Skip to content
compliancebase

ISO 27001:2013 Certifications Are Dead — What the 2022 Transition Means for Your ISMS

June 26, 2026 · ComplianceBase Editorial, Independent security compliance reference editors; frameworks cited to primary sources (AICPA TSC, ISO/IEC 27001, GDPR, HIPAA)

The 2022 edition restructured Annex A into four themes. Here is what SaaS teams should update in scope, SoA, and buyer language.

ISO/IEC 27001:2022 is the current edition for Information Security Management System requirements. Organizations that still speak only in 2013 Annex A control numbers create avoidable questionnaire friction — and risk mismatched Statements of Applicability (SoA).

What actually changed

  • Clauses 4–10 remain the management-system core.
  • Annex A was reorganized into four themes: organizational (A.5), people (A.6), physical (A.7), and technological (A.8) — 93 reference controls aligned with ISO/IEC 27002:2022 guidance.
  • You still do not implement all 93 by default; risk assessment drives SoA applicability.

Official overview: ISO/IEC 27001.

SaaS implications

  1. Rewrite mappings from old 2013 A.x numbers to 2022 IDs (for example access themes often land in A.5.15 and A.8.x — see /controls/iso-27001/a-5-15).
  2. Update customer language to say “ISO/IEC 27001:2022” with an accurate scope statement.
  3. Keep dual-track evidence with SOC 2 where buyers differ — sequencing notes at /compare/soc-2-vs-iso-27001.
  4. Budget for certification-body cadence — educational ranges at /costs/iso-27001/overview.

Hub depth on this site

Start at /frameworks/iso-27001. Organizational controls such as /controls/iso-27001/a-5-1 and technological themes such as /controls/iso-27001/a-8-24 are live reference pages.

Disclaimer: Educational only — not certification advice. Your accredited certification body governs certificate issuance.