Learn about 11 new controls, restructuring of Annex A controls, transition deadline, the new clause 6.3, five control attributes and more, through the Frequently Asked Questions (FAQs) below. Please schedule a meeting if you are looking for an authorized certifying body for your ISO 27001 Certification.
Table of Contents
What changed between ISO 27001:2013 and ISO 27001:2022?
Summary: ISO 27001:2022 introduced significant structural changes to Annex A, minor updates to management clauses, and 11 entirely new controls addressing modern cybersecurity challenges including cloud computing, remote working, and threat intelligence.
ISO/IEC 27001:2022 introduced changes across two areas: the management system clauses (4, 10) and Annex A. Clause changes were minor: Clause 4.2 now requires organizations to specify how interested parties’ requirements are addressed in the ISMS; Clause 6.2 explicitly requires security objectives to be documented and monitored; Clause 6.3 (Planning of Changes) is entirely new; and Clause 9.2 was split into two sub, clauses for clarity. The most significant changes were in Annex A: the 2013 version had 114 controls in 14 domains; the 2022 version restructured these into 93 controls in 4 themes, Organizational, People, Physical, and Technological. Eleven brand, new controls were introduced. The restructuring reflects modern security realities including cloud, first environments, distributed workforces, and sophisticated supply chain threats.
What are the 11 new controls introduced in ISO 27001:2022?
ISO 27001:2022 introduced 11 new Annex A controls addressing modern information security challenges not present in the 2013 version. The 11 new controls are: Control 5.7 (Threat Intelligence), collecting and analyzing threat data to inform security decisions; Control 5.23 (Information Security for Use of Cloud Services), governing the security of cloud service acquisition and use; Control 5.30 (ICT Readiness for Business Continuity), ensuring technology systems support continuity plans; Control 7.4 (Physical Security Monitoring), surveillance and monitoring of secure physical areas; Control 8.9 (Configuration Management), maintaining secure baseline configurations; Control 8.10 (Information Deletion), secure erasure of information no longer needed; Control 8.11 (Data Masking), protecting sensitive data through masking and pseudonymization; Control 8.12 (Data Leakage Prevention), detecting and preventing unauthorized data exfiltration; Control 8.16 (Monitoring Activities), continuous monitoring for anomalous behavior; Control 8.23 (Web Filtering), controlling external website access to reduce malware exposure; and Control 8.28 (Secure Coding), mandating secure software development principles.
How were the Annex A controls restructured in ISO 27001:2022?
Summary: The Annex A controls were restructured from 114 controls across 14 domains in the 2013 version to 93 controls across 4 themes in the 2022 version, through a combination of merging, retaining, and adding controls.
In ISO 27001:2022, Annex A was reorganized from the 2013 structure of 14 domains into four broader themes: Organizational Controls (37 controls), People Controls (8 controls), Physical Controls (14 controls), and Technological Controls (34 controls). The reduction from 114 to 93 controls was achieved by consolidating related controls from the 2013 version, retaining the majority with updates for modern relevance, and adding 11 entirely new controls that did not previously exist. The restructuring also introduced five control attributes, control type, security properties, cybersecurity concepts, operational capabilities, and security domains, that help organizations categorize and filter controls by relevance. The new structure makes it more straightforward to map ISO 27001 controls against frameworks such as NIST CSF, SOC 2, and CIS Controls.
What was the deadline to transition from ISO 27001:2013 to ISO 27001:2022?
The deadline to transition from ISO 27001:2013 to ISO 27001:2022 was October 31, 2025. ISO and the International Accreditation Forum (IAF) established a three, year transition period beginning when the 2022 standard was published on October 25, 2022. After October 31, 2025, all remaining ISO/IEC 27001:2013 certificates expired and ceased to be recognized by accreditation bodies worldwide. Organizations that did not complete a transition audit before the deadline were required to restart the certification process from scratch under ISO 27001:2022. The transition deadline created significant market demand for transition audits throughout 2024 and 2025, with many certification bodies experiencing constrained auditor availability as the date approached.
What happens to an ISO 27001:2013 certificate that was not transitioned by October 31, 2025?
