ISO/IEC 27001:2013 ceased being valid on October 31, 2025. Every organization certified under 2013 must migrate to 2022 at their next audit. The update is not cosmetic: 11 completely new Annex A controls.
Complete list with evidence needed for each below.
Structural Annex A changes
- From 114 controls → 93 (some merged)
- From 14 domains → 4 themes: Organizational, People, Physical, Technological
- 11 new controls
- Attributes per control: purpose, type, security properties, operational capabilities
The 11 new controls
A.5.7 — Threat intelligence
Formal process for collection, analysis, application of cyber threat intelligence.
A.5.23 — Information security for cloud services
Specific security policy for cloud service adoption.
A.5.30 — ICT readiness for business continuity
IT capability for business continuity beyond traditional BCP.
A.7.4 — Physical security monitoring
Continuous monitoring of physical perimeters with intrusion detection.
A.8.9 — Configuration management
Hardware/software/networks/services configuration management with secure baselines.
A.8.10 — Information deletion
Secure verifiable deletion of information at end of lifecycle.
A.8.11 — Data masking
Sensitive data masking/anonymization in non-production environments.
A.8.12 — DLP
Technical controls to prevent sensitive information leakage.
A.8.16 — Monitoring activities
Active network, system, application monitoring for anomaly detection.
A.8.23 — Web filtering
Filtering access to malicious/unauthorized websites.
A.8.28 — Secure coding
Secure development practices integrated into SDLC.
Typical transition roadmap
- Gap analysis (2-3 weeks)
- SoA update (1 week)
- Gap implementation (2-4 months)
- Internal audit (1 week)
- External transition audit
Total: 3-5 months for organizations with mature ISMS.
How we help
Our ISO 27001 practice includes transition support from gap analysis to external audit.
