ISO 27001:2022: The Most Significant Update in a Decade
The International Organization for Standardization released ISO/IEC 27001:2022 in October 2022, replacing the 2013 version. For organizations already certified — or pursuing certification — this update introduces meaningful changes that require careful planning. The transition deadline for existing certified organizations is October 31, 2025.
What Has Changed?
Structural Revisions to Annex A
Annex A — the reference set of security controls — has been completely restructured:
- Controls reduced: From 114 controls across 14 categories to 93 controls across 4 themes.
- New themes: The four themes are Organizational Controls (37), People Controls (8), Physical Controls (14), and Technological Controls (34).
- 11 new controls introduced, covering areas such as:
- Threat intelligence
- Cloud services security
- Data masking
- Physical security monitoring
- Web filtering
- Secure coding
Clause-Level Changes
Clauses 4–10 of the standard remain structurally similar to 2013, but with added nuance:
- Clause 6.3 now requires a formal process for planning and communicating changes to the ISMS.
- The concept of "interested parties" and their requirements has been expanded.
What Does This Mean for Certified Organizations?
If your organization is currently certified to ISO 27001:2013, you must:
- Conduct a gap analysis against the 2022 standard
- Update your Statement of Applicability (SoA) to reference the new Annex A control numbering
- Address the 11 new controls — assess applicability, implement where required, and document decisions
- Re-train internal auditors on the updated requirements
- Complete a transition audit with your certification body before October 2025
Planning Your Transition
Oberon recommends a structured 3-phase approach:
Phase 1 (Weeks 1–4): Gap analysis against the 2022 standard, mapping existing controls to the new Annex A.
Phase 2 (Months 2–4): Implement missing controls, update policies, and revise the Risk Treatment Plan and SoA.
Phase 3 (Month 5–6): Internal audit, management review, and transition audit with your certification body.
Key Takeaway
ISO 27001:2022 is not a wholesale replacement of your ISMS — it is an evolution. Organizations that start their transition planning now, rather than in 2025, will avoid the certification body backlog and demonstrate proactive security governance to their stakeholders.
Oberon Services provides end-to-end ISO 27001:2022 transition support. Contact us to begin your gap analysis.