Skip to content
    Back to Regulatory Radar
    ImportantFramework UpdateFebruary 15, 2022

    ISO/IEC 27002:2022 Published with Restructured Controls

    ISO/IEC 27002:2022 replaced the 2013 edition with a completely restructured control set, consolidating 114 controls into 93 controls organized under four themes: Organizational, People, Physical, and Technological. The update introduced 11 new controls addressing cloud security, threat intelligence, ICT readiness for business continuity, and data masking, among others. This restructuring directly reshaped Annex A of ISO 27001 and set the foundation for the ISO/IEC 27001:2022 revision published in October 2022.

    ISO 27001SaaSHealthcareFinTechDefense

    Key Analytics

    February 15, 2022
    Event Date
    Time Remaining
    August 1, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    The IAF three-year transition window closed on 31 October 2025, so ISO 27001:2013 certificates are now expired or withdrawn and all certified organizations operate against the 2022 control structure. Statements of Applicability, risk treatment plans, and internal audit programs must consistently reference the 93-control, four-theme taxonomy rather than the legacy 2013 numbering. The controls introduced in 2022, including threat intelligence (5.7), information security for use of cloud services (5.23), and data masking (8.11), may still need maturation where implementations were completed close to the transition deadline.

    Recommended Actions

    • Confirm your current certificate was issued against ISO/IEC 27001:2022; any remaining 2013 certificate expired on 31 October 2025
    • Verify the Statement of Applicability, risk treatment plan, and internal audit program reference the 93-control, four-theme structure of the 2022 edition
    • Review the maturity of 2022-era controls such as 5.7 (Threat Intelligence), 5.23 (Cloud Services Security), and 8.11 (Data Masking) ahead of surveillance audits

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant90-180 hours
    Key Workstreams
    • Renumbering of control documentation from the 2013 114-control set to the 2022 taxonomy
    • Statement of Applicability and risk treatment plan rewrite against the four themes
    • Gap closure on threat intelligence, cloud services security, and data masking
    • Internal audit checklist realignment to the 2022 control references

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 90-180 hours
    Start cold under pressureMajor · 220-500 hours

    Roughly 130 to 320 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events