What changed in the ISO 27001:2022 Annex A controls?

Last verified 2026-08-19 · UK focus

Short answer

ISO/IEC 27001:2022 reduced Annex A from 114 controls in 14 domains to 93 controls in 4 themes: Organisational, People, Physical and Technological. Fifty-seven controls were merged into 24, one was split, 58 were renamed or updated, and 11 controls were added — including threat intelligence, cloud services security, data masking and secure coding. No control was removed outright.

Key facts

  • 114 controls in 14 clauses became 93 controls in 4 themes.
  • 11 new controls; 57 merged into 24; 0 deleted.
  • Controls now carry attributes (control type, security property, cybersecurity concept, operational capability, security domain).
  • The transition deadline for 2013-certified organisations was 31 October 2025.

The 11 new controls introduced in ISO/IEC 27001:2022 Annex A

The 11 new controls introduced in ISO/IEC 27001:2022 Annex A
ControlTitleTheme
A.5.7Threat intelligenceOrganisational
A.5.23Information security for use of cloud servicesOrganisational
A.5.30ICT readiness for business continuityOrganisational
A.7.4Physical security monitoringPhysical
A.8.9Configuration managementTechnological
A.8.10Information deletionTechnological
A.8.11Data maskingTechnological
A.8.12Data leakage preventionTechnological
A.8.16Monitoring activitiesTechnological
A.8.23Web filteringTechnological
A.8.28Secure codingTechnological

Caveats

  • Annex A controls remain a reference set — you select controls from your risk treatment, then justify inclusion or exclusion in the Statement of Applicability.
  • The clause 4-10 management system requirements changed only marginally; the headline change is Annex A restructuring.

Sources

  1. ISO/IEC 27001:2022 Annex A. International Organization for Standardization, 2022-10-25.
  2. ISO/IEC 27002:2022 Information security controls. International Organization for Standardization, 2022-02-15.
  3. IAF MD 26: Transition requirements for ISO/IEC 27001:2022. International Accreditation Forum, 2023-04-25.

Check your own position

Run the free ISO 27001 gap analysis for an instant score against clauses 4-10 and Annex A, then manage risks, controls, owners and evidence in one workspace.

Related