An ISO 27001:2013 certificate not transitioned to ISO/IEC 27001:2022 by October 31, 2025, automatically expired and is no longer recognized as valid certification by any accredited certification body or national accreditation authority worldwide. The certificate cannot be reinstated, organizations in this situation must pursue initial certification under ISO/IEC 27001:2022, completing a full two, stage audit process as though certifying for the first time. The practical consequences are immediate: enterprise contracts requiring valid ISO 27001 certification may lapse, regulatory compliance claims relying on the certificate become untenable, and the organization must disclose to customers and partners that its certification has expired. The recommended course of action is to immediately contact an accredited certification body and begin the initial ISO/IEC 27001:2022 certification process.
How do organizations transition from ISO 27001:2013 to ISO 27001:2022?
Summary: Transitioning from ISO 27001:2013 to ISO 27001:2022 requires a gap assessment, SoA update, risk treatment plan revision, and a formal transition audit conducted by the organization’s existing certification body.
The transition process follows these steps. First, the organization purchases the official ISO/IEC 27001:2022 standard and conducts a gap analysis comparing its existing ISMS against new requirements, identifying areas needing updates. Second, it evaluates the 11 new Annex A controls for applicability and updates the Statement of Applicability to reflect the new four, theme control structure. Third, the risk treatment plan is revised to incorporate newly applicable controls. Fourth, all affected policies, procedures, and documentation are updated. The organization then undergoes a transition audit, conducted as a stand, alone special audit, combined with a scheduled surveillance audit, or combined with a recertification audit. Upon successful completion, the certification body issues a new certificate referencing ISO/IEC 27001:2022. Organizations should engage their certification body early, as auditor availability can be constrained.
What is the new Clause 6.3 (Planning of Changes) in ISO 27001:2022?
Clause 6.3 (Planning of Changes) is an entirely new requirement introduced in ISO 27001:2022 that mandates organizations to manage changes to their ISMS in a controlled, systematic manner. When an organization determines that a change is necessary, such as expanding the ISMS scope, implementing new technology, restructuring the organization, or modifying security controls, it must plan those changes to ensure they are carried out in an orderly fashion without compromising information security. The clause does not prescribe a specific change management process but requires organizations to consider: the purpose of changes, potential consequences for the ISMS, resource needs, and responsibilities. Most organizations implement a formal change management procedure that documents proposed changes, evaluates their security impact, obtains approval, tracks implementation, and reviews outcomes. Poorly managed organizational change is a recognized source of new information security vulnerabilities, which is why this clause was added.
What are the five control attributes introduced in ISO 27002:2022?
ISO 27002:2022 introduced five control attributes that can be used to categorize, filter, and sort the 93 Annex A controls based on different organizational perspectives. The five attributes are: Control Type, whether the control is preventive, detective, or corrective; Information Security Properties, which CIA triad dimension (Confidentiality, Integrity, Availability) the control primarily addresses; Cybersecurity Concepts, mapping the control to the NIST CSF functions of Identify, Protect, Detect, Respond, and Recover; Operational Capabilities, categorizing the control by the security function it supports, such as access control, incident management, or asset management; and Security Domains, grouping controls by domain such as Governance and Ecosystem, Protection, Defense, or Resilience. These attributes are not mandatory for ISO 27001 certification but provide a flexible taxonomy for organizing controls, simplifying framework mappings, and focusing security investment.
Do organizations newly seeking ISO 27001 certification have to certify against the 2022 version?
Organizations pursuing ISO 27001 certification for the first time must certify against ISO/IEC 27001:2022, the 2013 version is no longer available for initial certification. ISO and the IAF mandated that certification bodies stop issuing initial ISO 27001:2013 certifications from April 30, 2024. After October 31, 2025, all ISO 27001:2013 certificates, whether initial or previously certified, expired globally. Any organization beginning the certification process in 2026 must ensure that all ISMS documentation, risk assessment processes, Annex A control selections, and the Statement of Applicability are aligned with ISO/IEC 27001:2022 and its companion implementation guide, ISO/IEC 27002:2022, from the outset.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties