ISO 27001:2022 transition checklist and audit evidence
The ISO 27001:2022 transition is not only a documentation update. Auditors will expect evidence that your ISMS was reviewed, updated, and operating effectively under the 2022 requirements. The International Accreditation Forum mandatory document sets a 36-month transition period from the end of the publication month, which points to 31 October 2025 as the completion date for certification transitions. ISO 27001:2022 was published on 25 October 2022. If you start with a structured gap assessment now, you can avoid rushed transition audits and reduce nonconformities.
Why this transition matters
Time efficiency
Planned transition work costs less than urgent remediation close to an audit.
Audit ready formatting
Transition success is proven through evidence: updated SoA, risk treatment updates, internal audit outputs, and management review decisions.
Risk reduction
The new Annex A alignment and planning for change expectations reduce blind spots in modern threat environments.
Knowledge transfer
A good transition pack becomes onboarding for new ISMS owners.

What changed, in practical terms
IAF notes that ISO 27001:2022 includes a new Annex A aligned to ISO 27002:2022, plus structural updates aligned to Annex SL, and additions like planning for changes. The impact is often manageable, but auditors will check that you updated the right artefacts and implemented changes effectively.
The ISO 27001:2022 transition checklist
1) Run a focused gap assessment
- Map existing controls and processes to the updated Annex A structure
• Identify new or changed controls that affect your scope
• Confirm your risk assessment and risk treatment approach still fits
2) Update your Statement of Applicability
IAF calls out updating the Statement of Applicability as part of the transition audit scope.
• Update control selection, justification, and implementation status
• Ensure SoA matches real operations, not policy statements only
3) Update the risk treatment plan if needed
IAF also highlights updating the risk treatment plan where applicable.
• Confirm new controls are reflected in treatment actions
• Confirm owners, due dates, and evidence records exist
4) Evidence of implementation and effectiveness
The transition audit should not rely only on document review, especially for technology controls.
Collect evidence such as:
• Access control logs and reviews
• Supplier assessments and security clauses
• Vulnerability management outputs
• Incident response exercises and post incident actions
• Backup and recovery tests
• Security awareness completion and effectiveness checks
5) Internal audit and management review evidence
- Internal audit programme updated to cover changed areas
• Findings closed with root cause and corrective actions
• Management review minutes show decisions, resourcing, and risk acceptance

A word from the auditor’s perspective
Auditors look for alignment: scope, risk, SoA, treatment plan, and real evidence must tell the same story. A “paper transition” often fails when operational evidence is thin or inconsistent with the SoA.
To pass an ISO 27001:2022 transition audit, you need a gap assessment, updated SoA, updated risk treatment where needed, and evidence that controls are working. If you want, we can run a structured transition gap assessment workshop and deliver an audit evidence pack that matches the IAF transition expectations.