News

Information about changes to the ISO/IEC 27001:2022 standard

2024 - 10 - 25

On October 25, 2022, the international standard ISO/IEC 27001:2022 was released. Lithuania adopted this standard in 2023.

Organizations that have implemented a management system in accordance with the provisions of the ISO/IEC 27001:2013 standard must update their management system by applying the provisions set out in the document IAF MD 26:2023 "Transition requirements for ISO/IEC 27001:2022" (document attached), i.e. update their management system in accordance with the requirements of the new version of the standard within 3 years (with reservations) and assess it during an external audit.

NOTE: The attached document provides basic guidelines for the changes.

The transition period is 36 months, meaning that until October 25, 2025, in order to maintain a valid certificate, you need to undergo an audit according to the requirements of the ISO/IEC 27001:2022 standard.

You can read more about auditing changes to the standard in the "Regulations for Certification (Conformity Assessment) of Management Systems" section 6.2. "Special audits. Audit of changes to the requirements of the standard(s)" (the regulations can be found here).