If your organization holds an ISO/IEC 27001:2013 certificate, it has until October 31, 2025 to transition to ISO/IEC 27001:2022. After that date, 2013-based certificates expire or are withdrawn. The good news is that the 2022 revision is evolutionary. The management system clauses changed only modestly, while Annex A was reorganized from 114 controls into 93, grouped under four themes, with 11 new controls. Most of the work is updating your risk treatment, your Statement of Applicability and a handful of new controls.

Here's what changed, the dates that matter, and a practical plan for getting through your transition audit.

What changed in ISO 27001:2022?

ISO published ISO/IEC 27001:2022, the third edition of the standard, on October 25, 2022. Its full title now reads Information security, cybersecurity and privacy protection — Information security management systems — Requirements.

The changes fall into three groups:

  • Management system clauses (4 to 10). A few new or clarified requirements, mostly around planning, processes and interested parties.
  • Annex A. A full restructure to match ISO/IEC 27002:2022, which was published earlier in 2022.
  • An amendment. In February 2024, ISO published Amendment 1:2024, which adds climate change considerations to clauses 4.1 and 4.2.

Your ISMS doesn't need to be rebuilt. It needs to be remapped, with some gaps filled.

What changed in the ISO 27001:2022 clauses?

The clause changes are small in wording but worth taking seriously, because auditors will look for evidence of each one.

Clause What changed
4.2 You must determine which interested-party requirements will be addressed through the ISMS
4.4 The ISMS must include the processes needed and their interactions
5.3 Roles and responsibilities must be communicated within the organization
6.2 Information security objectives must be monitored and available as documented information
6.3 New: changes to the ISMS must be carried out in a planned manner
7.4 Communication requirements simplified to cover what, when, with whom and how
8.1 You must set criteria for your processes and control externally provided processes, products and services relevant to the ISMS
9.2 Split into 9.2.1 (General) and 9.2.2 (Internal audit programme)
9.3 Split into three parts, with a new management review input: changes in the needs and expectations of interested parties
10 Continual improvement (10.1) and nonconformity and corrective action (10.2) swapped order

Annex A also stopped listing control objectives. Clause 6.1.3 now refers to it as a list of possible information security controls.

What does clause 6.3 "Planning of changes" require?

Clause 6.3 is the one genuinely new clause. It says that when you decide the ISMS needs to change, the change must be carried out in a planned manner. In practice, that means showing you considered the purpose of the change, its consequences, the resources needed and who is responsible before you made it.

You probably already have a change management process for IT. Extend it, or write a short procedure, so that changes to the ISMS itself are covered too: scope changes, new policies, reorganizations and new sites.

How did Annex A change in ISO 27001:2022?

The 2013 Annex A had 114 controls across 14 domains. The 2022 version has 93 controls across four themes.

Theme Annex A section Number of controls
Organizational A.5 37
People A.6 8
Physical A.7 14
Technological A.8 34

Most 2013 controls didn't disappear. Many were merged with related controls or renamed, and ISO/IEC 27002:2022 includes mapping tables between the old and new numbering. That mapping is the fastest way to carry your existing evidence forward.

What are the 11 new controls in ISO 27001:2022?

Control Name
5.7 Threat intelligence
5.23 Information security for use of cloud services
5.30 ICT readiness for business continuity
7.4 Physical security monitoring
8.9 Configuration management
8.10 Information deletion
8.11 Data masking
8.12 Data leakage prevention
8.16 Monitoring activities
8.23 Web filtering
8.28 Secure coding

Several of these describe work you may already do without calling it a formal control. Configuration baselines, log monitoring and cloud security reviews are common examples. The job is to decide whether each control applies, record the decision in your Statement of Applicability, and have evidence ready for the ones you include.

Two tend to take the most effort for smaller organizations. Threat intelligence (5.7) needs a defined process for collecting and acting on threat information, not just a news feed. Data leakage prevention (8.12) needs you to know where sensitive data lives and how it can leave, which often means some data classification work first.

What are control attributes?

ISO/IEC 27002:2022 tags each control with attributes, such as control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability) and operational capabilities. Attributes aren't a certification requirement. They're useful for filtering and reporting, for example when showing leadership how your controls spread across prevention and detection.

What is the ISO 27001 transition deadline?

The International Accreditation Forum (IAF) sets the rules for how accredited certification bodies handle the transition, in IAF MD 26:2023. The key dates are:

Date Milestone
October 25, 2022 ISO/IEC 27001:2022 published
February 23, 2024 Amendment 1:2024 (climate action changes) published
April 30, 2024 From this point, initial certification and recertification audits are carried out against the 2022 version only
October 31, 2025 Transition period ends; all 2013-based certifications expire or are withdrawn

The April 30, 2024 date is next week. After that, any recertification audit will be against the 2022 version, and there will be no option to recertify to 2013 and transition later.

How does the transition audit work?

IAF MD 26 allows the transition audit to be done alongside a surveillance audit, alongside a recertification audit, or as a separate audit. It sets a minimum transition audit time of 0.5 auditor days when combined with a recertification audit, and 1.0 auditor day when combined with a surveillance audit or run separately.

The transition audit must cover, at minimum:

  • A gap analysis against ISO/IEC 27001:2022
  • The updated Statement of Applicability
  • The updated risk treatment plan
  • Implementation and effectiveness of new or changed controls

Your certification body sets its own scheduling and may have added requirements, so confirm the details with them early.

What is ISO 27001 Amendment 1:2024?

In February 2024, ISO published amendments to a large set of management system standards, including ISO/IEC 27001:2022, to add climate change considerations. A joint ISO and IAF communiqué dated February 22, 2024, sets out the two additions:

  • Clause 4.1: "The organization shall determine whether climate change is a relevant issue."
  • Clause 4.2: "NOTE: Relevant interested parties can have requirements related to climate change."

For most information security programs, the practical effect is modest. Consider whether climate-related risks, such as severe weather affecting a data center or supplier, are relevant to your ISMS, and record your conclusion. If they are, feed them into your risk assessment and business continuity planning.

The communiqué said IAF would issue further guidance for certified organizations and certification bodies. Until then, assume your auditor will ask how you addressed it.

How to plan your ISO 27001:2022 transition

A focused team can handle the transition as a structured project. Here's the sequence we recommend:

  1. Check your dates. Look at your certificate expiry and audit schedule. Decide with your certification body whether to transition at your next surveillance audit, at recertification or in a separate audit.
  2. Get the right documents. You need ISO/IEC 27001:2022, Amendment 1:2024, and ideally ISO/IEC 27002:2022 for the control guidance and mapping tables.
  3. Run a clause gap analysis. Walk through clauses 4 to 10 and note where you need new evidence, especially 4.2, 4.4, 6.2, 6.3, 8.1 and 9.3.
  4. Map your controls. Use the 27002:2022 mapping tables to move each existing control to its new number. Flag the 11 new controls for review.
  5. Update your risk assessment and treatment plan. Re-check your risks against the new control set, and include climate change where relevant.
  6. Implement new and changed controls. Prioritize by risk. Start collecting evidence as soon as each control is in place, so the auditor can see it operating.
  7. Rewrite your Statement of Applicability. List all 93 controls, whether each applies, why, and its implementation status.
  8. Update policies and procedures. Fix control references, add an ISMS change procedure for clause 6.3, and update the communication plan.
  9. Run an internal audit and a management review. Audit against the 2022 requirements and include the new management review input on interested parties.
  10. Hold the transition audit. Resolve any nonconformities within the timeframe your certification body sets.

Build in slack. Certification bodies will be busy as October 2025 approaches, and nonconformities take time to close.

Frequently asked questions

Is our ISO 27001:2013 certificate still valid?

Yes, until you transition or until October 31, 2025, whichever comes first. After that date, 2013-based certificates expire or are withdrawn.

Can we transition at our next surveillance audit?

Yes. IAF MD 26 permits the transition audit alongside a surveillance audit, a recertification audit or as a separate audit. Expect at least one extra auditor day if it's combined with surveillance.

Do we have to implement all 11 new controls?

Not automatically. As with every Annex A control, you decide applicability based on your risk assessment and justify any exclusion in the Statement of Applicability. In practice, few organizations can credibly exclude controls like configuration management or monitoring activities.

Does the climate change amendment need its own audit?

The ISO and IAF communiqué didn't set a separate transition period and said IAF would provide further guidance. Address the new text in your context analysis now so it's ready whenever your auditor reviews it.

Key takeaways

  • ISO/IEC 27001:2022 was published on October 25, 2022. The transition period ends on October 31, 2025.
  • From April 30, 2024, initial certification and recertification audits use the 2022 version only.
  • Annex A now has 93 controls in four themes, including 11 new controls.
  • Clause 6.3 on planning changes is the main new clause requirement, and several others were clarified.
  • Amendment 1:2024 asks you to decide whether climate change is a relevant issue for your ISMS.
  • Start with a gap analysis and control mapping, and book your transition audit early.