🌍 ISO 27001🔄 2022 Revision⚠️ Transition

ISO 27001:2022 Changes vs 2013 — What You Must Update Before Deadline

The 2013 version is retired. The 2022 revision restructured Annex A from 114 controls to 93, added 11 new ones, and changed what auditors expect — here's exactly what moved, and what your ISMS still has to reflect.

SS
Soham Sawant
🔐 Cybersecurity Expert·📖 9 min read
📅 June 2026·🏢 SecComply
ISO 27001:2022 Annex A restructured into four themes

The 2022 revision regrouped Annex A into four themes, cut 114 controls to 93, and added 11 new ones — the SoA is where the change lands hardest.

For nearly a decade, ISO/IEC 27001:2013 was the version every certified organisation lived by. That era is over. The 2022 revision didn't touch the core management system in any dramatic way, but it took Annex A — the catalogue of security controls everyone maps their ISMS against — and rebuilt it: 114 controls became 93, fourteen domains collapsed into four themes, and eleven genuinely new controls appeared to cover the world that had grown up since 2013. The three-year transition window has now closed. If your certificate didn't make the move by 31 October 2025, it isn't valid any more. This is the definitive account of what changed and what your ISMS still has to reflect.

114 → 93
Annex A controls, restructured and consolidated
11 new
Controls added for cloud, threat intel, and secure development
4 themes
Organisational, People, Physical, Technological
Oct 2025
The transition deadline — already passed, so 2013 certs are now void

Why ISO 27001 Was Revised

The 2013 standard was written for a 2013 world — one where most data sat in a data centre you could walk into, where DevOps was an emerging idea, and where "the cloud" was a procurement footnote rather than the default place applications run. Over the following decade Annex A quietly drifted out of step with how organisations actually operate. Teams ship code continuously, run workloads across providers they don't own, and face a threat landscape that moves faster than any annual review cycle. The control set still worked, but it described the wrong shape of organisation.

The 2022 revision is the response to that drift. It modernises the control catalogue for cloud, automation and contemporary threats, and — just as importantly — reorganises it so the structure matches the way security is actually run today. The underlying management discipline didn't need fixing; the list of what to protect, and how, did.

What Changed in the Structure

The headline change is the reorganisation of Annex A. The fourteen control domains of 2013 — the familiar A.5 through A.18 numbering — were regrouped into four themes: Organisational, People, Physical and Technological. It is a flatter, more intuitive arrangement that maps to who owns each kind of control rather than to an arbitrary taxonomy.

The control count fell from 114 to 93. That reduction is misleading if you read it as deletion: the bulk of it comes from merges, where several overlapping 2013 controls were consolidated into a single, clearer one. Very little was genuinely dropped. So the work of transition is rarely about removing controls — it's about re-mapping the ones you already have onto the new numbers and themes.

The revision also introduced five attributes that can be attached to every control for filtering and reporting: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (aligned to identify-protect-detect-respond-recover), operational capabilities, and security domains. These are optional lenses, not new requirements, but auditors increasingly expect to see an organisation using them to slice its control set.

By contrast, the management system clauses — Clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation and improvement — saw only minor wording alignment. If your ISMS governance was sound under 2013, it remains sound under 2022. The disruption is concentrated almost entirely in Annex A.

The 11 New Controls

Eleven controls in the 2022 Annex A have no direct predecessor in 2013. They are where the revision earns its keep — each one closes a gap that a decade of cloud, DevOps and modern attack patterns had opened. These are the controls most likely to need fresh evidence, because in many ISMSs they were never formally addressed at all.

ControlWhat it requires
A.5.7 Threat intelligenceCollect and act on information about threats
A.5.23 Information security for use of cloud servicesGovern cloud acquisition, use and exit
A.5.30 ICT readiness for business continuityPlan ICT recovery to meet continuity objectives
A.7.4 Physical security monitoringDetect unauthorised physical access
A.8.9 Configuration managementControl secure configurations of hardware and software
A.8.10 Information deletionDelete data no longer required
A.8.11 Data maskingMask data to limit exposure
A.8.12 Data leakage preventionStop unauthorised data exfiltration
A.8.16 Monitoring activitiesMonitor systems for anomalous behaviour
A.8.23 Web filteringControl access to external websites
A.8.28 Secure codingApply secure development practices in code

Read as a group, these eleven controls tell a clear story: ISO 27001 finally expects organisations to govern their cloud, watch their own systems, protect data in transit and at rest more deliberately, and build security into software rather than bolt it on. None of them are exotic — most mature security teams were already doing the work — but the 2022 standard now requires you to show it.

