ISO 27001:2022: what changed and what applies now the transition deadline has passed

Security9 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

ISO 27001:2022 was published on 25 October 2022 as the successor to ISO 27001:2013. The transition period that followed is over: since 31 October 2025, certificates against the 2013 version are no longer valid. Even so, we still regularly come across management systems that were moved across on paper while the substance stayed where it was. This article sets out what actually changed, what it does to your Statement of Applicability, what the 2024 climate amendment adds, and what applies to organisations that let the deadline pass.

The changes sit in two places

The standard has two parts. The main text, clauses 4 to 10, sets the requirements for the management system itself. Annex A holds the controls. In almost every transition the attention went to Annex A, while the changes in the main text feed more directly into the findings an auditor ends up writing down.

What changed in the main text

Clause 4.2 now asks explicitly which requirements of interested parties you will address through the ISMS. Naming interested parties and their expectations is no longer enough; you have to make the selection and record it.

Clause 6.3 is new and covers planning changes to the management system. If you adjust your ISMS without recording why, who decided it and what the consequences are, you have a gap here.

Clause 6.2 gained the requirement that information security objectives are monitored. Clause 8.1 was tightened: you establish criteria for the processes that run the ISMS and you control those processes in line with those criteria. Clause 9.3 was reorganised into general, inputs and results.

Annex A: from 114 controls to 93

The old Annex A held 114 controls across fourteen domains. The 2022 version holds 93, grouped into four themes: organisational (37), people (8), physical (14) and technological (34).

That drop is not a relaxation. According to the mapping tables in Annex B of ISO 27002:2022, 58 controls carried over roughly one to one, 57 were merged into 24, one was split, and eleven are new. Add those up and you reach 93. The set was reordered rather than reduced.

ISO 27002:2022 is the accompanying guidance document. That is where you look when you want to know what a control means in practice; ISO 27001 itself only gives the title and the core requirement.

Each control also gained five attributes: control type, information security properties, cybersecurity concepts, operational capabilities and security domains. Those attributes are informative. You are not obliged to use them and an auditor does not test against them. They are useful for looking at your control set from a different angle, for instance to see whether the weight sits on prevention or on detection.

The eleven new controls

Three were added under organisational. A.5.7 threat intelligence requires you to collect, analyse and use information about threats. A.5.23 information security for use of cloud services sets requirements for selecting, using and exiting cloud services. A.5.30 ICT readiness for business continuity ties your continuity plans to what your ICT can actually restore, and within what timeframe.

One control was added under physical: A.7.4 physical security monitoring, on monitoring premises and buildings for unauthorised access.

Seven were added under technological: A.8.9 configuration management, A.8.10 information deletion, A.8.11 data masking, A.8.12 data leakage prevention, A.8.16 monitoring activities, A.8.23 web filtering and A.8.28 secure coding.

In most organisations the underlying work already exists. Configuration management, logging and secure coding are rarely entirely new. What is missing is the explicit link: a recorded position, an identifiable owner and evidence that it was carried out over a period. That last point is what an auditor asks for, and it is usually where things come apart.

What this does to your Statement of Applicability

The Statement of Applicability has to be redone in full. The mapping from 114 to 93 is not one to one, so you cannot renumber the old SoA and call it finished. For each control you reassess whether it applies, how you implement it and where the evidence sits. For the eleven new controls you start from scratch. In almost every transition this is the most labour-intensive step. How to build that document, and what an auditor checks in it, is covered in the article on the Statement of Applicability.

The climate amendment that often gets skipped

In February 2024, ISO/IEC 27001:2022/Amd 1:2024 was published. It changes two things. A sentence was added to clause 4.1 stating that the organisation shall determine whether climate change is a relevant issue. A note was added to clause 4.2 stating that relevant interested parties can have requirements related to climate change.

The amendment does not oblige you to find climate change relevant. It obliges you to ask the question and support your answer. Concluding that it is not relevant is an acceptable outcome, provided that consideration is demonstrable. In practice this shows up as a paragraph in the context analysis, attention to availability and physical risks in the risk assessment, and a line in the management review.

Because the amendment appeared after most transitions were finished, this is a common gap in organisations that completed their move in 2023 or early 2024. It gets picked up at the next audit.

What applies after 31 October 2025

Certificates based on ISO 27001:2013 expired or were withdrawn after that date. The transition period followed from IAF MD 26: 36 months from the last day of the month in which the standard was published.

Anyone who missed the deadline cannot still arrange a transition audit. The route is then full certification against the 2022 version, with a stage 1 and a stage 2 audit. That takes more time and costs more than the transition would have, and in the meantime you hold no valid certificate. For tenders, client contracts and supplier questionnaires that is a problem separate from whether your security is in order.

Where transitions came apart in practice

Four patterns kept returning. The SoA was renumbered rather than revised, so the justification per control no longer held. The eleven new controls got a policy but no execution, leaving no evidence over a period at audit time. The main text changes were skipped because all attention went to Annex A, producing findings on 4.2, 6.3 and 8.1. And the internal audit was still run against the 2013 version, so the organisation met the new requirements for the first time during the external audit.

Getting started

Start with a gap analysis against the 2022 requirements, including the 2024 amendment. Then revise the SoA control by control, and schedule an internal audit against the new version before the certification body arrives. If you are at the start of a certification project, the ISO 27001 certification roadmap describes the order of the whole route.

Secure Audit carries out gap analyses and internal audits against the 2022 version and assesses whether your SoA and documentation hold up. See our compliance services or get in touch. The certification itself is carried out by an accredited body such as DigiTrust.

Frequently asked questions

Is my ISO 27001:2013 certificate still valid?+

No. The transition period set out in IAF MD 26 ran for 36 months after publication of the 2022 version and ended on 31 October 2025. Certificates based on ISO 27001:2013 expired or were withdrawn after that date. New certificates are issued exclusively against ISO 27001:2022.

Which eleven controls are new in ISO 27001:2022?+

Organisational: A.5.7 threat intelligence, A.5.23 information security for use of cloud services and A.5.30 ICT readiness for business continuity. Physical: A.7.4 physical security monitoring. Technological: A.8.9 configuration management, A.8.10 information deletion, A.8.11 data masking, A.8.12 data leakage prevention, A.8.16 monitoring activities, A.8.23 web filtering and A.8.28 secure coding.

Do I have to implement all 93 Annex A controls?+

No. Annex A is a reference set, not a mandatory checklist. Your risk assessment determines which controls apply. In the Statement of Applicability you record for each control whether you apply it and, if not, why not. Exclusions are allowed, provided the justification traces back to your risk assessment.

What does the February 2024 climate amendment require?+

ISO/IEC 27001:2022/Amd 1:2024 adds to clause 4.1 that the organisation shall determine whether climate change is a relevant issue, and adds a note to clause 4.2 that interested parties can have requirements related to climate change. You are not required to conclude that it is relevant; you are required to show you considered it. It is picked up at your next audit.

What if I missed the transition deadline?+

A transition audit is no longer an option. You go through full certification against ISO 27001:2022, with a stage 1 and a stage 2 audit. That is more work and more expensive than the transition, and until the new certification is complete you hold no valid certificate to show clients or use in tenders.

Need help with security?

How secure is your IT environment really? We test it with vulnerability scans and pentests, and guide the implementation of ISO 27001 and IEC 62443.

Explore Security

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us
ISO 27001:2022 changes: the 93 controls and the deadline · Secure Audit