Discover the key changes to Annex A between 2013 and 2022 and how to integrate them without disrupting your certification.
Published on August 31, 2026 — Conformité
The 2022 version reorganizes the 114 Annex A controls into 93 controls grouped under four themes: organizational, people, physical, and technological. This simplification aims to align the standard with modern cybersecurity practices, incorporating requirements related to resilience, supplier management, and cloud security. For already certified organizations, a gap analysis is needed to identify removed, merged, or new controls and update the Statement of Applicability (SoA) accordingly.
Among the major additions are control A.5.23 on operational resilience, A.8.33 on digital asset management, and A.12.7 dedicated to cloud service security. These controls address current threats such as ransomware and data leaks in multi‑cloud environments. Implementing them often requires automated monitoring tools and stronger supplier governance, which can lead to technological and organizational investments.
Already certified companies must refresh their documentation, train staff, and revise internal audit processes to reflect the new controls. The transition period set by ISO is three years, but it is advisable to start the process as soon as possible to avoid non‑compliance during the next surveillance audit. EBH Security supports organizations in this update through targeted audits and awareness workshops.
For organizations currently pursuing certification, it is crucial to embed the 2022 controls during the ISMS design phase. A typical action plan includes: a gap analysis, updating the SoA, revising security policies, staff training, and implementing specific control measures. By taking an iterative approach, projects can meet compliance requirements while maintaining operational continuity.
Start by mapping the 114 controls from 2013, then compare them to the 93 controls from 2022, identifying matches, deletions, and additions. Use a tracking spreadsheet to document gaps, assess the associated risk level, and plan corrective actions.
ISO/IEC 27001:2022 provides a three‑year window from the standard’s publication for certified organizations to adjust their ISMS and SoA.
Yes, secure cloud management typically involves multi‑cloud visibility solutions, configuration management (CSPM), and threat detection (CWPP) tools to meet the requirements of control A.12.7.