Back to Columns
ISMS & Certification12 min read

ISO/IEC 27001:2022 — What Changed from the 2013 Edition

September 14, 2026

ISO/IEC 27001:2022 — What Changed from the 2013 Edition
Share this article

The 2022 edition of ISO/IEC 27001 has been published, and the Japanese edition, JIS Q 27001:2023, was issued on 20 September 2023. The transition deadline from the 2013 edition was 31 October 2025 and has passed. For any organisation certifying now, there is only one target: the 2022 edition.

So why does the difference still matter? Because material written against the old edition is still everywhere. Legacy internal procedures, books on the shelf, articles ranking well in search, questions on security check sheets sent by customers, excerpts of other companies' Statements of Applicability — these are frequently written in 2013-edition control numbers and fourteen-category vocabulary.

Build your documents from a source you did not realise was outdated, and you end up citing control references that no longer exist, or mixing four themes with fourteen categories in the same document. This article sets out the differences so that does not happen.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

Where Things Stand

DateEvent
2013ISO/IEC 27001:2013 published (Japanese edition JIS Q 27001:2014)
2022ISO/IEC 27001:2022 published
20 September 2023JIS Q 27001:2023 published — the Japanese 2022 edition
31 October 2025Transition deadline from the 2013 edition. Passed
NowNew certifications and recertifications alike target the 2022 edition

Three practical consequences:

  1. If you are considering certification: build against the 2022 edition from the start. There is no reason to consult the 2013 edition
  2. If you already hold certification: transition is complete. Surveillance and recertification audits run against the 2022 edition
  3. In either case: check whether the reference material in your hands predates the change

See What Is an ISMS for the overview.

Annex A Restructured: 114 to 93

The largest change is Annex A. The 114 controls of the 2013 edition became 93 in 2022, described as:

CategoryCountDescription
Updated58Carried over with revised wording and scope
Merged24Several former controls consolidated into one
New11Added in the 2022 edition
Total93

The reduction does not mean the requirements got lighter. Overlapping controls were consolidated, and modern concerns (cloud, threat intelligence, data leakage prevention) were added. The practical workload is, if anything, larger by the eleven new controls.

The eleven new controls

ReferenceControlWhat it means in practice
A.5.7Threat intelligenceCollect and analyse threat information relevant to you and feed it into your controls
A.5.23Information security for use of cloud servicesDefine a process and security requirements covering selection, use, and exit
A.5.30ICT readiness for business continuityMake ICT recovery objectives and means concrete within the BCP
A.7.4Physical security monitoringWhere you hold facilities, consider continuous monitoring via cameras and sensors
A.8.9Configuration managementDefine hardware, software, and service configurations and control changes to them
A.8.10Information deletionDelete information no longer needed — paired with defined retention periods
A.8.11Data maskingMask or pseudonymise production data used in development and testing
A.8.12Data leakage preventionDetect and prevent exfiltration of sensitive information
A.8.16Monitoring activitiesMonitor networks, systems, and applications for anomalies
A.8.23Web filteringRestrict access to malicious sites
A.8.28Secure codingApply secure coding principles where development occurs

Six of the eleven are technological controls (A.8). For healthcare SaaS companies that build and run their own product, that is where the real additional work sits. See Annex A 2022: 93 Controls Across Four Themes and Reading the 34 Technological Controls.

Fourteen Categories Become Four Themes

The 2013 Annex A ran from A.5 to A.18 — fourteen categories. The 2022 edition restructures them into four themes.

2013 category (A.5–A.18)Where it mainly lands in 2022
A.5 Information security policiesOrganizational (A.5)
A.6 Organization of information securityOrganizational (A.5) / People (A.6)
A.7 Human resource securityPeople (A.6)
A.8 Asset managementOrganizational (A.5) / Technological (A.8)
A.9 Access controlOrganizational (A.5) / Technological (A.8)
A.10 CryptographyTechnological (A.8)
A.11 Physical and environmental securityPhysical (A.7)
A.12 Operations securityTechnological (A.8)
A.13 Communications securityTechnological (A.8)
A.14 System acquisition, development and maintenanceTechnological (A.8)
A.15 Supplier relationshipsOrganizational (A.5)
A.16 Information security incident managementOrganizational (A.5)
A.17 Information security aspects of business continuityOrganizational (A.5)
A.18 ComplianceOrganizational (A.5)

The 2022 structure:

ThemeReferenceControls
OrganizationalA.537
PeopleA.68
PhysicalA.714
TechnologicalA.834

This is where reference collisions cause accidents. "A.8" meant asset management in 2013 and means technological controls in 2022. "A.9 Access control" does not exist in the 2022 edition at all. When reading older material, confirm the edition before quoting any reference.

The table above gives approximate destinations only. Because controls were merged and split, many do not map one to one; consult the correspondence tables in the standard itself for precision.

Attributes

The 2022 Annex A assigns attributes to each control, so controls can be viewed across several dimensions.

AttributeExample values
Control typePreventive / detective / corrective
Information security propertiesConfidentiality / integrity / availability
Cybersecurity conceptsIdentify / protect / detect / respond / recover
Operational capabilitiesGovernance, asset management, information protection, human resource security, physical security, system and network security, and others
Security domainsGovernance and ecosystem / protection / defence / resilience

Crucially, using attributes is optional. There is no obligation to add attribute columns to the SoA, and not using them does not affect conformity.

