ISO 27001:2013 Certifications Are Dead — What the 2022 Transition Means for Your ISMS
The 2022 edition restructured Annex A into four themes. Here is what SaaS teams should update in scope, SoA, and buyer language.
ISO/IEC 27001:2022 is the current edition for Information Security Management System requirements. Organizations that still speak only in 2013 Annex A control numbers create avoidable questionnaire friction — and risk mismatched Statements of Applicability (SoA).
What actually changed
- Clauses 4–10 remain the management-system core.
- Annex A was reorganized into four themes: organizational (A.5), people (A.6), physical (A.7), and technological (A.8) — 93 reference controls aligned with ISO/IEC 27002:2022 guidance.
- You still do not implement all 93 by default; risk assessment drives SoA applicability.
Official overview: ISO/IEC 27001.
SaaS implications
- Rewrite mappings from old 2013 A.x numbers to 2022 IDs (for example access themes often land in A.5.15 and A.8.x — see /controls/iso-27001/a-5-15).
- Update customer language to say “ISO/IEC 27001:2022” with an accurate scope statement.
- Keep dual-track evidence with SOC 2 where buyers differ — sequencing notes at /compare/soc-2-vs-iso-27001.
- Budget for certification-body cadence — educational ranges at /costs/iso-27001/overview.
Hub depth on this site
Start at /frameworks/iso-27001. Organizational controls such as /controls/iso-27001/a-5-1 and technological themes such as /controls/iso-27001/a-8-24 are live reference pages.
Disclaimer: Educational only — not certification advice. Your accredited certification body governs certificate issuance.