Expansión TI
Insights

ISO 27001

ISO 27001:2013 → 2022 transition: the 11 new controls

Threat intelligence, data leakage, secure coding and 8 more. What evidence to prepare before the transition audit.

Rodrigo Roncancio··7 min read

ISO/IEC 27001:2013 ceased being valid on October 31, 2025. Every organization certified under 2013 must migrate to 2022 at their next audit. The update is not cosmetic: 11 completely new Annex A controls.

Complete list with evidence needed for each below.

Structural Annex A changes

  • From 114 controls → 93 (some merged)
  • From 14 domains → 4 themes: Organizational, People, Physical, Technological
  • 11 new controls
  • Attributes per control: purpose, type, security properties, operational capabilities

The 11 new controls

A.5.7 — Threat intelligence

Formal process for collection, analysis, application of cyber threat intelligence.

A.5.23 — Information security for cloud services

Specific security policy for cloud service adoption.

A.5.30 — ICT readiness for business continuity

IT capability for business continuity beyond traditional BCP.

A.7.4 — Physical security monitoring

Continuous monitoring of physical perimeters with intrusion detection.

A.8.9 — Configuration management

Hardware/software/networks/services configuration management with secure baselines.

A.8.10 — Information deletion

Secure verifiable deletion of information at end of lifecycle.

A.8.11 — Data masking

Sensitive data masking/anonymization in non-production environments.

A.8.12 — DLP

Technical controls to prevent sensitive information leakage.

A.8.16 — Monitoring activities

Active network, system, application monitoring for anomaly detection.

A.8.23 — Web filtering

Filtering access to malicious/unauthorized websites.

A.8.28 — Secure coding

Secure development practices integrated into SDLC.

Typical transition roadmap

  1. Gap analysis (2-3 weeks)
  2. SoA update (1 week)
  3. Gap implementation (2-4 months)
  4. Internal audit (1 week)
  5. External transition audit

Total: 3-5 months for organizations with mature ISMS.

How we help

Our ISO 27001 practice includes transition support from gap analysis to external audit.

Ready for the next step?

Book a free initial consultation. We deliver a quick assessment with no strings attached.