Since 31 October 2025, ISO 27001:2013 certificates have officially ceased to be valid. Any organization that has not yet transitioned to the 2022 edition must now undergo a full recertification audit — the shortened transition audit process is no longer available.
The Essence of the Change
At the heart of the 2022 revision is the restructuring of Annex A, the list of information security controls — reduced from 114 controls across 14 categories to 93 controls, regrouped under four main themes: Organizational, People, Physical, and Technological controls.
New Controls Added
Beyond consolidating overlapping controls, the 2022 edition adds 11 new controls reflecting modern threats, including threat intelligence, cloud services security, ICT readiness for business continuity, and data leakage prevention.
Impact on the Statement of Applicability
Organizations in transition must rebuild their Statement of Applicability (SoA) from scratch, determining whether each control in the new structure applies, with supporting rationale — a valuable opportunity to comprehensively revisit information security risk, not merely to patch documentation for an audit.
