← All posts
Thought Leadership

ISO/IEC 27000:2026: What the New Edition Means for Communication Risk Programs

July 5, 2026 · 7 min read

ISO/IEC 27000 just got its first major rewrite since 2018, and the timing is not neutral. The sixth edition, published this month, lands only months after the mandatory transition deadline of 31 October 2025, the date by which every organization still certified under ISO/IEC 27001:2013 had to move to the 2022 version or lose certification. Teams that spent the better part of three years migrating to the new control set are now looking at a rewritten front door to the whole standards family, right after they finished renovating the house behind it.

What ISO/IEC 27000 actually is, and why the rewrite matters

ISO/IEC 27000 is not the standard organizations get certified against. That is ISO/IEC 27001, which specifies the requirements for an information security management system, or ISMS. ISO/IEC 27000 is the overview and vocabulary document underneath it: it explains what an ISMS is, how the family of standards (27001, 27002, and the sector-specific extensions) relates, and gives buyers and implementers the shared concepts everyone else assumes you already have.

The fifth edition, from 2018, leaned heavily on being a terminology reference. The sixth edition shifts the emphasis toward overview and relationships between the documents, according to the publication itself. That sounds like a small editorial choice, but it changes who the document is actually useful for. A terminology-first document serves people who already know they need ISO/IEC 27001 and want the definitions straight. An overview-and-relationships document serves the person one step earlier: the one deciding whether to pursue certification at all, or trying to explain to a board why 27001 and 27002 are not the same thing.

That relationship question is more tangled than it looks from outside the family. ISO/IEC 27001 sets the requirements an ISMS must meet and is the document an auditor certifies against. ISO/IEC 27002 is the companion code of practice: it is where the detailed guidance behind each Annex A control actually lives, and it is not itself certifiable. Beyond those two sit sector-specific extensions built on the same foundation: ISO/IEC 27017 for cloud service security, ISO/IEC 27018 for protecting personal data in public clouds, ISO/IEC 27701 for privacy information management layered on top of an existing ISMS. An organization evaluating a vendor’s security questionnaire, or deciding which of these to pursue, needs the map ISO/IEC 27000 provides before any of the individual documents make sense on their own.

The context this edition arrives in: fewer, better-organized controls

To understand why the timing matters, it helps to recall what changed in the 2022 revision of ISO/IEC 27001, since that is the standard most organizations are actually implementing. The 2013 version listed 114 controls in its Annex A. The 2022 version consolidated these into 93 controls, organized into four themes instead of the previous 14 domains:

Theme What it covers
Organizational Policies, roles, supplier relationships, threat intelligence, cloud security
People Screening, awareness and training, remote working, acceptable use, disciplinary process
Physical Secure areas, equipment, media handling, physical entry
Technological Access control, cryptography, logging, monitoring, data masking, secure coding

The consolidation added several new controls that did not exist in 2013, including threat intelligence, information security for cloud services, and data masking, reflecting how much the operating environment changed in nine years. Certification bodies enforced the 31 October 2025 deadline strictly: organizations that had not completed the transition audit by that date needed a new certification cycle, not an extension.

The people theme, and where communication risk sits inside it

Three of the four themes are infrastructure: physical security, technical controls, organizational policy. The people theme is different. It is the one built around the assumption that a compliant system still depends on what an individual chooses to do at a keyboard, and it includes controls for security awareness and training, acceptable use of information and assets, and remote working, alongside the disciplinary process for when those controls fail.

Long-running industry breach research has repeatedly found that human action, not just external attack techniques, accounts for a majority of security incidents, whether through misdirected information, misconfiguration, or simple error in what someone sent to whom. ISO/IEC 27001’s people controls exist because the standard’s authors already know this. An auditor reviewing your awareness and training control does not just want a slide deck confirming staff attended a session. A mature implementation shows evidence that the training changes what people actually do when they are about to make a mistake, not only what they can recite afterward.

This is where a written record matters more than a training completion certificate. If your ISMS documentation can show where communication risk actually concentrates, which department, which type of language, whether it is trending down after a training push, that is a materially stronger answer to an auditor’s question than attendance logs alone.

A short way to check where your own evidence stands: for the awareness and training control, do you have anything dated after the training that shows behavior change, or only a record of who sat through the session? For acceptable use, can you point to what actually gets flagged when someone drafts a message that breaches policy, or does the policy exist only as a document staff signed once? For the disciplinary process, is there a pattern of repeat issues by department that would let you act before an incident, or does the process only start after one has already happened? Auditors increasingly ask the second question in each pair, not the first.

Where a pre-send check fits, and where it stops

VerbaPulse does not certify anything and does not replace the ISMS your organization builds around ISO/IEC 27001. What it does produce is exactly the kind of evidence the people theme’s controls ask for: an anonymized, department-level record of where risky language shows up in email before it sends, and whether that pattern improves over time. It flags a risky phrase, explains why in plain language, and leaves the decision with the person writing, which keeps it a support for the acceptable-use and awareness controls rather than a monitoring system layered on top of them. The audit trail this produces names no individual and stores no message text, only the pattern an auditor actually needs to see. For teams already mapping controls to evidence ahead of a certification or transition audit, that is a real, usable input, not a new obligation to track.

The one thing to check this week

If your organization holds or is pursuing ISO/IEC 27001 certification, do not treat the people theme as the easy quarter of the audit. Ask what evidence currently backs your awareness and training control beyond a log of who attended a session, and whether that evidence would hold up if an auditor asked whether the training actually changed behavior. The sixth edition of ISO/IEC 27000 will not change what you are certified against. It is a good prompt to check whether your evidence for the human-layer controls has kept pace with everything else you migrated in 2025.

If your next surveillance audit is more than a quarter away, that is enough runway to close the gap properly rather than assembling evidence the week before the auditor arrives.

See it on your own emails

VerbaPulse flags risky wording as you write in Outlook and Gmail, then offers a safer phrasing before you send. Run it against your own messages and your own rules in a 30-day pilot.

Start a pilot

Up to 10 seats. EUR 120, credited to your plan if you continue.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← Email compliance for law firms: the risk that lives in a single sentence What actually counts as an NDA breach by email, and the four ways it happens →