CAI Technology
Menu ☰
lexnomia · · 14 min read

ISO/IEC 27001:2022 — migrating from the 2013 edition with the 93 controls reorganised into 4 themes

ISO 27001:2013 → 2022 changes: from 114 to 93 controls, the 11 new controls, reorganisation into 4 themes, and a concrete migration path for already certified organisations.

CAI Technology · Last reviewed: 4/30/2026
ISO/IEC 27001:2022 — migrating from the 2013 edition with the 93 controls reorganised into 4 themes

ISO/IEC 27001:2022 — migrating from the 2013 edition with the 93 controls reorganised into 4 themes

ISO/IEC 27001 was updated in October 2022, nine years after the previous edition. The most visible change: the number of controls in Annex A dropped from 114 to 93, and the 14 categories from the 2013 edition were reorganised into 4 themes. For already certified organisations, the IAF transition window closed on 31 October 2025 — all certification bodies began auditing exclusively on the 2022 edition from 1 November 2025.

This article explains the key changes and offers a practical migration path for an existing ISMS.

TL;DR

Main changes versus 2013

Number of controls. 114 → 93. The reduction comes from merging similar controls (e.g. security policies were grouped into a single control 5.1) and retiring controls no longer relevant in modern context (e.g. certain controls related to fax and printed media).

Reorganisation by themes. The 14 categories from 2013 were simplified into 4 themes:

  1. A.5 Organisational (37 controls) — policies, roles, supplier management, incident management.
  2. A.6 People (8 controls) — screening, training, termination, NDAs, remote work.
  3. A.7 Physical (14 controls) — perimeter, physical access, equipment.
  4. A.8 Technological (34 controls) — endpoint, network, cryptography, software development, monitoring, backup.

Control attributes. The 2022 edition introduces an attribute system that allows filtering/reporting of controls along 5 dimensions:

Attributes are optional but extremely useful for organisations using multiple frameworks (NIST CSF, SOC 2, NIS2). They enable rapid cross-mapping.

Clause 4-10 requirements. Minor changes, mainly to align with Annex SL (the common structure for ISO management systems). Notably: new clause 6.3 on “planning of changes” and extended requirements on organisational context.

The 11 new controls in 2022

ControlNameWhat you must prove
5.7Threat intelligenceThreat intel collection and analysis processes; application in operational decisions.
5.23Information security for use of cloud servicesFormal cloud risk assessment processes, CSP contracts, exit plan.
5.30ICT readiness for business continuityAnnually tested IT-DR plan, multiple scenarios, documented RTO/RPO.
7.4Physical security monitoringCCTV, alarms, continuous monitoring of critical physical perimeter.
8.9Configuration managementApproved configuration baselines, drift detection, remedial action.
8.10Information deletionRetention-aligned deletion policies, proof of execution at EOL.
8.11Data maskingMasking techniques for sensitive data in non-production.
8.12Data leakage preventionDLP at endpoint, network, cloud; classification supported.
8.16Monitoring activitiesActive logging on systems, networks, applications; SIEM integration.
8.23Web filteringURL/category filtering for endpoint and gateway.
8.28Secure codingWritten standards (OWASP Top 10, SAMM), dev training, code review.

For organisations already operating at medium maturity, many of these controls were implemented de facto. With ISO 27001:2022 they become formalised and explicitly audited.

6-month migration path — checklist

Month 1 — gap analysis:

Month 2 — document update:

Month 3 — new control implementation:

Month 4 — internal audit & management review:

Month 5 — preparing the transition audit:

Month 6 — transition audit:

Requirements for organisations in regulated industries

For entities operating in regulated sectors, ISO 27001:2022 substantially covers the technical requirements of other frameworks. Typical cross-mapping:

The practical benefit: with a mature 27001:2022 ISMS, audits on other frameworks become a derivative. Roughly 70-80% of evidence is reused.

How Lexnomia helps

Lexnomia includes an ISO 27001:2022 module that:

See also our article on the US GRC stack alternative for strategic context.

Next steps

For an ISO 27001:2022 readiness assessment and transition plan, the Lexnomia page holds the ISO module. Or write to contact for a technical discussion.

References

We start with a 30-minute conversation.

Free AI-readiness audit for companies with 50+ employees. We reply within 24 hours.