ISO 27001:2022 — What Has Changed and What You Need to Do
Back to Insights
Threat IntelligenceISO 27001

ISO 27001:2022 — What Has Changed and What You Need to Do

June 29, 20262 Min Read

ISO 27001:2022: The Most Significant Update in a Decade

The International Organization for Standardization released ISO/IEC 27001:2022 in October 2022, replacing the 2013 version. For organizations already certified — or pursuing certification — this update introduces meaningful changes that require careful planning. The transition deadline for existing certified organizations is October 31, 2025.

What Has Changed?

Structural Revisions to Annex A

Annex A — the reference set of security controls — has been completely restructured:

  • Controls reduced: From 114 controls across 14 categories to 93 controls across 4 themes.
  • New themes: The four themes are Organizational Controls (37), People Controls (8), Physical Controls (14), and Technological Controls (34).
  • 11 new controls introduced, covering areas such as:
    • Threat intelligence
    • Cloud services security
    • Data masking
    • Physical security monitoring
    • Web filtering
    • Secure coding

Clause-Level Changes

Clauses 4–10 of the standard remain structurally similar to 2013, but with added nuance:

  • Clause 6.3 now requires a formal process for planning and communicating changes to the ISMS.
  • The concept of "interested parties" and their requirements has been expanded.

What Does This Mean for Certified Organizations?

If your organization is currently certified to ISO 27001:2013, you must:

  1. Conduct a gap analysis against the 2022 standard
  2. Update your Statement of Applicability (SoA) to reference the new Annex A control numbering
  3. Address the 11 new controls — assess applicability, implement where required, and document decisions
  4. Re-train internal auditors on the updated requirements
  5. Complete a transition audit with your certification body before October 2025

Planning Your Transition

Oberon recommends a structured 3-phase approach:

Phase 1 (Weeks 1–4): Gap analysis against the 2022 standard, mapping existing controls to the new Annex A.

Phase 2 (Months 2–4): Implement missing controls, update policies, and revise the Risk Treatment Plan and SoA.

Phase 3 (Month 5–6): Internal audit, management review, and transition audit with your certification body.

Key Takeaway

ISO 27001:2022 is not a wholesale replacement of your ISMS — it is an evolution. Organizations that start their transition planning now, rather than in 2025, will avoid the certification body backlog and demonstrate proactive security governance to their stakeholders.

Oberon Services provides end-to-end ISO 27001:2022 transition support. Contact us to begin your gap analysis.