ISO 27001:2022 changes What Changed From the 2013 Version
ISO 27001:2022 changes eventually ran into the same question: what actually changed in the 2022 update, and how much of it applies to us? The short answer is that the core management system barely moved, while Annex A got a genuine overhaul. This guide walks through exactly what changed — clause by clause, control by control — who needs to act on it, and what the transition actually involved.
What ISO 27001:2022 changes Actually Is
ISO 27001:2022 changes is the current version of the world’s leading information security management system (ISMS) standard, published by ISO on October 25, 2022. It replaced ISO 27001:2013, which had been in place for nearly a decade. The update didn’t change what ISO 27001 is or how it works — it’s still a risk-based management system standard, not a fixed checklist — but it did rewrite Annex A almost entirely and add a handful of new requirements to the main clauses.
Quick definition ISO 27001:2022 changes = the current revision of the ISO/IEC 27001 information security standard, published October 25, 2022, distinguished mainly by a restructured 93- control Annex A (down from 114) and one new subclause (6.3) in the main body of the standard.
At-a-Glance Comparison
The table below lines up the two versions side by side.
| Category | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Published | September 25, 2013 | October 25, 2022 |
| Total Annex A controls | 114 | 93 |
| Control differences | — | 11 new controls, 57 old controls merged into 24, none deleted |
| Total control domains | 14 | 4 (called "themes") |
| Control attributes | Not available | Yes (introduced for categorization) |
| Clause 6.3 | Not included | Added ("Planning of Changes") |
| Clauses 9.2 and 9.3 | Single clauses | Split into subsections |
| Main clause structure (4–10) | 11 clauses | Same 11 clauses, lightly reworded |
| Transition deadline | — | October 31, 2025 (now passed) |
History of the Standard
ISO 27001 didn’t appear in 2013 or 2022 out of nowhere — it’s the product of a lineage that goes back to the mid-1990s. ISO standards are typically reviewed on a five-year cycle. By 2022, the 2013 edition was approaching a decade old, and the threat landscape it was written for had shifted substantially — cloud infrastructure, remote work, and supply-chain attacks had all moved from edge cases to everyday risk.
What ISO 27001:2022 changes in the Main Clauses (4–10)
This is the part that surprises people: the core management system barely moved. If you understand the 2013 clause structure, the 2022 version is immediately familiar. Most changes are wording clarifications made to align ISO 27001 with other management-system standards (ISO 9001, ISO 14001) under the shared Annex SL structure.
| Clause | What changed |
|---|---|
| 4.2 | Added a requirement to determine which interested-party requirements will actually be addressed through the ISMS |
| 4.4 | Now explicitly requires establishing, implementing, maintaining, and improving ISMS processes and their interactions |
| 5.1 | Clarifying note added on the term "business" |
| 6.3 (new) | "Planning of Changes" — any change to the ISMS must now be planned, not made ad hoc |
| 8.1 | Now requires criteria for the processes that address risk, with controls implemented against those criteria |
| 9.1 | Reworded to make clear the organization must evaluate ISMS performance, not just monitor it |
| 9.2 | Split into 9.2.1 (General) and 9.2.2 (Internal audit programme) |
| 9.3 | Split into subsections; a new bullet requires stakeholder needs and expectations to be considered in management review |
Drafting tip: None of these are structural overhauls. Most organizations find their existing ISMS processes already satisfy the reworded clauses — the gap is usually documentation catching up to practice, not practice changing.
What ISO 27001:2022 changes in Annex A — The Real Story
The headline number — 114 controls down to 93 — makes it sound like a third of the old controls were cut. That’s not what happened. No controls were deleted. Fifty-seven of the old controls were merged into 24 new ones, 58 carried over with only light rewording, and 11 are genuinely new.
The 14 domains from 2013 were consolidated into four themes, and the new names were deliberately written for a management audience rather than IT specialists:
The 11 New Controls
These are the controls with no 2013 equivalent — the ones that require an actual gap assessment, not just a renumbering exercise.
- Threat intelligence
- Information security for use of cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
Sample of How 2013 Controls Map to 2022
Because most controls were merged rather than replaced, mapping old to new is the bulk of transition work. A short sample:
| ISO 27001:2022 Annex A Control | Merged from ISO 27001:2013 |
|---|---|
| 5.1 Policies for information security | 5.1.1, 5.1.2 |
| 5.9 Inventory of information and other associated assets | 8.1.1, 8.1.2 |
| 5.15 Access control | 9.1.1, 9.1.2 |
| 5.17 Authentication information | 9.2.4, 9.3.1, 9.4.3 |
| 6.8 Information security event reporting | 16.1.2, 16.1.3 |
| 7.2 Physical entry controls | 11.1.1, 11.1.6 |
| 8.8 Management of technical vulnerabilities | 12.6.1, 18.2.3 |
| 8.24 Use of cryptography | 10.1.1, 10.1.2 |
| 8.32 Change management | 12.1.2, 14.2.2, 14.2.3, 14.2.4 |
Timing tip: Don’t try to map controls from memory. ISO/IEC 27002:2022 Annex B publishes an official mapping table between 2013 and 2022 controls — use it as your working document rather than reconstructing the logic yourself.
