Information security · 7 minute read

ISO 27001:2022 — What Changed and How to Transition Without Theatre

The 2022 revision reorganized Annex A. Your ISMS still has to match how people work.

ISO 27001:2022 updated the management-system clauses modestly and restructured Annex A controls (now aligned with ISO 27002:2022). Organizations certified to 2013 have a transition window they cannot ignore.

The work is not renaming controls. It is confirming that the Statement of Applicability still matches the risk assessment, and that new or re-grouped controls (threat intelligence, cloud, data masking, secure coding, ICT readiness) are evidenced if they apply.

WCH implements 2022 ISMS programs and audits both 2013 and 2022. We also add ISO 27701 when privacy is in the customer contract.

Integrated with ISO 9001, the ISMS shares leadership, internal audit, and management review so information security does not become a second bureaucracy in IT.

WCH Professional Services

Choose the firm that has never missed a certification.

Tell us the standard, the sites, and the date you need to be ready. ISO, IATF, AS9100 / IA9100 — on-site, virtual, or both, serving every U.S. state.