ISO 27001

ISO 27001:2022 Certification: Complete Guide to Annex A, Transition & Implementation

The definitive guide to ISO/IEC 27001:2022 — new Annex A structure, 93 controls, transition deadline, implementation roadmap, and certification cost — for CISOs and compliance leaders.

May 30, 202613 min readBy GRC XL Advisory

Quick Answer

ISO/IEC 27001:2022 is the current international standard for Information Security Management Systems (ISMS). It restructured Annex A into 93 controls across 4 themes (Organizational, People, Physical, Technological), introduced 11 new controls, and requires all existing certified organizations to transition from the 2013 version by 31 October 2025.

Key Takeaways

  • The 2022 revision consolidates 114 controls into 93, organized into 4 themes.
  • 11 new controls were added, most notably Threat Intelligence, Data Masking, and Secure Coding.
  • The transition deadline for existing 2013-certified organizations is 31 October 2025.
  • Certification is issued for 3 years, with annual surveillance audits.
  • Total certification cost typically ranges $20K–$100K depending on organization size and existing maturity.

What is ISO 27001:2022?

ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). Published jointly by ISO and IEC, it is the world's most widely adopted certifiable framework for information security.

The 2022 edition — published 25 October 2022 — is the current version. It replaces ISO/IEC 27001:2013 and aligns Annex A with ISO/IEC 27002:2022, which was updated earlier that year.

Unlike SOC 2, ISO 27001 is a certification (not an attestation). An accredited certification body issues a certificate valid for three years, subject to annual surveillance audits. The certificate is globally recognized, particularly in Europe, APAC, and the Middle East where it is often a mandatory procurement requirement.

What changed in the 2022 revision

The 2022 revision is the most significant update to ISO 27001 in nearly a decade. The management system clauses (4–10) are largely unchanged, but Annex A was completely restructured to match ISO 27002:2022.

AspectISO 27001:2013ISO 27001:2022
Total Annex A controls11493
Structure14 domains (A.5–A.18)4 themes
New controls11 new controls
Merged controls24 controls consolidated
Renamed controls58 controls updated
Transition deadline31 October 2025

The 93 Annex A controls — organized into 4 themes

The four themes replace the fourteen domains of the 2013 edition. This structure aligns Annex A with the modern operational reality of information security.

ThemeControlsFocus
A.5 Organizational37 controlsPolicies, roles, threat intel, supplier relationships, cloud services, incident management
A.6 People8 controlsScreening, terms of employment, awareness, disciplinary process, remote working
A.7 Physical14 controlsPhysical perimeters, entry controls, secure areas, equipment, media handling
A.8 Technological34 controlsUser endpoint devices, access rights, cryptography, secure development, logging, monitoring, data masking

The 11 new controls in ISO 27001:2022

The new controls modernize the standard for cloud, DevSecOps, and threat-informed defense.

New Annex A controls (2022)

  • A.5.7 Threat intelligence — collect and analyze threat information to inform decisions
  • A.5.23 Information security for use of cloud services — govern acquisition, use, management, and exit of cloud services
  • A.5.30 ICT readiness for business continuity — plan, implement, maintain, and test ICT continuity
  • A.7.4 Physical security monitoring — continuously monitor premises for unauthorized access
  • A.8.9 Configuration management — establish, document, implement, monitor, and review configurations
  • A.8.10 Information deletion — delete information when no longer required
  • A.8.11 Data masking — mask data in accordance with policy, business need, and legal requirements
  • A.8.12 Data leakage prevention — apply DLP measures to systems, networks, and devices
  • A.8.16 Monitoring activities — monitor networks, systems, and applications for anomalous behavior
  • A.8.23 Web filtering — manage access to external websites to reduce exposure to malicious content
  • A.8.28 Secure coding — apply secure coding principles to software development

Clauses 4–10: the management system requirements

Certification requires more than implementing controls. Clauses 4–10 define the management system — the discipline that makes controls repeatable and auditable.

Clause 4 — Context of the organization

Identify internal and external issues, interested parties, and ISMS scope.

Clause 5 — Leadership

Top management commitment, information security policy, roles and responsibilities.

Clause 6 — Planning

Risk assessment methodology, risk treatment plan, information security objectives.

Clause 7 — Support

Resources, competence, awareness, communication, documented information.

Clause 8 — Operation

Operational planning, risk assessment execution, risk treatment execution.

Clause 9 — Performance evaluation

Monitoring, measurement, analysis, internal audit, management review.

Clause 10 — Improvement

Nonconformity and corrective action, continual improvement.

The Statement of Applicability (SoA)

The Statement of Applicability is the single most-scrutinized document in an ISO 27001 audit. It lists every Annex A control, states whether it is applicable to your ISMS, provides justification (for inclusion or exclusion), and records implementation status.

The SoA is the auditor's map for Stage 2. A weak SoA — vague justifications, blanket applicability, missing implementation evidence — is the fastest route to a nonconformity.

When transitioning from 2013 to 2022, do not simply renumber controls. Reassess applicability against the new structure. Some 2013 controls have been merged, split, or absorbed into the new set.

Path to certification

ISO 27001 certification follows a defined sequence. Skipping stages accelerates neither the timeline nor the audit outcome.

1. Gap assessment

Compare current state to ISO 27001:2022 requirements. Typically 3–6 weeks.

2. ISMS design & implementation

Build the management system, implement Annex A controls, generate operating evidence. 3–9 months.

