Blog

ISO 27001:2022: The Version You Certify Against

ISO/IEC 27001:2022 is the current version of the standard and the only one you can be certified against. It was published on 25 October 2022 as the third edition, and it has one amendment, Amendment 1:2024, which adds climate change to the issues you must consider. Certificates against the older ISO/IEC 27001:2013 all expired or were withdrawn on 31 October 2025. If you are starting certification now, there is only one version to buy, one control set to work through, and no transition to worry about.

Most of what is written online about ISO 27001:2022 was produced for companies migrating from the 2013 version, which is now history. This article is written for the other reader: an Australian business starting from scratch, or renewing, who wants to know what the current standard actually asks for.

What is the current version of ISO 27001?

The current version of ISO 27001 is ISO/IEC 27001:2022, published on 25 October 2022. Its full title covers information security, cybersecurity and privacy protection, and it sets out the requirements for an information security management system, usually shortened to ISMS. It is a requirements standard, which means an accredited certification body can audit you against it and issue a certificate.

One amendment has been published since. ISO/IEC 27001:2022 Amendment 1:2024, issued in February 2024, adds two narrow requirements: you must determine whether climate change is a relevant issue when you consider the context of your organisation under clause 4.1, and whether interested parties have climate related requirements under clause 4.2. It does not change a single Annex A control. For most Australian businesses it amounts to one considered paragraph in the ISMS context document.

What is the difference between ISO 27001:2013 and ISO 27001:2022?

The difference between ISO 27001:2013 and ISO 27001:2022 sits almost entirely in Annex A. The 2013 version listed 114 controls across 14 domains numbered A.5 to A.18. The 2022 version lists 93 controls grouped into four themes numbered A.5 to A.8. Controls were merged and renumbered rather than deleted, so the reduction from 114 to 93 does not mean less work.

ISO 27001 2013 and 2022 Annex A control counts compared, showing 114 controls in 14 domains against 93 controls in four themes
Annex A was regrouped into four themes, not made smaller in substance.

The management system clauses 4 to 10 were not rewritten. The changes there are small clarifications, with one genuine addition: clause 6.3, planning of changes, is new. It requires that when you decide the ISMS needs to change, the change is carried out in a planned way. It does not prescribe a format, so a short change record is usually enough to satisfy an auditor.

How many controls are in ISO 27001:2022?

ISO 27001:2022 has 93 Annex A controls, grouped into four themes:

Annex A themeNumber of controlsWhat it covers
A.5 Organisational37Policies, roles, supplier management, incident management, legal obligations
A.6 People8Screening, terms of employment, awareness, disciplinary process, remote working
A.7 Physical14Secure areas, equipment, clear desk, physical monitoring, utilities
A.8 Technological34Access control, cryptography, logging, network security, secure development
The four Annex A themes in ISO/IEC 27001:2022, totalling 93 controls.

Eleven of the 93 controls did not exist in the 2013 version. They are threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23) and secure coding (A.8.28).

Those eleven are where most first time certification projects lose time, because they tend to be the controls a small business has never formally documented. You do not have to implement all 93. You have to consider all 93, decide which apply, and record the reasoning in your Statement of Applicability.

What happened to the ISO 27001:2013 transition deadline?

The transition deadline has passed. IAF Mandatory Document 26, the international rule that certification bodies follow, set the end of the transition period at 31 October 2025 and states that all certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of that period.

Two practical consequences follow. First, if a supplier sends you a certificate that names ISO/IEC 27001:2013, it is not a valid certificate, whatever the expiry date printed on it. Second, if you are starting certification now, you never had a transition to plan, so ignore the migration content that still dominates search results and work straight from the 2022 requirements.

Should you buy ISO 27001 or ISO 27002?

Buy ISO/IEC 27001 if you intend to get certified. ISO/IEC 27002:2022 is a different document: it is guidance, not requirements, and no organisation is certified against it. What it gives you is several pages of implementation advice for each of the same 93 controls that Annex A of ISO 27001 lists in a single line.

The common and expensive mistake is buying only ISO 27002 and assuming you have the certifiable standard, or buying both when the budget only stretched to one. A first time certification project needs ISO 27001. Add ISO 27002 later if the person writing your controls wants the detailed guidance, or skip it and use a consultant who already has it.

What is the Australian version of ISO 27001:2022?

