ISO/IEC 27001 remains the international benchmark for information security management, but the standard is not static. Published in October 2022, the current version brought the most significant revision in nearly a decade, reshaping the well-known Annex A controls and introducing new requirements built for a threat landscape that has changed considerably since 2013. For organisations pursuing certification for the first time, or those whose certificates lapsed when the transition window closed on 31 October 2025, understanding what changed is now a practical necessity rather than an academic exercise.
Why the standard was updated
The 2013 edition was written for a world in which most workloads sat inside a corporate perimeter and staff worked from fixed offices. That world has largely gone. Cloud services now underpin core business operations, remote and hybrid working are permanent fixtures, and adversaries have grown more organised and better resourced. The 2022 revision responds to these shifts by giving explicit weight to cloud security, supply chain risk, threat intelligence and operational resilience. The intent is not to reinvent the management system, but to make sure the controls organisations implement reflect how technology is actually used and attacked today.
The Annex A restructure and the four themes
The most visible change is to Annex A. The previous 114 controls spread across 14 domains have been consolidated into 93 controls, grouped into four clear themes:
- Organisational (37 controls) covering policies, roles, supplier relationships and cloud governance.
- People (8 controls) addressing screening, awareness, responsibilities and conduct.
- Physical (14 controls) covering premises, equipment and physical monitoring.
- Technological (34 controls) covering configuration, logging, secure development and data protection.
The reduction in count is largely down to merging overlapping controls rather than removing protections. The thematic grouping makes the framework easier to navigate and map to organisational responsibilities, which in turn simplifies allocation of ownership and reporting to leadership.
The eleven new controls and what they mean in practice
Eleven controls are genuinely new to the 2022 edition. Each reflects a capability that modern organisations are expected to demonstrate:
- Threat intelligence: collecting and acting on information about relevant threats.
- Information security for use of cloud services: governing how cloud is acquired, used and exited.
- ICT readiness for business continuity: ensuring technology can recover to agreed objectives.
- Physical security monitoring: detecting unauthorised physical access.
- Configuration management: establishing and maintaining secure baselines.
- Information deletion: removing data when it is no longer required.
- Data masking: limiting exposure of sensitive data.
- Data leakage prevention: stopping unauthorised extraction of information.
- Monitoring activities: watching networks and systems for anomalous behaviour.
- Web filtering: controlling access to malicious or inappropriate sites.
- Secure coding: embedding security into software development.
In practice, many organisations already perform some of these activities informally. The task is to formalise them: document the approach, assign ownership, and generate the evidence an auditor will expect to see. Threat intelligence, monitoring activities and cloud governance in particular tend to require the most attention, because they cut across teams and tooling.
What a transition or new certification involves
Whether you are moving from an older certificate or certifying for the first time, the path against the 2022 standard follows a consistent shape. A standards compliance programme typically begins with a gap analysis against the revised Annex A, identifying which of the new controls are already met and where work is needed. The Statement of Applicability is then updated to reflect the 93 controls and the justification for including or excluding each one.
From there, the outstanding controls are implemented and, crucially, evidenced, because a control that cannot be demonstrated will not pass audit. An internal audit tests the management system against the standard, and a management review ensures leadership has considered the results and committed the resources needed to sustain it. Only once these steps are complete does the certification body carry out its own assessment.
Advice for organisations certifying for the first time
If you are starting now, there is a clear advantage: you can build directly against the 2022 structure without unwinding legacy documentation. Begin by scoping the information security management system honestly around what the business actually does, then use the four themes to allocate ownership from the outset. Treat the eleven newer controls as design requirements rather than afterthoughts, and establish evidence-gathering as a routine habit rather than a pre-audit scramble. Sound cyber advisory support early in the process helps you avoid over-engineering controls that do not fit your risk profile, keeping the system proportionate and maintainable.
How Baknet can help
Baknet supports SMEs and enterprises through every stage of the ISO/IEC 27001:2022 journey, from initial gap analysis and Statement of Applicability through to control implementation, internal audit and certification readiness. Our approach is evidence-driven and proportionate, focused on a management system you can sustain rather than a one-off exercise. To discuss your transition or first certification, book a consultation with our team.
