ISO 27001:2013 to 2022: what IAF MD 26 actually requires
Unlike almost everything else in this market, the transition rules are public. IAF MD 26 is a free document, we read it, and it says precisely what had to happen and by when. What it does not contain is a price, because the transition audit is work your certification body quotes per engagement like any other. Here are the mechanics, verbatim where it matters, and the questions worth asking.
Updated July 2026
The instrument that governs the transition
IAF MD 26:2023
Transition Requirements for ISO/IEC 27001:2022
Transition period
3 Years (36 months)
Issue
Issue 2, issued 15 February 2023
Application date
15 February 2023
On what happens to a certificate that did not transition, the document is unambiguous:
"All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period."
The Key Timescale, as the document sets it out
Every date below is read directly from Clause 3 of IAF MD 26:2023. The document expresses each deadline as a number of months from the last day of the publication month of ISO/IEC 27001:2022 and then resolves it to a date itself. Both are shown.
| Actor | Activity | Due date as expressed | Resolved |
|---|---|---|---|
| AB | Accreditation body ready to assess to ISO/IEC 27001:2022 | no later than 6 months from the last day of the publication month | 30 April 2023 |
| AB | Accreditation body transitions of certification bodies completed | by 12 months from the last day of the publication month | 31 October 2023 |
| CAB | Initial certification and recertification by the certification body to ISO/IEC 27001:2022 only, to begin | no later than 18 months from the last day of the publication month | 30 April 2024 |
| CAB | Certification body transitions of certified clients completed | by 36 months from the last day of the publication month | 31 October 2025 |
Two of these still matter in practice. The 30 April 2024 line means every initial certification and recertification has been against the 2022 revision for some time, so a fresh engagement today is a 2022 engagement by default. The 31 October 2025 line closed the transition period entirely.
There is also a useful detail about how a transition interacts with your cycle. IAF MD 26:2023 states: "When the certification document is updated because the client successfully completed only the transition audit, the expiration of its current certification cycle will not be changed." In other words, a transition performed alongside a surveillance visit moved you onto the 2022 standard without restarting or extending your three-year cycle.
Why this page carries no transition fee
IAF MD 26:2023 sets the mechanics and the deadlines. It sets no fee, and it was never going to: the IAF governs how accreditation and certification work, not what they cost. The transition audit is work your certification body performs and quotes per engagement, exactly like your initial audit and your surveillance visits.
So both inputs to a transition fee are unpublished. The audit time is determined by the body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C that ISO sells rather than publishes openly, and the day rate is commercial and published by nobody. We do not print a figure we would have to invent. Your body can tell you the audit time it determined and why, and that is the question worth asking. See how audit fees are set.
The structural change: 114 controls in 14 clauses becomes 93 in 4 themes
The 2022 revision restructured Annex A from 114 controls across 14 clauses into 93 controls across four themes: Organisational (A.5), People (A.6), Physical (A.7) and Technological (A.8). The mapping between the two sets is not one-to-one. Some 2013 controls were merged into a single 2022 control, some were separated for clarity, and 11 are genuinely new. This is why re-mapping a Statement of Applicability is analysis rather than a find-and-replace: for each control you confirm which 2022 control or controls it lands on, re-examine whether the applicability decision still holds, and repoint the evidence.
The ISMS clauses, 4 through 10, were aligned with the harmonised structure used across modern ISO management-system standards. The substantive requirements for running an ISMS did not change shape in the way Annex A did, so documentation impact there is mostly a matter of cross-references rather than rework.
The honest note about re-mapping quality: a Statement of Applicability re-mapped quickly to hit a deadline, or a control adopted on paper without being operationalised, is a thing an auditor can find at a later surveillance visit. Data leakage prevention, web filtering, threat intelligence and the cloud-services control are the ones most often adopted as documentation first. If your transition was compressed, those are the places worth looking before someone else does.
The 11 controls new in 2022
We publish no implementation cost against these. Whether a control is new work or already substantively in place depends entirely on what you were doing under the 2013 framework, and ISO 27001 requires risk-based selection rather than a fixed shopping list. What the standard asks is that you justify the applicability decision for each one.
Full catalogue on the 93 Annex A controls page.
Which situation are you actually in
Transitioned before the close
Your certificate is a 2022 certificate and your cycle is unchanged, because a transition audit does not move the expiry of the current certification cycle. The live question is whether the re-mapping and the new controls hold up at your next surveillance visit rather than only on paper.
Certificate lapsed
There is nothing to transition. Certifications based on the 2013 revision expire or are withdrawn at the end of the transition period, which has closed. The route back is an initial certification against the 2022 standard: a two-stage audit, quoted per engagement.
Certifying for the first time
The transition does not apply to you at all. You are certifying against the 2022 revision, as every initial certification has been since April 2024. Read this page for the Annex A structure and skip the timescale.
What this teaches about the next revision
ISO standards are reviewed periodically, and when a revision lands the IAF publishes a mandatory document setting the transition requirements, as it did here. We do not predict a date for the next one, because nothing published says when it is coming and a guess dressed as a forecast is not useful to a budget.
What the 2013-to-2022 window does show is what makes a transition cheap or expensive, and none of it is about price negotiation. A Statement of Applicability written as a modular structure, with the applicability rationale stated per control and evidence referenced rather than inlined, is one you can re-map. A flat template inherited from someone else is one you have to re-derive. And the mechanics rewarded acting early: MD 26 explicitly allowed the transition to ride alongside a scheduled surveillance visit without changing your cycle, which is a cheaper shape than a standalone engagement against a deadline.