2022 edition in force

ISO 27001

ISO/IEC 27001:2022 Information Security

The 2022 edition reorganized Annex A around four themes and 93 controls, including 11 new controls aimed at current information-security practice. New and continuing certifications are to ISO/IEC 27001:2022.

When it changed — or when it will

ISO/IEC 27001:2022 was published on 25 October 2022. The IAF three-year transition from the 2013 edition closed on 31 October 2025. Certificates to ISO/IEC 27001:2013 are no longer valid.

Current edition: ISO/IEC 27001:2022. Incoming edition: ISO/IEC 27001:2022.

When certification to the new edition is required

31 October 2025 was the last date 2013-edition certificates remained recognized. Organizations that did not complete a transition audit by that date generally need a full initial certification (Stage 1 and Stage 2) to the 2022 edition rather than a transition audit. Confirm any residual options with your certification body.

How the standard is changing

  • Annex A moved from 14 domains to four themes: organizational, people, physical, and technological controls.
  • 93 controls in total, including 11 new controls such as threat intelligence, cloud services, ICT readiness for business continuity, and secure coding.
  • The Statement of Applicability, risk treatment plan, and control implementation must match the 2022 Annex A set.
  • ISO 27701 remains available as a privacy extension when contracts require it.

Transitioning

If you already hold ISO/IEC 27001:2022, the work now is sustaining the ISMS — internal audit, risk review, and control operation. If a 2013 certificate lapsed, the path back is initial certification to 2022, not a closed transition process.

Timing that fits the organization

Organizations that moved during the 2022–2025 window are on the current edition. Organizations still operating a 2013-style ISMS should treat 2022 implementation as current-state certification work. There is no remaining official choice to stay on 2013.

Free planning tool

ISO/IEC 27001:2022 Readiness Assessment Checklist

A readiness checklist for organizations that hold — or still need — ISO/IEC 27001:2022 after the 2013 edition ceased to be recognized.

Complete the Readiness Assessment Request to open the checklist. It is free. Print it or work it on screen before you schedule a gap analysis.

How WCH can help

Advice, gap analysis, support, and internal audit.

Advice

A straight assessment of whether you are on a valid 2022 certificate, need a transition-style upgrade of the ISMS, or need a full initial certification.

Gap analysis

A 2022-edition gap including Annex A, the Statement of Applicability, and evidence of control operation.

Support

ISMS scope, risk assessment, SoA, and control implementation written so the team can run them after certification.

Internal audit

ISO 27001:2022 internal audits before Stage 1 / Stage 2 or as the ongoing internal audit program.

WCH Professional Services

Set the ISO 27001 transition on a date you control.

Request a quote online or call (570) 350‑9256. Tell us the sites and the next audit date. WCH will recommend a pace that matches your certificate cycle.