ISO/IEC 27001:2022 is the current edition of the international standard for information security management systems. Organizations holding certification under the previous 2013 edition must complete a transition audit by October 2025. The revision changes how controls are structured, adds requirements in areas including threat intelligence and cloud security, and revises governance expectations. For certified organizations, this is not an administrative update. It requires reassessment of control implementation, documentation updates, and in many cases reconfiguration of how security responsibility is assigned.

What Changed Between ISO/IEC 27001:2013 and 27001:2022

The 2022 revision reorganizes Annex A controls from 14 categories and 114 controls into four themes and 93 controls. This is not a reduction in scope. Some controls were consolidated; others were expanded. The four new themes are: Organizational controls, People controls, Physical controls, and Technological controls. Eleven controls are entirely new, covering areas that were implicit or absent in the 2013 edition.

New controls address threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23), and secure coding (8.28). Organizations already subject to regulatory requirements in healthcare, finance or critical infrastructure may have addressed some of these areas under other obligations. Others represent genuinely new ground.

The standard also changes how organizations document control applicability. The Statement of Applicability must now justify excluded controls more rigorously, and the language around risk treatment has been tightened. Certification bodies will scrutinize whether documented controls reflect actual practice, particularly in the new control areas.

The October 2025 Deadline and What Reassessment Entails

Organizations certified to ISO/IEC 27001:2013 must complete a transition audit by October 31, 2025. After this date, 2013 certificates are no longer valid. The transition is not automatic. It requires a formal audit against the 2022 standard, conducted by the organization's accredited certification body. This audit evaluates whether the information security management system meets the new control requirements and whether governance processes align with the updated standard.

Most organizations will conduct the transition as part of a scheduled surveillance or recertification audit, provided that audit falls before the deadline. If the next scheduled audit is after October 2025, or if there is insufficient time to remediate gaps identified during a routine audit, a separate transition audit must be arranged. The certification body determines audit scope and duration based on the organization's size, complexity, and the extent of changes required.

Reassessment begins with gap analysis: comparing existing controls against the 2022 requirements. This is a technical exercise requiring detailed knowledge of both the control set and the organization's current implementation. Each new control must be evaluated for applicability. If applicable, evidence of implementation must be prepared. For consolidated controls, documentation must demonstrate that all aspects of the merged requirement are addressed. The Statement of Applicability and risk treatment plan require revision to reflect these changes.

Why This Matters Beyond Certification Maintenance

Certification lapse carries contractual and reputational consequences. Many organizations hold ISO/IEC 27001 certification because customers, partners or regulators require it. Loss of certification can trigger contract renegotiation, disqualify the organization from procurement processes, or raise questions with oversight bodies. For publicly traded companies or those in regulated sectors, the lapse may require disclosure.

The revision also surfaces a question of control effectiveness. An organization may have documentation that satisfied auditors under the 2013 standard but does not reflect how security is actually managed. The new controls, particularly those related to cloud security, threat intelligence and data leakage prevention, often expose gaps between written policy and operational reality. Addressing these gaps improves security posture, but doing so under audit pressure and on a fixed timeline is inefficient.

Organizations approaching this as a documentation exercise risk a failed audit or findings that require remediation before the certificate is issued. The certification body is evaluating whether the management system functions as described. If new controls have been added to the Statement of Applicability but are not yet operational, or if existing controls have been relabeled without substantive update, the audit will identify nonconformities.

Who Owns the Transition and What Adequate Ownership Looks Like

ISO/IEC 27001 assigns ultimate accountability for the information security management system to top management. In practice, execution is often assigned to an information security manager, IT director, or compliance officer. The 2022 transition exposes the limitations of this arrangement. The person managing the certification process typically does not have authority over all the organizational changes required to address new controls. Cloud security involves procurement and vendor management. Threat intelligence requires decisions about external services and information sharing. Data leakage prevention affects application development, HR policy and acceptable use standards.

Adequate ownership means an individual with strategic visibility, cross-functional authority, and accountability to executive leadership for the outcome. This individual defines what the organization is trying to achieve with the management system, determines how new requirements map to existing processes, identifies where gaps require investment or policy change, and coordinates implementation across departments. They translate the standard's requirements into decisions, and they report progress in terms leadership can act on.

In organizations without a full-time chief information security officer, this role is often unfilled or distributed across several people without clear assignment of authority. The result is incremental progress, last-minute preparation before audits, and management systems that satisfy certification requirements without delivering the risk management and governance benefits the standard is designed to provide. The transition deadline makes this gap visible. Organizations that wait until 2025 to assign ownership will compress months of cross-functional work into weeks.

How This Relates to Regulatory and Framework Readiness

ISO/IEC 27001 is one framework among several that organizations use to demonstrate security and privacy practices. The standard does not operate in isolation. Organizations in healthcare address HIPAA Security Rule requirements. Financial services firms navigate examination authority expectations. Companies handling European personal data implement GDPR technical and organizational measures. The 2022 revision brings ISO/IEC 27001 into closer alignment with these requirements, particularly in areas like data protection, monitoring and incident response.

This creates both opportunity and complexity. Organizations can use the transition to rationalize control implementation across multiple frameworks, reducing duplication and addressing common gaps. But doing so requires understanding how requirements map to one another and where a single control can satisfy multiple obligations. This is not a task for certification consultants focused on a single standard. It requires strategic oversight of the organization's entire regulatory and contractual position.

Regulatory and framework readiness means maintaining a coherent view of what the organization is required to do, what it has chosen to do, and how those obligations are met through implemented controls. It means understanding when a new requirement changes existing practice and when it formalizes something already in place. It means preparing for audits and examinations without separate preparation cycles for each one. For organizations holding or pursuing ISO/IEC 27001 certification alongside other compliance obligations, the 2022 transition is a point at which this coordination either happens or the cost of fragmented approaches becomes clear.

Practical Next Steps for Leadership

First, confirm the organization's certification status and audit schedule. Contact the certification body to determine when the transition audit is planned. If the next scheduled audit is within six months of the October 2025 deadline, or if no audit is scheduled before that date, arrange the transition sooner. Compressed timelines limit the organization's ability to address findings before the deadline.

Second, assign executive ownership of the transition. This is not a project to delegate to the person who coordinates with auditors. It requires someone accountable for security outcomes who can make decisions about policy changes, resource allocation and competing priorities. If the organization does not have this role filled, define it explicitly and assign it with appropriate authority. The alternative is distributed responsibility, which produces documentation without accountability.

Third, conduct a structured gap analysis. Compare the organization's current Statement of Applicability and implemented controls against the 2022 Annex A control set. For each of the eleven new controls, determine applicability and document the basis for inclusion or exclusion. For consolidated controls, verify that all merged requirements are addressed. For controls where language changed materially, evaluate whether current implementation meets the updated requirement. This analysis should produce a specific list of documentation updates, control enhancements, and new implementations required before the audit.

Fourth, integrate the transition into the organization's broader framework and compliance work. If the organization is subject to other regulatory requirements, map the new ISO/IEC 27001 controls to existing obligations. Identify where a single enhancement addresses multiple requirements. Update governance documentation, including the risk register and treatment plan, to reflect the unified view. This reduces duplicated effort and improves the consistency of evidence provided to auditors and examiners.

Fifth, establish reporting that makes progress visible to executive leadership. Certification maintenance is often treated as an IT or compliance task, with leadership involved only when problems arise. The transition creates an opportunity to reposition the management system as a governance tool. Report in terms of risk decisions, control gaps that affect business operations, and alignment between documented practices and actual behavior. This shifts the conversation from certification status to security effectiveness.

For organizations where these steps reveal capacity or expertise gaps, [virtual CISO leadership](/vciso/) provides executive ownership of the information security management system and related governance work. Heights Consulting Group structures this role to include strategy, risk decisions, regulatory positioning and board reporting, in addition to certification readiness. This is not consulting advice delivered on a project basis. It is ongoing accountability for security outcomes, assigned to an individual with defined authority and reporting obligations.

If you are accountable for maintaining ISO/IEC 27001 certification and are evaluating how to approach the 2022 transition, a confidential discussion of your organization's specific circumstances may be useful. Heights offers a single consultation to organizations at a decision point. Contact information is available on the firm's website. There is no cost and no follow-up beyond what you request.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness