iso27001partnersUK certification, costed Get a cost estimate

Worth an hour

The supplier certificates that expired quietly in October 2025

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 2026-09-20
By the iso27001partners.co.uk editorial team · Published 2026-09-20 · Last reviewed 2026-09-20 · 6 min read
4 primary sources cited on this page. How we check what is on this site

Key points

  • Certificates naming ISO/IEC 27001:2013 ceased to be valid on 31 October 2025.
  • A supplier assurance folder assembled before then is now partly out of date by default.
  • Check three things on every certificate - edition, expiry, and whether the scope covers what you buy.
  • Your own Annex A supplier controls are what an auditor samples this against.

There is an hour of work sitting in most organisations’ supplier folders, and almost nobody has done it.

ISO/IEC 27001:2022 was published in October 2022, and the transition rules gave existing certificate holders three years to move. That window closed on 31 October 2025. Certificates issued against the 2013 edition stopped being valid on that date, whoever issued them and however long they had left to run.

Which means any supplier assurance pack assembled before late 2025 and not revisited since contains certificates that are now expired by definition rather than by date.

Why this is easy to miss

A certificate does not change appearance when the edition behind it is withdrawn. It still has a logo, a number, a scope and an expiry date that may well be in the future. If nobody reads the standard number, nothing looks wrong.

The organisations most exposed are the ones that did supplier assurance properly the first time. They collected certificates, filed them, recorded the expiry dates, and set reminders against those dates. The reminder fires when the certificate says it expires — which, for a 2013-edition certificate, is not when it actually stopped meaning anything.

The three checks

For each certificate in the folder:

Which edition does it name? If it says ISO/IEC 27001:2013, it is expired regardless of the date printed on it. Ask the supplier for their current one.

Is it current? The ordinary expiry check. Certificates run three years with surveillance audits in between, and a suspended or withdrawn certificate does not announce itself to you.

Does the scope cover what you actually buy from them? This is the one that finds the most problems and gets checked the least. A certificate scoped to a supplier’s UK operations does not cover the service delivered from elsewhere. A certificate scoped to one product line says nothing about the other product you use. The scope is printed on the certificate for exactly this reason.

Why an auditor cares

If you are certified yourself, this is not housekeeping. It is a control.

The supplier relationship controls in Annex A ask you to manage information security risk in your supply chain and to monitor and review supplier service delivery. A folder of certificates nobody has examined is the visible evidence of a control that is documented but not operating, and that distinction is exactly what a Stage 2 or surveillance auditor is trained to find.

The awkward version of this conversation goes: you present the supplier register, the auditor picks one supplier, asks to see the assurance evidence, and the certificate produced names a withdrawn edition of the very standard being audited. It is a small finding with an unhelpful amount of symbolism attached.

While you have the folder open

Two other things are worth checking at the same time, because you will not open it again for a year.

Is the certificate accredited? An accredited certificate comes from a body assessed by a national accreditation body and carries an accreditation symbol and number you can resolve against a register. A non-accredited one comes from a body nobody has assessed. Both look like certificates.

Do you have anything at all for your most critical suppliers? Most registers are complete for the suppliers who volunteered a certificate and thin for the ones who did not. The second group is usually more interesting.

None of this is difficult. It is an hour, once a year, and the calendar entry is better set against your own management review than against the dates printed on other people’s paperwork.

Sources cited on this page

  1. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
  2. ISO/IEC 27001:2022
  3. BS EN ISO/IEC 17021-1:2015, clause 5.2

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

All notes · Cost calculator · ISO 27001 consultants

Want this costed for your own scope?

Enter the number of people who would be inside it. The audit days come from the published rule; nothing is charged to you.

Get a costed answer, not a call-back to discuss pricing

Five questions, all of them click-only. Your details are the last step, never the first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now