Why there is a new version of ISO 27001
The previous version, ISO/IEC 27001:2013, remained in force for almost a decade. During that time the information security landscape changed a great deal: the massive adoption of cloud services, remote working, targeted threats and regulatory pressure meant some controls fell short or were laid out impractically.
That's why ISO/IEC 27001:2022 was published. It isn't a completely different standard: the core of the information security management system (clauses 4 to 10, on context, leadership, planning, support, operation, performance evaluation and improvement) stays practically the same, with minor wording tweaks. The substantive change is in Annex A, which is aligned with the new edition of controls published in ISO/IEC 27002:2022.
In my experience supporting companies through these processes, it's worth understanding it this way: the structure of the management system stays the same; what's reorganised and modernised is the catalogue of controls you apply to treat your risks.
What changes between ISO 27001:2013 and 2022
The most visible change, and the one that generates the most work, is the reorganisation of Annex A. Where there used to be 114 controls spread across 14 domains, there are now 93 controls grouped into four broad themes. It's not that 21 controls were simply removed: many were merged or consolidated, others were rewritten, and 11 controls that didn't previously exist as such were added.
These are the four groups Annex A is now structured into:
| Control group | Focus | No. of controls |
|---|---|---|
| Organisational | Policies, roles, supplier management, incident management, continuity | 37 |
| People | Awareness, responsibilities, remote working, confidentiality agreements | 8 |
| Physical | Security of facilities, equipment, media and secure areas | 14 |
| Technological | Access control, cryptography, logging, secure development, configuration | 34 |
Besides the new grouping, each control in the 2022 version includes attributes (for example, control type, security properties, cybersecurity concepts or operational capabilities) that help filter and classify them. It's a practical aid, not a mandatory requirement.
The 11 new controls
What really requires you to review your system are the controls that were added, because they reflect risks that were barely considered in 2013. Among them are threat intelligence, information security for the use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention (DLP), monitoring of activities, web filtering and secure coding.
Each of these new controls can involve documentation, procedures or tools that your organisation may not have had formalised. That's why the transition isn't just a change of labels: it's an opportunity to genuinely review how you manage security.
The ISO 27001:2013 to 2022 transition deadline
This is the part that raises the most questions. When a new version of a certifiable standard is published, the IAF (the international forum that coordinates accreditation bodies) sets a transition period so that already-certified organisations can migrate their certificate in an orderly way.
For ISO/IEC 27001:2022, the IAF set a transition period of three years counted from the standard's publication. That deadline has now ended. In other words, organisations that held a certificate under the 2013 version should have completed their transition audit within that window.
As the specific closing dates, exceptional extensions and audit calendars can vary by body and by case, my recommendation is clear: check the current deadline and the actual status of your certificate with your certification body. It's the only source that will give you the exact situation of your certificate, without assumptions. And if you're not yet certified and you're starting now, you'll go straight onto the 2022 version, so this concern doesn't apply to you.
Steps to make the transition
If your system is still documented against the 2013 version, the path to migrate it is fairly predictable. These are the steps I follow when I support a transition:
- Gap analysis. Compare your current system against the requirements of the 2022 version, control by control. Identify what stays, what's been merged, what needs rewriting and which new controls apply to you.
- Update the risk analysis. Review your risk assessment and treatment in light of the new controls and current threats (cloud, data leakage, targeted threats).
- Update the Statement of Applicability (SoA). This is the key document of the transition. You have to redo it against the 93 controls of the 2022 version, justifying which ones you apply, which you exclude and why.
- Implement the new controls. Put in place procedures, policies or tools for the controls you didn't previously have formalised, as applicable to your organisation.
- Update documentation and train the team. Adjust policies, procedures and records, and make sure the people involved know about the changes.
- Internal audit. Before the certification body's visit, it's worth running an ISO internal audit to catch deviations and correct them in time.
- Transition audit. Your certification body carries out the audit that verifies your system complies with the 2022 version. It can coincide with a surveillance or renewal audit, depending on your cycle.
If you need support to organise this process, at ISO consulting we help plan the transition and prepare the documentation without disrupting the company's day-to-day.
What happens if you don't transition in time
This is the consequence that's worth being very clear about: if the transition period ends and you haven't migrated, your certificate under the 2013 version stops being valid. It doesn't automatically become a 2022 certificate, nor does it extend itself.
In practice, losing the certificate's validity can affect your reputation, tenders that require a valid certification, and contracts with clients that include it as a requirement. Recovering it usually means going through the certification process again, with the cost and time that involves. So if you have any doubt about your certificate's status, the first thing to do is talk to your certification body as soon as possible.
Recommendations for a smooth transition
Of everything I've seen in these processes, these are the recommendations that add the most value:
- Don't leave it to the last minute. The transition works best with margin, fitting it into a surveillance or renewal audit that's already scheduled.
- Start with the gap analysis. It gives you a realistic picture of the effort and avoids surprises with the new controls.
- Take care of the Statement of Applicability. It's the document that best reflects the maturity of your system and the one the auditor looks at most closely.
- Choose your auditor well. Work with an ENAC-accredited certification body so your certificate carries real recognition.
- Budget realistically. If you're wondering how much it costs to get certified in ISO 27001 or to transition, factor in internal hours, possible tools and the audit itself.
Conclusion
The transition from ISO 27001:2013 to 2022 isn't just a date change on the certificate: it's a thorough review of Annex A, with 93 controls reorganised into four groups and 11 new controls that reflect today's risks. The transition period set by the IAF was three years from publication and has now ended, so the sensible move is to check the actual status of your certificate with your certification body and, if applicable, plan the migration as soon as possible. Doing it methodically (gap analysis, risks, SoA, new controls and audit) turns an obligation into a genuine improvement in your security.
If you'd like us to review together where your system stands and how to approach the transition without slowing down your business, get in touch and let's take a look.