audit time is determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C that ISO sells rather than publishes openly, and the day rate is commercial and published by nobody. We do not print a figure we would have to invent. Your body can tell you the audit time it determined and why, and that is the question worth asking. See how audit fees are set.

The structural change: 114 controls in 14 clauses becomes 93 in 4 themes

The 2022 revision restructured Annex A from 114 controls across 14 clauses into 93 controls across four themes: Organisational (A.5), People (A.6), Physical (A.7) and Technological (A.8). The mapping between the two sets is not one-to-one. Some 2013 controls were merged into a single 2022 control, some were separated for clarity, and 11 are genuinely new. This is why re-mapping a Statement of Applicability is analysis rather than a find-and-replace: for each control you confirm which 2022 control or controls it lands on, re-examine whether the applicability decision still holds, and repoint the evidence.

The ISMS clauses, 4 through 10, were aligned with the harmonised structure used across modern ISO management-system standards. The substantive requirements for running an ISMS did not change shape in the way Annex A did, so documentation impact there is mostly a matter of cross-references rather than rework.

The honest note about re-mapping quality: a Statement of Applicability re-mapped quickly to hit a deadline, or a control adopted on paper without being operationalised, is a thing an auditor can find at a later surveillance visit. Data leakage prevention, web filtering, threat intelligence and the cloud-services control are the ones most often adopted as documentation first. If your transition was compressed, those are the places worth looking before someone else does.

The 11 controls new in 2022

We publish no implementation cost against these. Whether a control is new work or already substantively in place depends entirely on what you were doing under the 2013 framework, and ISO 27001 requires risk-based selection rather than a fixed shopping list. What the standard asks is that you justify the applicability decision for each one.

A.5.7Threat intelligence
A.5.23Information security for use of cloud services
A.5.30ICT readiness for business continuity
A.7.4Physical security monitoring
A.8.9Configuration management
A.8.10Information deletion
A.8.11Data masking
A.8.12Data leakage prevention
A.8.16Monitoring activities
A.8.23Web filtering
A.8.28Secure coding

Full catalogue on the 93 Annex A controls page.

Which situation are you actually in

Transitioned before the close

Your certificate is a 2022 certificate and your cycle is unchanged, because a transition audit does not move the expiry of the current certification cycle. The live question is whether the re-mapping and the new controls hold up at your next surveillance visit rather than only on paper.

Certificate lapsed

There is nothing to transition. Certifications based on the 2013 revision expire or are withdrawn at the end of the transition period, which has closed. The route back is an initial certification against the 2022 standard: a two-stage audit, quoted per engagement.

Certifying for the first time

The transition does not apply to you at all. You are certifying against the 2022 revision, as every initial certification has been since April 2024. Read this page for the Annex A structure and skip the timescale.

What this teaches about the next revision

ISO standards are reviewed periodically, and when a revision lands the IAF publishes a mandatory document setting the transition requirements, as it did here. We do not predict a date for the next one, because nothing published says when it is coming and a guess dressed as a forecast is not useful to a budget.

What the 2013-to-2022 window does show is what makes a transition cheap or expensive, and none of it is about price negotiation. A Statement of Applicability written as a modular structure, with the applicability rationale stated per control and evidence referenced rather than inlined, is one you can re-map. A flat template inherited from someone else is one you have to re-derive. And the mechanics rewarded acting early: MD 26 explicitly allowed the transition to ride alongside a scheduled surveillance visit without changing your cycle, which is a cheaper shape than a standalone engagement against a deadline.

Frequently asked questions

What did IAF MD 26 require and when did it close?
IAF MD 26:2023 sets the transition requirements for ISO/IEC 27001:2022. It defines a transition period of 3 years (36 months) and states in its Key Timescale clause that certification body transitions of certified clients had to be completed by 36 months from the last day of the publication month of ISO/IEC 27001:2022, which the document itself resolves as 31 October 2025. The document also states that all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period. It was issued on 15 February 2023 as Issue 2, with the same application date.
What does the transition cost?
No accredited certification body publishes a rate card, so there is no published transition fee for us to report, and any site quoting you one has assembled it from assumptions. The transition audit is work performed by your certification body and quoted by them per engagement, like every other audit they run. The audit-time provisions that shape it sit in ISO/IEC 27006-1:2024 Annex C, which is normative and which ISO sells rather than publishes openly. What you can do is ask your body directly: how much audit time did you determine for the transition, on what basis, and how does it interact with my scheduled surveillance visit.
What changed in ISO 27001:2022?
Annex A was restructured from 114 controls in 14 clauses to 93 controls across 4 themes: Organisational (A.5), People (A.6), Physical (A.7) and Technological (A.8). The mapping between the 2013 and 2022 control sets is not one-to-one: some controls were merged, some were split, and 11 are new. The 11 new controls are threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. The ISMS clauses 4 through 10 were aligned with the harmonised structure used across modern ISO management-system standards.
Does a transition audit change my certificate expiry date?
No. IAF MD 26 addresses this directly: when the certification document is updated because the client successfully completed only the transition audit, the expiration of its current certification cycle will not be changed. So a transition performed alongside a surveillance visit moves you onto the 2022 standard without restarting or extending your three-year cycle. Your recertification still falls where it always did.
What happens if a 2013 certificate was never transitioned?
There is nothing left to transition. IAF MD 26 states that all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period, which closed on 31 October 2025. An organisation in that position is uncertified and needs a fresh certification engagement against the 2022 standard: a two-stage initial audit by an accredited body, a scope and Statement of Applicability built against the 2022 structure, and evidence that the applicable controls are implemented and operating. That is an initial certification, priced per engagement like any other, not a transition.
Is the 2022 revision the only certifiable version now?
Yes. IAF MD 26's Key Timescale also required that initial certification and recertification by certification bodies to ISO/IEC 27001:2022 only had to begin no later than 18 months from the last day of the publication month, which the document resolves as 30 April 2024. Combined with the 31 October 2025 close of the transition period, any certificate issued or maintained today should be against the 2022 revision. Separately, your certification body should now be determining audit time under ISO/IEC 27006-1:2024, whose own accreditation-body transition deadlines have also passed.

Related reading

Updated July 2026