Compliance

ISO 27001:2022: What's Changed and What It Means for Your Certification

The 2022 update restructured the framework and introduced eleven new controls. With the transition period now closed, here is where that leaves you.

E7
Edge7 Networks Team
Networking & Security Specialists
12 November 2025
5 min read
Share

Why the 2022 revision happened

ISO 27001 had not been substantially revised for the best part of a decade, and the security landscape had moved considerably in that time. Cloud adoption, remote work, and a shift in the threat landscape all outpaced a control set written for an earlier era. The 2022 revision brought the standard up to date, both in the controls it expects and in how they are organised.

If you hold, are pursuing, or have let lapse an ISO 27001 certification, the changes matter, and the timeline around them has now passed a significant milestone.

What actually changed

The core of ISO 27001 (the requirement to run a risk-based Information Security Management System) is unchanged. The management system clauses saw only modest updates. The substantial change is in Annex A, the catalogue of controls.

  • The number of controls reduced from 114 to 93, largely through merging overlapping ones rather than removing protection.
  • The controls were reorganised from fourteen domains into four themes: organisational, people, physical, and technological.
  • Eleven new controls were introduced, addressing areas the 2013 version did not adequately cover.
  • Each control gained attributes (such as control type and security property) to make the set easier to filter and map.
Worth being clear

Fewer controls does not mean less work

The drop from 114 to 93 is mostly consolidation. Overlapping controls were merged, not deleted. The eleven new controls, meanwhile, expect capabilities many organisations did not formally have before. On balance the 2022 set asks for more, not less.

The eleven new controls

The additions are the clearest signal of where the standard has moved. They are:

  • Threat intelligence
  • Information security for use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Monitoring activities
  • Web filtering
  • Secure coding

Read together, they point squarely at cloud, monitoring, and data protection. the areas where a decade of change had left the older standard behind.

The transition has closed

The three-year transition window from ISO 27001:2013 to the 2022 revision ended on 31 October 2025. That deadline has now passed, which changes the practical picture depending on where you sit.

Timeline reality

2013 certificates are no longer valid

Since 31 October 2025, certifications against the 2013 version have expired. New and existing certifications are against ISO 27001:2022. If your certificate lapsed at the deadline, you are now looking at a fresh certification against the 2022 standard (a full two-stage audit), rather than the lighter transition audit that was available during the window.

What it means for you now

Where the 2022 changes leave you depends on your situation:

  • Already certified to 2022. No immediate action beyond maintaining the ISMS through your surveillance cycle. The new controls are part of your scope.
  • Certifying for the first time. You certify directly against 2022, so build your ISMS and control set around the current structure from the outset.
  • Lapsed at the deadline. Recertification is against 2022 as a fresh certification. The work done previously is not wasted, but the path back is a full audit rather than a transition.

"The 2022 revision is less a paperwork exercise than a nudge toward controls that reflect how organisations actually operate now: in the cloud, with more monitoring, and with data protection front of mind."

Edge7 Networks, Compliance Practice

Where to start

Whatever your position, the useful first step is a gap assessment against the 2022 control set, with particular attention to the eleven new controls. For most organisations, threat intelligence, cloud security, monitoring, and data leakage prevention are where the real work sits, because these are capabilities that were often informal or absent under the older standard.

Edge7 Networks holds ISO 27001:2022 and helps IT teams across Ireland and the UK with certification and ISMS work, from gap assessment through to audit readiness. If you are certifying, maintaining, or returning after a lapse, a gap assessment is the right place to begin.


E7
Edge7 Networks Team
Networking & Security Specialists, Ireland & UK

Edge7 Networks is a specialist networking and security provider, founded in 2018. Our team works with IT leaders across Ireland and the UK on enterprise networking, managed security, and compliance. We hold ISO 27001:2022, ISO 9001:2015, and Cyber Essentials certifications.

Working toward ISO 27001:2022?

Our team helps IT leaders across Ireland and the UK certify and maintain ISO 27001. If you would like to talk through your position, we are easy to reach.