ISO 27001

ISO 27001:2022 changes, explained

The 2022 edition reorganised Annex A, added eleven controls and merged dozens. Here is what changed, what it means for an existing ISMS, and how to map old to new without redoing the work.
Certifyi compliance team · Updated September 2026
Short answer. ISO/IEC 27001:2022 kept the management-system clauses 4 to 10 almost unchanged but replaced the 114 controls in 14 domains of the 2013 Annex A with 93 controls in four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are new, including threat intelligence, cloud services security, data leakage prevention, data masking, secure coding and ICT readiness for business continuity. Certified organisations had until 31 October 2025 to transition.

What did not change

The core of the standard, the requirements in clauses 4 to 10, received only small edits: clearer wording on planning changes to the ISMS, a note on defining the processes needed to implement actions, and alignment with the harmonised structure used across ISO management-system standards. If your ISMS already covers context, leadership, planning, support, operation, performance evaluation and improvement, that work carries over intact.

The new Annex A structure

ThemeControlsExamples
Organisational (A.5)37Policies, roles, threat intelligence, cloud services, supplier relationships, incident management, legal and contractual
People (A.6)8Screening, terms of employment, awareness, disciplinary process, remote working, reporting events
Physical (A.7)14Perimeters, entry, monitoring, equipment, clear desk, secure disposal
Technological (A.8)34Endpoints, privileged access, malware, vulnerability management, logging, backup, cryptography, secure development

The eleven new controls

Attributes: the quiet improvement

Every 2022 control carries five attributes: control type (preventive, detective, corrective), information security property (confidentiality, integrity, availability), cybersecurity concept (identify, protect, detect, respond, recover), operational capability, and security domain. They let you filter the control set by the language your board or a US customer already uses, which makes mapping to NIST CSF or SOC 2 far easier than it was under the 2013 domains.

Mapping an existing ISMS

Most of the 2013 controls survive as merged or renamed items, so the practical work is a mapping exercise, not a rebuild: take your Statement of Applicability, map each 2013 control to its 2022 successor using the correspondence table in Annex B of ISO/IEC 27002:2022, add the eleven new controls with a justification for inclusion or exclusion, and update the risk treatment plan. Certifyi ships the 2022 control set with the 2013 correspondence built in, so an existing SoA is re-mapped in the platform and the evidence already collected stays attached to the successor controls.

ISO 27001:2022, answered

No. The transition period ended on 31 October 2025. Certificates against the 2013 edition are no longer valid, and new audits are conducted against 2022.

No. Annex A is a reference list. You select controls based on your risk assessment and justify exclusions in the Statement of Applicability. The auditor checks the justification, not the count.

From 114 to 93, but mostly through merging. Fifty-seven controls were merged into twenty-four, one was split, and eleven were added, so the coverage is broader even though the count is lower.

For a mature ISMS, one to three weeks of work: mapping the SoA, adding the new controls, and updating the risk treatment plan and internal audit programme.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top