IAF Transition Requirements For 27001-2022
IAF Transition Requirements For 27001-2022
IAF Transition Requirements For 27001-2022
Issue 2
(IAF MD 26:2023)
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
The International Accreditation Forum, Inc. (IAF) facilitates trade and supports
industry and regulators by operating a worldwide mutual recognition arrangement
among Accreditation Bodies (ABs) in order that the results issued by Conformity
Assessment Bodies (CABs) accredited by IAF members can be accepted globally.
Accreditation reduces risk for business and its customers by assuring them that
accredited CABs are competent to carry out the work they undertake within their
scope of accreditation. ABs that are members of IAF and their accredited CABs are
required to comply with appropriate international standards and IAF mandatory
documents for the consistent application of those standards.
ABs that are signatories to the IAF Multilateral Recognition Arrangement (MLA) are
evaluated regularly by an appointed team of peers to provide confidence in the
operation of their accreditation programs. The structure of the IAF MLA is detailed in
IAF PL 3 - Policies and Procedures on the IAF MLA Structure and for Expansion of
the Scope of the IAF MLA. The scope of the IAF MLA is detailed in the IAF MLA
Status document.
The IAF MLA is structured in five levels: Level 1 specifies mandatory criteria that
apply to all ABs, ISO/IEC 17011. The combination of a Level 2 activity(ies) and the
corresponding Level 3 normative document(s) is called the main scope of the MLA,
and the combination of Level 4 (if applicable) and Level 5 relevant normative
documents is called a sub-scope of the MLA.
• The main scope of the MLA includes activities e.g. product certification and
associated mandated standards e.g. ISO/IEC 17065. The attestations made by
CABs at the main scope level are considered to be equally reliable.
• The sub scope of the MLA includes conformity assessment requirements e.g.
ISO 9001 and scheme specific requirements, where applicable, e.g. ISO 22003-
1. The attestations made by CABs at the sub scope level are considered to be
equivalent.
The IAF MLA delivers the confidence needed for market acceptance of conformity
assessment outcomes. An attestation issued, within the scope of the IAF MLA, by a
body that is accredited by an IAF MLA signatory AB can be recognized worldwide,
thereby facilitating international trade.
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
TABLE OF CONTENTS
1 Introduction ...............................................................................................................5
Issue No 2
Prepared by: IAF Technical Committee
Approved by: IAF Members Date: 03 February 2023
Issue Date: 15 February 2023 Application Date: 15 February 2023
Name for Enquiries: Elva Nilsen
IAF Corporate Secretary
Telephone: +1 613 454-8159
Email: [email protected]
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
The term “should” is used in this document to indicate recognised means of meeting
the requirements of the standard. A Conformity Assessment Body (CAB) can meet
these in an equivalent way provided this can be demonstrated to an Accreditation
Body (AB). The term “shall” is used in this document to indicate those provisions
which, reflecting the requirements of the relevant standard, are mandatory.
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
1. INTRODUCTION
This document provides transition requirements for the following and is mandatory for
the related IAF MLA AB signatories and accredited CABs:
2.1 Background
According to the related ISO policy, ISO/IEC FDIS 27001:2022 was prepared through
integrating ISO/IEC 27001:2013 with ISO/IEC 27001:2013/COR 1:2014, ISO/IEC
27001:2013/COR 2:2015 and ISO/IEC 27001:2013/DAmd1 in July 2022. Additionally,
ISO required ISO/IEC FDIS 27001:2022 to align with the harmonized structure for
management system standards (MSS) defined in Annex SL of the ISO/IEC
Directives, Part 1, Consolidated ISO supplement, 2022. Based on the result of the
FDIS ballot, ISO published ISO/IEC 27001:2022 on 25 October 2022.
Note 1: ISO/IEC 27001:2013/DAmd1 was prepared to align with ISO/IEC 27002:2022, which
updated Annex A and the notes of Clause 6.1.3 c). DAmd is the abbreviation of Draft
Amendment.
Note 2: No more than two separate documents in the form of amendments shall be published
modifying a current International Standard (see ISO/IEC Directive Part 1, 2022, Clause 2.10.3),
therefore, the new edition of ISO/IEC 27001 had to be published after the preparation of ISO/IEC
27001:2013/DAmd1.
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
Note 2: Compared with the old edition, the number of information security controls in ISO/IEC
27002:2022 decreases from 114 controls in 14 clauses to 93 controls in 4 clauses. For the
controls in ISO/IEC 27002:2022, 11 controls are new, 24 controls are merged from the existing
controls, and 58 controls are updated. Moreover, the control structure is revised, which introduces
“attribute” and “purpose” for each control and no longer uses “objective” for a group of controls.
The impact of the changes in ISO/IEC 27001:2022 includes, but is not limited to the
introduction of a new Annex A and Clause 6.3 - Planning for changes because:
The requirements in ISO/IEC 27001 that use the reference control set in Annex A are
the comparison process between the information security controls determined by the
organization and those in Annex A (6.1.3 c)) and the production of a Statement of
Applicability (6.1.3 d)). By comparing the necessary information security controls to
those in Annex A, the organization may confirm that any necessary information
security control from the reference set in Annex A of ISO/IEC 27001:2022 is not
inadvertently omitted.
Such comparison might not lead to the discovery of any necessary information
security control that has been inadvertently omitted. However, if inadvertently omitted
necessary information security controls are discovered, the organization shall update
its risk treatment plans to accommodate the additional necessary information security
controls and implement them.
As implied above, the impact of ISO/IEC 27001:2022 on the organizations that have
implemented ISMS need not be significant.
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
3. KEY TIMESCALE
4.1 AB Actions
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
Transition audit Y 1) CAB may conduct the transition audit in conjunction with
the surveillance audit, recertification audit or through a
separate audit.
2) The transition audit shall not only rely on the document
review, especially for reviewing the technological
information security controls.
3) The transition audit shall include, but not be limited to the
following:
• The gap analysis of ISO/IEC 27001:2022, as well as
the need for changes to the client’s ISMS.
• The updating of the statement of applicability (SoA).
• If applicable, the updating of the risk treatment plan.
• The implementation and effectiveness of the new or
changed information security controls chosen by the
clients.
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
4.3 Other
4.3.1 The CAB office assessment following the transition decision shall focus on the
verification of the implementation of the transition arrangement before the CAB’s
transition arrangement was totally completed. This office assessment shall include
the following, at a minimum:
4.3.2 All witness assessments selected following the transition decision shall be
based on ISO/IEC 27001:2022 and focus on the CAB’s competence for conducting
an audit based on ISO/IEC 27001:2022.
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2
Further Information
For further information on this document or other IAF documents, contact any
member of IAF or the IAF Secretariat.
For contact details of members of IAF see the IAF website: http://www.iaf.nu.
Secretariat:
Elva Nilsen
IAF Corporate Secretary
Telephone: +1 (613) 454-8159
Email: [email protected]
Issued: 15 February 2023 Application Date: 15 February 2023 IAF MD 26:2023, Issue 2