The Shift in ISO 27001:2022
The transition to the ISO/IEC 27001:2022 standard simplified the previous control structure, consolidating the 114 Annex A controls into 93 controls grouped into 4 distinct categories. This restructure makes it easier to assign control owners and collect audit evidence across modern technological stacks.
The transition is no longer optional. The International Accreditation Forum set 31 October 2025 as the deadline for every certified organisation to move from the 2013 revision to ISO/IEC 27001:2022. Certificates that had not transitioned by that date were withdrawn or allowed to expire. If your organisation holds a certificate today, it maps to the 2022 controls, and any auditor reviewing your programme is working from the new structure.
The standard is also more widely held than most teams assume. The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates across roughly 180,000 sites worldwide — nearly a threefold increase in five years, with information technology the most-certified sector. That growth means procurement teams increasingly treat the certificate as a baseline expectation rather than a differentiator, which raises the bar on the evidence you present at audit.
However, Stage 1 (Document Review) and Stage 2 (On-site/Technical Verification) certification audits remain rigorous. Auditors will not just look at your policies; they will demand proof of control execution over time.
The Four Control Domains of Annex A
Understanding the four restructured domains is essential for managing your preparation checklist:
| Domain | Controls Count | Key Focus Areas | Example Controls |
|---|---|---|---|
| Organizational Controls (A.5) | 37 controls | Policies, roles, asset management, risk reviews, and vendor relationship rules. | A.5.15 (Access control), A.5.36 (Compliance with policies) |
| People Controls (A.6) | 8 controls | Screening, onboarding, security awareness training, and remote working. | A.6.3 (Security awareness, education and training) |
| Physical Controls (A.7) | 14 controls | Perimeter security, equipment protection, facility monitoring, and storage. | A.7.2 (Physical entry), A.7.10 (Storage media) |
| Technological Controls (A.8) | 34 controls | Network security, system hardening, log monitoring, vulnerability management, and secure coding. | A.8.8 (Management of technical vulnerabilities), A.8.20 (Network security) |
Step-by-Step Audit Preparation Roadmap
Security teams should follow this roadmap in the months leading up to their certification audit:
- Establish the ISMS Scope: Clearly define the boundaries of your Information Security Management System (ISMS), identifying the physical locations, networks, and product applications in scope.
- Perform a Gap Analysis: Review all 93 controls against your current state. Document which controls are implemented, which are in progress, and which are excluded (with justification in your Statement of Applicability).
- Conduct a Risk Assessment: Map assets, identify threat vectors, and calculate likelihood vs. impact. Record these in your GRC Risk Register, showing clear treatment plans for high-risk items.
- Implement Policies & Procedures: Draft clear, standard-aligned operational policies for access control, cryptography, incident response, and vendor management.
- Gather Continuous Evidence: Run regular, automated security scans. Having active reports from vulnerability assessments and penetration testing proves to the auditor that your technical controls (especially under Domain A.8) are operating continuously.
Auditor Tip: One of the most common findings in Stage 2 audits is a lack of historical evidence. An auditor wants to see that you didn't just run a scanner the week before the audit. Proving that you run automated, weekly assessments across your APIs, cloud setups, and code commits shows a mature, operating ISMS.
Why Technological Controls Fail Stage 2 Most Often
Of the four domains, the technological controls in Annex A.8 are where audit preparation most often unravels. Policy documents are static: you write them once and update them periodically. Technical controls are dynamic, and the auditor knows it. Control A.8.8, management of technical vulnerabilities, cannot be satisfied by a single scan report. The auditor is looking for a pattern of activity that proves the control operated across the whole audit period.
This is the trap teams fall into. They stand up a vulnerability scanner in the final weeks, generate one clean report, and present it as evidence. A seasoned auditor reads the timestamp, sees a single dated artefact, and records a nonconformity for a control that exists on paper but was not operating. The fix is not more documentation. It is a cadence of testing that leaves a trail: weekly or per-release scans whose dates line up with your development history.
The ISO 27001:2022 revision sharpens this expectation. Several of the eleven new controls — threat intelligence (A.5.7), secure coding (A.8.28) and information security for cloud services (A.5.23) — assume an organisation that tests its own attack surface continuously. Mapping a live pentest programme to those controls turns an abstract requirement into a concrete, dated body of evidence, and it is far easier to defend in the interview than a folder of policies alone.
It also changes how you should sequence the year. Rather than treating the certification audit as a one-off sprint, ISO 27001:2022 rewards teams that build the evidence continuously and arrive at Stage 2 with the trail already complete. A team that scans on every release, records remediation, and re-tests to confirm a fix has landed walks into the audit with the technological domain effectively pre-answered. The auditor still verifies, but the burden of proof has already been met, and the conversation shifts from “show me you did this” to a routine confirmation of records that plainly exist.
Documenting Readiness
Using a structured readiness spreadsheet allows teams to maintain control progress, tag evidence documents, and calculate compliance percentages across organizational, people, physical, and technological sectors before Stage 1 commences. Pair that readiness tracker with a recurring testing schedule and each row in the spreadsheet points to a dated artefact rather than an intention, which is exactly the shape of evidence a Stage 2 auditor is trained to accept.
Frequently Asked Questions
Is ISO 27001:2013 still valid after October 2025?
No. The International Accreditation Forum set 31 October 2025 as the final date for transition to ISO/IEC 27001:2022. Certificates that had not moved to the 2022 revision by that date were withdrawn or expired, so every valid certificate now maps to the 93 Annex A controls of the 2022 edition.
How many controls are in ISO 27001:2022 Annex A?
The 2022 revision consolidates the previous 114 controls into 93, grouped into four themes: organisational (37), people (8), physical (14) and technological (34). Eleven controls are entirely new, including threat intelligence, secure coding and information security for cloud services.
What is the difference between a Stage 1 and Stage 2 ISO 27001 audit?
Stage 1 is a documentation review where the auditor confirms your ISMS, scope, risk assessment and Statement of Applicability exist and are coherent. Stage 2 is the on-site technical audit where the auditor demands evidence that controls have been operating over time, not just written down.
What evidence do auditors want for the technological controls in Annex A.8?
For controls such as A.8.8 (management of technical vulnerabilities), auditors expect dated, recurring proof of activity: vulnerability assessment reports, penetration test findings and remediation records spread across the audit period, rather than a single scan run the week before the audit.
How does continuous penetration testing help an ISO 27001 audit?
Continuous testing produces a running, timestamped evidence trail that demonstrates controls under Annex A.8 operate throughout the year. AssurePort scans start from $69 and run against web apps, APIs, cloud and source code, giving security teams the historical record auditors look for during Stage 2.