Standards briefing · updated 5 August 2026
ISO/IEC 27001 — the transition is over, and that is the opportunity
The 2013 to 2022 transition deadline passed on 31 October 2025. Anyone who missed it faces full initial certification rather than a transition audit — larger scope, higher price, and commercial pressure from their own customers.
The lapsed cohort
Organisations that did not complete the transition by 31 October 2025 did not simply slip a deadline. Their certification lapsed. Re-entry is a full initial certification — a larger audit, a higher fee, and a gap in their certified status that their own customers are asking about.
That is a targeted campaign in its own right, and it is a warmer conversation than a cold transition pitch because the commercial pressure is already being applied by someone else.
Where the replacement pipeline is
For a 27001 practice whose transition work dried up last October, NIS2 is the replacement. Around 160,000 entities are in scope, fines reach €10m or 2% of global turnover, and ISO 27001 maps directly onto Article 21.
As of July 2026, 22 of 27 member states have transposed. The Commission referred Ireland, Spain, France and the Netherlands to the CJEU with financial sanctions requested on 8 July 2026. Dutch law came into force 15 August 2026; Austria follows on 1 October.
Prioritise the Netherlands, Austria, France, Ireland and Spain. Unlike almost everything else on the regulatory calendar, NIS2 has not been delayed or watered down — it accelerated.
On the next revision
There is no announced revision of ISO/IEC 27001. Anyone selling “27001:2027” is speculating. Do not put it in a proposal — this audience checks.
See the assessment running
A live environment with 23 sample clients and a real assessment at 60% complete. Nothing to install.