Information security
ISO 27001 certification
The information security management standard. ISO/IEC 27001:2022 is current, and if you still hold a 2013 certificate, the transition deadline passed on 31 October 2025.
- 93Annex A controls
- 4Control themes
- SoAThe document auditors read first
- Oct 20252013 deadline already passed
ISO/IEC 27001:2022 replaced the 2013 edition in October 2022, and the IAF transition period ended 31 October 2025. Certificates still referencing the 2013 standard are no longer valid.
- ISO/IEC 27001:2022 — current and certifiable
- 2013 certificates expired 31 October 2025
- Climate amendment in force since February 2024
- Still on 2013? Your next audit is assessed against 2022
ISO 27001 sets the requirements for an information security management system: identifying what information matters, assessing the risks to it, selecting controls to treat those risks, and proving the whole thing works. Unlike most standards, it centres on a single document. The Statement of Applicability, which records every Annex A control and your justification for using it or leaving it out.
It is not an IT project. The clause structure is the same one used by ISO 9001, 14001 and 45001, so an organization that already runs a management system has done more of the work than it realises.
Who needs it
Choose ISO 27001 if
Almost always driven from outside. A customer, a tender, or a contract clause.
- A customer or tender demands it. Increasingly standard in enterprise procurement and public sector contracts.
- You hold other people's sensitive data. If a breach would be their problem as much as yours, expect to be asked.
- You're an ITAD handling data-bearing devices. R2v3 Core 7 and Appendix B already cover data security. ISO 27001 covers the rest of your business, and customers who ask about one often ask about both.
- Your certificate says 2013. That deadline has passed. Transitioning is now urgent rather than planned.
The parts specific to information security
Context, leadership, internal audit and management review behave as they do in any ISO standard. These are the ones that only exist here.
Clause 6.1.2 & 6.1.3
Risk assessment and treatment
A defined, repeatable method for identifying information security risks and deciding what to do about each. The method matters as much as the output — auditors check that it produces consistent results, not just that a register exists.
Clause 6.1.3 d)
The Statement of Applicability
The central document. Every one of the 93 Annex A controls, whether you apply it, and why. Exclusions need justification. This is the first thing an auditor reads and the document most often found incomplete.
Annex A
93 controls across four themes
The 2022 revision restructured 114 controls in 14 domains into 93 across four themes — organizational, people, physical and technological. Eleven are entirely new, including threat intelligence, cloud services security and data leakage prevention.
Clause 4.1 & 4.2 — In force since February 2024
Climate change in your context
The same amendment applied across 31 ISO management system standards, with no transition period. Determine whether climate change is relevant to your ISMS context and document the assessment either way.
Clause and control references reflect ISO/IEC 27001:2022. Confirm against your own copy of the standard before using them in documentation.
How we work
Certifying, or transitioning late
A first certification runs on the same three-to-six month shape as our other ISO work. A late transition from 2013 is usually faster. The management system exists, and the work concentrates on remapping controls.
Scope and readiness call. first, What's driving it, what's in scope, and whether you're certifying fresh or catching up on a lapsed transition.
Risk assessment and gap analysis. then Your risk method, then control by control against Annex A to build an honest Statement of Applicability.
Build and document. after that, Policies, procedures, the SoA, the risk treatment plan, and evidence that the controls you claim are actually operating.
Internal audit, then certification. finally, Full internal audit and management review with findings closed, then Stage 1 and Stage 2.
Integration
Sits on the same frame as your other standards
ISO 27001 shares the harmonized clause structure, so if you already hold ISO 9001 or 14001 the context, leadership, internal audit and management review work is largely done. The new work is the risk method, the Statement of Applicability and the controls.
For electronics recyclers there's a natural overlap: R2v3 already requires data security controls under Core 7, and Appendix B if you sanitise for reuse. ISO 27001 extends that discipline across the whole organization rather than just the devices.
-
For ITAD
R2v3 data security Core 7 and Appendix B cover device-level sanitization. R2v3 requirements → -
Related
Internal auditing Independent internal audits against the 2022 Annex A structure. Auditing →
The deadline passed on 31 October 2025, so this is a live problem rather than a planning exercise. Your next surveillance or recertification audit will be assessed against the 2022 standard.
Common questions
Is ISO 27001:2013 still valid?
No. The IAF transition period ended on 31 October 2025, and certificates referencing the 2013 standard are no longer valid. Organizations that haven't transitioned will be assessed against the 2022 version at their next audit.
What actually changed in the 2022 version?
The management system clauses changed modestly. Annex A was restructured from 114 controls across 14 domains into 93 controls across four themes, with 11 entirely new controls including threat intelligence, cloud services security and data leakage prevention. For a mature ISMS the transition is largely a remapping and documentation exercise.
What is the Statement of Applicability?
The document listing every Annex A control, whether you apply it, and your justification either way. It's the centre of an ISO 27001 certification and the document auditors read first — which is why an incomplete or unjustified SoA is such a common finding.
Do we need ISO 27001 if we already have R2v3?
Not necessarily. R2v3 Core 7 and Appendix B cover data security for the devices you process. ISO 27001 covers information security across your whole organization. ITADs whose customers ask about corporate information security, not just device sanitization, tend to need both.
Is this an IT project?
No, and treating it as one is a common failure. ISO 27001 is a management system standard with the same structure as ISO 9001. IT implements many of the controls, but scope, risk assessment, leadership and audit are organizational work.
Next step
Still on the 2013 version?
That deadline has passed. A short call establishes how much work the transition actually is, usually less than people fear.