Cybersecurity
ISO/IEC 27001 in 2026: No New Edition, But Real Changes for NZ Businesses
The current standard has not changed edition
There is no ISO/IEC 27001:2026 edition, and anyone selling you one is mistaken. The current published standard is ISO/IEC 27001:2022, published in October 2022 and carrying a 2024 climate-action amendment. If you are aligning or certifying in 2026, you align with the 2022 edition and address that amendment where it applies.
The 2013 edition is officially gone
The transition from the 2013 edition ended on 31 October 2025. Certifications issued against ISO/IEC 27001:2013 expired after that date. Organisations that did not transition in time are no longer certified under the old edition and must either recertify against the 2022 edition or begin the certification process again.
If a supplier or partner is still presenting a certificate dated against the 2013 text, treat it as a live procurement question - not a formality.
The climate-action amendment is in force
Published in February 2024, Amendment 1 adds a climate-action consideration to the standard. It requires organisations to determine whether environmental changes and extreme weather are relevant issues in their context, and to recognise that interested parties may have environment-related requirements. If you conclude they are not relevant, you must still document that decision.
It is a small change with a real point: floods, fires and supply-chain disruption can affect the availability of the systems and data your ISMS protects, so they belong in the risk conversation.
What the 2022 revision changed in Annex A
The 2022 revision restructured Annex A from 114 controls in 14 domains down to 93 controls grouped into four themes: organisational, people, physical and technological. The reduction came from merging similar controls and adding 11 new ones - covering areas such as threat intelligence, cloud service security, configuration management, information deletion, data masking, data leakage prevention, monitoring, web filtering and secure coding.
The standard also added clause 6.3 on planning changes and sharpened the requirements around interested parties and process interactions. The core ISMS machinery - context, leadership, risk assessment, risk treatment, internal audit and management review - is unchanged, which is why the transition was mostly about re-mapping evidence rather than rebuilding.
What auditors expect in 2026
The emphasis has moved from the presence of controls to their effectiveness. Auditors increasingly want to see documented risk treatment plans, an up-to-date statement of applicability, and traceable evidence that controls operate continuously - not a binder assembled the week before the audit. Environmental risk considerations are part of the review too.
At the same time, procurement has tightened. Enterprise buyers, councils, ports, health providers and insurers now ask for assurance evidence before they sign, and ISO/IEC 27001 certification is frequently the baseline. Certification is issued by an accredited certification body - we prepare organisations for it, we do not issue it ourselves.
Where New Zealand businesses should start
Start with a gap analysis: it tells you honestly where you stand against the 2022 standard, what the effort and cost look like, and whether certification is the right move yet. Then build the ISMS around how your business actually operates - not a template dump - and fix the foundational controls (MFA, patching, verified backups, access reviews) that auditors examine first and that reduce real risk the most.
Quick answers
No. The current edition is ISO/IEC 27001:2022, with the 2024 climate-action amendment. There is no separate 2026 edition, and certifications based on the old 2013 text expired after 31 October 2025.
Yes. Transition ended on 31 October 2025 and 2013 certifications expired after that date. You now need to certify against ISO/IEC 27001:2022, which typically starts with a gap analysis to map existing controls and evidence.
Need help putting this into practice?
The Click IT team is based in Tauranga and helps businesses across New Zealand act on advice like this.
Last updated: 2026-10-03. This article is general information, not specific advice for your situation - talk to us about your circumstances.