If you hold International Organization for Standardization (ISO) certification or are planning to get certified soon, at some point you will likely go through a transition. So, you may be wondering: why do standards get revised, who decides, and what does it mean for your certification – whether that’s updating an existing certificate or choosing which version to certify against in the first place?
Drawing on knowledge shared in our recent webinar, What Do ISO Revisions Mean for Leadership Teams?, this article answers those questions, unpacking the ISO revision cycle from a certification body’s (CB) perspective.
The opening message is key: revision is a normal, structured part of how ISO standards work – not a signal that anything is wrong. That said, it does carry real commercial risk if it is ignored.
“In our experience, the organisations that come out ahead are the ones that treat transitions as something to plan around, not something to react to.” Steve Russell, Chief Governance Officer, Amtivo Group
The ISO Revision Cycle
Every ISO standard has a systematic review cycle, typically running every five years. At the relevant time, a technical committee examines the standard and decides on the appropriate action. That decision can go a few ways:
- Confirm the standard remains as it is
- Amend it
- Revise it fully
- Or, in some cases, withdraw it altogether
It’s worth stressing that a review does not always lead to change; no change is a perfectly valid outcome. For example, ISO 9001:2015 was confirmed without revision in 2021 before a later re-evaluation restarted the process.
Similarly, a change does not have to mean a full rewrite. In 2024, a small, targeted amendment on climate change was added to ISO 27001 (and other management system standards) without triggering a transition at all.
In other words, revisions can be as narrow or as broad as the evidence demands.
The cycle then begins again A revision is a scheduled part of how ISO standards stay relevant (a review can also confirm a standard unchanged).
Why Do ISO Standards Get Revised?
So, what pushes a committee towards revision rather than confirmation? Standards are not revised in a vacuum – they evolve because the environment they were written for keeps moving. The world a standard was drafted against five or ten years ago is not the world certified organisations are operating in today.
There are some consistent drivers behind many revisions:
- New and emerging risks: Threats and issues the original technical committee either did not anticipate or that did not exist at today’s scale.
- Shifts in international best practice: The way “good” is defined internationally does not stand still, and standards need to keep pace with that consensus.
- Real-world certification feedback: Input from auditors, fed back through national bodies into the technical committees.
That third driver deserves particular attention, because it is often the least visible from outside the certification world.
“Auditors are often the first people to spot where a standard is starting to creak. They see it in ambiguous wording that different organisations interpret in different ways, in controls that have quietly become outdated, and in organisations that are technically compliant on paper but aren’t actually secure, safe or in control of their management system in practice.” Kelly Thornton, Group QEHS Technical Manager, Amtivo Group
That gap between compliant and genuinely effective is exactly the kind of feedback that shapes why and when a standard gets revised. A revision is the standard catching up with what auditors, certified organisations and the wider market are experiencing.
What Does a Revision Signal?
A revision doesn’t mean the previous version was flawed. Rather, it can be seen as a signal that the collective expectation of good practice has moved on. What counted as adequate risk management, governance or control five or ten years ago may not reflect good practice today and a revision formally acknowledges that the bar has shifted.
Perhaps most importantly, though, a revision and the following transition period give certified organisations a clear, structured route to move with that bar.
That is why revisions should be seen as constructive rather than corrective. Organisations aren’t being penalised for following the previous version. Instead, the purpose of a revision is to keep the standard relevant, credible and genuinely useful as a benchmark. They play a key role in keeping certification meaningful for the businesses that hold it and the customers who rely on it.
Revision vs. Transition
A revision is the process of updating the standard itself – the technical committee’s work of reviewing, redrafting and publishing a new edition.
A transition is what follows for certified organisations: the defined period in which they should move their management system and certification from the old edition to the new one (if they want to remain certified).
The revision happens to the standard; the transition happens to organisations. But a transition doesn’t have to mean additional audits. For many certified organisations, the work which may be needed to transition to the revised standard can slot into the existing three-year certification cycle. This would typically be at a surveillance or recertification visit, so it would require planning early.
Contact us to see where any upcoming revisions may fit into your certification cycle.
The ISO Revision Process Step-by-Step
Once a technical committee decides a standard should be revised, the drafting process follows a defined sequence:
- Systematic review: The committee assesses the current standard and agrees the case for change, where needed.
- Working draft and committee draft: Early drafts are developed, balloted and agreed among committee members.
- Draft international standard (DIS): The draft goes out for wider consultation, giving national bodies and stakeholders the chance to comment.
- Final draft international standard (FDIS): Feedback is incorporated and the near-final text goes out for a last vote and review.
- Publication: The revised standard is formally published.
Publication is the moment that matters most for certified organisations, because that is when the transition clock starts. From that date, a defined transition period (typically three years for major management system standards) begins, at the end of which certificates to the old version cease to be valid.
- Systematic review Technical committee agrees the case for change
- Committee drafts Working and committee drafts balloted
- DIS Draft international standard – wider consultation
- FDIS Final draft – last vote and review
- Publication The transition clock starts
One practical implication is often missed: because the DIS and FDIS stages are public, organisations don’t need to wait for publication to start preparing. The FDIS, in particular, gives a solid picture of where a management system may need to change – meaning publication day can be a confirmation point rather than a starting gun.
A recent example: the ISO 27001 transition
A good recent example is ISO 27001, which has completed a full transition. The 2013 version was revised to ISO 27001:2022, with the transition clock starting on 31st October 2022 and closing on 31st October 2025. Certification bodies and certified organisations had defined milestones to hit within that window, and all new audits moved to the 2022 version once the transition period ended.