They are worth using when you want to:

  • Expose thin detection coverage — classifying by control type reveals a portfolio skewed towards prevention
  • Explain coverage to executives across confidentiality, integrity, and availability
  • Map to other frameworks — the identify/protect/detect/respond/recover axis connects readily

For a first certification with limited capacity, skipping attributes is reasonable. See How to Write a Statement of Applicability.

Changes in the Main Text (Clauses 4–10)

Smaller than the Annex A restructure, but a few points require documents or processes to be rebuilt.

ClauseMain changePractical impact
4 ContextClarified that you determine which interested-party requirements will be addressed through the ISMS; determining the processes needed for the ISMS and their interactions is made explicitThe interested-parties register needs a column for "addressed via the ISMS?"
5 LeadershipNo substantive change
6 PlanningWording reorganised so that controls determined for risk treatment are compared against Annex A to verify nothing necessary was omitted; objectives must be monitored, communicated, and documented; 6.3 planning of changes is newThe SoA is built risk → controls → Annex A verification. A procedure for planned ISMS changes is needed
7 SupportNo substantive change (communication requirements tidied)
8 OperationClarified establishment of process criteria and control to those criteria, control of planned changes and review of unintended changes, and control of externally provided processes, products and servicesChange records become effectively mandatory
9 Performance evaluation9.2 and 9.3 subdivided; "changes in needs and expectations of interested parties" added explicitly to management review inputsAdd a field to the minutes template
10 ImprovementOrder swapped: 10.1 continual improvement, 10.2 nonconformity and corrective actionUpdate cross-references inside your documents

Clause-by-clause detail: Clause 4: Context, Clause 5: Leadership, Clause 6: Planning, Clause 7: Support, Clause 8: Operation, Clause 9: Performance Evaluation, Clause 10: Improvement.

Reading Old-Edition Material Safely

SituationWhat goes wrongWhat to do
Legacy internal proceduresReferences like "in accordance with A.12 Operations security" buried in the textFull-text search the references and replace with 2022 numbering; update theme names too
Books and web articlesChapter structure built on fourteen categories; old numberingCheck publication date and target edition. Treat anything before October 2022 as old-edition
Another company's SoA as a modelA 114-row format with old referencesUse the structure as a model; do not reuse the numbers
A customer's check sheet follows the old editionQuestions like "regarding access control under A.9…"Map to the 2022 control and answer — and state in your response that you did so
Checking a supplier's certificateThe certificate cites the old standardCertificates citing the old edition may still look current; verify the edition and the expiry date
Reusing an old risk assessmentControl column carries old referencesReuse the risk content, but rebuild the control linkage

The fourth row deserves particular care. Security check sheets sent by customers are often reused without updating. Answering in old numbering leaves your response inconsistent with your own documents; a single line noting the mapping saves later queries. See Security Check Sheets for Vendors.

New Controls That Bite Hardest in Healthcare

A.5.23 Information security for use of cloud services

Putting medical information in the cloud means defining selection criteria, contractual security requirements, the responsibility split, and data return and deletion on exit. This overlaps with what Japan's three-ministry guidelines require of cloud use, so covering both in one procedure is efficient. See Cloud Security for Medical Institutions and Shared Responsibility in AI EMR Security Design.

A.8.10 Information deletion / A.8.11 Data masking

Retention periods for medical information and reliable deletion afterwards map directly onto these two. And copying production medical data into development or test environments is the textbook practice that A.8.11 forces you to revisit. Defining pseudonymisation and masking procedures lets you comply without slowing development.

A.8.16 Monitoring activities

Medical information systems need more than log collection — they need anomaly detection. The question is not only whether you record who viewed what and when, but whether you detect access patterns that differ from normal. See Reviewing EMR Access Logs.

A.8.28 Secure coding

If you build healthcare products yourself, this brings coding standards, review, static analysis, and dependency management into scope. See Security by Design for Medical Systems.

All four are demanded by both the guidelines and the ISMS. See Integrating ISMS Documents with the Three-Ministry Guidelines and Japan's Three-Ministry Guidelines.

Conclusion

  1. The transition deadline (31 October 2025) has passed. New certifications and recertifications alike target the 2022 edition; migration is no longer a live topic
  2. The diff still matters because internal documents, books, web articles, and customer check sheets written against the old edition remain in circulation
  3. Annex A went from 114 to 93: 58 updated, 24 merged, 11 new. The count fell through consolidation, not relaxation
  4. Fourteen categories became four themes (organizational 37, people 8, physical 14, technological 34). Old A.8 and A.9 mean different things now — always confirm the edition before citing a reference
  5. Attributes are optional. No obligation to add them to the SoA; useful for exposing weak detection coverage
  6. In the main text, new 6.3 planning of changes, clarified change control in 8.1, the added management review input in 9.3, and the reordering of clause 10 are what affect practice
  7. Six of the eleven new controls are technological. In healthcare, A.5.23 cloud, A.8.10 deletion, A.8.11 masking, A.8.16 monitoring, and A.8.28 secure coding carry the most weight

Pottech supports ISMS certification with a focus on healthcare. Our procedure, register, and training templates are built on the 2022 edition, so you do not start by translating old-edition material. We also work through which of the eleven new controls genuinely apply to you.

See ISMS Certification Support for scope and pricing, or contact us if you want a view on whether your existing documents align with the 2022 edition.

References and Sources

Note: for the exact correspondence of merged and split controls, consult the mapping tables included in the standard. The formal handling of the transition is governed by the publications of the accreditation and certification bodies.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.