Skip to main content
Category: Certification and Accreditation

Transition Audit

Also known as: Transition Assessment, Migration Audit
Simply put

A transition audit is a focused assessment of an organization's move from one version of a certification standard to a newer version. For example, an ISO/IEC 27001-certified organization may undergo a transition audit to move from an earlier edition of the standard to a more recent one. It differs from a recertification audit, which renews the certification at the end of its cycle rather than migrating the underlying standard version.

Formal definition

A transition audit is an assessment conducted by an accredited certification body to evaluate whether an organization's information security management system (ISMS) conforms to the requirements of a newer edition of a certification standard, such as the move from ISO/IEC 27001:2013 to ISO/IEC 27001:2022. In the ISO 27001 context this typically involves reviewing changes to the ISMS requirements in clauses 4 through 10 and the corresponding updates to the reference controls in Annex A, which were restructured in the 2022 revision. It is distinct from a recertification audit, which renews certification at the end of a certification cycle, and its scope is limited to the defined ISMS and the specific version change being evaluated; it does not by itself guarantee freedom from security incidents. Depending on scope and the certification body, a transition audit may be combined with a scheduled surveillance or recertification activity.

Why it matters

When a certification standard is revised, existing certificates do not automatically carry over to the new edition. Certification bodies and accreditation systems typically set a transition window during which organizations must demonstrate conformance to the newer version, after which certificates issued against the superseded edition cease to be valid. A transition audit is the mechanism by which an accredited certification body confirms that an organization's information security management system now meets the updated requirements, allowing the certificate to remain current rather than lapsing.

For ISO/IEC 27001, the move from the 2013 edition to the 2022 revision illustrates why transition audits matter. The 2022 revision restructured the Annex A reference controls into a smaller set of themes and introduced updates that organizations must reflect in their Statement of Applicability and supporting documentation. A transition audit gives organizations a defined, focused opportunity to have those changes assessed rather than waiting for a full recertification cycle, and it helps ensure continuity of the certificate throughout the version change.

It is important to understand the limits of a transition audit. Its scope is confined to the defined ISMS and the specific version change being evaluated, and passing a transition audit does not by itself guarantee freedom from security incidents. Organizations should treat it as evidence of conformance to a newer edition of the standard within a stated scope, not as a broad assurance of security outcomes.

Who it's relevant to

Compliance and GRC Managers
Those responsible for maintaining an ISO 27001 certificate need to plan for transition audits when a standard is revised, ensuring the ISMS documentation, Statement of Applicability, and risk assessment reflect the newer edition before the transition window closes.
Internal Auditors and ISMS Owners
Internal audit and ISMS teams typically prepare the organization for the transition by identifying changes specific to their environment on a case-by-case basis and aligning controls with the updated requirements ahead of the certification body's assessment.
Certification Bodies
Accredited certification bodies perform the transition audit, evaluating conformance to the newer edition within the defined ISMS scope and determining whether the certificate can be updated to the current standard version.
Executive and Risk Leadership
Leaders accountable for certification continuity benefit from understanding that a transition audit maintains the validity of an existing certificate through a version change, while recognizing that its scope is limited to the defined ISMS and does not guarantee freedom from security incidents.

Inside Transition Audit

Purpose of a Transition Audit
An assessment conducted to move an organization's ISO/IEC 27001 certification from one edition of the standard to a newer one, most commonly the transition from the 2013 revision to the 2022 revision. It confirms that the information security management system (ISMS) continues to meet the requirements of the updated standard.
Annex A Restructuring Review
Because Annex A was restructured in the 2022 revision (from 114 controls in the 2013 version to 93 controls organized into four themes), a transition audit typically reviews how the organization has re-mapped its controls and updated its Statement of Applicability to reflect the new reference control set. Exact treatment depends on the certification body and scope.
Statement of Applicability Update
The transition typically requires the organization to revise its Statement of Applicability so that control selection, justification, and inclusion or exclusion decisions align with the Annex A structure of the applicable edition, informed by the risk assessment.
ISMS Clause Verification
The audit examines whether the certifiable requirements in clauses 4 through 10 continue to be satisfied, since any changes introduced by the newer edition to the ISMS requirements must be reflected in the management system.
Certification Body Involvement
A transition audit is performed by an accredited certification body, and its outcome affects the certification issued against the standard. It is not an attestation or a report in the SOC 2 sense; it results in confirmation or continuation of certification under the updated edition, subject to the defined ISMS scope.
Scoping and Timing
The transition may be conducted as part of a scheduled surveillance or recertification audit, or as a dedicated engagement, depending on decisions made by the certification body and the organization. The precise approach and duration vary by scope.

Common questions

Answers to the questions practitioners most commonly ask about Transition Audit.

