In 2026, the question for an ISO 27001-certified organization is no longer whether it is ready to migrate from the 2013 edition. That transition ended on 31 October 2025. The question is whether its information security management system (ISMS) still reflects the assets, identities, suppliers and risks it manages today.
A Statement of Applicability (SoA) may say that privileged access is controlled. But are newly created administrator accounts included? A backup policy may be approved. But have critical systems been added to the backup scope, and can the team show recent test results? These are the questions that turn ISO 27001 from a periodic documentation exercise into an operating management system.
This article explains what’s new in ISO 27001:2022 as background, then focuses on what security, IT and GRC teams need to maintain in 2026: current control scope, reliable evidence, accountable exceptions and verified remediation.
Which ISO 27001 version applies in 2026?
ISO/IEC 27001:2022 is the published edition for ISMS requirements, with Amendment 1:2024 applying to it. There is no separate ISO/IEC 27001:2026 edition. The amendment adds a climate relevance consideration to clause 4.1 and a note on interested-party requirements to clause 4.2. It does not add Annex A security controls.
The International Accreditation Forum set 31 October 2025 as the end of the transition period for accredited ISO/IEC 27001:2013 certifications.
Articles that still tell organizations to begin that migration or prepare for its deadline are dated. For a particular certificate, check its current status and scope with the issuing certification body.
In 2026, use the current clauses for the ISMS cycle: 6.1.3 for risk treatment and the SoA, 9.1 for monitoring and evaluation, 9.2 for internal audit, and 9.3 for management review. Operate the selected controls and act when the evidence shows gaps.
What should organizations focus on in 2026?
The accredited certification transition from 2013 has ended. Organizations maintaining ISO 27001 certification should now focus on whether the 2022-aligned ISMS stays accurate as assets, identities, suppliers and services change.
Keep the SoA connected to reality
The SoA is more useful when a control maps to an owner, scope, implementation and evidence source. If a new SaaS platform or critical business service appears, check whether the associated risks and controls are reflected. Review exclusions when circumstances change. A statement that a control is “implemented” should have a clear operational basis.
Test control coverage and effectiveness
Deployment is one step. Ask whether the control reaches all intended assets and whether it is healthy. For privileged access, for example, the team might compare protected accounts with all in-scope privileged accounts, investigate exceptions and prioritize exposed gaps. The same approach can be applied to endpoint protection, vulnerability remediation, backup and cloud configuration.
Track exceptions through to revalidation
Every material gap needs a defined owner and an outcome. Record the affected service, the business risk, the agreed action and the expected completion date. After remediation, test again and retain the result. An approved temporary exception should have a clear scope and review point so it does not become an invisible permanent state.
Reuse evidence across the ISMS cycle
Evidence collected during operations can support risk reviews, management reviews, internal audits and corrective action. Keep timestamps, asset scope and owners clear. An isolated screenshot from the week before an audit may show a state at one moment, but it rarely explains how the control behaved over the review period.
Why the 2022 update still matters
The 2022 edition updated the information security management system (ISMS) standard after the 2013 edition. Organizations had become more dependent on cloud services, distributed work, complex supply chains and rapidly changing technology. The revision aligned Annex A with ISO/IEC 27002:2022, the companion guidance on information security controls. It also aligned parts of the management system text with the common structure used in other ISO management system standards.
Its title now includes information security, cybersecurity and privacy protection. This wording does not create a separate privacy certification requirement.
The risk-based ISMS approach remains: understand risks, select controls, evaluate performance and improve.
What changed in ISO 27001:2022?
There are two different parts to consider:
| Part of the standard | What changed | What it means in practice |
|---|---|---|
| ISMS requirements, clauses 4 to 10 | Mostly targeted wording and structural updates, including clause 6.3 on planning ISMS changes | Review how your ISMS handles changes, interested parties, evidence and continual improvement |
| Annex A control reference set | 114 controls in 14 groups became 93 controls in four groups | Revisit your risk treatment mapping and SoA rather than assuming old control numbers still correspond one to one |
The smaller number does not mean that organizations can drop 21 security practices. According to the International Accreditation Forum (IAF), the 93-control set includes 11 new controls, 24 resulting from merges, and 58 updated controls. Some earlier material was combined or rewritten. A control count is a description of the reference set, not a measure of an organization’s security coverage.
What changed in the ISMS requirements?
