The 2022 revision restructured the control set and added eleven controls, but left the management system clauses largely intact. That shapes the whole transition: most of your ISMS carries over unchanged, and the work concentrates in Annex A and the documents that reference it.
What changed
- Annex A restructured from 114 controls in 14 domains to 93 in 4 themes — organisational, people, physical, technological. Most of the reduction is merging, not removal.
- Eleven new controls, reflecting cloud adoption, detection over pure prevention, and software development practice.
- Control attributes added as an optional filtering aid — not a requirement, and no auditor will ask for them.
- Clause changes are minor, with some clarification around planning and objectives.
The eleven new controls
Threat intelligence; information security for cloud services; ICT readiness for business continuity; physical security monitoring; configuration management; information deletion; data masking; data leakage prevention; monitoring activities; web filtering; secure coding.
Start your gap analysis here. Existing certified organisations almost always find real gaps in threat intelligence (feeds consumed but no process to act on them), cloud service exit arrangements, and configuration management.
Run the transition gap analysis in hours
GRC Copilot scores you against the 2022 control set, shows exactly which of the new controls you are missing, and regenerates your Statement of Applicability.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
What the transition requires
- Gap assess against the new Annex A, concentrating on the eleven new controls.
- Rewrite the Statement of Applicability against the new numbering. This is unavoidable and is the largest documentation task.
- Revisit risk treatment where new controls address risks you had accepted — a new control may change a decision you documented years ago.
- Update cross-references in policies and procedures that cite old control numbers.
- Implement and evidence the new controls, allowing time for records to accumulate.
- Internal audit against the new version before the transition audit.
- Management review covering the transition.
What does not need to change
Your scope, risk methodology, management system processes, and the substance of most controls carry over. Resist the temptation to rebuild — a transition is a remapping exercise, not a re-implementation, and treating it as the latter is how organisations spend three times what they need to.
How the transition audit works
Transition is normally handled at a scheduled surveillance or recertification visit rather than as a separate engagement, which is considerably cheaper. Talk to your certification body early about which visit will carry it and how much extra time they need.
Transition periods are finite: miss the deadline and certification to the old version lapses. If you have not started, that timing is the first thing to confirm.
Frequently asked questions
How much work is it really?
For a well-run ISMS, modest — the SoA rewrite plus implementing whichever of the eleven new controls you lack. For a paper-only ISMS, it surfaces everything that was never real.
Do we have to use the control attributes?
No. They are optional and useful mainly for producing management views of the control set.
Can we transition at a surveillance audit?
Usually yes, and it is the cheapest route. Confirm with your certification body and book the extra time.
What happens if we miss the deadline?
Certification against the withdrawn version lapses. Confirm your specific deadline with your certification body now rather than assuming.
Key takeaways
- Clauses barely changed; the work is in Annex A and the SoA.
- Start the gap analysis at the eleven new controls.
- Revisit risk acceptances that a new control now addresses.
- Transition at a scheduled visit, and confirm your deadline early.