What You Must Update

Transitioning an ISMS to 2022 is a concrete piece of documentation and evidence work, not a paperwork rename. The pieces that have to change are:

  • The Statement of Applicability — remapped to the 93 controls and, where you use them, the five attributes. This is the single largest task.
  • The risk treatment plan — re-aligned so each risk traces to the controls it now maps to under the new Annex A.
  • Policies and documents — anything that references old 2013 control numbers (A.5–A.18) updated to the 2022 numbering and themes.
  • Internal audit and management review — the audit programme and review agenda re-scoped against the new control set, so your own assurance is testing the right things.
  • Evidence for the 11 new controls — fresh records demonstrating that threat intelligence, cloud governance, configuration management, secure coding and the rest are actually operating.
💡
THE SoA IS WHERE THE TRANSITION IS WON OR LOST

Most of the migration effort lands in the Statement of Applicability. It has to be rebuilt against the 93 controls, justify each inclusion or exclusion afresh, and trace back to the risk assessment. An SoA that still lists 114 controls in 14 domains is the clearest signal to an auditor that the transition was cosmetic.

The Deadline Has Passed — What That Means Now

The transition window — the three years certification bodies gave organisations to move from 2013 to 2022 — closed on 31 October 2025. That date is now behind us, and the consequences are no longer hypothetical.

ISO/IEC 27001:2013 has been withdrawn. Any certificate that was not migrated to 2022 by the deadline is no longer valid — it didn't lapse gently into a grace period, it ceased to be recognised. Every certification audit and every surveillance audit now runs against the 2022 version; there is no 2013 audit to fall back on. And any organisation pursuing certification for the first time today starts directly on 2022 — the older standard isn't an option, even as a stepping stone. In short, 2022 is no longer "the new version" you are moving toward. It is simply ISO 27001.

2013 vs 2022 at a Glance

The full picture, side by side — the structural and substantive differences in one view:

ISO 27001:2013ISO 27001:2022
114 Annex A controls93 Annex A controls
14 control domains4 themes
No attributes5 attributes for filtering
No cloud-specific controlA.5.23 cloud services
No threat intelligence controlA.5.7 threat intelligence
No secure coding controlA.8.28 secure coding
Status: withdrawnStatus: current standard

Final Thought

The 2022 revision was never a tear-up of ISO 27001 — the management system you built remains the management system you keep. What changed is the control catalogue, and it changed for good reasons: to describe organisations that run on cloud and continuous delivery, to make the structure legible, and to require evidence for the security practices that had quietly become essential. The organisations that handled the transition well treated it as a chance to genuinely re-examine their controls against how they now operate, not as a numbering exercise to survive.

The test: open your SoA — does it list 93 controls in four themes, with real evidence for the eleven new ones, or is it still a 2013 document with a new cover page? With the deadline behind us, that question no longer has a comfortable answer. An ISMS that only looks transitioned is, at the next audit, an ISMS that isn't certified.

Still Carrying 2013-Era Documentation?

SecComply remaps your ISMS to ISO 27001:2022 — rebuilding the SoA against the 93 controls and five attributes, closing evidence gaps on the 11 new controls, and updating policies, risk treatment and internal audit so your next audit is clean.

Frequently Asked Questions

What is the difference between ISO 27001:2013 and 2022?

The management clauses (4 to 10) are largely the same with minor wording updates; the big change is Annex A, restructured from 114 controls in 14 domains to 93 controls in 4 themes — Organisational, People, Physical and Technological — with 11 new controls and many merges.

What are the 11 new controls in ISO 27001:2022?

Threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

Has the ISO 27001 transition deadline passed?

Yes. The transition period ended on 31 October 2025. Certificates not migrated to 2022 by then are no longer valid, the 2013 standard is withdrawn, and all certification and surveillance audits are now conducted against ISO 27001:2022.

I am certifying for the first time — which version?

ISO 27001:2022. The 2013 version is withdrawn and new certifications are issued only against 2022, so build your SoA and controls to the 93-control Annex A from the start.