The 2022 version restructured Annex A to 93 controls in 4 themes and added 11. Here is everything that changed, and why.
ISO 27001:2022 is the current version of the standard, published in October 2022, and its headline change is a restructured Annex A: 93 controls organised into four themes, down from 114 controls in fourteen domains in the 2013 version. The update did not weaken the standard; it merged overlapping controls, added 11 new ones covering modern risks such as cloud and threat intelligence, and introduced attributes for filtering controls. The transition period from the 2013 version ended on 31 October 2025, so every current certificate is now to the 2022 version. Here is what actually changed and what it means for you.
The latest version of ISO 27001 is ISO/IEC 27001:2022, published in October 2022. It replaced ISO 27001:2013, and following the end of the transition period on 31 October 2025, ISO 27001:2013 certificates are no longer recognised. So any organisation certified today, or seeking certification, works to the 2022 version. When people write iso27001 2022 or ask which version applies, this is the answer: the 2022 revision is the standard in force.
The biggest change in ISO 27001:2022 is Annex A. The 2013 version listed 114 controls across fourteen domains; the 2022 version reorganises the control set into 93 controls across four themes: organisational, people, physical and technological. Many controls were merged, which is why the total fell, and none of the protection was genuinely removed. The four-theme structure is simpler to navigate than the old fourteen domains, and it aligns Annex A with the guidance in ISO 27002:2022, so the two standards now share the same control language.
ISO 27001:2022 introduced 11 new controls to address risks that had grown since 2013. They are threat intelligence, information security for the use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. These reflect the shift to cloud, the rise of data-centric threats, and modern software practices. If you are moving from a 2013-era programme, these 11 are where you will find genuinely new work rather than relabelled existing controls.
| Theme | Controls in 2022 | Focus |
|---|---|---|
| Organisational | 37 | Policies, roles, suppliers, cloud, threat intelligence |
| People | 8 | Screening, awareness, responsibilities |
| Physical | 14 | Facilities, equipment, physical monitoring |
| Technological | 34 | Access, cryptography, logging, secure coding |
ISO 27001:2022 Annex A: 93 controls across four themes. Counts are from the 2022 standard.
Yes, but less dramatically than Annex A. The management-system clauses, four to ten, saw refinements rather than an overhaul: clearer wording on planning of changes, on the needs of interested parties, and on the definition of processes and their criteria. If your ISMS was already well run under the 2013 version, the clause changes are modest and mostly about tightening and clarity. The substantive work in transitioning sits in remapping to the new Annex A structure and addressing the 11 new controls, not in the clauses.
ISO 27001:2022 introduced attributes that tag each Annex A control against dimensions such as control type, information security properties, cybersecurity concepts, operational capabilities and security domains. Attributes are not new requirements; they are an optional way to filter and view the controls, for example to see all preventive controls or all controls related to a particular capability. They help larger organisations organise and report on their controls, and they can be safely ignored by a small team that simply implements the controls, since they do not change what you must do.
Because the transition period ended on 31 October 2025, organisations that held a 2013 certificate needed to transition by then, and any that did not now require a fresh certification to the 2022 standard. If you are certifying for the first time today, you certify directly to ISO 27001:2022 and there is nothing to transition. If you are maintaining an existing 2022 certificate, you continue with normal surveillance audits. In short, the 2022 version is simply the standard now, and new work should be built around it from the start.
CertAssist encodes ISO 27001:2022, so you work from the current 93-control, four-theme structure and the 11 new controls rather than the retired 2013 layout, with editable templates and the Statement of Applicability handled. That means no remapping from an outdated control set and no risk of building against a standard that is no longer recognised. CertAssist does not connect to your systems, and the price is a published US$225 per month during its launch.
The latest version is ISO/IEC 27001:2022, published in October 2022. It replaced ISO 27001:2013, and after the transition period ended on 31 October 2025, 2013 certificates are no longer recognised. Any organisation certified or seeking certification today works to the 2022 version.
ISO 27001:2022 has 93 Annex A controls in four themes: organisational (37), people (8), physical (14) and technological (34). That is down from 114 controls in fourteen domains in the 2013 version, mainly because overlapping controls were merged rather than protection being removed.
The 2022 version added 11 controls: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. They reflect the shift to cloud and modern, data-centric threats.
The transition period from ISO 27001:2013 to the 2022 version ended on 31 October 2025. After that date, 2013 certificates are no longer recognised by auditors, customers or the accreditation bodies. Organisations that had not transitioned by then need a fresh certification to the 2022 standard.
If you held a 2013 certificate, you needed to transition by 31 October 2025, and if you did not, you now require fresh certification to the 2022 standard. If you are certifying for the first time, you certify directly to ISO 27001:2022. Existing 2022 certificate holders simply continue with normal surveillance audits.
CertAssist encodes the current 93 controls and four themes with editable templates and your SoA handled, for a published $225 a month during the launch.
See pricing FrameworksFlat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.