ISO/IEC 27001:2022 Published
ISO/IEC 27001:2022 was officially published, replacing the 2013 edition as the global standard for information security management systems (ISMS). The revision incorporates the restructured Annex A controls from ISO 27002:2022, updates clause language to align with the latest ISO Harmonized Structure, and adds explicit requirements for monitoring organizational context changes and stakeholder needs. A three-year transition period was established, requiring all certified organizations to migrate by October 31, 2025.
Key Analytics
Impact Analysis
The three-year transition window closed on October 31, 2025; any certificate still referencing ISO 27001:2013 became invalid at that date, and certification bodies now audit exclusively against the 2022 edition. The consolidated Annex A with 93 controls (down from 114) required a full Statement of Applicability rewrite, and the new controls for threat intelligence, cloud services security, and data leakage prevention may require tooling and processes that some organizations are still maturing. Organizations that missed the transition deadline must pursue initial certification against the 2022 standard rather than a transition audit.
Recommended Actions
- Confirm your current certificate references ISO/IEC 27001:2022; any certificate still citing the 2013 edition is no longer valid and requires initial certification against the 2022 standard
- Maintain the Statement of Applicability against the 93-control Annex A structure with documented justification for any exclusions
- Verify sustained implementation of the new controls, including threat intelligence, cloud services security, and data leakage prevention, ahead of surveillance audits
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Statement of Applicability rewrite from the 114-control 2013 structure to the 93-control 2022 Annex A
- ›Gap closure on the new 2022 controls, including data leakage prevention tooling
- ›Clause-level updates for organizational context and interested-party monitoring
- ›Certification body coordination and audit evidence assembly
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 180 to 450 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.