Short answer
ISO/IEC 27001:2022 reduced Annex A from 114 to 93 controls, grouped into four themes (organisational, people, physical, technological), and added 11 new controls such as threat intelligence and cloud services security. Certificates against the 2013 version expired on 31 October 2025, so every certified organisation should now be audited against 2022.
Key takeaways
- Annex A now has 93 controls in four themes instead of 114 in 14 domains.
- 11 controls are new, including threat intelligence, data leakage prevention and secure coding.
- Update the Statement of Applicability first; it drives the audit plan.
- 2013-version certificates are no longer valid after 31 October 2025.
What changed in the 2022 revision
The management-system clauses (4 to 10) received light edits, mostly clarifications around planning of changes and monitoring. The larger change is Annex A, which was restructured to align with ISO/IEC 27002:2022.
| Area | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Annex A controls | 114 | 93 |
| Grouping | 14 domains | 4 themes |
| New controls | n/a | 11 |
Timeline
The transition, start to finish
- ISO/IEC 27001:2022 published
- Last initial audits against 2013Certification bodies stop initial and recertification audits to the 2013 edition (IAF MD 26).
- 2013 certificates expireAny certificate not transitioned is withdrawn or cancelled.
The 11 new controls
Hover or focus a control number to see its title. Organisational controls start with 5, people with 6, physical with 7 and technological with 8.
- Collect and analyse information about threats.
- Govern how cloud services are acquired, used and exited.
- Plan and test ICT continuity against business needs.
- Monitor premises for unauthorised physical access.
- Establish and review secure configurations.
- Delete information when it is no longer required.
- Mask data in line with access policy and legal requirements.
- Apply leakage prevention to systems and networks handling sensitive data.
- Monitor networks, systems and applications for anomalous behaviour.
- Manage access to external websites to reduce exposure to malicious content.
- Apply secure coding principles to software development.
How to update your ISMS
Checklist
ISMS transition checklist
0 of 6 done
Seed content: verify every clause reference against the licensed standard before publishing.
Frequently asked questions
How many controls are in ISO 27001:2022 Annex A?
Annex A of ISO/IEC 27001:2022 contains 93 controls grouped into four themes: organisational (37), people (8), physical (14) and technological (34).
Is an ISO 27001:2013 certificate still valid?
No. The transition period ended on 31 October 2025, after which certificates issued against ISO/IEC 27001:2013 are no longer valid.