Skip to content
Back to Knowledge Base
ISO 27001

ISO 27001:2013 Certificates Are No Longer Valid — What to Do If You Missed the Deadline

1 July 20263 min read
ISO 27001:2013 Certificates Are No Longer Valid — What to Do If You Missed the Deadline

The ISO/IEC 27001:2013 to ISO/IEC 27001:2022 transition period ended on October 31, 2025. As of November 1, 2025, every ISO/IEC 27001:2013 certificate in the world is invalid — no exceptions, no extensions. If your organisation is still holding (or citing) a 2013 certificate, it no longer provides any assurance to your customers, partners, or regulators.

The good news: the path back is well understood, and organisations with a previously certified ISMS are usually faster to recertify than those starting from scratch.

What the Expiry Means in Practice

A lapsed certificate is more than an administrative gap:
  • Contractual exposure — many enterprise and government contracts require current ISO 27001 certification. An expired certificate can put you in breach, or disqualify you from renewals and tenders.
  • Procurement and RFP blockers — security questionnaires increasingly ask for certificate numbers and expiry dates, which are checked against certification body registers.
  • Audit findings — if you claim certification in policies, marketing, or trust pages that you no longer hold, that's a misrepresentation risk.
  • Insurance — some cyber insurance policies reference maintained certifications in their terms.

Key Changes You Still Need to Absorb

The 2022 revision restructured the control framework and added controls for the modern threat landscape:

Control Framework Restructuring:
  • 2013 version: 114 controls across 14 domains
  • 2022 version: 93 controls organized into 4 domains (Organisational, People, Physical, Technological)
11 New Controls Added:

Including threat intelligence, cloud service security, ICT business continuity readiness, physical security monitoring, configuration management, data deletion, data masking, and secure coding practices.

Where Things Stand Now

MilestoneDateStatus
ISO/IEC 27001:2022 PublishedOctober 25, 2022Done
Transition Period EndedOctober 31, 2025Passed
2013 Certificates InvalidNovember 1, 2025In effect

The Path Back: Recertification Against ISO/IEC 27001:2022

Because the transition window has closed, you can no longer book a "transition audit". Recertification now means a certification audit against the 2022 standard — but your existing ISMS is a head start, not a write-off.

  1. Gap Assessment — Compare your current ISMS against the 2022 requirements, including the 11 new controls
  2. Update Documentation — Revise your Statement of Applicability and policies to the 4-domain structure
  3. Implement Changes — Deploy new or revised controls, and remediate anything that decayed since your last audit
  4. Internal Audit — Assess compliance against the updated standard
  5. Management Review — Confirm leadership sign-off on the updated ISMS and risk picture
  6. Certification Audit — Engage a certification body for a Stage 1 and Stage 2 audit against ISO/IEC 27001:2022
If your ISMS documentation and risk register are still in reasonable shape, expect the heavy lifting to be the Statement of Applicability rewrite and the new controls — not a full rebuild. If the ISMS has been unmaintained since expiry, treat it closer to a fresh implementation and budget accordingly.

How CyberNinja Can Help

Our team specialises in ISO 27001 implementation and recertification. Whether you're recertifying a lapsed ISMS or starting fresh with 2022, we provide end-to-end support — from gap assessment through certification.

Contact us to discuss your recertification timeline, or explore our ISO 27001 Implementation Services.

ISO 27001

Need Help With Your Security?

Our team of experts can guide you through implementation and certification. Start with a free assessment.

Start Free Assessment