The mandatory management system clauses still address organizational context, leadership, planning, support, operation, performance evaluation and improvement. Several changes are especially useful to understand:
1. Planning changes to the ISMS. Clause 6.3 explicitly addresses planned changes to the ISMS. This concerns the management system itself, such as a change in its scope or operating approach. Annex A control 8.32 addresses changes to information processing facilities and systems; the two should not be treated as interchangeable.
2. Interested-party requirements. Clause 4.2 clarifies the need to determine which requirements of interested parties are addressed through the ISMS. The organization should be able to explain its decisions, not just maintain a list of stakeholders.
3. Risk treatment and the SoA. Annex A now references the ISO/IEC 27002:2022 control set. Organizations determine necessary controls through risk treatment, compare them against Annex A to avoid omissions, and document inclusion or exclusion in the Statement of Applicability.
4. Evidence and evaluation. Wording across parts of the standard was adjusted to clarify documented information used as evidence. Monitoring, internal audit, management review and corrective action still need to operate as a continuing cycle.
These are highlights, not a replacement for the standard’s complete text or an organization-specific gap review. The IAF characterized many management system changes as editorial, while identifying the revised Annex A and clause 6.3 as notable changes.
What are the four Annex A control groups?
The ISO 27001:2022 Annex A controls are organized as follows:
| Group | Number of controls | Typical areas covered |
|---|---|---|
| Organizational, section 5 | 37 | Policies, roles, supplier relationships, incident management and continuity arrangements |
| People, section 6 | 8 | Responsibilities before, during and after employment, awareness and reporting |
| Physical, section 7 | 14 | Physical access, facilities, equipment and physical security monitoring |
| Technological, section 8 | 34 | Identity, access, configuration, logging, networks, development and data protection |
The four groups make the reference set easier to navigate. They are not four separate certifications or a directive to deploy every control in the same way. The SoA should record the controls selected through the organization’s risk treatment process, their status and the rationale for inclusion or exclusion.
For teams updating older documentation, a direct rename of control numbers is risky. A former control can be merged into a broader control, while a current control may address material that was spread across several earlier controls. Map the underlying risk, objective, implemented measure and evidence, then update the cross-reference.
What are the 11 new ISO 27001:2022 controls?
The 2022 revision identified 11 new controls within the 93-control Annex A set. They address areas including threat intelligence, information security for the use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.
“New” describes their classification relative to the 2013 control set. It does not mean an organization necessarily lacked every corresponding practice before 2022. For example, many teams already monitored logs or managed cloud security under other controls and procedures. The useful task is to check whether the current risk treatment and SoA cover each applicable area, and whether its implementation can be demonstrated.
Consider three examples:
Cloud services: A supplier review alone may not show whether a newly deployed cloud account has the expected access, logging and configuration controls. Link the cloud service to an owner and to current operating evidence.
Configuration management: A documented baseline matters, but changes to actual systems can introduce drift. Define which assets are in scope, what states are acceptable and how deviations are handled.
Monitoring activities: Logging may be enabled but incomplete for critical systems. Check coverage, the health of data feeds, alert handling and the ownership of gaps.
This moves the discussion from whether a control appears in a spreadsheet to whether the selected measure operates where it is needed.
What did the 2024 amendment change?
Amendment 1:2024 changes clauses 4.1 and 4.2: organizations determine whether climate change is relevant to their context, and interested parties may have related requirements.
This does not add a climate-specific control to Annex A or turn the 93-control set into a different count. For an ISMS team, the practical question is whether climate-related issues are relevant to its context, services, sites, suppliers or interested parties, and how that determination is recorded. The effect will differ by organization. Avoid presenting the amendment as a new blanket technical security checklist.
How SPOG.AI helps connect controls to evidence
ISO 27001 controls are often defined in governance documents but operated in IAM, cloud, endpoint, vulnerability, ITSM and other systems. SPOG.AI connects security and IT evidence with assets, controls, risks and ownership, helping teams identify where coverage or effectiveness has changed. Its continuous control monitoring and GRC capabilities support visibility into gaps, exceptions, remediation and revalidation.
For a CISO or GRC leader, the useful view is more specific than “93 controls mapped.” It shows which selected controls apply to critical services, which are performing as expected, where exceptions remain and who is closing them. Certification decisions belong to the independent certification body; a platform supports the evidence and operational follow-through behind the organization’s ISMS.
See how SPOG.AI connects control performance with risk and remediation.