ISO Management Systems

Transitioning to ISO/IEC 27001:2022. A practitioner's roadmap

The 2022 revision consolidates Annex A controls and introduces new attributes. Here is how to plan a defensible transition without disrupting your operations.

Transitioning to ISO/IEC 27001:2022. A practitioner's roadmap
14 May 2026 · 8 min read

What actually changed in ISO/IEC 27001:2022

ISO/IEC 27001:2022 is not a complete rewrite of the management system. Clauses 4 to 10 remain structurally familiar. The material change sits in Annex A, which now references ISO/IEC 27002:2022 and consolidates the previous 114 controls into 93, organised into four themes: Organisational, People, Physical and Technological.

Eleven controls are new (including threat intelligence, information security for cloud services, ICT readiness for business continuity, and secure coding). Many existing controls were merged or retitled. Attributes were introduced to help organisations filter and report controls more usefully.

If you are already certified to the 2013 version, the transition is primarily a control mapping and evidence exercise, not a full re-implementation.

A practical transition sequence

Start with a formal gap assessment against the 2022 control set. Map every 2013 control you currently claim to its 2022 equivalent, identify the eleven new controls, and decide which are applicable based on risk. Update the Statement of Applicability and risk treatment plan before you rewrite policies.

Next, refresh documentation only where the control intent or evidence requirement has changed. Avoid a wholesale policy rewrite. Auditors want to see that the system still works, not that every document has a new date stamp.

Run an internal audit against the 2022 version, close findings, and schedule the certification body transition audit within your allowed window.

Common failure points we see in Kenya and internationally

Treating cloud services as out of scope without a documented risk decision. Control 5.23 (information security for use of cloud services) is frequently under-implemented.

Leaving threat intelligence as a subscription to a feed with no process for intake, prioritisation or action.

Physical and people controls that were informal under 2013 becoming visible gaps under the clearer 2022 structure.

Management review still focused on audit findings alone, with no discussion of threat landscape changes or performance of the new controls.

How AACL supports ISO 27001:2022 transitions

We run focused gap assessments against the 2022 control set, rebuild Statements of Applicability that boards can defend, and support internal audit and certification body liaison for transition audits. Delivery is available onsite in Nairobi and Kenya, or fully remote worldwide.

If you are planning a first-time ISO 27001 certification on the 2022 version, the same methodology applies from day one. Talk to us early if your certificate transition deadline is approaching.

To discuss this subject with our practitioners, write to info@aacl.co.ke.

WhatsAppSignalThreemaCall now