Skip to content
    Back to Regulatory Radar
    CriticalFramework UpdateOctober 25, 2022

    ISO/IEC 27001:2022 Published

    ISO/IEC 27001:2022 was officially published, replacing the 2013 edition as the global standard for information security management systems (ISMS). The revision incorporates the restructured Annex A controls from ISO 27002:2022, updates clause language to align with the latest ISO Harmonized Structure, and adds explicit requirements for monitoring organizational context changes and stakeholder needs. A three-year transition period was established, requiring all certified organizations to migrate by October 31, 2025.

    ISO 27001SaaSHealthcareFinTechDefense

    Key Analytics

    October 25, 2022
    Event Date
    Time Remaining
    August 1, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    The three-year transition window closed on October 31, 2025; any certificate still referencing ISO 27001:2013 became invalid at that date, and certification bodies now audit exclusively against the 2022 edition. The consolidated Annex A with 93 controls (down from 114) required a full Statement of Applicability rewrite, and the new controls for threat intelligence, cloud services security, and data leakage prevention may require tooling and processes that some organizations are still maturing. Organizations that missed the transition deadline must pursue initial certification against the 2022 standard rather than a transition audit.

    Recommended Actions

    • Confirm your current certificate references ISO/IEC 27001:2022; any certificate still citing the 2013 edition is no longer valid and requires initial certification against the 2022 standard
    • Maintain the Statement of Applicability against the 93-control Annex A structure with documented justification for any exclusions
    • Verify sustained implementation of the new controls, including threat intelligence, cloud services security, and data leakage prevention, ahead of surveillance audits

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant120-250 hours
    Key Workstreams
    • Statement of Applicability rewrite from the 114-control 2013 structure to the 93-control 2022 Annex A
    • Gap closure on the new 2022 controls, including data leakage prevention tooling
    • Clause-level updates for organizational context and interested-party monitoring
    • Certification body coordination and audit evidence assembly

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 120-250 hours
    Start cold under pressureMajor · 300-700 hours

    Roughly 180 to 450 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events