ISO 27001:2013 Certifications Are Dead — What the 2022 Transition Means for Your ISMS
The 2022 edition restructured Annex A into four themes. Here is what SaaS teams should update in scope, SoA, and buyer language.
ISO/IEC 27001:2022 is the current edition for Information Security Management System requirements. Organizations that still speak only in 2013 Annex A control numbers create avoidable questionnaire friction — and risk mismatched Statements of Applicability (SoA).
What actually changed
- Clauses 4–10 remain the management-system core — context, leadership, planning, support, operation, performance evaluation, improvement.
- Annex A was reorganized into four themes: organizational (A.5), people (A.6), physical (A.7), and technological (A.8) — 93 reference controls aligned with ISO/IEC 27002:2022 guidance.
- You still do not implement all 93 by default; risk assessment drives SoA applicability and exclusions must be justified.
Official overview: ISO/IEC 27001.
Why 2013 language still shows up in RFPs
Many enterprise security questionnaires were written years ago and reference 2013 Annex A numbering or “ISO 27001 certified” without an edition year. Accredited certificates today should cite ISO/IEC 27001:2022. When your customer-facing collateral still maps to retired control IDs, security reviewers spend cycles translating — or assume your ISMS documentation is stale.
SaaS implications
1. Rewrite control mappings
Build a crosswalk from legacy 2013 A.x references to 2022 IDs. Access themes often land across organizational and technological controls — for example identity and access topics may appear in A.5.15 (access rights) and A.8.x technical controls such as A.8.2 (privileged access) depending on your SoA.
Use /tools/cross-framework-mapper for educational crosswalks to SOC 2 Common Criteria where buyers ask for both frameworks.
2. Update customer and sales language
State clearly:
- Standard edition: ISO/IEC 27001:2022
- Certification scope: products, sites, and boundaries the certificate covers
- SoA approach: risk-based applicability, not “all 93 implemented”
Misstating scope is a common procurement blocker even when technical controls are sound.
3. Keep dual-track evidence with SOC 2
US enterprise buyers often want SOC 2 Type II; EU tenders and global vendors frequently ask for ISO 27001. Shared IAM, change, logging, and vendor evidence reduces duplicate engineering — but documentation trees differ (system description vs ISMS pack, internal audit, management review).
Sequencing notes: /compare/soc-2-vs-iso-27001. Multi-framework cost framing: /costs/soc-2/multi-framework.
4. Budget certification-body cadence
Transition work is not only documentation — Stage 1 and Stage 2 audit days depend on scope breadth and ISMS maturity. Educational ranges: /costs/iso-27001/overview and /costs/iso-27001/stage-1-vs-stage-2. Interactive heuristic: /tools/iso-27001-cost-calculator.
ISMS artifacts to refresh
| Artifact | 2022 transition action | |---|---| | Statement of Applicability | Remap control IDs; revisit exclusions with risk rationale | | Risk assessment | Confirm treatments still map to applicable Annex A controls | | Policies and procedures | Update references from 2013 annex numbering | | Internal audit program | Sample against 2022 control set | | Management review records | Note edition change and any scope adjustments |
The management system clauses (4–10) are where ISO differs most from SOC 2’s attestation model — do not assume SOC 2 evidence alone satisfies internal audit and management review expectations.
Certification body timing
Accredited certification bodies migrated existing certificates on defined transition timelines. If your certificate or surveillance plan still references 2013-only documentation, treat that as a program debt item in your roadmap — not a cosmetic label change.
Gap analysis before Stage 1: /tools/control-gap-analyzer.
Hub depth on this site
Start at /frameworks/iso-27001. Organizational controls such as A.5.1 (policies for information security) and technological themes such as A.8.24 (use of cryptography) are live reference pages across the 93-control Annex A set.
Comparison with 2013 structure for procurement conversations: /compare/iso-27001-2013-vs-2022.
Disclaimer: Educational only — not certification advice. Your accredited certification body governs certificate issuance, surveillance, and transition requirements for your contract.