ISO 27001
ISO 27001:2022 Certification: Complete Guide to Annex A, Transition & Implementation
The definitive guide to ISO/IEC 27001:2022 — new Annex A structure, 93 controls, transition deadline, implementation roadmap, and certification cost — for CISOs and compliance leaders.
Quick Answer
ISO/IEC 27001:2022 is the current international standard for Information Security Management Systems (ISMS). It restructured Annex A into 93 controls across 4 themes (Organizational, People, Physical, Technological), introduced 11 new controls, and requires all existing certified organizations to transition from the 2013 version by 31 October 2025.
Key Takeaways
- The 2022 revision consolidates 114 controls into 93, organized into 4 themes.
- 11 new controls were added, most notably Threat Intelligence, Data Masking, and Secure Coding.
- The transition deadline for existing 2013-certified organizations is 31 October 2025.
- Certification is issued for 3 years, with annual surveillance audits.
- Total certification cost typically ranges $20K–$100K depending on organization size and existing maturity.
What is ISO 27001:2022?
ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published jointly by ISO and IEC, it is the world's most widely adopted certifiable framework for information security.
The 2022 edition — published 25 October 2022 — is the current version. It replaces ISO/IEC 27001:2013 and aligns Annex A with ISO/IEC 27002:2022, which was updated earlier that year.
Unlike SOC 2, ISO 27001 is a certification (not an attestation). An accredited certification body issues a certificate valid for three years, subject to annual surveillance audits. The certificate is globally recognized, particularly in Europe, APAC, and the Middle East where it is often a mandatory procurement requirement.
What changed in the 2022 revision
The 2022 revision is the most significant update to ISO 27001 in nearly a decade. The management system clauses (4–10) are largely unchanged, but Annex A was completely restructured to match ISO 27002:2022.
| Aspect | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Total Annex A controls | 114 | 93 |
| Structure | 14 domains (A.5–A.18) | 4 themes |
| New controls | — | 11 new controls |
| Merged controls | — | 24 controls consolidated |
| Renamed controls | — | 58 controls updated |
| Transition deadline | — | 31 October 2025 |
The 93 Annex A controls — organized into 4 themes
The four themes replace the fourteen domains of the 2013 edition. This structure aligns Annex A with the modern operational reality of information security.
| Theme | Controls | Focus |
|---|---|---|
| A.5 Organizational | 37 controls | Policies, roles, threat intel, supplier relationships, cloud services, incident management |
| A.6 People | 8 controls | Screening, terms of employment, awareness, disciplinary process, remote working |
| A.7 Physical | 14 controls | Physical perimeters, entry controls, secure areas, equipment, media handling |
| A.8 Technological | 34 controls | User endpoint devices, access rights, cryptography, secure development, logging, monitoring, data masking |
The 11 new controls in ISO 27001:2022
The new controls modernize the standard for cloud, DevSecOps, and threat-informed defense.
New Annex A controls (2022)
- A.5.7 Threat intelligence — collect and analyze threat information to inform decisions
- A.5.23 Information security for use of cloud services — govern acquisition, use, management, and exit of cloud services
- A.5.30 ICT readiness for business continuity — plan, implement, maintain, and test ICT continuity
- A.7.4 Physical security monitoring — continuously monitor premises for unauthorized access
- A.8.9 Configuration management — establish, document, implement, monitor, and review configurations
- A.8.10 Information deletion — delete information when no longer required
- A.8.11 Data masking — mask data in accordance with policy, business need, and legal requirements
- A.8.12 Data leakage prevention — apply DLP measures to systems, networks, and devices
- A.8.16 Monitoring activities — monitor networks, systems, and applications for anomalous behavior
- A.8.23 Web filtering — manage access to external websites to reduce exposure to malicious content
- A.8.28 Secure coding — apply secure coding principles to software development
Clauses 4–10: the management system requirements
Certification requires more than implementing controls. Clauses 4–10 define the management system — the discipline that makes controls repeatable and auditable.
Clause 4 — Context of the organization
Identify internal and external issues, interested parties, and ISMS scope.
Clause 5 — Leadership
Top management commitment, information security policy, roles and responsibilities.
Clause 6 — Planning
Risk assessment methodology, risk treatment plan, information security objectives.
Clause 7 — Support
Resources, competence, awareness, communication, documented information.
Clause 8 — Operation
Operational planning, risk assessment execution, risk treatment execution.
Clause 9 — Performance evaluation
Monitoring, measurement, analysis, internal audit, management review.
Clause 10 — Improvement
Nonconformity and corrective action, continual improvement.
The Statement of Applicability (SoA)
The Statement of Applicability is the single most-scrutinized document in an ISO 27001 audit. It lists every Annex A control, states whether it is applicable to your ISMS, provides justification (for inclusion or exclusion), and records implementation status.
The SoA is the auditor's map for Stage 2. A weak SoA — vague justifications, blanket applicability, missing implementation evidence — is the fastest route to a nonconformity.
When transitioning from 2013 to 2022, do not simply renumber controls. Reassess applicability against the new structure. Some 2013 controls have been merged, split, or absorbed into the new set.
Path to certification
ISO 27001 certification follows a defined sequence. Skipping stages accelerates neither the timeline nor the audit outcome.
1. Gap assessment
Compare current state to ISO 27001:2022 requirements. Typically 3–6 weeks.