In Australia and New Zealand, the standard has been adopted identically as AS/NZS ISO/IEC 27001:2023, with the climate amendment adopted as AS/NZS ISO/IEC 27001:2023 Amendment 1:2024. Identical adoption means the technical content is the same as the ISO version; only the cover page differs.

For certification purposes this rarely matters. Australian certification bodies accredited by JAS-ANZ audit and issue certificates against ISO/IEC 27001:2022, which is the designation your customers and overseas buyers will recognise. Buy whichever copy is convenient. For what the audit itself looks like, see what to expect at Stage 1 and Stage 2, and our complete guide to ISO 27001 certification in Australia for the wider process.

What does first time ISO 27001:2022 certification involve?

First time ISO 27001:2022 certification involves building a management system, running it long enough to produce real records, then passing a two stage audit by an accredited certification body. Stage 1 reviews your documented ISMS. Stage 2 tests whether it operates in practice. A certificate then runs for three years, with a surveillance audit each year in between.

Timeline of a first time ISO 27001 2022 certification project for an Australian business
An indicative timeline for a first ISO 27001:2022 certification.

Two things reliably decide how long it takes. The first is scope: a tightly drawn boundary certifies faster than an everything included one, which is why defining your ISMS boundary is the first decision to make properly. The second is how much already exists. A business with written policies, an asset register and access reviews already running is months ahead of one starting cold. A gap analysis tells you which of those two you are.

What evidence does an ISO 27001:2022 auditor ask for?

An ISO 27001:2022 auditor asks for records, not intentions. Written policies get you through Stage 1. Stage 2 is passed on evidence that the ISMS ran: dated risk assessments, access reviews with names and outcomes, supplier reviews, incident records including the ones where nothing serious happened, training completions, and the minutes of a management review that actually took decisions.

The two documents auditors read hardest are the Statement of Applicability, because it shows whether you thought about all 93 controls or copied a template, and the internal audit report, because a report with no findings tells an auditor the internal audit was not real. Running an internal audit that adds value before Stage 2 is the single most useful thing a small team can do, and it is a requirement of the standard rather than an optional extra.

Common questions

What is the current version of ISO 27001?

ISO/IEC 27001:2022, published on 25 October 2022, is the current version. It has one amendment, Amendment 1:2024, which adds climate change considerations to clauses 4.1 and 4.2. No later edition has been published. Certification bodies audit against ISO/IEC 27001:2022, and the identical Australian and New Zealand adoption is AS/NZS ISO/IEC 27001:2023.

What is the difference between ISO 27001:2013 and 2022?

Annex A changed from 114 controls in 14 domains to 93 controls in four themes, with eleven genuinely new controls covering areas such as cloud services, threat intelligence, data masking and secure coding. The management clauses 4 to 10 were largely unchanged apart from a new clause 6.3 on planning changes to the management system.

How many ISO 27001 controls are there?

There are 93 controls in Annex A of ISO/IEC 27001:2022: 37 organisational, 8 people, 14 physical and 34 technological. You are not required to implement all of them. You are required to consider each one, decide whether it applies to your scope, and record the decision and justification in your Statement of Applicability, which the auditor will read closely.

Is ISO 27001 mandatory in Australia?

No Australian law requires ISO 27001 certification for general business. It is a voluntary standard. In practice it becomes effectively mandatory through commercial pressure: government tenders, enterprise procurement and large customer contracts increasingly name it, and losing a deal over a missing certificate costs more than the certificate.

How often is the ISO 27001 standard updated?

Rarely. ISO 27001 was published in 2005, revised in 2013 and revised again in 2022, so roughly every eight to nine years. Smaller amendments can appear between editions, as Amendment 1:2024 did. A new edition triggers a transition period, normally three years, after which certificates against the old edition are withdrawn.

Is an ISO 27001:2013 certificate still valid?

No. Under IAF Mandatory Document 26, all certifications based on ISO/IEC 27001:2013 expired or were withdrawn at the end of the transition period on 31 October 2025. If a supplier gives you a 2013 certificate during due diligence, ask for the current one. If they cannot produce a 2022 certificate from an accredited body, treat them as uncertified.

Where to go next

If ISO 27001:2022 is on your roadmap, the useful first step is not buying the standard, it is finding out how far off you are. A gap analysis against the 93 controls and clauses 4 to 10 gives you a scope, a list of what is missing and a realistic timeline before you commit to a certification body. See our ISO 27001 services for how we run that, or talk to us about what your certification would actually involve.