ISO 27001
ISO 27001:2022 changes, explained
The 2022 edition reorganised Annex A, added eleven controls and merged dozens. Here is what changed, what it means for an existing ISMS, and how to map old to new without redoing the work.
Certifyi compliance team · Updated September 2026
Short answer. ISO/IEC 27001:2022 kept the management-system clauses 4 to 10 almost unchanged but replaced the 114 controls in 14 domains of the 2013 Annex A with 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are new, including threat intelligence, cloud services security, data leakage prevention, data masking, secure coding and ICT readiness for business continuity. Certified organisations had until 31 October 2025 to transition.
What did not change
The core of the standard, the requirements in clauses 4 to 10, received only small edits: clearer wording on planning changes to the ISMS, a note on defining the processes needed to implement actions, and alignment with the harmonised structure used across ISO management-system standards. If your ISMS already covers context, leadership, planning, support, operation, performance evaluation and improvement, that work carries over intact.
The new Annex A structure
| Theme | Controls | Examples |
|---|---|---|
| Organisational (A.5) | 37 | Policies, roles, threat intelligence, cloud services, supplier relationships, incident management, legal and contractual |
| People (A.6) | 8 | Screening, terms of employment, awareness, disciplinary process, remote working, reporting events |
| Physical (A.7) | 14 | Perimeters, entry, monitoring, equipment, clear desk, secure disposal |
| Technological (A.8) | 34 | Endpoints, privileged access, malware, vulnerability management, logging, backup, cryptography, secure development |
The eleven new controls
- A.5.7 Threat intelligence: collect and analyse information about threats and use it in your controls.
- A.5.23 Information security for use of cloud services: acquisition, use, management and exit for cloud services.
- A.5.30 ICT readiness for business continuity: ICT continuity planned, implemented and tested.
- A.7.4 Physical security monitoring: premises monitored for unauthorised access.
- A.8.9 Configuration management: secure configurations defined, implemented and reviewed.
- A.8.10 Information deletion: delete information when no longer required.
- A.8.11 Data masking: masking in line with policy and legal requirements.
- A.8.12 Data leakage prevention: DLP applied to systems that process sensitive information.
- A.8.16 Monitoring activities: networks, systems and applications monitored for anomalous behaviour.
- A.8.23 Web filtering: manage access to external websites.
- A.8.28 Secure coding: secure coding principles applied to development.
Attributes: the quiet improvement
Every 2022 control carries five attributes: control type (preventive, detective, corrective), information security property (confidentiality, integrity, availability), cybersecurity concept (identify, protect, detect, respond, recover), operational capability, and security domain. They let you filter the control set by the language your board or a US customer already uses, which makes mapping to NIST CSF or SOC 2 far easier than it was under the 2013 domains.
Mapping an existing ISMS
Most of the 2013 controls survive as merged or renamed items, so the practical work is a mapping exercise, not a rebuild: take your Statement of Applicability, map each 2013 control to its 2022 successor using the correspondence table in Annex B of ISO/IEC 27002:2022, add the eleven new controls with a justification for inclusion or exclusion, and update the risk treatment plan. Certifyi ships the 2022 control set with the 2013 correspondence built in, so an existing SoA is re-mapped in the platform and the evidence already collected stays attached to the successor controls.
ISO 27001:2022, answered
Is ISO 27001:2013 still valid?
No. The transition period ended on 31 October 2025. Certificates against the 2013 edition are no longer valid, and new audits are conducted against 2022.
Do we have to implement all 93 controls?
No. Annex A is a reference list. You select controls based on your risk assessment and justify exclusions in the Statement of Applicability. The auditor checks the justification, not the count.
Did the number of controls really drop?
From 114 to 93, but mostly through merging. Fifty-seven controls were merged into twenty-four, one was split, and eleven were added, so the coverage is broader even though the count is lower.
How long does the re-mapping take?
For a mature ISMS, one to three weeks of work: mapping the SoA, adding the new controls, and updating the risk treatment plan and internal audit programme.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.