In this guide
- Four domains instead of fourteen
- Five attributes on every control
- The eleven new controls
- 27002 guides, 27001 certifies
- How it shows up in an audit
- Missed the 31 October 2025 deadline?
- Where Singahi fits
- FAQ
- Is ISO 27002 mandatory?
- What are the 11 new controls in ISO 27002:2022?
- Is an ISO 27001:2013 certificate still valid?
- Did any controls disappear in the 2022 revision?
ISO/IEC 27002:2022 is a genuine rewrite, not a tidy-up. It reflects how security actually works now: cloud by default, faster-moving threats, and tighter regulation. The control count drops from 114 to 93, the old fourteen groups become four, and eleven controls are new.
The transition window has closed, too. ISO 27001:2013 certificates expired on 31 October 2025, so the 2022 controls are no longer a change to plan for: they are the only version an auditor will certify against. Here is what changed, what each new control asks of you, and what to do if you missed the deadline.
Four domains instead of fourteen
The control groups now map to how teams really run security:
- Organizational: direction, structure, risk and supplier relationships
- People: staff security, training and remote work
- Physical: premises, secure areas and monitoring
- Technological: systems, development, networks and monitoring
The smaller count is consolidation, not cuts. Of the 93 controls, eleven are new, 24 merge what were 57 overlapping controls in the 2013 edition, and 58 are updated. Nothing you were doing under the old standard stops mattering; it just lives in fewer, clearer places.
Five attributes on every control
Each control now carries five attributes, written as hashtag values: control type (#Preventive, #Detective, #Corrective), information security properties (#Confidentiality, #Integrity, #Availability), cybersecurity concepts (#Identify through #Recover, mirroring the NIST CSF functions), operational capabilities, and security domains.
It sounds bureaucratic and is actually the most useful practical change. The attributes work like tags: filter your Statement of Applicability by #Detective and you see at a glance where you would spot an attack in progress; filter by #Availability and you have the resilience view a continuity reviewer asks for. Our ISO 27001 toolkit works through all 93 controls one by one.
The eleven new controls
Every one of these came from real attack patterns, not committee theory.
- Threat intelligence (5.7). Collect threat data from government advisories, vendor feeds and your own incidents, then actually analyse it and feed it into risk decisions. Sharing intelligence with suppliers lines up with guidance from NCSC, ENISA and CISA. We unpack it in our A.5.7 guide.
- Information security for use of cloud services (5.23). Treat cloud as the default it now is. Build security into how you buy, onboard, run and offboard cloud services.
- ICT readiness for business continuity (5.30). Go past backups to real resilience: recovery planning, redundancy, incident simulation and recovery testing. It lines up closely with ISO 22301.
- Physical security monitoring (7.4). Watch sensitive sites for things like tailgating and hardware theft, with surveillance and procedural checks tied into your access records.
- Configuration management (8.9). Misconfigurations are among the most exploited weaknesses, so the standard now wants documented baselines, change control, automated checks and audit trails.
- Information deletion (8.10). Delete data securely once you no longer need it, using techniques like overwriting, degaussing or physical destruction, and keep it auditable. This maps to GDPR and India's DPDP Act.
- Data masking (8.11). Protect sensitive data outside production with pseudonymisation, anonymisation and field-level masking.
- Data leakage prevention (8.12). Combine tooling (DLP, encryption, egress controls) with process (classification, policy, monitoring) to reduce exposure.
- Monitoring activities (8.16). Run continuous monitoring across systems, networks and user activity, with baselines and threshold alerts.
- Web filtering (8.23). Restrict access to dangerous or unsuitable sites, with technical controls and user training, to cut phishing and drive-by malware.
- Secure coding (8.28). A dedicated control for secure development: code review, input validation, safe error handling and dependency management, drawing on OWASP's ASVS and NIST's Secure Software Development Framework. Our secure code review service maps directly to it.
27002 guides, 27001 certifies
A point that trips people up: you do not certify against ISO 27002. ISO 27001 is the certifiable standard; its Annex A lists the 93 controls, and 27002 is the companion volume explaining how to implement each one. When the 2022 edition of 27002 landed, Annex A was rewritten to match, so "the new 27002 controls" and "the new Annex A" are the same list. Your auditor reads both.
How it shows up in an audit
Each new control comes with its rationale, not just a requirement, which pushes you toward real resilience rather than box-ticking. Auditors expect the controls scoped to your actual risk, with evidence behind them, not a generic checklist applied wholesale.
Concretely, that means artefacts like these:
- Threat intelligence (5.7): named intelligence sources, analysis notes, and risk-register entries that cite them
- Configuration management (8.9): documented baselines per platform, drift alerts, and the tickets that closed them
- Monitoring activities (8.16): a monitoring standard saying what you watch and at what thresholds, with triage records showing it runs
Missed the 31 October 2025 deadline?
Certificates issued against ISO 27001:2013 stopped being valid on 31 October 2025, whatever expiry date is printed on them. If you transitioned in time, these controls are already your Annex A and this is business as usual. If you did not, there is no late-transition route: the way back is a full initial certification against the 2022 standard, Stage 1 and Stage 2 audits included.
That is more work than the transition audit would have been, but it is a known path: gap assessment against the 93 controls, remediation with evidence as you go, then the certification audit. Budget roughly three to six months depending on how far your 2013-era ISMS has drifted.
Where Singahi fits
We run ISO 27001 and ISO 27002 work end to end, from the gap assessment through the controls and evidence to audit support. If your certificate lapsed with the deadline, we scope the recertification honestly and get you back under it without repeating work you have already done. Book an ISO 27001:2022 gap assessment, or see our ISO 27001 service.
FAQ
Is ISO 27002 mandatory?
No. ISO 27002 is guidance and nobody certifies against it. Certification is against ISO 27001, whose Annex A contains the same 93 controls that 27002 explains in implementation detail.
What are the 11 new controls in ISO 27002:2022?
Threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28).
Is an ISO 27001:2013 certificate still valid?
No. The transition period ended on 31 October 2025 and 2013 certificates are no longer valid, regardless of the printed expiry date. Getting certified again means a full Stage 1 and Stage 2 audit against ISO 27001:2022.
Did any controls disappear in the 2022 revision?
No control was simply dropped. The count fell from 114 to 93 because 57 controls were merged into 24; the rest were updated or carried over with new numbering, and eleven were added.
