certifications7 min read

ISO 27001:2022 explained: Annex A, 93 controls, transition over

ISO/IEC 27001 was revised in October 2022, and that edition is now the only one that matters: the transition period from the 2013 edition has closed, the old certificates have expired, and every certification project is built on ISO/IEC 27001:2022. If you are discovering the standard, good news: you will never have to manage the migration. If you knew it in its 2013 edition, here is precisely what changed — and why the new Annex A is easier to read than the old one.

The essentials: a revision centred on Annex A

The body of the standard — clauses 4 to 10, which describe the management system (context, leadership, planning, support, operation, evaluation, improvement) — evolved only at the margins. The logic remains that of every modern management standard: defined scope, risk assessment, controls selected and justified, internal audit, management review, continual improvement.

The real change is in Annex A, the reference list of security controls, aligned with the revision of the companion standard ISO/IEC 27002 published the same year. Two figures sum up the shift:

2013 edition 2022 edition
Number of controls 114 93
Organisation 14 domains 4 themes

The smaller number of controls does not mean lighter requirements: it mostly results from merging redundant controls, alongside new controls reflecting today’s threat landscape and IT architectures.

The 4 themes of the new Annex A

The 93 controls are grouped into four themes, far more intuitive than the 14 domains of 2013:

  • Organisational controls: policies, roles and responsibilities, supplier relationships, incident management, compliance — the largest block;
  • People controls: hiring, awareness, staff obligations, departures;
  • Physical controls: security of premises, equipment and media;
  • Technological controls: access, cryptography, secure development, network and operations security.

This structure by “who owns the control” makes workload distribution easier: the security officer cannot carry the organisational and people controls alone, and the new Annex makes that visible at a glance.

The new controls: catching up with reality

The 2022 edition introduces controls that did not exist in 2013 and that speak immediately to any modern organisation, including:

  • threat intelligence: collecting and analysing information on relevant threats;
  • information security for the use of cloud services: unavoidable in the age of ubiquitous SaaS;
  • ICT readiness for business continuity: IT’s ability to meet continuity objectives;
  • physical security monitoring and monitoring activities on systems;
  • configuration management, information deletion, data masking and data leakage prevention;
  • web filtering and secure coding for development teams.

For a new project, these controls are not an extra burden: they match what buyers and enterprise clients already ask for in their security questionnaires. The reference study by Culot, Nassimbeni, Podrecca and Sartor, published in 2021 in The TQM Journal, which reviews the scientific literature on ISO/IEC 27001, was already stressing the standard’s need to keep pace with the fast-moving threat and technology landscape — which is exactly what this revision does (see the study).

One last note: like the other major management standards, ISO/IEC 27001:2022 received a 2024 amendment asking organisations to consider climate change in their context analysis — a limited adjustment, but one your analysis of issues should mention.

What this means for your project in 2026

Starting from scratch: build directly on the 2022 edition. Your statement of applicability will review the 93 Annex A controls, with choices justified by your risk assessment. The full journey is detailed in our guide to getting ISO 27001 certified step by step.

Previously certified against 2013: your certificate was necessarily migrated before the end of the transition (or expired). If your documentation still carries traces of the old structure — references to the 14 domains, an SoA in 114 controls — use your next internal audit to finish the clean-up: leftover transition inconsistencies are among the easiest audit remarks to avoid.

Assessing suppliers: require a certificate against ISO/IEC 27001:2022, check its exact scope and the certifier’s accreditation. A “certificate” without accreditation, or with a vague scope, is worth little — the same reflex applies to any management-system certificate, as we describe for the ISO 9001 surveillance cycle.

Take action

The 2022 edition is clearer, closer to real-world threats, and the only valid basis for certification today. To see the whole scheme — status, certification bodies, costs, frequent questions — visit the ISO 27001 certification profile and download the free ebook there to structure your project.

FAQ

Frequently asked questions

+Is an ISO 27001:2013 certificate still valid in 2026?

No. The transition period set by the accreditation bodies is over: certificates issued against ISO/IEC 27001:2013 ceased to be valid at its close, at the end of October 2025. Every certificate currently in force rests on the 2022 edition, and any new project starts directly on it.

+Do you have to implement all 93 Annex A controls?

No: Annex A remains a reference list, not a list of obligations. You must review every control, adopt those your risk assessment justifies, and document exclusions in the statement of applicability. That principle did not change between 2013 and 2022 — only the list was restructured.

+Did the 2022 edition change the body of the standard (clauses 4 to 10)?

Very little: the management-system requirements (context, leadership, risks, support, operation, evaluation, improvement) stay aligned with the common structure of management standards, with limited adjustments. The bulk of the change is in Annex A, reorganised and modernised.

Read next