Suspect a breach? Report it immediately — response within 1 hour.Report an incident

ISO/IEC 27001:2022 The New Annex A Controls and Their Implications

Discover the key changes to Annex A between 2013 and 2022 and how to integrate them without disrupting your certification.

Published on August 31, 2026Conformité

A Structured Overhaul of Annex A

The 2022 version reorganizes the 114 Annex A controls into 93 controls grouped under four themes: organizational, people, physical, and technological. This simplification aims to align the standard with modern cybersecurity practices, incorporating requirements related to resilience, supplier management, and cloud security. For already certified organizations, a gap analysis is needed to identify removed, merged, or new controls and update the Statement of Applicability (SoA) accordingly.

New Priority Controls

Among the major additions are control A.5.23 on operational resilience, A.8.33 on digital asset management, and A.12.7 dedicated to cloud service security. These controls address current threats such as ransomware and data leaks in multi‑cloud environments. Implementing them often requires automated monitoring tools and stronger supplier governance, which can lead to technological and organizational investments.

Impact on Certified Organizations

Already certified companies must refresh their documentation, train staff, and revise internal audit processes to reflect the new controls. The transition period set by ISO is three years, but it is advisable to start the process as soon as possible to avoid non‑compliance during the next surveillance audit. EBH Security supports organizations in this update through targeted audits and awareness workshops.

Action Plan for Certification Projects

For organizations currently pursuing certification, it is crucial to embed the 2022 controls during the ISMS design phase. A typical action plan includes: a gap analysis, updating the SoA, revising security policies, staff training, and implementing specific control measures. By taking an iterative approach, projects can meet compliance requirements while maintaining operational continuity.

FAQ

How do you conduct a gap analysis between the 2013 and 2022 versions?

Start by mapping the 114 controls from 2013, then compare them to the 93 controls from 2022, identifying matches, deletions, and additions. Use a tracking spreadsheet to document gaps, assess the associated risk level, and plan corrective actions.

What is the official deadline for achieving compliance with the 2022 version?

ISO/IEC 27001:2022 provides a three‑year window from the standard’s publication for certified organizations to adjust their ISMS and SoA.

Do the new cloud controls require specific tools?

Yes, secure cloud management typically involves multi‑cloud visibility solutions, configuration management (CSPM), and threat detection (CWPP) tools to meet the requirements of control A.12.7.