ISO 27001:2022: What Changed From the 2013 Version (2026 Guide)

ISO 27001:2022 changes What Changed From the 2013 Version

ISO 27001:2022 changes eventually ran into the same question: what actually changed in the 2022 update, and how much of it applies to us? The short answer is that the core management system barely moved, while Annex A got a genuine overhaul. This guide walks through exactly what changed — clause by clause, control by control — who needs to act on it, and what the transition actually involved.

ISO 27001:2022 changes

What ISO 27001:2022 changes Actually Is

ISO 27001:2022 changes is the current version of the world’s leading information security management system (ISMS) standard, published by ISO on October 25, 2022. It replaced ISO 27001:2013, which had been in place for nearly a decade. The update didn’t change what ISO 27001 is or how it works — it’s still a risk-based management system standard, not a fixed checklist — but it did rewrite Annex A almost entirely and add a handful of new requirements to the main clauses.

 Quick definition ISO 27001:2022 changes = the current revision of the ISO/IEC 27001   information   security standard, published October 25, 2022, distinguished mainly by a   restructured 93-   control Annex A (down from 114) and one new subclause (6.3) in the main   body of the     standard.

At-a-Glance Comparison

The table below lines up the two versions side by side.

ISO 27001:2013 vs 2022
Category ISO 27001:2013 ISO 27001:2022
Published September 25, 2013 October 25, 2022
Total Annex A controls 114 93
Control differences 11 new controls, 57 old controls merged into 24, none deleted
Total control domains 14 4 (called "themes")
Control attributes Not available Yes (introduced for categorization)
Clause 6.3 Not included Added ("Planning of Changes")
Clauses 9.2 and 9.3 Single clauses Split into subsections
Main clause structure (4–10) 11 clauses Same 11 clauses, lightly reworded
Transition deadline October 31, 2025 (now passed)

History of the Standard

ISO 27001 didn’t appear in 2013 or 2022 out of nowhere — it’s the product of a lineage that goes back to the mid-1990s. ISO standards are typically reviewed on a five-year cycle. By 2022, the 2013 edition was approaching a decade old, and the threat landscape it was written for had shifted substantially — cloud infrastructure, remote work, and supply-chain attacks had all moved from edge cases to everyday risk.

What ISO 27001:2022 changes in the Main Clauses (4–10)

This is the part that surprises people: the core management system barely moved. If you understand the 2013 clause structure, the 2022 version is immediately familiar. Most changes are wording clarifications made to align ISO 27001 with other management-system standards (ISO 9001, ISO 14001) under the shared Annex SL structure.

ISO 27001 Clause Changes
Clause What changed
4.2 Added a requirement to determine which interested-party requirements will actually be addressed through the ISMS
4.4 Now explicitly requires establishing, implementing, maintaining, and improving ISMS processes and their interactions
5.1 Clarifying note added on the term "business"
6.3 (new) "Planning of Changes" — any change to the ISMS must now be planned, not made ad hoc
8.1 Now requires criteria for the processes that address risk, with controls implemented against those criteria
9.1 Reworded to make clear the organization must evaluate ISMS performance, not just monitor it
9.2 Split into 9.2.1 (General) and 9.2.2 (Internal audit programme)
9.3 Split into subsections; a new bullet requires stakeholder needs and expectations to be considered in management review

 Drafting tip: None of these are structural overhauls. Most organizations find their existing   ISMS processes already satisfy the reworded clauses — the gap is usually documentation   catching up to practice, not practice changing.

What ISO 27001:2022 changes in Annex A — The Real Story

The headline number — 114 controls down to 93 — makes it sound like a third of the old controls were cut. That’s not what happened. No controls were deleted. Fifty-seven of the old controls were merged into 24 new ones, 58 carried over with only light rewording, and 11 are genuinely new.

The 14 domains from 2013 were consolidated into four themes, and the new names were deliberately written for a management audience rather than IT specialists:

The 11 New Controls

These are the controls with no 2013 equivalent — the ones that require an actual gap assessment, not just a renumbering exercise.

