ISO/IEC 27001:2022 · Global
ISO 27001 awareness evidence
without the spreadsheet.
ISO/IEC 27001:2022 includes an Annex A control on information security awareness, education and training, and since 31 October 2025 certification is to the 2022 edition only, because certificates to the 2013 edition expired or were withdrawn at the end of the transition.
- Standard
- ISO/IEC 27001:2022, with Amendment 1:2024
- Where awareness fits
- Annex A control 6.3: awareness, education and training
- Transition
- Certificates to the 2013 edition expired or were withdrawn by 31 October 2025
- KeenSec evidence
- Training certificates, policy acknowledgements, simulation results, report logs
Ready when the auditor asks
Stop assembling evidence
from five places.
Training in one tool, policy sign-offs in email, phishing results in a spreadsheet: that is how audit week becomes a project.
Show awareness for these people
- Current information security policy acknowledged
- Annual awareness course completed, with certificate
- Included in phishing simulations this year
- Reporting behaviour over the period
- Reminders and escalations for anyone late
Illustrative request.
Expectation to record
Awareness, education
and training, proven.
Education and training delivered.
LMS completions, assessments and certificates.
Policies communicated and accepted.
Dated records per person, policy and version.
Awareness tested in practice.
Outcomes per channel, team and campaign.
Staff report suspicious messages.
Phishing Reporter logs with automated analysis.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- IAF MD 26:2023, transition requirements for ISO/IEC 27001:2022Transition completed by 31 October 2025
- ISO/IEC 27001:2022 on iso.orgThe standard itself is sold by ISO
Questions buyers ask
Frequently asked questions.
Which edition of ISO 27001 applies now?
ISO/IEC 27001:2022. The transition from the 2013 edition ended on 31 October 2025, and certificates to the 2013 edition expired or were withdrawn.
Does KeenSec make us ISO 27001 compliant?
No tool makes you compliant or certified on its own. KeenSec helps you run and evidence awareness, education and training; your certification body decides.
Is KeenSec ISO 27001 certified?
No. KeenSec is SOC 2 Type II ready: the controls and documentation are prepared, but no audit is complete.
What evidence will our auditor want for awareness?
Typically training records, policy acknowledgements and proof the programme runs over time. KeenSec keeps these per person, with simulation and reporting results alongside.
Let’s connect the dots
Answer the auditor
in minutes.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo