ISO 27001:2022 Post-Transition: What Happens to Your ISMS Now

October 31, 2025 was the deadline for transitioning from ISO/IEC 27001:2013 to ISO/IEC 27001:2022. If your organization completed the transition, your certificate now references the 2022 version, and your ISMS should reflect the updated standard's requirements including the restructured Annex A controls. If you missed the deadline, your 2013 certificate has expired, and you are technically operating without a valid ISO 27001 certification. This has real consequences — clients who require ISO 27001 as a contractual condition may flag your organization as non-compliant in their vendor risk assessments. The path forward depends on your situation. Organizations that transitioned on time now need to focus on operationalizing the new controls, preparing for their next surveillance audit under the 2022 standard, and integrating the new control categories into their daily operations. Organizations that missed the deadline need to pursue recertification against the 2022 standard, which involves a more comprehensive assessment than a transition audit would have required. Regardless of which situation you are in, understanding the practical differences between the 2013 and 2022 versions is essential for maintaining a healthy ISMS.

What Actually Changed Between 2013 and 2022
The main body of ISO 27001 received relatively minor updates — mostly clarifications in terminology and alignment with the ISO Harmonized Structure. The significant changes are in Annex A, which was completely restructured from 14 control categories with 114 controls to 4 themes with 93 controls. The four themes are Organizational, People, Physical, and Technological. Eleven new controls were introduced that reflect the evolving threat landscape. These include threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. For organizations that were already following security best practices, many of these controls were likely already implemented informally. The difference now is that they must be formally documented, implemented, monitored, and evidenced as part of your ISMS. The Statement of Applicability needs to be updated to reflect the new control structure. If your SoA still references the 114-control format from 2013, it needs to be remapped to the 93-control format even if the underlying controls have not changed.

Preparing for Your First Surveillance Audit Under 2022
Your certification body will conduct surveillance audits at defined intervals to verify that your ISMS continues to meet the standard's requirements. Your first surveillance audit under the 2022 version will likely receive closer scrutiny than previous audits because the auditor will be verifying that the transition was substantive, not just a document update. Focus on three areas. First, demonstrate that the new Annex A controls are operationally effective, not just documented. If your SoA includes the threat intelligence control, show that you have a process for collecting, analyzing, and acting on threat intelligence relevant to your organization. If data leakage prevention is applicable, demonstrate the technical controls and monitoring processes you have in place. Second, ensure your risk assessment methodology reflects the updated control set. Your risk treatment plan should reference the 2022 controls, and the mapping between identified risks and selected controls should be current. Auditors will check that controls were selected based on risk, not just because they appear in Annex A. Third, update your internal audit program to cover the new controls. Your internal audit schedule should ensure that every applicable control is audited within the certification cycle, with priority given to the new controls that may not have been previously audited.

Five Controls Most Organizations Struggle to Implement
Threat intelligence is the control most organizations implement superficially. It is not enough to subscribe to a threat feed — you need to demonstrate that threat intelligence is analyzed in the context of your organization's specific threat landscape and that it informs your security decisions. Establish a regular threat intelligence review process and document how specific intelligence has influenced your security controls or incident response preparation. Cloud security controls are challenging because they span both your responsibilities and your cloud provider's. Document your shared responsibility model clearly. Map which security controls are your responsibility, which are the provider's, and which are shared. Evidence this through your cloud provider's SOC 2 report, your own configuration audits, and your cloud security monitoring processes. Data leakage prevention requires both technical controls and process discipline. Implement DLP controls at key data egress points — email, web uploads, removable media, and cloud storage. But also address the process dimension — data classification policies, user awareness training, and incident response procedures for data leakage events. Secure coding is often treated as a development team responsibility without ISMS integration. Bring your secure coding practices under the ISMS umbrella — include secure coding standards in your documented information, conduct periodic reviews of code security practices, and maintain evidence of developer security training. Configuration management requires a baseline configuration standard for each technology in your environment and a process for detecting and remediating configuration drift. Automated configuration monitoring tools are practically essential for implementing this control effectively.

Building a Continuous Improvement Cycle for Your ISMS
The most common failure mode for ISO 27001-certified organizations is treating the ISMS as a compliance artifact rather than a living system. The 2022 version's emphasis on monitoring and continuous improvement makes this distinction even more important. Establish quarterly ISMS review meetings that evaluate the effectiveness of controls, review incident trends, assess the relevance of risk treatment plans, and identify areas for improvement. These reviews feed into your management review, which remains a requirement of the standard. Implement metrics that tell you whether your ISMS is working, not just whether it exists. Useful metrics include the number of security incidents detected versus those reported by third parties, the time to remediate identified vulnerabilities, the percentage of employees completing security awareness training, the number of nonconformities found in internal audits and their remediation timelines, and the coverage of your asset inventory. Integrate your ISMS with other compliance programs. If your organization also maintains PCI DSS compliance, SOC 2 reports, or DPDP compliance, there is significant control overlap. An integrated compliance approach reduces duplication, improves consistency, and provides a more comprehensive view of your security posture. Use ISO/IEC TS 27103 as the bridging mechanism between ISO 27001 and other cybersecurity frameworks.

Q: What happens if we missed the ISO 27001:2022 transition deadline?
A: Your ISO 27001:2013 certificate has expired. You need to pursue recertification against the 2022 version through a full certification audit, which is more comprehensive than a transition audit.

Q: How many controls are in ISO 27001:2022?
A: Annex A contains 93 controls organized into four themes: Organizational (37), People (8), Physical (14), and Technological (34). This replaces the previous 114 controls across 14 categories.

Q: Can we maintain both ISO 27001 and PCI DSS simultaneously?
A: Yes. Approximately 60-70% of controls overlap between the two frameworks. An integrated compliance approach is more efficient than managing them separately.

QRC provides ISO 27001 certification and surveillance audit support. Contact us to ensure your ISMS meets the 2022 standard.

LinkedIn Youtube

We use cookies to enhance your user experience. By continuing to browse, you hereby agree to the use of cookies. Know more Privacy Policy & Cookies Policy.

X