Does a transition audit convert a SOC 2 report into an ISO 27001 certificate, or vice versa?
No. A transition audit does not transform one framework's outcome into the other. A SOC 2 examination results in an attestation report issued by a licensed CPA firm under the AICPA's SSAE 18 standard, while ISO 27001 results in a certification issued by an accredited certification body against the ISMS requirements. These are distinct engagements performed under different standards, and one cannot be exchanged for the other through a transition audit. Where the term applies to moving between framework versions or auditors, it still remains within a single framework's structure rather than crossing between them.
If our organization already holds one framework's outcome, does a transition audit let us skip most of the work for the other?
Not automatically. Mapping between SOC 2 and ISO 27001 is possible but partial, and satisfying one framework does not by itself satisfy the other. Some evidence and control activities may be reusable across engagements, but the SOC 2 Trust Services Criteria and the ISO 27001 clause 4-10 requirements plus Annex A reference controls are structured differently and assessed differently. Any efficiency gained typically depends on scope, the auditor or certification body, and how well existing controls align with the criteria being newly assessed.
How does a transition audit typically address a change in the ISO 27001 standard version?
When transitioning between editions of ISO 27001, the certification body typically reviews how the ISMS has been updated to reflect the revised requirements, including any restructuring of Annex A. For example, the 2022 revision reorganized Annex A into four themes and changed the reference control count relative to the 2013 version. In most engagements the organization is expected to update its Statement of Applicability and risk assessment accordingly. The exact expectations and timelines depend on the certification body and the applicable accreditation rules.
What documentation should we prepare before a transition audit?
The specific documentation depends on the framework and scope, but organizations transitioning within ISO 27001 typically prepare an updated Statement of Applicability, current risk assessment and treatment records, and evidence of ISMS operation across clauses 4 through 10. For a SOC 2 engagement, the relevant materials generally include control descriptions and supporting evidence tied to the Trust Services Criteria in scope. Confirm the precise requirements with your auditor or certification body, as expectations vary by engagement.
How should we handle scope changes during a transition audit?
Any change to the defined scope should be reflected in the relevant scoping documents before the audit proceeds. For ISO 27001 this typically means updating the ISMS scope statement and Statement of Applicability; for SOC 2 it means revisiting which Trust Services Criteria categories apply, recalling that Security (the Common Criteria) is required while Availability, Processing Integrity, Confidentiality, and Privacy are optional and selected based on scope. It is important to remember that any resulting SOC 2 report attests only to the controls and period covered, and any ISO 27001 certificate covers only the defined ISMS scope.
For a SOC 2 transition, does the review period carry over across the transition?
It depends on the type of examination and scoping decisions. A SOC 2 Type I assesses the suitability of design of controls at a point in time, while a Type II assesses both design and operating effectiveness over a defined review period whose length is set by scoping decisions rather than fixed. During a transition, the applicable period and whether prior coverage is relevant are determined by the CPA firm and the engagement scope, so these details should be confirmed with the auditor rather than assumed to carry over.

Common misconceptions

A transition audit produces a new report attesting to control effectiveness, similar to a SOC 2 examination.
ISO/IEC 27001 transition activities result in continuation or renewal of a certification issued by an accredited certification body, not an attestation report. SOC 2 is a separate attestation examination performed by a licensed CPA firm under SSAE 18, and the two outcomes should not be conflated.
Transitioning to the newer edition simply means adopting fewer controls, since the count dropped from 114 to 93.
The change in Annex A control counts between the 2013 and 2022 versions reflects restructuring and consolidation into four themes rather than a straightforward reduction. Organizations typically must re-map controls and revise the Statement of Applicability; the certifiable ISMS requirements in clauses 4 through 10 still apply, and specific control numbers depend on the edition cited.
Completing a transition audit guarantees the organization is free from security breaches.
An ISO 27001 certificate, including one confirmed through a transition audit, covers only the defined scope of the ISMS and confirms conformity with the standard at the time of assessment. It does not guarantee freedom from breaches or cover activities outside the certified scope.

Best practices

Review the differences between your current and target editions of the standard early, focusing on both the Annex A restructuring and any changes to the ISMS requirements in clauses 4 through 10.
Re-map existing controls to the applicable edition's Annex A themes and update the Statement of Applicability so that inclusion, exclusion, and justification decisions are consistent with the current risk assessment.
Confirm the certification body's expectations for the transition approach, including whether it will be combined with a surveillance or recertification audit, since scoping and timing vary by engagement.
Verify that the ISMS scope statement remains accurate and that certification will continue to reflect only the intended boundaries of the management system.
Update internal documentation, records, and evidence to reference the applicable edition and specify version numbers whenever citing control counts, since precise figures depend on the edition.
Where the organization also maintains a SOC 2 report or other standards, keep the frameworks distinct and avoid assuming that transition to the newer ISO 27001 edition satisfies SOC 2 or related requirements, since mapping between frameworks is partial.