Report an Incident
ComplianceGlobal2025-07-308 min read

ISO 27001:2022 Annex A Controls: What Changed and How to Map Your Existing ISMS

By XYBERU Compliance Practice

A structured comparison of the 2013 vs 2022 control sets, with a practical mapping approach for transition planning.

What actually changed in 2022

The headline change: 114 controls across 14 domains became 93 controls in 4 themes (organizational, people, physical, technological), with 11 genuinely new controls covering threat intelligence, cloud service security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Nothing was deleted outright — 57 controls merged and 23 were renamed.

The transition is a mapping exercise, not a rebuild

A functioning 2013-era ISMS carries forward substantially intact. The efficient path is a control-by-control mapping: identify where your existing controls satisfy merged 2022 equivalents, gap-assess only the 11 new controls, and update the Statement of Applicability and risk treatment plan to the new structure. Organizations that treated the transition as a fresh implementation spent triple the effort for the same certificate.

Where auditors are focusing

Certification bodies have converged on the new controls with teeth: threat intelligence (5.7) expects an actual feed-to-action process, not a subscription receipt; cloud services (5.23) expects lifecycle governance from onboarding through exit; data leakage prevention (8.12) expects risk-based scoping with evidence of tuning. Attribute-based thinking — the 2022 annex tags every control with attributes like control type and security domain — also gives auditors a new lens for probing coverage claims.

Using the transition strategically

The restructure is a rare license to prune. Controls implemented in 2015 for risks that no longer exist, documentation nobody reads, metrics nobody actions — the SoA update is the natural moment to retire them with documented justification. A leaner ISMS that people actually operate outperforms a comprehensive one they route around.

Talk to the team behind this research
Map your 2013-era ISMS to the 2022 control set with a realistic transition plan.
Start Your Certification Roadmap