The major change to ISO 27001, with the publication of the 2022 version, was the incorporation of the control set from ISO 27002:2022 into Annex A of ISO 27001:2022.  With ISO 27002:2022, there was a a significant revision of the set of information security controls with the previous 114 being reduced to 93.   Of those 93 controls:

  • 58 have been updated
  • 24 controls represent merging of 57 of the previous controls
  • 11 new controls have been introduced.

More information on ISO 27002:2022 can be found here.

A number of changes to the management system clauses were made in ISO/IEC 27001:2022 with the goal of making some of the requirements more explicit and improving the alignment with other Annex SL standards, such as ISO 9001 and ISO 22301, e.g. sub clause titles, terms and definitions.

We have just received the CE+ certificate and notification that we have passed; we wanted to thank our assessor for all his help with this. It is greatly appreciated. I know that our team is very grateful as they were expecting the process to be difficult. Instead of being difficult, URM’s assessor made it a smooth process and we have all learned a lot
Contact centre software provider
Contact the ISO 27001 Experts Today

ISO 27001 – Clause 6.3: The Importance of Planned ISMS Change Management

Published on
20 Mar
2026

URM’s blog explains the purpose & requirements of ISO 27001 Clause 6.3, types of ISMS change it covers, and key considerations when putting it into practice.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
10/3/2026
ISO 27001 Clause 5.1: Leadership and Commitment Explained

URM’s blog explores Clause 5.1 of ISO 27001, what you must do to meet its requirements, and why leadership & commitment are vital to an effective ISMS.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
10/3/2026
ISO 27001: How Certification Works

URM’s blog breaks down the ISO 27001 certification process, the roles of certification bodies and UKAS, what auditors look for during assessments, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
9/3/2026
Implementing and Auditing ‘People Controls’ from ISO 27001:2022

URM’s blog explains why ‘people’ warrants its own control theme in ISO 27001 and how to prepare for a people controls audit, offering advice for each control.

Read more
"
Whenever we have asked our QSA and account manager whether additional work is required outside of the annual cycle, there has never been a hard sell of any of URM’s services, and instead offer advice based on our compliance requirements and business needs.
CISO at University of Surrey
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.