Transition Audit
A transition audit is a focused assessment of an organization's move from one version of a certification standard to a newer version. For example, an ISO/IEC 27001-certified organization may undergo a transition audit to move from an earlier edition of the standard to a more recent one. It differs from a recertification audit, which renews the certification at the end of its cycle rather than migrating the underlying standard version.
A transition audit is an assessment conducted by an accredited certification body to evaluate whether an organization's information security management system (ISMS) conforms to the requirements of a newer edition of a certification standard, such as the move from ISO/IEC 27001:2013 to ISO/IEC 27001:2022. In the ISO 27001 context this typically involves reviewing changes to the ISMS requirements in clauses 4 through 10 and the corresponding updates to the reference controls in Annex A, which were restructured in the 2022 revision. It is distinct from a recertification audit, which renews certification at the end of a certification cycle, and its scope is limited to the defined ISMS and the specific version change being evaluated; it does not by itself guarantee freedom from security incidents. Depending on scope and the certification body, a transition audit may be combined with a scheduled surveillance or recertification activity.
Why it matters
When a certification standard is revised, existing certificates do not automatically carry over to the new edition. Certification bodies and accreditation systems typically set a transition window during which organizations must demonstrate conformance to the newer version, after which certificates issued against the superseded edition cease to be valid. A transition audit is the mechanism by which an accredited certification body confirms that an organization's information security management system now meets the updated requirements, allowing the certificate to remain current rather than lapsing.
For ISO/IEC 27001, the move from the 2013 edition to the 2022 revision illustrates why transition audits matter. The 2022 revision restructured the Annex A reference controls into a smaller set of themes and introduced updates that organizations must reflect in their Statement of Applicability and supporting documentation. A transition audit gives organizations a defined, focused opportunity to have those changes assessed rather than waiting for a full recertification cycle, and it helps ensure continuity of the certificate throughout the version change.
It is important to understand the limits of a transition audit. Its scope is confined to the defined ISMS and the specific version change being evaluated, and passing a transition audit does not by itself guarantee freedom from security incidents. Organizations should treat it as evidence of conformance to a newer edition of the standard within a stated scope, not as a broad assurance of security outcomes.
Who it's relevant to
Inside Transition Audit
Common questions
Answers to the questions practitioners most commonly ask about Transition Audit.