ISO/IEC 27001:2022 was published in October 2022, and the transition period for certificates issued against the 2013 edition ended on 31 October 2025. Every certificate in circulation now is, or should be, against the 2022 edition, and every audit is against it. If your documentation still speaks the language of 14 domains and 114 controls, an auditor will notice on page one.
The management-system clauses (4 to 10) changed only lightly. The substantive change is in Annex A, which was rebuilt to match the new ISO/IEC 27002:2022.
The new structure of Annex A
The 2013 edition grouped 114 controls into 14 domains. The 2022 edition groups 93 controls into four themes:
- Organisational controls (37): policies, roles, asset management, access control policy, supplier relationships, incident management, business continuity, legal and compliance.
- People controls (8): screening, terms of employment, awareness and training, disciplinary process, remote working, reporting of events.
- Physical controls (14): perimeters, entry, protection against environmental threats, equipment, clear desk, secure disposal.
- Technological controls (34): endpoint devices, privileged access, authentication, malware protection, logging, backup, network security, secure development, and the new controls below.
The reduction from 114 to 93 came from merging controls that overlapped, not from dropping requirements. Twenty-four controls were consolidated, 58 were carried over with updated wording, and eleven are new.
The eleven new controls
These are where auditors concentrate, because they are the ones a 2013-era system will not have addressed:
- Threat intelligence (5.7): collecting and analysing information about threats and feeding it into risk decisions. Auditors look for a source, a cadence, and evidence that something changed because of it.
- Information security for use of cloud services (5.23): a process for acquiring, using, managing and exiting cloud services, with security requirements defined up front.
- ICT readiness for business continuity (5.30): ICT continuity planned and tested against the organisation's continuity objectives, linking security to the wider continuity programme.
- Physical security monitoring (7.4): premises monitored for unauthorised access, which for most organisations means alarms, CCTV or guarding proportionate to the site.
- Configuration management (8.9): secure baseline configurations defined, documented, applied and monitored for hardware, software, services and networks.
- Information deletion (8.10): deleting information when no longer required, including in systems and services operated by others.
- Data masking (8.11): masking or pseudonymisation where policy or law requires it, with a decided technique and scope.
- Data leakage prevention (8.12): measures applied to systems, networks and devices that process or store sensitive information.
- Monitoring activities (8.16): networks, systems and applications monitored for anomalous behaviour, with the anomalies evaluated.
- Web filtering (8.23): access to external websites managed to reduce exposure to malicious content.
- Secure coding (8.28): secure coding principles applied to software development.
None of these will surprise a mature security function. What surprises organisations is the evidence requirement. "We have EDR" is not evidence of 8.16 unless someone can show the alerts, the evaluation and the outcomes. "We use a cloud provider" is not 5.23 unless the requirements were defined before the contract and are reviewed.
Attributes: the new way to slice controls
27002:2022 attaches five attribute sets to each control: control type (preventive, detective, corrective), information security property (confidentiality, integrity, availability), cybersecurity concept (identify, protect, detect, respond, recover), operational capability, and security domain. They are not requirements and an auditor will not test them, but they let you present the same control set through the lens a customer or regulator wants, for instance mapped to the NIST CSF functions. Organisations that manage many frameworks find them worth adopting in the control register.
The management-system changes
Clause changes were modest but each one is a question an auditor now asks:
- 4.2: interested parties' requirements must be identified and the organisation must decide which will be addressed through the ISMS.
- 4.4: the ISMS must include the processes needed and their interactions, which in practice means a process map or equivalent.
- 6.2: objectives must be monitored and available as documented information.
- 6.3: changes to the ISMS must be planned. This is new as an explicit clause and auditors do ask for the change planning record.
- 8.1: the wording on outsourced processes now covers externally provided processes, products and services, matching the supplier controls.
- 9.3: management review must consider changes in the needs and expectations of interested parties.
A 2024 amendment added a requirement to consider whether climate change is a relevant issue in clause 4.1, and whether interested parties have climate-related requirements in 4.2. It applies across all ISO management-system standards. The expected evidence is a documented consideration, even if the conclusion is that it is not relevant.
What a current audit looks like
Stage 1 will check that the statement of applicability is against the 93 controls, that the risk treatment plan references them, and that the new controls are either applied or justified as not applicable. Stage 2 and surveillance audits then sample. For a 2022-edition system in its first or second cycle, expect the sampling to be weighted towards the new controls and the changed clauses, because those are where the auditor expects to find gaps.
If you transitioned late or with a light touch, the risk is not the certificate; it is the surveillance audit that finds the new controls were declared applicable and never operated. Minor nonconformities on that are common in the first surveillance cycle after transition. Major ones happen when the statement of applicability and reality disagree on something the auditor considers fundamental, such as monitoring or backup.
The useful preparation is a control-by-control walk through the eleven new ones with the person who actually owns each, asking two questions: what do we do, and where is the record. Where the second answer is a shrug, you have found your gap before the auditor does.
