Homepage / Favorites / 中文版
Announcement on Certification Conversion of ISO/IEC 27001:2002
Public Time:2023-02-13 Origin:CHINA QUALITY CERTIFICATION CENTRE

Dear certified organizations,

International Standardization Organization (ISO) issued ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection - Information Security Management Systems - Requirements in October 2022, which replaces ISO/IEC 27001:2013. In August 2022, the Member Assembly of the International Accreditation Forum (IAF) released the IAF MD26:2012 Conversion Requirements for ISO/IEC 27001:2022 (Version 1). The document identifies the main changes and impacts of ISO/IEC 27001:2002, proposes the conversion cycle, and specifies the specific requirements for the implementation of the conversion by accreditation bodies and certification bodies.

China National Accreditation Service for Conformity Assessment (CNAS) has carried out the work of ISMS certification bodies related to the accreditation business according to the requirements of international organizations and in combination with its own situation, and issued the CNAS-EC-066:2022 Instructions for Certification Conversion of ISO/IEC 27001:2002 Certification Standard Version, an explanatory document related to certification, on November 14, 2022.

CQC will carry out the conversion of ISO/IEC 27001:2002 certification standards according to the requirements of CNAS and IAF. Notice on the conversion of ISO/IEC 27001:2002 certification standards is shown as follows:

(I) Complete the conversion of all certified customers with certification standards including ISO/IEC 27001:2013 before October 31, 2025. All certificates including ISO/IEC 27001:2013 certification standards will be invalid from November 1, 2025.

(II) CQC will not issue the initial certificate with ISO/IEC 27001:2013 certification standard after October 31, 2023; and recertification certificates with ISO/IEC 27001:2013 certification standard after October 31, 2024, according to the conversion requirements of CNAS to protect the interests of certified customers. But certificate change is available. Ensure that the on-site audit and certification decision of the signed certification contract containing the ISO/IEC 27001:2013 certification standard is completed before the corresponding date. Customers need to establish a management system according to the standards and requirements in the new version and reapply for certification if the certification fails due to the problems found in the certification decision.

(III) The certificates issued before CQC obtained the recognition of the new standard do not bear the approval mark of CNAS because CNAS has just carried out the accreditation according to ISO/IEC 27001:2002 standard. The certificates with the approval mark will be replaced by CQC according to the scope of accreditation upon approval.

(IV) Relevant certified organization may complete the conversion of ISO/IEC 27001:2022 standards in combination with annual supervision or recertification, and determine whether it meets the conversion requirements in combination with the increase of at least 0.5 day of a reviewer (the specific days need to be determined after review according to the actual situation) to supervise and audit the on-site audit of standard conversion.

(V) For details of the version change, please contact the companies or the System Department of Certification Center of the China Certification & Inspection Group.

Contact information of each company can be found on: https://ccic.e-ciie.com/cn/

Contact person of CQC: Liu Zhan 010-83886959; Liu Yanlong 010-83886621


Introduction of Website / Exception Clause
Copyright by CHINA QUALITY CERTIFICATION CENTRE CO., LTD.