ISO 27001:2022 — the key changes

ISO 27001 · · 1 min read

ISO 27001:2022 is the latest version of the international standard for information security management systems. The update introduces important changes that affect both new implementations and existing certified organisations.

New control structure

The previous control annex (Annex A) with 14 categories and 114 controls has been restructured into 4 themes and 93 controls:

  • Organisational controls (37)
  • People controls (8)
  • Physical controls (14)
  • Technological controls (34)

New controls

11 entirely new controls have been added, including:

  • Threat intelligence
  • Information security for use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Data masking

What does this mean for you?

If you are already certified, you need to update your Statement of Applicability (SoA) and ensure that the new controls are addressed. The transition period expires in October 2025.

If you are planning a new certification, you should base it directly on the 2022 version.

Need support with the transition? Contact us and we will help you.

Author

KB
Kim Borg

Founder & CEO

25+ years of experience in IT leadership — from software developer and Scrum Master to IT Director and Group CIO. Deep expertise in ISO 27001, NIS2, risk management, and information security governance. Educated in ISMS at the University of Skovde.

Ready to strengthen your cybersecurity?

Book a free meeting and we will discuss how we can help your organisation meet the new requirements.

Book a meeting