The revision of ISO 27006 brings significant changes for ISMS audits according to ISO 27001—especially for digitized companies. I have looked into this and identified the following key points:

New calculation logic for audit days

  • Number of employees instead of locations: Audit time is now calculated solely on the basis of the number of people working within the ISMS scope—including freelancers and external staff.
  • Location relevance no longer applies: The previous requirement to automatically include physical locations in the calculation has been removed. Instead, audit days are allocated according to risk assessment and key activities.

Updated remote audit policies

  • More flexible remote auditing: The previous 30% cap on remote auditing has been removed. Instead, the focus is on the effectiveness of the methodology.
  • Clear documentation requirement: For companies that operate virtually without physical locations, this must be explicitly noted in the audit report.

Simplified auditor qualification

No rigid experience requirements: Quantitative requirements such as “four years of professional experience” for auditors have been eliminated. Competence assessment is now risk-based.

Technical adjustments

  • Control alignment: Annex E has been aligned with the updated security controls in ISO 27001:2022.
  • Redundancies removed: Duplications with ISO/IEC 17021-1 (General requirements for certification bodies) have been eliminated.

More transparent multi-site audits

Detailed specifications: Annex C now provides explicit calculation methods for surveillance audits, recertifications, and multi-site scenarios.

All in all, I believe these are very helpful adjustments that will make the audit procedures of certification bodies more realistic than before. What strikes me is that not all certification bodies seem to have implemented these changes yet. In any case, just last week I received another data request document that still asked for the number of locations—and in which these were also included in the calculation of the audit effort.

Tags

Share post

More articles

Cybercrime only affects the big players? Certainly not! Last week, we witnessed live how an attacker – unfortunately successfully – defrauded the customers of a retailer and stole a considerable amount of money in the...
Risk precautions are supposedly just as unwelcome as health precautions. But they are just as important! Various studies prove: Attacks on IT systems and applications are increasing significantly. The consequences are financially devastating. At the...
Cloud security myth busted: Common misconceptions about security ownership in the cloud In recent years, cloud technology has become one of the most important and widely used IT infrastructures. Organisations of all sizes are taking...