ISO 27001:2022: What has changed and what it means for UK SMEs
The publication of ISO 27001:2022 brought the most significant update to the standard since its 2013 revision. For UK organisations seeking or maintaining ISO 27001 certification, understanding what has changed and what those changes mean in practice is essential for managing the transition effectively.
The most visible change in ISO 27001:2022 is the restructuring of Annex A controls. The 2013 version contained 114 controls across 14 domains. The 2022 version reduces this to 93 controls across 4 themes: Organisational controls, People controls, Physical controls, and Technological controls. This restructuring reflects how information security is managed in modern organisations.
Eleven controls are entirely new in the 2022 standard. These include threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. Each of these reflects threats and technologies that were either nascent or non-existent when the 2013 standard was published.
For UK SMEs, the most practically significant new controls are likely to be threat intelligence, cloud services security, and data leakage prevention. Many SMEs now rely heavily on cloud services such as Microsoft 365 and Azure, and the new cloud services control requires organisations to document and manage the security implications of cloud usage explicitly.
The transition deadline for organisations already certified to ISO 27001:2013 has passed, all certificates should now reference the 2022 version. Organisations that have not yet completed their transition should treat this as urgent, as 2013-based certificates are no longer valid.
FortressPoint supports UK micro and large enterprise through the full ISO 27001:2022 implementation lifecycle from gap assessment through to certification audit readiness. Our GRC team has supported organisations across financial services, professional services, and technology sectors in achieving and maintaining ISO 27001 certification.
Related services
Further reading
Related articles
Have a security question?
Speak with a FortressPoint consultant. We engage with specific questions, not just general enquiries.
