The 2022 revision of ISO/IEC 27001 restructures Annex A from fourteen domains and 114 controls into four themes and 93. Organisations already certified have a three-year transition window.
The headline reduction is misleading. Very little has been removed; a great deal has been merged. The genuinely new controls are the interesting part: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.
For Terravek, most of these were already in place — we run a SOC and a secure development lifecycle. What was not in place was the evidence that they were in place, expressed against a control reference an auditor recognises.
That is the actual work of a transition: not building controls, but mapping what you do to what the standard says, finding the four or five places where you genuinely have a gap, and being honest about them rather than writing a paragraph that sounds like compliance.
Ours were configuration management drift on long-lived infrastructure, and information deletion at end of contract. Both are now remediated and both took longer than the mapping exercise.