ISO 27001:2022 Transition Guide: What Changed and What It Means Now
Executive Summary
ISO/IEC 27001:2022 was released in October 2022, restructuring the standard's control set and introducing new controls addressing cloud security, remote work, and supply chain risk — realities that barely existed when the prior 2013 version was written. This guide covers what actually changed structurally, the 11 new controls organizations should know about, and — critically — corrects a since-expired transition deadline that appeared in this article's original 2025 version, rather than republishing it as if still current.
Key Takeaways
- The total control count went down from 114 (in the 2013 version) to 93 (in the 2022 version) — but this reflects consolidation and restructuring, not a reduction in security rigor.
- Controls are now organized into 4 unified themes instead of 14 separate domains: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls).
- 11 entirely new controls were introduced, addressing cloud security governance, threat intelligence, configuration management, and modern data-protection practices.
- The core management-system clauses (4–10) remain largely unchanged — the framework's governance backbone is stable even as the control set was restructured.
- A previously-stated transition deadline in this article's original version has passed — see the flag above and the corrected framing in §5.
Why ISO 27001 needed an update {#why-updated}
When ISO/IEC 27001:2013 was published, cloud infrastructure was still emerging, remote work was uncommon, and supply chain attacks were not yet a mainstream concern. The 2022 revision addresses the environment organizations actually operate in now: cloud-specific security controls for multi-cloud environments, remote-working security guidance for distributed teams, supply chain risk management for interconnected vendor ecosystems, and data privacy controls aligned with regulations like GDPR.
What changed: the numbers {#the-numbers}
| Aspect | ISO 27001:2013 | ISO 27001:2022 | Impact |
|---|---|---|---|
| Total controls | 114 | 93 | Consolidated, not weakened |
| Control domains | 14 separate domains | 4 unified themes | Simplified organization |
| New controls | — | 11 | Coverage for modern threats |
| Management system clauses | 4–10 | 4–10 (minor updates) | Core framework largely unchanged |
The drop from 114 to 93 controls reflects consolidation of overlapping requirements into more comprehensive, better-organized controls — not a loosening of the standard.
The four new control themes {#four-themes}
The 2022 revision replaces the prior 14 control domains with four organizing themes:
- Organizational Controls (37 controls) — governance, policies, incident management
- People Controls (8 controls) — HR security, training, remote work
- Physical Controls (14 controls) — facility security, equipment protection
- Technological Controls (34 controls) — access control, encryption, monitoring
The 11 new controls {#new-controls}
Grouped by the modern risk area they address:
Cloud era
- 5.23 — Information security for cloud services: formal cloud governance requirements
- 8.9 — Configuration management: automated configuration control and monitoring
Modern threats
- 5.7 — Threat intelligence: systematic threat intelligence collection and analysis
- 7.4 — Physical security monitoring: continuous physical security surveillance
- 8.16 — Monitoring activities: advanced system and network monitoring
Data protection
- 8.10 — Information deletion: secure deletion of information once no longer needed
- 8.11 — Data masking: protecting data in non-production environments through masking
- 8.12 — Data leakage prevention: controls preventing unauthorized data exfiltration
(The source article referenced 11 new controls in total; the remaining controls beyond those listed above were not fully detailed in the original source and should be confirmed against the official ISO/IEC 27001:2022 Annex A control list before this section is considered complete.)
Where the transition deadline stands now {#deadline-status}
The original version of this article, published in September 2025, stated that organizations certified under ISO 27001:2013 had "until October 31, 2025" to complete their transition to the 2022 version, and that missing the deadline would mean losing certification and restarting the process. As of this 2026 review, that date has passed. Rather than republish that framing as if the deadline were still upcoming — which would actively misinform a 2026 reader — this guide flags it explicitly: any organization that has not yet completed its transition should treat this as an urgent, not routine, compliance gap, and confirm current status directly with its certification body rather than relying on this article's original timeline.
How getTRAC helps {#how-gettrac-helps}
getTRAC maps control evidence to ISO 27001 (and seven other frameworks) continuously, which is particularly relevant during a standard transition like 2013→2022 — instead of manually re-mapping every piece of evidence against a new control structure, getTRAC's control mapping updates to reflect the current standard version. Organizations mid-transition or approaching recertification can pair the platform with Threat ResQ's Compliance Consulting service for hands-on guidance through the gap assessment and remediation process.
FAQ {#faq}
Do I need to recertify from scratch if I miss the transition deadline? Per the original source material, missing the transition deadline meant losing certification and restarting the process — but given that deadline has now passed, any organization in this position should confirm current status and options directly with its certification body rather than relying on this guide's original framing.
Are the ISO 27001:2013 controls now invalid? The 2022 revision consolidates and restructures the control set rather than invalidating the underlying security principles — many 2013 controls map directly to a corresponding 2022 control, just reorganized under the new four-theme structure.
What's the single most significant new control area? Cloud services governance (control 5.23) and threat intelligence (control 5.7) address risk areas that had no formal coverage in the 2013 version and are highly relevant to most organizations' current environments.
Does getTRAC handle the 2022 control structure specifically? Yes — getTRAC's control mapping for ISO 27001 reflects the current standard version, which matters specifically during a transition period like this one.
Frequently asked questions
Do I need to recertify from scratch if I miss the transition deadline?
Per the original source material, missing the transition deadline meant losing certification and restarting the process — but given that deadline has now passed, any organization in this position should confirm current status and options directly with its certification body rather than relying on this guide's original framing.
Are the ISO 27001:2013 controls now invalid?
The 2022 revision consolidates and restructures the control set rather than invalidating the underlying security principles — many 2013 controls map directly to a corresponding 2022 control, just reorganized under the new four-theme structure.
What's the single most significant new control area?
Cloud services governance (control 5.23) and threat intelligence (control 5.7) address risk areas that had no formal coverage in the 2013 version and are highly relevant to most organizations' current environments.
Ask TIARA about this article
Get a grounded answer on ISO 27001:2022, or ask your own question.