ISO 27001 needed updating because the information security landscape had changed materially since 2013. Cyber security incidents have increased in both frequency and severity, and the need for robust governance has grown with them. Legislation is reshaping the landscape too – in the UK, the Cyber Security and Resilience Bill currently progressing through Parliament is a clear example of the kind of regulatory shift that influences what a standard needs to cover, and may well shape future revisions.
The 27001 example also illustrates the range revisions can take. Barely two years after the full 2022 revision, a small amendment was made to clause 4.1 on climate change – but it was targeted, minor, and didn’t require a transition. Revisions are proportionate to what has changed in the world, not rewrites for the sake of it.
What Happens After a Standard Is Published?
When a revised standard is published, Global ACI (the international authority for accredited conformity assessment, formed in January 2026 from the merger of the IAF and ILAC) issues a mandatory document setting out how the transition is to be managed globally.
National accreditation bodies, such as UKAS in the UK, then consolidate that framework into their own formalised transition approach, which every certification body they accredit must follow. Once a certification body has completed its own transition under its accreditation body’s oversight, then it can begin issuing accredited certificates against the updated standard.
“Audits available and accredited certificate available are two different milestones – and the gap between them is where we complete our own due diligence.” Kelly Thornton, Group QEHS Technical Manager, Amtivo Group
This is a part of the process that often catches organisations out. There’s a common assumption that once a revised standard is published, certification bodies can start issuing accredited certificates against it straight away.
Realistically, the sequence that needs to happen – from publication, through the accreditation body’s process, to a certification body being audited and cleared – can take somewhere in the region of six to twelve months.
But this doesn’t mean no progress can happen in the meantime. Transition audits can be delivered from day one of publication; what cannot happen is the issue of an accredited certificate until the certification body’s own transition is complete.
For certified organisations, the practical takeaway is this: the audit activity and the preparation behind it can, and should, start well before that accreditation process for certification bodies has run its course.
Meanwhile: transition audits – and your own preparation – can begin from day one of publication. Only the accredited certificate has to wait.
Where Organisations Can Go Wrong
Across transitions, common issues come up repeatedly where organisations:
- Wait for publication before doing anything: Rather than using the DIS or FDIS to prepare changes in advance, organisations can lose months of usable time and rush towards the end.
- Underestimate internal preparation: Gap analysis, documentation updates and internal audit are real operational changes, not admin. Leaving them late creates avoidable pressure.
- Assume there is a grace period: Once the transition period ends, certificates to the old version are no longer valid.
- Overlook commercial pressure: Customers and procurement teams often start asking about transition status well before any regulatory deadline is reached.
That last point is worth sitting with. An expired certificate doesn’t just create a compliance gap – it creates a commercial one.
What Happens if an Organisation Starts Certification Mid-Revision
If you have been holding off certification because a standard is undergoing a revision, it’s worth reframing: a revision doesn’t create a moving target, it creates a clearly signposted one.
You can still get certified now, and start realising the benefits of ISO certification, including tender eligibility, customer assurance, a working management system, meeting regulatory requirements – with a defined route to the new edition built into your certification cycle.
But there is a valid question: if you start certification when a revision is under way, which version will you be certified against? The short answer is that it’s your decision, with a few timing realities to factor in. What’s key to remember is that a new version being published while you are on your certification journey does not mean starting again.
Until a revised standard is published, the current edition is the only version a certificate can be issued against.
If the new edition is published while your implementation is under way, your work is not wasted – many requirements carry through between editions, and the drafts (DIS and FDIS) are public before publication, so the differences are known in advance. From publication onwards, the choice of version is yours to make. You could:
- Complete certification to the current edition, then transition: Recent transitions have allowed initial certifications to the outgoing edition to continue well into the transition window – during the ISO 27001 transition, for example, new certifications to the 2013 edition were permitted for 18 months after the 2022 edition was published. You then move to the new edition later in the window, with the transition typically folded into an audit you were already having.
- Certify against the new edition straight away: Audits against a new edition can be delivered from day one of publication. A certificate issued before your certification body has completed its own accredited transition would initially be unaccredited, then updated once that process is complete – so if your customers or tenders specifically require accredited (for example UKAS-accredited) certification, the timing of that gap is worth discussing with your certification body first.
- Time your certification to the new edition: If your timeline means you’d be certifying after accredited certification to the new edition becomes available, your implementation can be built against the new requirements from the outset.
One detail worth knowing before choosing the first route: a certificate issued against the outgoing edition during a transition window expires at the transition deadline rather than running the usual three years. That doesn’t diminish its value, but it does mean the transition date should be part of your planning conversation from day one.
The exact cut-off dates for each transition are set by Global ACI and the national accreditation bodies once a standard is published, so the practical step is to raise it early: tell your certification body where you are in your journey, and you can discuss options for your dates.
ISO Revisions Relevant Now
The revision cycle described above is playing out across three of the most widely held standards at once:
- ISO 14001: The revised 2026 edition has been published, and the transition window is open until April 2029.
- ISO 9001: Publication of the 2026 edition is scheduled for 16th September 2026, and the FDIS already gives a clear picture of what is changing.
- ISO 45001: A revision is in progress, expected to follow the same cycle.
Three concurrent transitions may be slightly unusual, but for organisations running integrated management systems it is both a coordination challenge and a genuine opportunity to align improvements across quality, environmental, and health and safety in one planned programme.
Speak to us about your transition
As a UKAS-accredited certification body, we have been involved in and have experience with many transitions. Whether your next transition is months away, already live, or you’re new to certification, the earlier the conversation starts, the more options you have.
Watch the full ISO revision webinar on demand or get in touch to talk through your transition timeline.
