Skip to content

Resources/Foundations/6 min read

Is ISO 27001 outdated?

The short answer

No. ISO/IEC 27001:2022, published in October 2022, is the current version and is far from outdated. It added 11 new controls covering cloud services, threat intelligence, data leakage prevention, and secure coding. The previous 2013 edition expired on 31 October 2025.

  • Dimitar YotovHead of Compliance
  • Steve ThomasCTO & Co-Founder

Last updated

No. ISO/IEC 27001:2022, published on 25 October 2022, is the current edition of the standard and it is thoroughly modern. It added 11 new controls covering cloud services, threat intelligence, secure coding, data leakage prevention, and monitoring activities. The number of valid certificates worldwide nearly doubled from 48,671 in 2023 to 96,709 at the end of 2024 [1]. A standard people are adopting at that rate is not fading away.

What you might actually be thinking of is the old 2013 version. That one did become outdated, and the International Accreditation Forum set a hard transition deadline of 31 October 2025 [2]. Any certificate still referencing ISO/IEC 27001:2013 after that date is void. If someone told you ISO 27001 is outdated, they were probably looking at the wrong edition.

The 2022 revision

The management-system clauses (4 through 10) received minor wording updates. If you have been through any ISO management system audit before, those clauses will feel familiar. The real overhaul happened in Annex A, which lists the reference controls.

The 2013 edition had 114 controls spread across 14 domains; the 2022 edition reorganised them into 93 controls across four themes — organisational (37), people (8), physical (14), and technological (34) [3] — which is not a reduction in scope, since twenty-four controls were merged, 58 were updated, and none were deleted outright.

The 11 new controls are where the standard caught up with how companies actually operate today:

ControlThemeWhat it covers
5.7 Threat intelligenceOrganisationalCollecting and analysing threat data
5.23 Cloud servicesOrganisationalSecurity for cloud adoption and use
5.30 ICT readiness for business continuityOrganisationalTech resilience planning beyond just backups
7.4 Physical security monitoringPhysicalCCTV, sensors, intrusion detection for premises
8.9 Configuration managementTechnologicalHardened, documented, tracked configs
8.10 Information deletionTechnologicalDisposing of data you no longer need
8.11 Data maskingTechnologicalObfuscating data in non-production environments
8.12 Data leakage preventionTechnologicalDLP tooling and processes
8.16 Monitoring activitiesTechnologicalLogging and alerting on anomalous behaviour
8.23 Web filteringTechnologicalControlling access to risky web content
8.28 Secure codingTechnologicalSecure development practices baked into the SDLC

If you are a tech company, controls like 5.23 (cloud services), 8.12 (data leakage prevention), and 8.28 (secure coding) are things you should already be doing. The standard now expects you to prove it.

The perception problem

We suspect three things feed this impression.

First, the standard's name still says "27001" and people assume it has not changed since they last heard about it in 2015. The revision got less press coverage than it deserved, partly because ISO standards do not have marketing departments.

Second, ISO moves slowly by design — a revision cycle of roughly nine years feels glacial compared to how quickly the threat landscape shifts. But the standard is deliberately framework-level: it tells you to assess risks and apply controls proportionate to those risks, without prescribing specific technologies, which is why it does not date in the way a vendor checklist would. Your Statement of Applicability (SoA) is the document that keeps pace with your actual environment, not the standard itself.

Third, some people confuse ISO 27001 with ISO 27002. The companion standard, ISO/IEC 27002:2022, provides implementation guidance for each control and introduced attribute values (control type, security properties, cybersecurity concepts, operational capabilities, and security domains) that make mapping to other frameworks much more practical [4]. If you only read 27001 in isolation, you miss how granular the guidance actually is.

Certificate growth

The ISO Survey 2024 recorded 96,709 valid ISO/IEC 27001 certificates worldwide, covering 179,877 sites [1] — nearly double the 48,671 certificates reported the previous year, with the UK alone holding 4,455 to place fourth globally behind China, India, and Japan.

Meanwhile, 43% of UK businesses identified a cyber breach or attack in the past 12 months [5]. The demand for demonstrable security management is not shrinking. If anything, regulations like the EU's NIS2 Directive and the UK Cyber Security and Resilience Bill are pushing more organisations toward a formal ISMS, and ISO 27001 remains the most internationally recognised framework for building one.

Still on the 2013 version

If your certificate references ISO/IEC 27001:2013, it became invalid on 31 October 2025 [2] — no grace period, no late "transition". You need a full Stage 1 and Stage 2 audit against the 2022 edition, the same process as a first-time certification.

We have seen a few organisations get caught by this — one client assumed their certification body (CB) would handle the transition automatically, which is not how it works. The transition required updating your SoA to map against the 93 Annex A controls, conducting a fresh risk assessment, and sitting two audits, and if you left it past the deadline you are starting from scratch.

At Calibre, we scope these engagements in hours rather than weeks, because a company that already ran an ISMS for three years does not need the same hand-holding as a first-timer. But the audit itself still needs to happen.

Alongside other frameworks

Some people ask whether SOC 2 or Cyber Essentials would be a more "modern" alternative. SOC 2 is not a certification in the ISO sense; it is an attestation based on the AICPA Trust Services Criteria, and it is predominantly recognised in North America [6]. Cyber Essentials covers five basic technical controls and is a useful baseline, but it does not address governance, risk management, or supplier relationships in any depth.

ISO 27001 sits in between: broad enough to be a genuine management system, specific enough (with the 2022 controls) to address real technical threats, and recognised in 179 countries. It is also the framework most commonly referenced in enterprise procurement questionnaires, which is usually why you are reading this article.

FAQ

The current edition, ISO/IEC 27001:2022, was published on 25 October 2022. It replaced the 2013 edition, whose certificates expired on 31 October 2025 [2].

Yes. Certificate numbers nearly doubled between 2023 and 2024 [1], and regulatory pressure from NIS2, DORA, and the UK Cyber Security and Resilience Bill is driving further adoption. The 2022 revision's new controls for cloud, threat intelligence, and secure coding make it more relevant to modern tech companies than any previous edition.

The 2022 edition introduced control 5.23 (information security for use of cloud services) as a standalone requirement. The companion standard ISO 27017 provides additional cloud-specific guidance.

ISO standards are reviewed at least every five years, with a revision published when the committee agrees changes are needed. The gap between the 2005, 2013, and 2022 editions has been roughly eight to nine years.

Sources

  1. 1.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html
  2. 2.International Accreditation Forum. (2023). "IAF Resolution 2023-17: Transition to ISO/IEC 27001:2022". https://iaf.nu/en/iaf-documents/
  3. 3.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
  4. 4.ISO/IEC. (2022). "ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls". https://www.iso.org/standard/75652.html
  5. 5.Department for Science, Innovation and Technology. (2026). "Cyber Security Breaches Survey 2025/2026". GOV.UK. https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026
  6. 6.AICPA. (2022). "SOC 2 - SOC for Service Organizations: Trust Services Criteria". https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services

Found this useful? Pass it on.

Certification, without the drag.

A process built for how modern teams actually work, run by tech-first auditors, and honest about what you do and don't need.