ISO 27001:2022: What Changed and What It Means for Your Transition

ISO 27001:2022: What Changed and What It Means for Your Transition

ISO 27001:2022 is the current version of the standard, and it looks different from the 2013 version many programs were built on. The changes are not cosmetic. If you are certifying for the first time, you build to 2022. If you held a 2013 certificate, you should already have transitioned, since that transition period ended October 31, 2025.

Here is what actually changed and what it means.

The Big Change: Annex A Was Restructured

The 2013 version listed 114 controls across 14 domains. The 2022 version consolidates these into 93 controls organized under four themes: organizational, people, physical, and technological. Nothing was really removed. Controls were merged, renamed, and regrouped to reduce overlap and make the set easier to navigate. The four-theme structure mirrors ISO 27002:2022, the companion guidance.

Eleven New Controls

The update added 11 controls that reflect how security actually works now. They are:

If your program was built on the 2013 controls, these are the areas most likely to need new work. Cloud, monitoring, and data leakage prevention in particular tend to expose gaps.

The Management Clauses Barely Moved

The core requirements in clauses 4 through 10, the actual management system, saw only minor wording changes. If your ISMS was healthy under 2013, the structure still holds. The real work of transition is in the Annex A controls and, importantly, the documents that reference them.

What a Transition Involves

Moving from 2013 to 2022 is mostly a mapping and gap exercise. You map your existing controls to the new structure, identify the new controls that apply, close any gaps, and update the documents that reference Annex A, especially your Statement of Applicability. Then a transition audit confirms the update.

The Statement of Applicability is the document that changes the most, because it is organized around the control set that was restructured. Rewriting it to the 2022 controls is the center of the work.

If You Are Certifying for the First Time

You have it easier in one respect: you build to 2022 from the start and never carry 2013 assumptions. Just make sure any consultant, template, or tool you use is current. Material built for the 2013 controls will send you down the wrong path.

Frequently Asked Questions

How many controls are in ISO 27001:2022?

93 controls, grouped into four themes: organizational, people, physical, and technological. The 2013 version had 114 across 14 domains.

What are the new controls in the 2022 version?

Eleven were added, including threat intelligence, cloud security, data leakage prevention, secure coding, configuration management, and monitoring activities. These are the areas most likely to need new work.

Is the 2013 version still valid?

No. The transition period for 2013 certifications ended October 31, 2025. Current certifications run on ISO 27001:2022.

Whether you are transitioning or certifying fresh, the 2022 control set is where the detail lives. A readiness assessment maps your controls to it and finds the gaps. Talk with a senior advisor at JBW Group.

← Back to all posts