Verigo Global
//Article
ISO 27001April 17, 20266 min read

Why ISO 27001:2022's Four-Theme Annex A Changes Your Implementation Approach

Moving from 114 controls across 14 domains to 93 controls across four themes changes more than the numbering.

Key takeaways
1

ISO 27001:2022 restructured Annex A from 114 controls across 14 domains to 93 controls across four themes: Organizational, People, Physical, and Technological.

2

11 new controls were added, including threat intelligence, ICT readiness for business continuity, and data leakage prevention.

3

The SoA must be rebuilt against the new Annex A structure — and the 11 new controls must be assessed for applicability even if excluded.

What actually changed

The ISO/IEC 27001:2022 revision replaced the 2013 Annex A entirely. The old standard had 114 controls organized across 14 domains (A.5 through A.18). The new standard has 93 controls organized across four themes: Organizational (37 controls), People (8), Physical (14), and Technological (34). The restructuring consolidated 24 pairs of controls that were essentially duplicates and reorganized the remaining controls to better reflect modern operational realities — cloud services, threat intelligence, and supply chain security now have explicit controls where they were previously implicit or absent.

For organizations currently certified against the 2013 standard, the transition deadline was October 2025 — all certificates should now reference the 2022 edition. For organizations starting their journey, the 2022 standard is the only target.

The 11 new controls

The most significant addition is a set of 11 controls that did not exist in the 2013 standard. These cover areas that have become operationally critical in the intervening decade: threat intelligence (A.5.7), ICT readiness for business continuity (A.5.30), data leakage prevention (A.8.12), data masking (A.8.11), web filtering (A.8.23), configuration management (A.8.9), monitoring activities (A.8.16), information security for cloud services (A.5.23), and physical security monitoring (A.7.4), among others.

These are not aspirational additions — they reflect practices that well-run ISMS programs were already implementing informally. The 2022 revision makes them explicit requirements that must be addressed in the Statement of Applicability and either implemented or excluded with a documented justification.

What this means for the SoA

The Statement of Applicability (SoA) is the instrument that connects the risk treatment plan to the Annex A controls. For the 2022 standard, the SoA must reference all 93 controls and document each as applicable or not applicable, with a justification for any exclusion. If you are updating an existing ISMS from the 2013 standard, you cannot simply remap old controls to new ones — the SoA must be rebuilt from the new Annex A structure.

For each of the 11 new controls, you must assess applicability against your risk treatment results. If your risk assessment does not identify a risk that the control addresses, you may exclude it — but the exclusion must be documented and defensible. In practice, most organizations implementing the 2022 standard will find that the majority of the 11 new controls are applicable to at least some degree.

Implementation priorities

Practitioners implementing the 2022 standard for the first time should prioritize the Organizational and Technological themes, which together contain 71 of the 93 controls and cover the broadest surface area of a modern ISMS. The Technological theme in particular includes controls that are most likely to require changes to existing systems and tooling: configuration management, data masking, web filtering, and the cloud services control.

For organizations transitioning from the 2013 standard, the highest-priority gap work is the 11 new controls — assess applicability, implement or document exclusion, and update the SoA. The existing control set will largely map across to the new structure; the new controls are where the transition work concentrates.

Related resources
Ready to act on this?

Have a practitioner walk through your specific situation.

More articles
Strategy8 min

SOC 2 vs ISO 27001: Which Certification Should You Pursue First?

June 12, 2026
CMMC 2.06 min

How to Scope a CUI Enclave — and Why It Changes Your Level 2 Cost

June 3, 2026
SOC 27 min

The Evidence Engine: How to Make Your Type II Observation Window Routine

May 22, 2026