Threat ResQ

Governance Risk Compliance

ISO 27001:2022 Transition Guide: What Changed and What It Means Now

ISO/IEC 27001:2022 was released in October 2022, restructuring the standard's control set and introducing new controls addressing cloud security, remote work, and supply chain risk — realities that barely existed when th

8 min readLast reviewed July 18, 2026Threat ResQ Technologies

ISO 27001:2022 Transition Guide: What Changed and What It Means Now

Executive Summary

ISO/IEC 27001:2022 was released in October 2022, restructuring the standard's control set and introducing new controls addressing cloud security, remote work, and supply chain risk — realities that barely existed when the prior 2013 version was written. This guide covers what actually changed structurally, the 11 new controls organizations should know about, and — critically — corrects a since-expired transition deadline that appeared in this article's original 2025 version, rather than republishing it as if still current.

Key Takeaways

  • The total control count went down from 114 (in the 2013 version) to 93 (in the 2022 version) — but this reflects consolidation and restructuring, not a reduction in security rigor.
  • Controls are now organized into 4 unified themes instead of 14 separate domains: Organizational (37 controls), People (8 controls), Physical (14 controls), and Technological (34 controls).
  • 11 entirely new controls were introduced, addressing cloud security governance, threat intelligence, configuration management, and modern data-protection practices.
  • The core management-system clauses (4–10) remain largely unchanged — the framework's governance backbone is stable even as the control set was restructured.
  • A previously-stated transition deadline in this article's original version has passed — see the flag above and the corrected framing in §5.

Why ISO 27001 needed an update {#why-updated}

When ISO/IEC 27001:2013 was published, cloud infrastructure was still emerging, remote work was uncommon, and supply chain attacks were not yet a mainstream concern. The 2022 revision addresses the environment organizations actually operate in now: cloud-specific security controls for multi-cloud environments, remote-working security guidance for distributed teams, supply chain risk management for interconnected vendor ecosystems, and data privacy controls aligned with regulations like GDPR.

What changed: the numbers {#the-numbers}

AspectISO 27001:2013ISO 27001:2022Impact
Total controls11493Consolidated, not weakened
Control domains14 separate domains4 unified themesSimplified organization
New controls11Coverage for modern threats
Management system clauses4–104–10 (minor updates)Core framework largely unchanged

The drop from 114 to 93 controls reflects consolidation of overlapping requirements into more comprehensive, better-organized controls — not a loosening of the standard.

The four new control themes {#four-themes}

The 2022 revision replaces the prior 14 control domains with four organizing themes:

  • Organizational Controls (37 controls) — governance, policies, incident management
  • People Controls (8 controls) — HR security, training, remote work
  • Physical Controls (14 controls) — facility security, equipment protection
  • Technological Controls (34 controls) — access control, encryption, monitoring

The 11 new controls {#new-controls}

Grouped by the modern risk area they address:

Cloud era

  • 5.23 — Information security for cloud services: formal cloud governance requirements
  • 8.9 — Configuration management: automated configuration control and monitoring

Modern threats

  • 5.7 — Threat intelligence: systematic threat intelligence collection and analysis
  • 7.4 — Physical security monitoring: continuous physical security surveillance
  • 8.16 — Monitoring activities: advanced system and network monitoring

Data protection

  • 8.10 — Information deletion: secure deletion of information once no longer needed
  • 8.11 — Data masking: protecting data in non-production environments through masking
  • 8.12 — Data leakage prevention: controls preventing unauthorized data exfiltration

(The source article referenced 11 new controls in total; the remaining controls beyond those listed above were not fully detailed in the original source and should be confirmed against the official ISO/IEC 27001:2022 Annex A control list before this section is considered complete.)

Where the transition deadline stands now {#deadline-status}

The original version of this article, published in September 2025, stated that organizations certified under ISO 27001:2013 had "until October 31, 2025" to complete their transition to the 2022 version, and that missing the deadline would mean losing certification and restarting the process. As of this 2026 review, that date has passed. Rather than republish that framing as if the deadline were still upcoming — which would actively misinform a 2026 reader — this guide flags it explicitly: any organization that has not yet completed its transition should treat this as an urgent, not routine, compliance gap, and confirm current status directly with its certification body rather than relying on this article's original timeline.

How getTRAC helps {#how-gettrac-helps}

getTRAC maps control evidence to ISO 27001 (and seven other frameworks) continuously, which is particularly relevant during a standard transition like 2013→2022 — instead of manually re-mapping every piece of evidence against a new control structure, getTRAC's control mapping updates to reflect the current standard version. Organizations mid-transition or approaching recertification can pair the platform with Threat ResQ's Compliance Consulting service for hands-on guidance through the gap assessment and remediation process.

FAQ {#faq}

Do I need to recertify from scratch if I miss the transition deadline? Per the original source material, missing the transition deadline meant losing certification and restarting the process — but given that deadline has now passed, any organization in this position should confirm current status and options directly with its certification body rather than relying on this guide's original framing.

Are the ISO 27001:2013 controls now invalid? The 2022 revision consolidates and restructures the control set rather than invalidating the underlying security principles — many 2013 controls map directly to a corresponding 2022 control, just reorganized under the new four-theme structure.

What's the single most significant new control area? Cloud services governance (control 5.23) and threat intelligence (control 5.7) address risk areas that had no formal coverage in the 2013 version and are highly relevant to most organizations' current environments.

Does getTRAC handle the 2022 control structure specifically? Yes — getTRAC's control mapping for ISO 27001 reflects the current standard version, which matters specifically during a transition period like this one.

Frequently asked questions

Do I need to recertify from scratch if I miss the transition deadline?

Per the original source material, missing the transition deadline meant losing certification and restarting the process — but given that deadline has now passed, any organization in this position should confirm current status and options directly with its certification body rather than relying on this guide's original framing.

Are the ISO 27001:2013 controls now invalid?

The 2022 revision consolidates and restructures the control set rather than invalidating the underlying security principles — many 2013 controls map directly to a corresponding 2022 control, just reorganized under the new four-theme structure.

What's the single most significant new control area?

Cloud services governance (control 5.23) and threat intelligence (control 5.7) address risk areas that had no formal coverage in the 2013 version and are highly relevant to most organizations' current environments.

Ask TIARA about this article

Get a grounded answer on ISO 27001:2022, or ask your own question.

Talk to an Expert

We use cookies for essential function and, with consent, analytics. Cookie Policy