ISO 27001:2022, What Has Actually Changed Since 2013

7 min readLast updated By Marc Grob

Introduction

ISO/IEC 27001 was published in a new version on 25 October 2022, the first major revision since 2013. The IAF transition window ended on 31 October 2025: since then, certificates are issued only against the 2022 version, and existing 2013 certificates are invalid. Any company that did not complete the transition in time has lost its ISO 27001 status. This reality is hitting Swiss companies that went through a reorganization, ownership change, or CISO vacancy during the transition window.

This article covers:

  • Structural changes to Annex A: from 114 to 93 controls, from 14 domains to 4 themes
  • The 11 new controls and their practical relevance
  • Changes in the main body (Clauses 4–10): climate-change consideration, planning of changes, clearer requirements on owner roles
  • ISO/IEC 27002:2022 as the implementation guidance and its attribute system
  • What Swiss companies must do for an effective transition
  • Realistic transition effort estimates

Intended audience: CISOs, ISMS managers, and executive sponsors who want to understand the scope of the revision and either close the transition retroactively or prepare a new certification under the 2022 standard.

Annex A, the structural revolution

The most visible change concerns Annex A. The 2013 version had 114 controls in 14 domains (A.5–A.18); the 2022 version reduces this to 93 controls in four themes. This is not pure consolidation, some controls were merged, others moved, and 11 are entirely new.

The four themes:

  • A.5 Organizational Controls (37 controls): policies, roles, suppliers, incidents, continuity, compliance. Aggregates the old A.5, A.6, A.15, A.17, A.18.
  • A.6 People Controls (8 controls): personnel security from joining to leaving. Aggregates A.7.
  • A.7 Physical Controls (14 controls): site, access, hardware. Aggregates A.11.
  • A.8 Technological Controls (34 controls): endpoint, access, cryptography, logging, network, app-sec, backup. Aggregates A.8, A.9, A.10, A.12, A.13, A.14, A.16.

The theme structure simplifies owner allocation: A.5 is ISMS manager + senior management + Legal; A.6 is HR + ISMS manager; A.7 is facility / IT operations; A.8 is engineering / SecOps. This clean responsibility architecture was less visible in the 2013 version's 14 domains.

Important: reducing 114 to 93 does not mean less work. Several older controls have been merged in substance, a single new control sometimes covers two or three former controls and demands correspondingly broader evidence. Anyone who performed the transition as pure mapping without substantive review risks gaps in the SoA.

The 11 new controls

The 2022 version introduces 11 new controls that close gaps in the 2013 version, particularly around cloud, DevOps, privacy, and threat intelligence. These 11 controls are in particular focus at Stage 1 and Stage 2 audits because they are the most frequent point of divergence between old and new practice.

  1. A.5.7 Threat intelligence: collection, analysis, and processing of threat information.
  2. A.5.23 Information security for use of cloud services: acquisition, use, management, and termination of cloud services.
  3. A.5.30 ICT readiness for business continuity: the capability of IT to maintain business-critical processes during and after incidents.
  4. A.7.4 Physical security monitoring: continuous monitoring of physical premises for unauthorized activities.
  5. A.8.9 Configuration management: definition, implementation, monitoring, and audit of configurations for hardware, software, services, and networks.
  6. A.8.10 Information deletion: secure deletion of information when no longer needed.
  7. A.8.11 Data masking: data masking in accordance with access policies and legal requirements.
  8. A.8.12 Data leakage prevention: DLP measures across systems, networks, and endpoints.
  9. A.8.16 Monitoring activities: monitoring of networks, systems, and applications for anomalous behavior.
  10. A.8.23 Web filtering: management of external website access to reduce the attack surface.
  11. A.8.28 Secure coding: secure coding principles and procedures across the software development lifecycle.

In audit practice, A.5.23 (cloud), A.8.9 (configuration management), and A.8.16 (monitoring) are the most common source of findings, because companies often run these operational practices without systematic documentation. Signing SaaS contracts without a cloud onboarding process means A.5.23 is not implemented.

Changes in the main body (Clauses 4–10)

In addition to Annex A, the main clauses were selectively revised, formally harmonized with the ISO Harmonized Structure (Annex SL), and substantively with three material additions.

  • Clause 4.4 Information security management system: now explicitly requires processes needed and their interactions, a clarification that was implicit in 2013.
  • Clause 6.3 Planning of changes: entirely new clause. Changes to the ISMS must be carried out in a planned manner, this includes scope changes, policy changes, role changes, and changes to material controls. In practice: change log with before and after state, risk-impact assessment.
  • Clause 9.3.2 Management Review Inputs: extended to include changes in needs and expectations of interested parties that are relevant to the ISMS, the explicit linkage to stakeholder analysis.
  • Climate change clause (Amendment 1, February 2024): Clauses 4.1 and 4.2 were extended to require checking whether climate change is a relevant topic for the organization and whether interested parties have climate-related requirements. This addition applies to all ISO management-system standards since February 2024.

