ISO 27001:2022 - Information Security Management Systems Requirements
Businesses of all sizes have experienced the benefits of becoming ISO 27001 certified:
ISO/IEC 27001:2022 was published in October 2022. It is not a fully revised edition; the main changes are:
The number of controls in ISO 27002:2022 decreases from 114 controls in 14 clauses to 93 controls in 4 clauses. Of those, 11 controls are new, 24 are merged from the existing controls, and 58 are updated. Moreover, the control structure is revised, which introduces “attribute” and “purpose” for each control and no longer uses “objective” for a group of controls.
Clients may apply to be audited and certified to the old Standard (ISO 27001:2013) until 30 April 2023, after which only applications against the new Standard (ISO 27001:2022) will be accepted. Clients may request to be audited and certified to the new Standard (ISO 27001:2022) from 1 November 2022.
All clients must be audited and certified to ISO 27001:2022 no later than three years following its publication (30 October 2022). No certification to ISO 27001:2013 is permitted after 30 October 2025.
Once obtained, this certification mark can be used on all marketing material to promote your ISO 27001 Information Security Management System certification.