Skip to content
compliancebase

Theme comparison · iso-27001-editions

ISO 27001:2013 vs 2022

ISO 27001:2013 vs ISO 27001:2022: compare clauses, 114-to-93 Annex A controls, new cloud and threat controls, attributes, and migration work.

Frameworks covered: ISO/IEC 27001

Key differences

DimensionApproach AApproach B
Annex A structure114 controls were arranged in 14 security domains from A.5 through A.18.93 controls are grouped into organizational, people, physical, and technological themes.
Control changesThe 2013 set used older control wording and distributed related topics across domain sections.The 2022 set adds 11 controls, merges 24, and updates 58 to reflect current technology and practices.
New topicsThreat intelligence, cloud-service security, data masking, DLP, monitoring activities, configuration management, and secure coding were not standalone controls.A.5.7, A.5.23, A.8.11, A.8.12, A.8.16, A.8.9, and A.8.28 make those topics explicit.
Control taxonomyControls were primarily navigated by domain and objective.Five attribute families—control type, information-security properties, cybersecurity concepts, operational capabilities, and security domains—support tailored views.
Clause updatesClause 6.1.3(d) framed the Statement of Applicability against Annex A controls; planning language predated harmonized amendments.Clause wording clarifies planned changes, process interactions, stakeholder communication, and comparison of controls with Annex A.
SoA impactOrganizations recorded applicability and implementation status against 114 reference controls.Organizations remap controls, justify the revised 93-control reference set, and add organization-specific controls where risk treatment requires them.
Certification status2013 certificates followed the transition window and are no longer the current certification basis.Certification and surveillance now use ISO/IEC 27001:2022, including the applicable climate-change amendment to management-system clauses.

Control overlap

The core ISMS did not disappear: context, leadership, risk assessment, treatment, competence, documented information, internal audit, management review, corrective action, and continual improvement remain recognizable. Most 2013 operating evidence still supports 2022 after remapping. For example, old A.9 access-control practices map into A.5.15–A.5.18 and technological controls; old A.12 operations topics map into controls such as /controls/iso-27001/a-8-6, /controls/iso-27001/a-8-13, and /controls/iso-27001/a-8-17. Migration requires more than renumbering: assess the 11 new controls, revised wording, changed risk context, SoA structure, attributes, and whether cloud, DLP, monitoring, or secure coding creates new evidence needs.

Sequencing advice

A SaaS team migrating an established ISMS should freeze neither engineering nor the risk program. Start with a documented 2013-to-2022 crosswalk, then update context, interested parties, risk assessment, treatment plan, and SoA. Assign owners for cloud-service governance A.5.23, configuration A.8.9, monitoring A.8.16, data leakage A.8.12, and secure coding A.8.28; collect operational evidence from cloud, CI/CD, endpoint, and SIEM systems. Update policies only where control intent changed, train affected owners, run an internal audit against the 2022 criteria, and complete management review before the certification-body visit. New applicants should implement 2022 directly rather than building a legacy 2013 control library.

Frequently Asked Questions

No. The count fell because controls were merged and reorganized, while 11 modern topics were added and many controls were rewritten. Risk treatment, evidence, and management-system requirements remain substantial.

The 11 additions cover threat intelligence, physical security monitoring, cloud services, ICT readiness for business continuity, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

Do not perform a blind number substitution. Record old-to-new mappings, assess changed intent, identify the 11 additions, revisit risk treatment, and document why each revised Annex A control is applicable or not applicable.

Existing procedures and evidence often remain usable, especially for established access, backup, incident, and supplier controls. Update mappings and close substantive gaps where the 2022 text or new controls demand different operation.

The transition period has ended, so current certification work should target ISO/IEC 27001:2022. Confirm audit scope, amendment expectations, and readiness dates directly with the accredited certification body.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above