These changes are less visible than the Annex A restructure but matter for audits. Auditors check whether the climate threshold has been considered in material business decisions (e.g. data center siting, supplier selection) and whether change management for the ISMS itself is documented.

ISO/IEC 27002:2022 as implementation guidance

While ISO/IEC 27001:2022 defines the normative what, ISO/IEC 27002:2022 provides the implementing how. The 2022 version of ISO 27002 was published in February 2022 (before ISO 27001:2022 itself) and defines the 93 controls with detailed implementation guidance.

A key innovation: every control in ISO/IEC 27002:2022 has an attribute system with five dimensions:

  • Control type: preventive, detective, corrective
  • Information security properties: confidentiality, integrity, availability
  • Cybersecurity concepts: identify, protect, detect, respond, recover (analogous to NIST CSF)
  • Operational capabilities: governance, asset management, information protection, human resource security, etc. (15 categories)
  • Security domains: governance and ecosystem, protection, defense, resilience

These attributes are not certification-relevant (the auditor does not check whether you use them) but they enable mapping to other frameworks, NIST CSF, CIS Controls, BSI IT-Grundschutz. We recommend tracking attributes as optional columns in the SoA when you operate across multiple frameworks in parallel (e.g. ISO 27001 + NIS2 + FINMA + SOC 2).

In audit, an experienced ISMS manager cleanly distinguishes between standard requirement (binding) and implementation guidance (recommendation). Reading ISO/IEC 27002 verbatim as a mandatory catalog overshoots and wastes resources.

What the transition actually required

The IAF transition window was originally 3 years (until 31 October 2025). Certified organizations that did not transition in time lost their certificate. The typical transition steps:

  1. Gap analysis: mapping the existing 114 controls to the new 93, identifying the 11 new controls and their coverage gaps.
  2. Update the risk treatment plan: integrate the new controls into the risk treatment, reassess risks if needed.
  3. Rebuild the SoA: migrate from 14 domains to 4 themes, formulate justifications for the 11 new controls.
  4. Update policies and procedures: especially for the new controls (cloud, configuration management, monitoring, DLP, secure coding).
  5. Training: brief internal auditors and key roles on the new structure and the new controls.
  6. Transition audit: external transition audit by the certification body, often combined with a surveillance or recertification audit.

Realistic effort: 60–120 person-days for an SME with 50–200 employees, 200–500 person-days for a mid-market with 200–1,000 employees. The most frequent underestimation was A.8.9 (configuration management), companies do have configurations but do not document them systematically in the sense of the standard. Building a compliant configuration management program takes 3–9 months depending on IT complexity.

After 31 October 2025, consequences

Since 1 November 2025, all ISO/IEC 27001:2013 certificates are invalid. Consequences for Swiss companies that missed the deadline:

  • Loss of certification: the 2013 certificate is no longer valid and may not be used in marketing or tenders.
  • Recertification required: instead of a transition (simplified process), a full new certification is needed, Stage 1 + Stage 2 + surveillance cycle.
  • Customer risk: contracts with ISO 27001 clauses (especially public sector, FINMA-regulated, international groups) can trigger penalties or termination on certificate loss.
  • Effort: a new certification takes 9–18 months and costs 1.5 to 2.5 times a regular transition.

Anyone currently without a valid certificate should immediately start an accelerated new certification. Typically much of the ISMS substance is still in place, the main task is updating the SoA, covering the 11 new controls, and re-implementing the CAPA cycle for the transition phase. Professional support shortens the path significantly and avoids repeat audits.

How SIDD supports you

SIDD runs both transition projects and accelerated new certifications under the 2022 version for Swiss companies. Our ISO 27001 / ISMS engagement includes the old-vs-new gap analysis, refreshing the risk register and SoA, implementing the 11 new controls (cloud, configuration management, monitoring, DLP, secure coding), and preparation for the external audit. We know the expectations of the common Swiss certification bodies for the transition and recertification audit and produce audit-ready deliverables.

For long-term operational ownership of the ISMS under the new standard, our external CISO / ISB service is available. Complementary: penetration tests and continuous vulnerability scanning as effectiveness evidence for A.8 controls and awareness workshops for A.6.3 (Information security awareness, education and training). Documentation and tracking happen in the Priverion platform.

If you missed the transition deadline or want to certify newly, contact us via the contact form, we deliver a binding timeline and effort estimate in a 60-minute initial conversation. For a written proposal, use the quote form.

Need help putting this into practice? SIDD operates the matching service.
See service →

ISO 27001:2022, What Has Actually Changed Since 2013

INSIGHT

InfoSec
24 May 2026
Marc Grob
What ISO/IEC 27001:2022 changed compared with 2013: the new Annex A with 93 controls, eleven new controls and the consequences of the transition.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.