Skip to content
Standards news

Updates

What is changing across the standards we certify to. Every entry links to the original — we tell you what it means and then send you to the people who published it.

  1. Scheme ISO/IEC 27001

    ISO/IEC 27001:2013 certificates ceased to be valid

    The transition period from ISO/IEC 27001:2013 to the 2022 edition ended. Certificates against the 2013 edition are no longer valid, whatever expiry date is printed on them. If you are holding one, you are not certified — a transition audit is required, and the certificate must state the 2022 edition. This is also why every UMA certificate names the edition it was audited against: the two are different claims.

    Source: IAF · iaf.nu

  2. Standard update ISO/IEC 27701

    ISO/IEC 27701 became a standalone management system standard

    The privacy information management standard was republished with its own clauses 4 to 10 and a redesigned Annex A. It is no longer an extension that requires an ISO/IEC 27001 certificate first — an organisation can now be certified to it in its own right. UMA does not currently offer certification against ISO/IEC 27701; we are noting the change because anyone holding the 2019 version, or planning against it, is planning against a superseded model.

    Source: ISO · iso.org

  3. Standard update ISO 9001ISO 14001ISO 45001ISO/IEC 27001

    Climate change amendments added to ISO management system standards

    ISO amended a large number of management system standards, including all four above, to require organisations to consider whether climate change is a relevant issue when determining their context — and to note that interested parties can have climate-related requirements. The amendment adds no new clause and no new certification requirement, but it is auditable: expect an auditor to ask whether you considered it and what you concluded. "Not relevant to us" is an acceptable answer if you have actually reached it.

    Source: ISO · iso.org

  4. Regulation ADHICS

    ADHICS V2.0 is the current standard for Abu Dhabi healthcare entities

    The Abu Dhabi Healthcare Information and Cyber Security Standard applies to healthcare entities licensed in the emirate, with requirements tiered by entity type and size. Unlike the ISO standards, this is a regulatory expectation rather than a voluntary one. Check the Department’s own resources page for the current version and any circulars — the Department is the authority, not us.

    Source: Department of Health – Abu Dhabi · doh.gov.ae

What we link to, and what we will not

We link to standards bodies, accreditation bodies, IAF mandatory documents, regulators and independent trade press. Everything above goes to its original source, and we would rather send you there than paraphrase it.

We do not link to consultancies or training providers. We have published that we do not recommend consultants, and a feed that quietly sends readers to one is doing exactly that, with a date on it. The rule is written down so it is not decided case by case when a tempting link appears.

This is publication, not advice. We will tell you that an edition has changed and what the change is; we will not tell you how to prepare for your audit. That is consultancy, and we do not provide it to anyone.

Dates and requirements are summarised in good faith and can change. The linked source is authoritative; this page is not.