ISO/IEC 27000:2026: what changes in the ISMS standards family

ISO/IEC 27000:2026: what changes in the ISMS standards family

ISO/IEC JTC 1/SC 27 published the sixth edition of ISO/IEC 27000 on 3 July 2026. The European version, EN ISO/IEC 27000:2026, followed on 15 July and replaced EN ISO/IEC 27000:2020. The certification standard is still ISO/IEC 27001:2022 — issued certificates and audit programmes are unaffected. The new edition still matters, because it changes what your documentation points at.

The vocabulary is no longer in the standard

The word "vocabulary" is gone from the title. The 2018 edition was Information technology — Security techniques — Information security management systems — Overview and vocabulary; the new one is Information security, cybersecurity and privacy protection — Information security management systems — Overview. That is not cosmetic: clause 3 shrank from 77 defined terms to 12, keeping only what the document itself needs to explain its own concepts. The rest of the terminology moved to the ISO Online Browsing Platform.

The impact lands in documentation. Security policies, glossaries, training material and contract annexes routinely say "terms as defined in ISO/IEC 27000". That reference now points at a document which no longer carries most of those terms. Not an urgent finding, but at the next review the reference needs redirecting or the terms defining locally.

The family of standards has been regrouped

The new edition organises the family by function rather than by number: ISMS specification (27001), candidate necessary information security controls (27002, 27010, 27011, 27017, 27019), fulfilment of ISMS requirements (27003, 27004, 27005, 27007), use of an ISMS (27013, 27014, TR 27016), control assessment, attributes, processes and competence (TS 27008, 27021, TS 27022, 27028), and conformity assessment (27006-1).

ISO/IEC 27028 on control attributes joins the list. In the other direction, 27009, 27018 and 27799 no longer appear in it — they are not withdrawn, the overview simply no longer counts them in the family. If your procedures cite 27018 for personal data in cloud services, nothing breaks; the map you hand an auditor just looks different now.

Annex A as a completeness check

The most useful part is how the new edition describes Annex A of ISO/IEC 27001. The order is: determine the necessary controls from risk treatment, design them or take them from any source, and only then compare them against Annex A to verify that no necessary control has been omitted. That is exactly what clause 6.1.3 of ISO/IEC 27001:2022 requires — the overview standard now says it out loud.

Most implementations work the other way round: start from the 93 Annex A controls in four themes, write the Statement of Applicability, then backfill the risks. An information security management system built that way will pass certification, but it carries two weaknesses — controls that cover no real risk, and risks with no control because Annex A has no entry for them. Your auditor reads the same overview standard you do.

What to do now

  • Find every reference to ISO/IEC 27000 as a source of definitions in your ISMS documentation and correct it at the next scheduled review.
  • Check that your risk treatment process describes the 6.1.3 order — risks, controls, then the comparison against Annex A.
  • Buy supporting standards against the new family grouping rather than the 2018 list.
  • Do not plan a transition. This is not the 2013 to 2022 situation; there is no transition period, because the certification standard did not change.

ISO/IEC 27000 was never a standard anyone read end to end. It was, however, a standard people referenced — and references are precisely what the sixth edition changes. The English version runs to eleven pages; reading it against your own documentation is an afternoon's work.

Need help with this topic?

Get in touch