D-WINGS Consulting LLP
ISO GUIDANCE

ISO/IEC 27001:2022: What Changed, and What It Means If You Haven't Transitioned Yet

D-WINGS Consulting LLP · 3 February 2026

ISO/IEC 27001:2022 replaced the 2013 version of the standard, and the change was more structural than cosmetic.

What changed in Annex A. The control set was reorganised from 14 clauses (A.5 to A.18) into four themes: Organizational, People, Physical, and Technological controls. The total control count dropped from 114 to 93 — partly through consolidation of overlapping controls, and partly through genuine simplification. Eleven new controls were introduced, including threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, data masking, and data leakage prevention. These additions reflect a decade of change in how organisations actually operate — cloud-first infrastructure, more distributed workforces, and a threat landscape that has moved well past the assumptions baked into the 2013 control set.

Where this leaves certified organisations. The international accreditation bodies set a transition deadline of 31 October 2025 for existing ISO/IEC 27001:2013 certificates to move to the 2022 version — that deadline has now passed. Any organisation still operating against the 2013 control set does not hold a currently valid ISO/IEC 27001 certification in the eyes of most certification bodies and enterprise customers who check certificate scope and revision. If your Statement of Applicability, risk treatment plan and internal audit programme haven’t been remapped to the 2022 Annex A, this is not a future item — it is an active gap.

What the transition actually involves, beyond a document update:

For organisations pursuing first-time certification, this question doesn’t arise — the 2022 version is simply the current standard. The more common situation is an organisation with a 2013-era ISMS that has been running on autopilot since the original certification project ended, where the annual surveillance audit becomes the first real test of whether the transition was actually completed. That is a considerably more expensive way to discover the gap than a planned gap assessment.

Have a question on this?

Talk to an Expert