The ISO 27001 deadline already passed. Is your certificate still valid?
If you have searched “ISO 27001 2026” recently, you have probably landed on a dozen articles implying there is a new version of the standard. There isn’t. ISO/IEC 27001:2022 is still the current standard. What changed is the deadline that used to give people breathing room, and a companion document that reframes how auditors expect you to justify your controls.
Here is what is actually going on, and why it matters more in South Africa than the generic compliance blogs let on.
The transition deadline already passed
If your organisation was still certified against ISO 27001:2013, the window to transition to the 2022 version closed on 31 October 2025. That deadline was set by the International Accreditation Forum three years earlier. Nobody can claim it snuck up on them.
If you missed it, your 2013 certificate is not just due for renewal. It is invalid. There is no quick transition audit anymore. You go back to square one: a full Stage 1 and Stage 2 audit against the 2022 requirements, from scratch.
If you are not sure which version your certificate is on, that is the first thing to check this week, not the fifth thing on next quarter’s list.
There is no “ISO 27001:2026”. Here is what did change
ISO/IEC 27001:2022 remains the current standard, with a minor 2024 amendment addressing climate related requirements. No new edition of 27001 itself has been published.
What did land in 2026 is a revised ISO/IEC 27000, the overview document for the whole ISMS standards family. It was rewritten from the ground up. The title dropped “and vocabulary.” The number of formally defined terms shrank from 77 to 12. And it now states plainly what practitioners have assumed since 2022: Annex A is a list of reference controls, not a checklist of control objectives you tick off.
That distinction sounds academic until an auditor asks you to justify why you selected, or excluded, a specific Annex A control based on your own risk assessment, rather than just showing you implemented it because it was on the list. That is the actual shift. Less “did you do the thing,” more “can you show your working.”
Why this bites harder in South Africa
Locally, ISO 27001 is adopted as SANS 27001, and it is explicitly positioned to align with POPIA and the Cybercrimes Act. Certification itself is still voluntary. Enforcement of the law underneath it is not.
POPIA penalties top out at R10 million, and the Information Regulator has moved from warnings to actually issuing multi million rand infringement notices. The 2025 amendment regulations tightened consent and breach reporting requirements further. For a business that has to show a regulator or a client it takes information security seriously, saying “we are POPIA compliant, trust us” does not land the way a structured ISMS with real risk assessments behind it does.
For the SMB segment specifically, the 50 to 200 person companies with an IT function but no dedicated security team, this is exactly the gap. You are now expected to produce evidence, not intentions, and most internal teams do not have the bandwidth to build and defend a full ISMS from a standing start.
The AI question nobody has fully answered yet
As AI tooling creeps into everyday operations, a genuine open question is whether ISO 27001 alone still covers you, or whether you also need ISO 42001 for AI management specifically. There is no clean industry consensus yet. For most SMBs, the practical answer today is to get your 27001 foundation right first: risk assessment discipline, access control, incident response. That foundation is what an AI governance layer gets bolted onto later, not a replacement for it.
What to check this week
- Certificate version – confirm which version your certificate, or your target framework, is actually built against. 2013 is dead weight now.
- Control justification – make sure your Annex A control selection is backed by a documented risk assessment, not just a completed checklist. That is what 2026’s clarified guidance expects auditors to ask for.
- The real driver – if POPIA exposure is what is actually pushing this, treat the ISMS as your evidence trail, not a side project.
None of this requires a big bang overhaul. It requires knowing exactly where the gaps are before someone else, a regulator, a client’s due diligence team, or an attacker, finds them for you.
If you want a clear picture of where your ISMS actually stands against the 2022 requirements, get in touch.
References
- ISO 27001:2022 Deadline Puts Legacy Certificates At Risk, BrightDefense
- ISO 27001:2022 Transition, Preparing for the October 2025 Deadline, LRQA
- Two Surprising Updates in ISO 27000:2026, GRC Lab
- Guide to ISO 27001 Certification in South Africa, ISMS.online
- Prevent Data Breaches and Compliance Risks for South African Businesses in 2026, Apliso Plus
- POPIA Compliance in South Africa: A Complete Guide for 2026, Qualysec




