Skip to content

What changed in ISO 27001:2022 Annex A

By Sam Rivera, Founder, SentinelPanda · April 28, 2026 · 3 min read · ISO 27001

The 2022 revision is structural, not philosophical. Most of the old controls survived under new numbers; the change is in the grouping and the 11 controls that did not exist before.

114 (2013) — became — 93 (2022) Four themes 37controlsOrganisationalpolicy, vendors,cloud, BC8controlsPeoplescreening, training,agreements14controlsPhysicalfacilities, equipment,monitoring34controlsTechnologicalaccess, crypto,logging, code
Annex A 2022 collapses the 14 original domains into four themes. Bar height shows relative control count.

From 14 domains to 4 themes

ISO 27001:2013 grouped its 114 Annex A controls into 14 domains (A.5 through A.18). The 2022 revision flattens this to four themes: organisational (A.5), people (A.6), physical (A.7), and technological (A.8). The flatter structure is easier to teach, easier to map across other frameworks, and easier to assign owners against — most modern programs already think in terms of people, process, technology, and governance.

Fewer controls, but mostly through consolidation

The 114-to-93 reduction is mostly bookkeeping: controls that overlapped or addressed the same risk under different domain headings were merged. The substantive coverage of the standard did not shrink. For most programs, every 2013 control still has a clear 2022 home; the work is in remapping evidence and policy references, not in rewriting controls.

The official mapping from ISO/IEC published with the revision is the authoritative reference, and most ISMS tooling — including SentinelPanda — applies it automatically when you move a workspace from a 2013 baseline to 2022.

The 11 new controls

  • <strong>A.5.7 Threat intelligence</strong> — formalises the use of threat intel to inform controls and risk.
  • <strong>A.5.23 Information security for use of cloud services</strong> — explicit cloud-service security, separate from generic supplier controls.
  • <strong>A.5.30 ICT readiness for business continuity</strong> — recovery objectives and capacity for ICT specifically, alongside the broader BCM requirement.
  • <strong>A.7.4 Physical security monitoring</strong> — monitoring of physical premises (CCTV, alarm, access logs) as an explicit control.
  • <strong>A.8.9 Configuration management</strong> — secure baselines, hardening, and drift detection.
  • <strong>A.8.10 Information deletion</strong> — defined deletion across the data lifecycle, including from backups and third parties.
  • <strong>A.8.11 Data masking</strong> — pseudonymisation and masking where the full data is not needed.
  • <strong>A.8.12 Data leakage prevention</strong> — DLP measures across endpoints, network, and cloud.
  • <strong>A.8.16 Monitoring activities</strong> — explicit monitoring of networks, systems, and applications for anomalous behaviour.
  • <strong>A.8.23 Web filtering</strong> — controls on access to external web content from corporate networks and devices.
  • <strong>A.8.28 Secure coding</strong> — secure development principles, training, and tooling across the SDLC.

Control attributes

Annex A also gained five attribute axes that let you slice the control catalogue: control type (preventive / detective / corrective), information security properties (CIA), cybersecurity concepts (NIST CSF mapping), operational capabilities, and security domains. These are optional but useful for reporting and for cross-framework mapping.

In practice the attribute most teams rely on is the NIST CSF mapping — it is a free cross-walk to the most widely-used US framework and makes a SOC 2 / NIST conversation easier to navigate.

Migration timing

Certifications issued against the 2013 version are valid through their normal three-year cycle. Most certification bodies require migration to 2022 at the next surveillance or recertification audit; a small number have been more flexible. Confirm directly with your CB rather than relying on community guidance — the timing varied by region.

If you are starting fresh, start on 2022. There is no reason to take a new certification against the 2013 version.

What to do this quarter

  • Pull the official 2013 → 2022 mapping and re-map your existing SoA.
  • Decide applicability for each of the 11 new controls and document the justification on the SoA.
  • Update policies, evidence references, and internal audit checklists to the new numbering.
  • Brief your auditor on the migration plan before fieldwork — surprises here are expensive.
ISO 27001 Statement of Applicability Cross-framework control mapping

Run your compliance program in one workspace.