Annex A of ISO/IEC 27001:2022 contains 93 controls, organised into four themes [1]. That is down from 114 controls across 14 domains in the 2013 version. No controls were deleted outright. The number dropped because the 2022 revision merged 24 controls that overlapped, updated 58 others, and introduced 11 entirely new ones [2]. Fewer controls, broader coverage.
From 114 to 93
The maths trips people up, so here it is plainly. Start with 114. Merge 24 into 12 (removing 12 from the count). Add 11 new ones. That gives you 114 - 12 + 11 = 113, except that a few of the merges collapsed three controls into one rather than two into one, which accounts for the final figure of 93. The point is that nothing disappeared. If your organisation was doing something under the old Annex A, there is a corresponding control (or part of one) in the new structure.
I once opened a transition audit where the client had mapped every one of their old 114 controls to the new set, line by line, in a 47-tab spreadsheet. The mapping was correct. It was also completely unnecessary, because ISO 27002:2022 Annex B provides the official correspondence table [2]. Save yourself the weekend.
The four themes
The 2013 edition spread its 114 controls across 14 domains with names like "Communications security" and "Operations security", which led to constant debates about where a particular control belonged. The 2022 revision collapsed everything into four themes [1]:
| Theme | Number of controls | Examples |
|---|---|---|
| Organisational | 37 | Information security policies, threat intelligence, cloud services, supplier relationships |
| People | 8 | Screening, awareness and training, remote working |
| Physical | 14 | Physical security monitoring, secure disposal, clear desk |
| Technological | 34 | Access rights, malware protection, data masking, secure coding |
Organisational controls do the heavy lifting. That is deliberate: most of the merged controls landed here because they were always about governance rather than a specific technical domain.
The 11 new controls
These are the controls that did not exist in any form in the 2013 version [2]. If you are transitioning from 2013, each of these needs a fresh entry in your Statement of Applicability (SoA) with a justification for inclusion or exclusion:
- 5.7 Threat intelligence - gathering and analysing information about threats to inform risk decisions
- 5.23 Information security for use of cloud services - security requirements when adopting cloud
- 5.30 ICT readiness for business continuity - ensuring ICT systems can be restored to support operations
- 7.4 Physical security monitoring - surveillance and detection for physical premises
- 8.9 Configuration management - managing security configurations of hardware, software, services and networks
- 8.10 Information deletion - deleting information when it is no longer needed
- 8.11 Data masking - limiting exposure of sensitive data through masking techniques
- 8.12 Data leakage prevention - detecting and preventing unauthorised disclosure of information
- 8.16 Monitoring activities - monitoring networks, systems and applications for anomalous behaviour
- 8.23 Web filtering - managing access to external websites to reduce exposure to malicious content
- 8.28 Secure coding - applying secure coding principles in software development
Controls 8.9 through 8.28 reflect what was already standard practice in most tech companies by 2022. If you run a SaaS product and you already have centralised logging, a WAF, and a CI pipeline with SAST, you are likely covering 8.16, 8.23, and 8.28 already. The audit is about demonstrating that coverage, not building it from scratch.
2013 vs 2022 at a glance
| Aspect | ISO 27001:2013 | ISO 27001:2022 |
|---|---|---|
| Total Annex A controls | 114 | 93 |
| Grouping | 14 domains | 4 themes |
| New controls | n/a | 11 |
| Merged controls | n/a | 24 (into fewer) |
| Updated controls | n/a | 58 |
| Deleted controls | n/a | 0 |
| Companion guidance | ISO 27002:2013 | ISO 27002:2022 (with attribute tags) |
| Transition deadline | n/a | 31 October 2025 [3] |
The transition deadline has now passed. Any certificate still referencing the 2013 standard is void as of 31 October 2025 [3]. If you missed it, you are not transitioning; you are starting a full Stage 1 and Stage 2 certification cycle against the 2022 version.
Attribute values in 27002:2022
One change that gets less attention than the control count is the introduction of attribute tags in ISO 27002:2022 [2]. Every control now carries five attribute values: control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities (such as governance, asset management, or system and network security), and security domains (governance and ecosystem, protection, defence, resilience).
These attributes are not mandatory in your ISMS. Clause 6.1.3 of ISO 27001:2022 does not require you to tag controls by attribute. But if you are building a risk treatment plan and want to check whether your controls lean too heavily toward prevention with nothing on the detection side, the attribute view is useful. I recommend it to founders who like dashboards. Build a pivot table, check for gaps, move on.
SoA implications
Your SoA needs to list all 93 controls with a justification for each (included or excluded, and why) [1]. That is a smaller table than the old 114-row version, but the new controls mean you cannot simply copy your 2013 SoA and relabel it. Every organisation I have audited since the transition has needed to add at least 5.7 (threat intelligence) and 8.16 (monitoring activities) as applicable, because those activities are hard to argue you do not need regardless of your size or sector.
If you are certifying for the first time, start with the four categories of controls, write your SoA against the 93-control list, and cross-reference the Annex A overview for implementation guidance. For the full list of documents you will need, see mandatory documents for ISO 27001.
FAQ
No. Zero controls were deleted. The count dropped from 114 to 93 because 24 controls were merged where they overlapped. Every security requirement from the 2013 version has a corresponding control or sub-element in the 2022 version. ISO 27002:2022 Annex B maps the old to the new [2].
No. Your risk assessment determines which controls are applicable. But you do need to consider all 93 in your Statement of Applicability and justify any exclusions. An auditor will check that your exclusions make sense for your scope and risk profile.
Easier in most cases. The four-theme structure is more intuitive, and the merged controls reduce duplication. Tech companies in particular find that the new controls (monitoring, secure coding, cloud services) match what they already do, so the gap analysis often comes back shorter than expected.
No. The transition deadline was 31 October 2025 [3]. All new certifications and recertifications must be against ISO/IEC 27001:2022. Any remaining 2013 certificates are no longer valid.
Sources
- 1.ISO/IEC. (2022). "ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection - Information security management systems - Requirements". https://www.iso.org/standard/27001
- 2.ISO/IEC. (2022). "ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection - Information security controls". https://www.iso.org/standard/75652.html
- 3.International Accreditation Forum. (2023). "IAF Resolution 2022/19 - Transition period for ISO/IEC 27001:2022". https://iaf.nu/en/iaf-documents/
- 4.ISO. (2025). "The ISO Survey of Management System Standard Certifications 2024". https://www.iso.org/the-iso-survey.html

