ISO 27001:2013 vs 2022: What Changed

ISO 27001 2013 vs 2022 controls restructure explained
ISO 27001:2013 vs 2022: What Changed | Osto

ISO 27001:2013 vs 2022: what actually changed, why 114 controls became 93, the 11 new controls that matter most, and what it means if you are certifying now.

Osto Security Team7 min readCompliance & Trust

TL;DR

The 2022 revision restructured Annex A: the 114 controls across 14 domains became 93 controls across four clean themes. Eleven entirely new controls were added, most reflecting the shift to cloud and modern development.

The management clauses (4 to 10) changed only modestly. The 2013 version is now retired, so any new certification is against ISO 27001:2022. If you certify today, you simply start on the current version.

ISO 27001:2013 vs 2022: why the update happened

The 2013 version was written for a different era of technology. Cloud had not yet become the default, modern software delivery looked different, and threats like large-scale data exfiltration were less central. The 2022 revision modernised the standard to reflect how organisations actually build and operate today, without changing its core philosophy of risk-based information security management.

The headline
The 2022 update is a modernisation, not a reinvention. The way ISO 27001 works, an ISMS driven by risk, is unchanged. What changed is the control set: fewer, better-organised controls, plus new ones for cloud and modern development.

The controls restructure

The most visible change is in Annex A. The count dropped and the structure was simplified, mostly by merging overlapping controls rather than removing protection.

The 2022 restructure
What changed in the controls
ISO 27001:2013 114 controls across 14 domains restructured ISO 27001:2022 93 controls across 4 themes, 11 new

The drop from 114 to 93 does not mean less security. Many controls were merged, several were updated, and eleven new ones were added. The old 14 domains became four clear themes: Organizational, People, Physical, and Technological.

AspectISO 27001:2013ISO 27001:2022
Number of controls11493
Structure14 domains4 themes
New controlsBaseline11 added
Focus areas addedLimited cloud coverageCloud, data leakage, secure coding
StatusRetiredCurrent standard

The 11 new controls that matter most

These additions are the clearest signal of what the update was for. For a modern SaaS company, several are likely to be highly relevant.

1

Cloud and continuity

  • Threat intelligence (5.7)
  • Cloud services (5.23)
  • ICT readiness (5.30)
2

Data and development

  • Data masking (8.11), leakage prevention (8.12)
  • Secure coding (8.28), configuration (8.9)
  • Information deletion (8.10), web filtering (8.23)

What did not change much

The management-system clauses, 4 through 10, saw only minor wording refinements. The requirements to define scope, show leadership, plan around risk, operate controls, evaluate performance, and improve remain the backbone of the standard. If you understood the 2013 clauses, the 2022 clauses will feel familiar.

What it means if you are certifying today

The practical takeaway is simple. The 2013 version has been retired, so any new certification is against ISO 27001:2022. If you are starting now, there is no transition to manage, you build directly to the current standard. The only teams who had to actively transition were those already certified under 2013, and that window has passed.

The one thing to get right
Because the new controls lean heavily toward cloud, data protection, and secure development, your certification now depends more than ever on real technical controls operating in those areas, not just documentation describing them.

The lean-team path to the 2022 standard

The 2022 additions, cloud security, configuration management, data leakage prevention, secure coding, monitoring, are precisely the areas where a modern security platform does the heavy lifting. Meeting them with scattered tools is slow; meeting them from one place is straightforward.

Certify against the current standard, the direct way.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Run the cloud, data, and development controls ISO 27001:2022 emphasises, mapped to the standard automatically. No security team required.

Book a Demo →

Frequently asked questions

What changed between ISO 27001:2013 and 2022?

Annex A was restructured: 114 controls across 14 domains became 93 controls across four themes, with 11 new controls added, mostly for cloud, data protection, and secure development. The management clauses (4 to 10) changed only slightly.

Why did the number of controls drop from 114 to 93?

Not because protection was reduced. Many overlapping controls were merged and the structure simplified into four themes, while eleven new controls were added to reflect modern cloud and development practices.

What are the 11 new controls in ISO 27001:2022?

Threat intelligence, cloud services, ICT readiness for continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.

Is ISO 27001:2013 still valid?

No. The 2013 version has been retired, and its certificates are no longer valid. Any new certification is against ISO 27001:2022, and organisations previously certified under 2013 needed to transition within the defined window, which has now passed.

If I certify now, which version do I use?

ISO 27001:2022, the current standard. Starting fresh means there is no transition to manage; you build directly to the 2022 requirements and control set.