The revision of ISO 27006 brings significant changes for ISMS audits according to ISO 27001—especially for digitized companies. I have looked into this and identified the following key points:

New calculation logic for audit days

  • Number of employees instead of locations: Audit time is now calculated solely on the basis of the number of people working within the ISMS scope—including freelancers and external staff.
  • Location relevance no longer applies: The previous requirement to automatically include physical locations in the calculation has been removed. Instead, audit days are allocated according to risk assessment and key activities.

Updated remote audit policies

  • More flexible remote auditing: The previous 30% cap on remote auditing has been removed. Instead, the focus is on the effectiveness of the methodology.
  • Clear documentation requirement: For companies that operate virtually without physical locations, this must be explicitly noted in the audit report.

Simplified auditor qualification

No rigid experience requirements: Quantitative requirements such as “four years of professional experience” for auditors have been eliminated. Competence assessment is now risk-based.

Technical adjustments

  • Control alignment: Annex E has been aligned with the updated security controls in ISO 27001:2022.
  • Redundancies removed: Duplications with ISO/IEC 17021-1 (General requirements for certification bodies) have been eliminated.

More transparent multi-site audits

Detailed specifications: Annex C now provides explicit calculation methods for surveillance audits, recertifications, and multi-site scenarios.

All in all, I believe these are very helpful adjustments that will make the audit procedures of certification bodies more realistic than before. What strikes me is that not all certification bodies seem to have implemented these changes yet. In any case, just last week I received another data request document that still asked for the number of locations—and in which these were also included in the calculation of the audit effort.

Tags

Share post

More articles

One of the core competences of cloud service providers is the safeguarding of infrastructures with regard to IT security. But what should be taken into account when using the cloud? The cloud has many advantages:...
Instant 27001 is a solution that saves an enormous amount of time and money when setting up and operating an ISMS according to ISO 27001. Users benefit not only from the fact that Instant 27001...
In many companies, information security is still treated as an IT issue. As a result, it gets delegated. → To the IT department.→ To external service providers.→ To “someone who takes care of it.” What...