3. Internal audit & management review

Mandatory before Stage 1. Auditor will ask for evidence of both.

4. Stage 1 audit (documentation review)

Accredited certification body reviews ISMS documentation, SoA, risk treatment plan.

5. Stage 2 audit (operational effectiveness)

On-site or remote review of operating evidence, control implementation, and management system discipline.

6. Certification decision

Certificate issued for 3 years, subject to annual surveillance audits and re-certification in year 3.

Transitioning from ISO 27001:2013

The transition deadline is firm: 31 October 2025. Organizations still certified against the 2013 version after that date will have their certification withdrawn.

Certification bodies typically bundle the transition audit with a scheduled surveillance visit to minimize disruption. Plan for a delta gap assessment, SoA update, control mapping, and evidence uplift for the 11 new controls.

The transition audit is not a full recertification — it is a focused review of the changes. But do not underestimate: threat intelligence, cloud services, secure coding, and data masking require real operational evidence, not policy-level statements.

Cost & timeline

ISO 27001 costs vary widely by organization size, maturity, and geography. The following ranges reflect typical mid-market engagements.

Organization sizeTimelineTotal first-year cost (USD)
1–50 employees4–7 months$20K–$50K
50–250 employees6–10 months$40K–$90K
250–1000 employees9–14 months$80K–$200K
1000+ employees12–18 months$150K–$500K+

ISO 27001 vs SOC 2 — which do you need?

The two frameworks overlap significantly but serve different audiences.

DimensionISO 27001SOC 2
TypeCertificationAttestation
Primary audienceGlobal, especially EU/APACNorth American enterprise
StructureManagement system + 93 controlsTrust Services Criteria
Validity3 years + annual surveillance12 months rolling
Cost$20K–$500K$30K–$150K audit fee
RecognitionGlobal standardStrong in North America
Most mid-market SaaS pursuing enterprise deals should hold both. Unified control mapping reduces duplicative effort by 40–60%.

ISO 27001:2022 implementation checklist

Use this checklist before booking your Stage 1 audit.

  • ISMS scope defined and approved
  • Information security policy signed by top management
  • Risk assessment methodology documented and applied
  • Risk treatment plan complete with owners and target dates
  • Statement of Applicability covers all 93 controls with justifications
  • All 11 new 2022 controls implemented with evidence
  • Internal audit completed with findings addressed
  • Management review held with documented outputs
  • Corrective actions tracked and closed
  • Awareness training delivered to all workforce
  • Supplier / cloud service inventory with security clauses in contracts
  • Incident response plan tested
  • Business continuity plan tested with ICT readiness evidence
  • Threat intelligence process operating with documented outputs
  • Secure coding standards adopted and evidenced in the SDLC

Build Trust. Reduce Risk. Achieve Compliance.

Talk to a senior GRC advisor

Free scoping call. Executive-grade guidance on your compliance roadmap.

Book a consultation

Frequently Asked Questions

What is the ISO 27001:2022 transition deadline?

31 October 2025. After this date, organizations still certified against the 2013 version will lose their certification.

How many controls are in ISO 27001:2022?

93 controls, organized into 4 themes: Organizational (37), People (8), Physical (14), and Technological (34).

What are the 11 new controls in ISO 27001:2022?

Threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

How long does ISO 27001 certification take?

Typically 4–14 months depending on organization size, existing maturity, and internal resource availability.

How much does ISO 27001 certification cost?

Total first-year cost typically ranges from $20K for small organizations to $200K+ for enterprises, including consulting, tooling, and certification body fees.

How long is an ISO 27001 certificate valid?

Three years, subject to annual surveillance audits in years 1 and 2, and a full recertification audit in year 3.

What is a Statement of Applicability?

A required document listing every Annex A control, whether it applies to your ISMS, the justification for inclusion or exclusion, and implementation status.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard with mandatory requirements. ISO 27002 is a companion guidance document that expands on how to implement the Annex A controls.

Do I need internal auditors to be certified?

The standard requires competent internal auditors. Formal certification (e.g., ISO 27001 Lead Auditor) is not required but is highly recommended and often expected.

Can I certify a subset of my organization?

Yes. The ISMS scope is defined by the organization and can cover specific products, services, or business units — provided the scope is defensible and not misleading.

Is ISO 27001 mandatory?

Not by law in most jurisdictions, but it is contractually required by many enterprise buyers, government agencies, and regulated industries — particularly in Europe and APAC.

How does ISO 27001 relate to GDPR?

ISO 27001 provides a strong foundation for GDPR technical and organizational measures, but does not by itself constitute GDPR compliance. ISO 27701 (privacy extension) fills that gap.

What is a nonconformity?

An audit finding indicating a failure to meet a requirement of the standard. Major nonconformities must be closed before certification is issued.

Can we lose ISO 27001 certification?

Yes. Serious nonconformities in surveillance audits, or failure to remediate previous findings, can result in suspension or withdrawal of certification.

How does ISO 27001 compare to NIST CSF?

ISO 27001 is a certifiable management system standard. NIST CSF is a voluntary framework focused on cybersecurity outcomes. Many organizations use CSF for internal maturity measurement and ISO 27001 for external certification.

Related Topics

ISO 27001:2022 certificationISO 27001 Annex A 2022ISO 27001 controlsISO 27001 transition 2025ISO 27001 implementation guideISO 27001 certification costISMS implementationStatement of ApplicabilityISO 27001 audit

Build Trust. Reduce Risk. Achieve Compliance.