  • Threat intelligence
  • Information security for use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Monitoring activities
  • Web filtering
  • Secure coding

Sample of How 2013 Controls Map to 2022

Because most controls were merged rather than replaced, mapping old to new is the bulk of transition work. A short sample:

ISO 27001:2022 Annex A Merged Controls
ISO 27001:2022 Annex A Control Merged from ISO 27001:2013
5.1 Policies for information security 5.1.1, 5.1.2
5.9 Inventory of information and other associated assets 8.1.1, 8.1.2
5.15 Access control 9.1.1, 9.1.2
5.17 Authentication information 9.2.4, 9.3.1, 9.4.3
6.8 Information security event reporting 16.1.2, 16.1.3
7.2 Physical entry controls 11.1.1, 11.1.6
8.8 Management of technical vulnerabilities 12.6.1, 18.2.3
8.24 Use of cryptography 10.1.1, 10.1.2
8.32 Change management 12.1.2, 14.2.2, 14.2.3, 14.2.4

 Timing tip: Don’t try to map controls from memory. ISO/IEC 27002:2022 Annex B publishes   an official mapping table between 2013 and 2022 controls — use it as your working   document rather than reconstructing the logic yourself.

Control Attributes — A New Concept

ISO 27001:2022 changes also introduced control attributes, a way to tag each Annex A control by properties such as control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), and relevant cybersecurity concepts. Attributes are optional — the standard doesn’t require you to use them — but they’re useful if you want to cross-map your control set to frameworks like NIST CSF or CIS Controls, or filter your Statement of Applicability by category.

Why the Update Happened

The 2013 edition wasn’t rewritten because it stopped working — it was rewritten because the environment it described had moved on. Cloud computing, remote and hybrid work, and supply-chain-based attacks had all become mainstream risks rather than edge cases, and the old 14-domain structure, written primarily for IT specialists, didn’t map cleanly onto how modern organizations actually think about risk ownership.

The Transition Timeline

ISO 27001 Transition Milestones
Milestone Date
ISO 27001:2022 published October 25, 2022
Certification bodies required to offer 2022 audits By October 31, 2023
New certifications had to use the 2022 version From April 2024 onward
Final deadline to transition existing 2013 certifications October 31, 2025
ISO 27001:2013 certifications Withdrawn after the deadline

The transition deadline has now passed. Any organization still holding a 2013-based certificate today no longer has a valid ISO 27001 certification — if your certificate still references 2013, it should have been upgraded at your last surveillance or re certification audit.

What the Transition Actually Involved

For organizations already certified to the 2013 version, the practical work looked like this:

Run a gap assessment mapping existing controls to the 2022 structure.

Review the 11 new controls and determine which apply to your environment.

Update the Statement of Applicability (SoA) to reflect the new control numbers and four-theme structure.

Update supporting policies and procedures where control wording changed materially.

Complete a transition audit, either standalone or combined with a scheduled surveillance or re certification audit.

Common Mistakes Companies Made With the Transition

Assuming the drop from 114 to 93 controls meant less work, rather than checking which 11 were genuinely new.

Renaming controls in the SoA without actually reassessing whether the merged control’s full scope was still covered.

Leaving the transition until close to the October 2025 deadline instead of folding it into a regular surveillance audit.

Treating control attributes as mandatory paperwork rather than the optional categorization tool they are.

Not updating risk treatment plans to reference the new control numbering, creating a mismatch between the SoA and internal risk records.

How B4Q Assurance Helps

As a licensed U.S. CPA firm (AICPA) handling SOC 1, SOC 2, and SOC 3 engagements, B4Q Assurance also works with clients navigating ISO 27001 gap assessments and control mapping — helping teams confirm their Statement of Applicability and risk treatment plans are actually aligned with the 2022 structure, not just relabeled.

Ready to Confirm Your Status?

If your certification still references the 2013 version, or you’re not sure your Statement of Applicability reflects the current 93-control structure, it’s worth a quick review before it surfaces in a customer’s security questionnaire.

Book a free strategy call to review your current ISMS documentation against the ISO 27001:2022 requirements.

Resources

 ISO — ISO/IEC 27001:2022: the official standard reference on the ISO website.

ISO/IEC 27002:2022: the companion standard with the official control mapping between 2013 and 2022 versions of Annex A.

IAF MD 26 — Transition Requirements for ISO/IEC 27001:2022: the source document for transition deadlines and certification body requirements.

FAQs

Is ISO 27001:2022 changes still valid?

No. The transition deadline was October 31, 2025. Certifications based on the 2013 version were withdrawn after that date.

No. All 114 original controls carried forward in some form — 58 with minor wording changes, 57 merged into 24 consolidated controls, and 11 added as entirely new.

No. Attributes are optional. They’re useful for cross-mapping to other frameworks but aren’t a certification requirement.

Clause 6.3, “Planning of Changes” — a new requirement that any change to the ISMS be planned rather than made informally.

It varies by organization size and can usually be combined with a scheduled surveillance or recertification audit rather than run as a separate event — your certification body can confirm what applies to your cycle.

What do you think?