Control Attributes — A New Concept
ISO 27001:2022 changes also introduced control attributes, a way to tag each Annex A control by properties such as control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), and relevant cybersecurity concepts. Attributes are optional — the standard doesn’t require you to use them — but they’re useful if you want to cross-map your control set to frameworks like NIST CSF or CIS Controls, or filter your Statement of Applicability by category.
Why the Update Happened
The 2013 edition wasn’t rewritten because it stopped working — it was rewritten because the environment it described had moved on. Cloud computing, remote and hybrid work, and supply-chain-based attacks had all become mainstream risks rather than edge cases, and the old 14-domain structure, written primarily for IT specialists, didn’t map cleanly onto how modern organizations actually think about risk ownership.
The Transition Timeline
| Milestone | Date |
|---|---|
| ISO 27001:2022 published | October 25, 2022 |
| Certification bodies required to offer 2022 audits | By October 31, 2023 |
| New certifications had to use the 2022 version | From April 2024 onward |
| Final deadline to transition existing 2013 certifications | October 31, 2025 |
| ISO 27001:2013 certifications | Withdrawn after the deadline |
The transition deadline has now passed. Any organization still holding a 2013-based certificate today no longer has a valid ISO 27001 certification — if your certificate still references 2013, it should have been upgraded at your last surveillance or re certification audit.
What the Transition Actually Involved
For organizations already certified to the 2013 version, the practical work looked like this:
Run a gap assessment mapping existing controls to the 2022 structure.
Review the 11 new controls and determine which apply to your environment.
Update the Statement of Applicability (SoA) to reflect the new control numbers and four-theme structure.
Update supporting policies and procedures where control wording changed materially.
Complete a transition audit, either standalone or combined with a scheduled surveillance or re certification audit.
Common Mistakes Companies Made With the Transition
Assuming the drop from 114 to 93 controls meant less work, rather than checking which 11 were genuinely new.
Renaming controls in the SoA without actually reassessing whether the merged control’s full scope was still covered.
Leaving the transition until close to the October 2025 deadline instead of folding it into a regular surveillance audit.
Treating control attributes as mandatory paperwork rather than the optional categorization tool they are.
Not updating risk treatment plans to reference the new control numbering, creating a mismatch between the SoA and internal risk records.
How B4Q Assurance Helps
As a licensed U.S. CPA firm (AICPA) handling SOC 1, SOC 2, and SOC 3 engagements, B4Q Assurance also works with clients navigating ISO 27001 gap assessments and control mapping — helping teams confirm their Statement of Applicability and risk treatment plans are actually aligned with the 2022 structure, not just relabeled.
Ready to Confirm Your Status?
If your certification still references the 2013 version, or you’re not sure your Statement of Applicability reflects the current 93-control structure, it’s worth a quick review before it surfaces in a customer’s security questionnaire.
Book a free strategy call to review your current ISMS documentation against the ISO 27001:2022 requirements.
Resources
ISO — ISO/IEC 27001:2022: the official standard reference on the ISO website.
ISO/IEC 27002:2022: the companion standard with the official control mapping between 2013 and 2022 versions of Annex A.
IAF MD 26 — Transition Requirements for ISO/IEC 27001:2022: the source document for transition deadlines and certification body requirements.
FAQs
Is ISO 27001:2022 changes still valid?
No. The transition deadline was October 31, 2025. Certifications based on the 2013 version were withdrawn after that date.
Were any Annex A controls deleted in the 2022 update?
No. All 114 original controls carried forward in some form — 58 with minor wording changes, 57 merged into 24 consolidated controls, and 11 added as entirely new.
Do I need to use the new control attributes?
No. Attributes are optional. They’re useful for cross-mapping to other frameworks but aren’t a certification requirement.
What's the single biggest change in the main clauses?
Clause 6.3, “Planning of Changes” — a new requirement that any change to the ISMS be planned rather than made informally.
How long does a transition audit take?
It varies by organization size and can usually be combined with a scheduled surveillance or recertification audit rather than run as a separate event — your certification body can confirm what applies to your cycle.