Don’t do SECURITY. Do business SECURELY.

ISO/IEC 27001:2022 published

The third edition of ISO/IEC 27001 has been published, with Annex A aligned to ISO/IEC 27002:2022 and a three-year transition period.

ISO has published ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection – Information security management systems – Requirements.

Key changes

  • Annex A is replaced to align with ISO/IEC 27002:2022: 93 controls in four themes, including 11 new controls.
  • Minor changes to the management system clauses, including a new clause 6.3 on planning of changes and clarification that processes needed for the ISMS must be determined.
  • Greater emphasis on monitoring, and on the needs of interested parties being addressed through the ISMS.

Transition: certified organisations have until 31 October 2025 to transition, and certification bodies will stop issuing certificates against the 2013 edition before then. Start with a gap analysis, then update your risk treatment, Statement of Applicability and supporting procedures.

Source: ISO/IEC 27001:2022 (ISO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights