Published 21 May 2026 · Dravincon Security Team
ISO/IEC 27001:2022 replaced the 2013 edition, and the transition period for existing certificates ended on 31 October 2025. Annex A was reorganised from 114 controls in 14 domains into 93 controls in four themes.
The four themes
- Organisational (37): policies, roles, supplier relationships, incident management, compliance.
- People (8): screening, awareness, remote working, reporting events.
- Physical (14): perimeters, equipment, clear desk, secure disposal.
- Technological (34): access, cryptography, logging, secure development, backups.
The 11 new controls
Threat intelligence · Information security for cloud services · ICT readiness for business continuity · Physical security monitoring · Configuration management · Information deletion · Data masking · Data leakage prevention · Monitoring activities · Web filtering · Secure coding.
What auditors look for
- Evidence over documents. A beautiful policy without access-review records is a finding.
- A living risk assessment. Risks that reflect your business, owners who know they own them.
- A justified Statement of Applicability. Every excluded control needs a reason.
- Management involvement. Management reviews with real decisions, minuted.
We have taken organisations — including a global data-centre provider — through this exact transition. See how we work.