+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Swedish
Brand Compliance
  • Our story
    • Accreditations, Conditions & Regulations
  • News
  • Contact form
  • What is ISO 27001?
  • ISO 27701 certification & audit
  • GDPR certification & audit
  • Directions
Application certification process
  • About us
    • Accreditations
    • Vacancies
    • Compliment, complaint or tip
    • Privacy Statement
  • Knowledge base
  • News
  • Quality
    • Application certification process
    • ISO 9001 certification & audit
    • ISO 22301 certification
    • Private Lease Quality Mark
    • Network Compliance Audits
    • Gap analysis
  • Information Security
    • Application certification process
    • ISO 19770-1 certification
    • ISO 27001 certification
    • ISO 27017 and ISO 27018 certification
    • Baseline Information Security Government (BIO)
    • NEN 7510 certification
    • ISAE 3402 certification
    • SOC 2 statement
    • Gap analysis
  • Privacy
    • Application certification process
    • Certification standard BC 5701:2022
    • BC 5701 (GDPR) certification
    • ISO 27701 certification
    • Gap analysis
  • Academy
    • Free online training course ISO 27001:2022
    • ISO 27001 Lead Implementer training course (version ISO 27001:2022)
    • ISO/IEC 19770-1 Practitioner course
    • Inhouse Training ISO 27001 Lead Implementer
    • Operational Cyber Security using IEC 62443 (OT security)
    • Implementation training BC 5701 (GDPR)
    • Request training
  • Contact
    • Contact Form
    • Application certification process
    • Introductory meeting
    • Directions

Certification process

  • How long does ISO certification take?
  • What is a certification cycle?
  • Applying for a certification process
  • Certification processes with multiple locations
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities management system
  • Certificate suspended or revoked? This is how you solve it!

Transfer of certification

  • Transfer of certification

Logo use

  • The use of certification logos

General

  • The Brand Compliance glossary
  • What is a management system?
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The differences between ISO 27001 and NEN 7510

ISO 27001:2022

  • ISO 27001:2022 – FAQ transition
  • ISO 27001:2022 – Transition process

ISO 27001:2022 – Transition process

Content
  • Version 2017 or 2022? 
  • Transition audit ISO 27001:2022
    • Transition activities 
    • Transition period ISO 27001:2022
      • Additional information 

In this article we describe the planned process for the transition from ISO 27001:2017 to ISO 27001:2022. We try to inform you as well as possible about how we deal with offering, planning and conducting audits, issuing certificates and the costs. 

ISO 27001:2022 Version 2017 or 2022?  #

As of February 1, 2023, we offer new customers proposals for ISO 27001:2022 certification processes. 

Customers who have already received a proposal for ISO 27001:2017 are basically audited against that version of the standard. However, an initial ISO 27001:2017 audit may no longer be performed after 1 May 2024. This means that if you wish to start a certification process after 1 May 2024, you must have set up your management system based on ISO 27001:2022. This also applies to recertifications, these can no longer be performed against the old version of the standard after this date.

Transition audit ISO 27001:2022 #

If your organization already is certified for ISO 27001:2017, a transition audit must take place to the new version of the standard. Preferably, this transition audit is scheduled as a separate audit, so that both you and the auditor can fully focus on the changes in the management system. 

The following steps must be planned and carried out for the transition audit: 

  • When you are ready (or know when you will be ready) for the audit to take place, please contact us at: planning@brandcompliance.com, +31 (0) 73 220 20 30. Your audit will then be scheduled by a Brand Compliance Customer and Project Coordinator. 
  • You will receive an audit plan with the subjects that will be discussed at least during the transition audit. 
  • The transition audit takes half a day, for which the agenda below will be used.
    • Opening meeting;
    • Explanation from you on the transition to the new standard;
    • Audit on the changes in the ISMS (gap between ISO 27001:2017 and ISO 27001:2022);
    • Audit on the updated Statement of Applicability;
    • Audit on the update of the risk treatment plan;
    • Audit on the implementation and effectiveness of the new or changed controls chosen by you. You must determine this by means of an internal audit and management review in relation to the new standard;
    • Closing meeting.
  • Our auditor prepares an audit report. 
  • You will receive the report after it has been internally reviewed. 
  • If nonconformities are found, you will be given a term to deal with them. 

When the conditions of ISO 27001:2022 are met, the time has come for you to receive a new certificate! The ISO 27001:2022 certificate will contain the same expiration date as your current certificate. 

Transition activities  #

For the above activities, at least one day of work will be delivered; this includes: 

  • The audit; 
  • Drafting the report; 

After the audit day, the following activities will be carried out for you:

  • The administrative handling of the audit; 
  • The certification process; 
  • Drawing up, registering and issuing the new certificate. 

If nonconformities are found during the audit, Brand Compliance may need more time in total to complete the transition process. 

Transition period ISO 27001:2022 #

The transition period has an end date of October 1, 2025. If the requirements of the new ISO 27001:2022 are not met at the end of this period, the current certificate will be revoked. 

Additional information  #

Any further questions regarding the transition process? View the FAQ or our news article about accreditation. You can also contact Brand Compliance at info@brandcompliance.com on telephone number +31 (0)73 220 2000.

Updated on 17 February 2023
ISO 27001:2022 – FAQ transition
Content
  • Version 2017 or 2022? 
  • Transition audit ISO 27001:2022
    • Transition activities 
    • Transition period ISO 27001:2022
      • Additional information 

Search

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16
SE-111 20 Stockholm

+46 73 157 7805
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2023 Brand Compliance