2. ISMS design & implementation
Build the management system, implement Annex A controls, generate operating evidence. 3–9 months.
3. Internal audit & management review
Mandatory before Stage 1. Auditor will ask for evidence of both.
4. Stage 1 audit (documentation review)
Accredited certification body reviews ISMS documentation, SoA, risk treatment plan.
5. Stage 2 audit (operational effectiveness)
On-site or remote review of operating evidence, control implementation, and management system discipline.
6. Certification decision
Certificate issued for 3 years, subject to annual surveillance audits and re-certification in year 3.
Transitioning from ISO 27001:2013
The transition deadline is firm: 31 October 2025. Organizations still certified against the 2013 version after that date will have their certification withdrawn.
Certification bodies typically bundle the transition audit with a scheduled surveillance visit to minimize disruption. Plan for a delta gap assessment, SoA update, control mapping, and evidence uplift for the 11 new controls.
The transition audit is not a full recertification — it is a focused review of the changes. But do not underestimate: threat intelligence, cloud services, secure coding, and data masking require real operational evidence, not policy-level statements.
Cost & timeline
ISO 27001 costs vary widely by organization size, maturity, and geography. The following ranges reflect typical mid-market engagements.
| Organization size | Timeline | Total first-year cost (USD) |
|---|---|---|
| 1–50 employees | 4–7 months | $20K–$50K |
| 50–250 employees | 6–10 months | $40K–$90K |
| 250–1000 employees | 9–14 months | $80K–$200K |
| 1000+ employees | 12–18 months | $150K–$500K+ |
ISO 27001 vs SOC 2 — which do you need?
The two frameworks overlap significantly but serve different audiences.
| Dimension | ISO 27001 | SOC 2 |
|---|---|---|
| Type | Certification | Attestation |
| Primary audience | Global, especially EU/APAC | North American enterprise |
| Structure | Management system + 93 controls | Trust Services Criteria |
| Validity | 3 years + annual surveillance | 12 months rolling |
| Cost | $20K–$500K | $30K–$150K audit fee |
| Recognition | Global standard | Strong in North America |
Most mid-market SaaS pursuing enterprise deals should hold both. Unified control mapping reduces duplicative effort by 40–60%.
ISO 27001:2022 implementation checklist
Use this checklist before booking your Stage 1 audit.
- ISMS scope defined and approved
- Information security policy signed by top management
- Risk assessment methodology documented and applied
- Risk treatment plan complete with owners and target dates
- Statement of Applicability covers all 93 controls with justifications
- All 11 new 2022 controls implemented with evidence
- Internal audit completed with findings addressed
- Management review held with documented outputs
- Corrective actions tracked and closed
- Awareness training delivered to all workforce
- Supplier / cloud service inventory with security clauses in contracts
- Incident response plan tested
- Business continuity plan tested with ICT readiness evidence
- Threat intelligence process operating with documented outputs
- Secure coding standards adopted and evidenced in the SDLC
Build Trust. Reduce Risk. Achieve Compliance.
Talk to a senior GRC advisor
Free scoping call. Executive-grade guidance on your compliance roadmap.
Book a consultationFrequently Asked Questions
What is the ISO 27001:2022 transition deadline?
31 October 2025. After this date, organizations still certified against the 2013 version will lose their certification.
How many controls are in ISO 27001:2022?
93 controls, organized into 4 themes: Organizational (37), People (8), Physical (14), and Technological (34).
What are the 11 new controls in ISO 27001:2022?
Threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
How long does ISO 27001 certification take?
Typically 4–14 months depending on organization size, existing maturity, and internal resource availability.
How much does ISO 27001 certification cost?
Total first-year cost typically ranges from $20K for small organizations to $200K+ for enterprises, including consulting, tooling, and certification body fees.
How long is an ISO 27001 certificate valid?
Three years, subject to annual surveillance audits in years 1 and 2, and a full recertification audit in year 3.
What is a Statement of Applicability?
A required document listing every Annex A control, whether it applies to your ISMS, the justification for inclusion or exclusion, and implementation status.
What is the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable standard with mandatory requirements. ISO 27002 is a companion guidance document that expands on how to implement the Annex A controls.
Do I need internal auditors to be certified?
The standard requires competent internal auditors. Formal certification (e.g., ISO 27001 Lead Auditor) is not required but is highly recommended and often expected.
Can I certify a subset of my organization?
Yes. The ISMS scope is defined by the organization and can cover specific products, services, or business units — provided the scope is defensible and not misleading.
Is ISO 27001 mandatory?
Not by law in most jurisdictions, but it is contractually required by many enterprise buyers, government agencies, and regulated industries — particularly in Europe and APAC.
How does ISO 27001 relate to GDPR?
ISO 27001 provides a strong foundation for GDPR technical and organizational measures, but does not by itself constitute GDPR compliance. ISO 27701 (privacy extension) fills that gap.
What is a nonconformity?
An audit finding indicating a failure to meet a requirement of the standard. Major nonconformities must be closed before certification is issued.
Can we lose ISO 27001 certification?
Yes. Serious nonconformities in surveillance audits, or failure to remediate previous findings, can result in suspension or withdrawal of certification.
How does ISO 27001 compare to NIST CSF?
ISO 27001 is a certifiable management system standard. NIST CSF is a voluntary framework focused on cybersecurity outcomes. Many organizations use CSF for internal maturity measurement and ISO 27001 for external certification.
Related Topics
