ISO/IEC 27001:2022 · Global

ISO 27001 awareness evidence
without the spreadsheet.

ISO/IEC 27001:2022 includes an Annex A control on information security awareness, education and training, and since 31 October 2025 certification is to the 2022 edition only, because certificates to the 2013 edition expired or were withdrawn at the end of the transition.

Standard
ISO/IEC 27001:2022, with Amendment 1:2024
Where awareness fits
Annex A control 6.3: awareness, education and training
Transition
Certificates to the 2013 edition expired or were withdrawn by 31 October 2025
KeenSec evidence
Training certificates, policy acknowledgements, simulation results, report logs

Ready when the auditor asks

Stop assembling evidence
from five places.

Training in one tool, policy sign-offs in email, phishing results in a spreadsheet: that is how audit week becomes a project.

SAMPLE AUDIT REQUEST

Show awareness for these people

  • Current information security policy acknowledged
  • Annual awareness course completed, with certificate
  • Included in phishing simulations this year
  • Reporting behaviour over the period
  • Reminders and escalations for anyone late

Illustrative request.

Expectation to record

Awareness, education
and training, proven.

TRAINING

Education and training delivered.

LMS completions, assessments and certificates.

POLICY ACKNOWLEDGEMENTS

Policies communicated and accepted.

Dated records per person, policy and version.

SIMULATION RESULTS

Awareness tested in practice.

Outcomes per channel, team and campaign.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. IAF MD 26:2023, transition requirements for ISO/IEC 27001:2022Transition completed by 31 October 2025
  2. ISO/IEC 27001:2022 on iso.orgThe standard itself is sold by ISO

Questions buyers ask

Frequently asked questions.

Which edition of ISO 27001 applies now?

ISO/IEC 27001:2022. The transition from the 2013 edition ended on 31 October 2025, and certificates to the 2013 edition expired or were withdrawn.

Does KeenSec make us ISO 27001 compliant?

No tool makes you compliant or certified on its own. KeenSec helps you run and evidence awareness, education and training; your certification body decides.

Is KeenSec ISO 27001 certified?

No. KeenSec is SOC 2 Type II ready: the controls and documentation are prepared, but no audit is complete.

What evidence will our auditor want for awareness?

Typically training records, policy acknowledgements and proof the programme runs over time. KeenSec keeps these per person, with simulation and reporting results alongside.

Let’s connect the dots

Answer the auditor
in minutes.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo