ISO 27001:2022: The 11 New Controls — and Why ENISA’s NIS2 Mapping Uses Only 6 of Them
Every valid ISO/IEC 27001 certificate in the world is now a 2022 certificate. The transition window closed on 31 October 2025, and the mandatory document that governed it, IAF MD 26:2023, is blunt about the rest: “All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period.”
So the useful question in 2026 is no longer what changed. It is what the change bought you. If your organisation sits in NIS2 scope, there is now an official answer to test that against. ENISA publishes a mapping table that lines every requirement of Commission Implementing Regulation (EU) 2024/2690 up against ISO/IEC 27001:2022. Parse it and a clear pattern falls out: of the 11 controls that were brand new in 2022, ENISA’s mapping leans on six. Five never appear in it at all.
Which Situation Are You In?
The 2022 revision lands differently depending on where you stand today. Find your row before reading further.
| Your situation | What the 2022 revision means for you | What to do next |
|---|---|---|
| Certified and transitioned before 31 October 2025 | You hold a 2022 certificate. Amendment 1:2024 (climate action) is picked up at your next audit, without recertification. | Confirm your Statement of Applicability is written against the 93-control reference set, not the old 114. |
| Certified against the 2013 edition, never transitioned | Your certificate has expired or been withdrawn. There is no transition route left. | Budget for a full Stage 1 and Stage 2 recertification, not the 0.5 to 1.0 auditor-day top-up a transition audit needed. |
| Not certified, using ISO 27001 as the framework for NIS2 work | The 2022 control set is the one the EU’s own guidance maps against. The 2013 numbering is now a liability in your documentation. | Work from the four-theme Annex A, and read section four below before assuming certification closes NIS2. |
| In scope of Implementing Regulation (EU) 2024/2690 | ENISA’s mapping table is written for your entity type specifically, and it is far more precise than any vendor percentage claim. | Use the mapping table as your crosswalk and record which requirement each control answers. |
What Actually Changed in ISO/IEC 27001:2022
Two things changed: a short list of edits to the management-system clauses, and a full restructure of Annex A. The clause edits are small. The Annex A restructure is what generates the paperwork.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
ISO published the third edition on 25 October 2022. In the management system itself, IAF MD 26 lists the substantive additions: a new item 4.2 c), requiring you to determine which interested-party requirements will be addressed through the ISMS; a new subclause 6.3 Planning of changes, which requires changes to the ISMS to be carried out in a planned manner; and in 8.1, “externally provided processes, products or services” replaces “outsourced processes”, with the term “outsource” deleted. The rest is housekeeping: subclauses in 9.2 and 9.3 renamed and reordered, the two subclauses of Clause 10 swapped, documented-information wording made consistent, and the notes to 6.1.3 c) revised so that control objectives disappear.
Annex A is the bigger job. The reference control set moved from 114 controls in 14 clauses to 93 controls in four themes: 37 organizational, 8 people, 14 physical, 34 technological. Each control now carries a stated purpose and a set of attributes, and the old grouped control objectives are gone.
The change arithmetic is quoted inconsistently across the market, so pin it down before you reconcile anything. IAF MD 26 counts on the 2022 side: 11 controls are new, 24 are merged from existing controls, and 58 are updated — which sums to exactly 93. Figures you will see elsewhere, such as “57 merged” or “35 unchanged”, count from the 2013 side, describing how many old controls collapsed into the new ones. Both describe the same event from opposite directions. For a Statement of Applicability, use the 2022-side numbers: that is the set the auditor works from.
| Date | What happened |
|---|---|
| 25 October 2022 | ISO/IEC 27001:2022 published. 36-month transition period begins. |
| February 2024 | Amendment 1:2024 published — a single page adding climate-change considerations to clauses 4.1 and 4.2. |
| 30 April 2024 | Certification bodies must run all initial certifications and recertifications against the 2022 edition only. |
| 31 October 2025 | Transition period ends. Remaining 2013 certificates expire or are withdrawn. |
The climate amendment causes more alarm than its single page deserves. The joint IAF/ISO position is that because the change is “treated as a clarification rather than a new requirement, it is considered that a full transition programme is not needed in this case.” What is expected of you is a determination: climate change, like any other issue, “should be determined as relevant or not and if so, considered within an evaluation of risk”. Concluding that it is not relevant is a legitimate outcome, provided you can show you asked the question.
One mechanism is worth stating plainly, because it is the source of most transition panic. Annex A is a reference set, not a checklist. Clause 6.1.3 c) asks you to compare the controls your risk treatment determined as necessary against Annex A, so that nothing necessary was inadvertently omitted. It does not ask you to implement 93 controls. That is why IAF’s own assessment of the revision is that “the impact of ISO/IEC 27001:2022 on the organizations that have implemented ISMS need not be significant.”
The 11 New Controls, and the Six the EU’s Mapping Actually Uses
Here is where the ISO story and the NIS2 story meet. ENISA’s technical implementation guidance, published in June 2025, ships a mapping table that correlates every requirement in the Annex to Implementing Regulation (EU) 2024/2690 with ISO/IEC 27001:2022, NIST CSF 2.0, ETSI EN 319 401 and several national frameworks. Version 1.2 of that table maps all 49 requirement points in the Annex, and in doing so cites 69 of the 93 Annex A controls. Twenty-four are never cited at all.
Filtering that to the 11 controls that did not exist before 2022 gives the clearest answer available on which parts of the revision carry regulatory weight in the EU.
| New in 2022 | Control | Where ENISA cites it (CIR Annex point) |
|---|---|---|
| A.5.7 | Threat intelligence | 2.1 Risk management framework |
| A.5.23 | Information security for use of cloud services | 6.1 Security in acquisition of ICT services and systems |
| A.5.30 | ICT readiness for business continuity | 4.1 Business continuity and disaster recovery plan; 4.3 Crisis management |
| A.7.4 | Physical security monitoring | 13.3 Perimeter and physical access control |
| A.8.9 | Configuration management | 6.3 Configuration management |
| A.8.16 | Monitoring activities | 3.2 Monitoring and logging; 6.7 Network security |
| A.8.10 | Information deletion | Not cited |
| A.8.11 | Data masking | Not cited |
| A.8.12 | Data leakage prevention | Not cited |
| A.8.23 | Web filtering | Not cited |
| A.8.28 | Secure coding | Not cited |
The absences have a mechanism behind them rather than an oversight. The Annex to the Implementing Regulation contains no requirement whose subject matter is information deletion, data masking, data leakage prevention or web filtering, so there is nothing for those controls to map onto. The secure coding case is more interesting: Annex point 6.2, Secure development life cycle, is the natural home for A.8.28, but ENISA maps it instead to A.8.25 (secure development life cycle) and A.8.31 (separation of development, test and production environments). The regulation specifies the lifecycle and the environments; it does not specify how the code is written.
That absence is easy to over-read. The mapping table states on its own cover page that it is not legally binding and is informative in nature, and Article 21 is risk-based — information deletion and data masking in particular do substantial work under the GDPR even when NIS2 is silent. What the absence tells you is narrower: rely on those five controls as NIS2 evidence and you are making a risk-based case in your own words, not citing a crosswalk.
One more absence is worth flagging, because it points at the next section. A.5.5 Contact with authorities never appears in the mapping either — not because it is unimportant, but because the Annex covers Article 21(2) risk-management measures and says nothing about the Article 23 duty to notify. That gap is not a mapping artefact. It is structural.
What ISO 27001 Is, Legally, Under NIS2
In plain terms: nothing in NIS2 requires ISO 27001, and the Directive never names it. That is not an interpretation, it is a full-text search result.
The string “27001” appears zero times in Directive (EU) 2022/2555. “ISO/IEC” appears four times, and all four are in recitals: Recital 33 borrows ISO/IEC 17788:2014 for cloud service and deployment model definitions, Recital 58 points to ISO/IEC 30111 and 29147 for vulnerability handling, and Recital 79 says risk-management measures should address physical and environmental security “in line with European and international standards, such as those included in the ISO/IEC 27000 series.” Recitals explain the legislator’s intent. They do not create obligations, and the ISO/IEC 27000 series appears nowhere in the enacting terms.
The operative provisions are deliberately technology-neutral, and their modal verbs matter:
- Article 21(1) requires measures taking into account the state of the art and, “where applicable”, relevant European and international standards, as well as the cost of implementation. Standards sit under a condition, alongside cost.
- Article 25(1) obliges Member States to encourage the use of European and international standards, and to do so “without imposing or discriminating in favour of the use of a particular type of technology.” A Member State cannot simply mandate ISO 27001 as the route to compliance.
- Article 24(1) says Member States “may require” entities to use ICT products, services and processes certified under European cybersecurity certification schemes adopted under Regulation (EU) 2019/881. That is product-level certification under an EU scheme, not management-system certification under ISO.
The strongest textual link runs the other way. Recital 3 of Implementing Regulation (EU) 2024/2690 states that the Annex requirements “are based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401.” The standard informed the regulation. It does not follow that holding the certificate discharges the regulation, and the same recital-versus-article distinction applies: this sentence sits in a recital too.
Scope matters as well. The Implementing Regulation binds eleven entity categories only — DNS providers, TLD name registries, cloud computing providers, data centre providers, CDN providers, managed service providers, managed security service providers, online marketplaces, online search engines, social networking platforms and trust service providers. Entities in other sectors follow their national transposition of Article 21, though supervisors may still read the Implementing Regulation as interpretive guidance. If you are mapping Article 21(2)(a) specifically, the comparison of ISO 27005:2022 against Article 21(2)(a) covers where the risk methodology holds and where it stops, and our guide to building a Clause 6.1.2 risk assessment methodology covers the clause the 2022 revision left largely intact.
What a 2022 Certificate Still Will Not Do
Germany’s BSI, the national competent authority, publishes a page dedicated to exactly this question. Its answer is unambiguous: “Nein. Eine Zertifizierung nach ISO/IEC 27001 bedeutet nicht automatisch, dass ein Unternehmen NIS-2-konform ist” — no, ISO/IEC 27001 certification does not automatically mean an organisation is NIS2-compliant, and such a certificate cannot be treated as proof of NIS2 conformity. The page names five gap areas. Mapped to the Directive itself, they are:
- Incident reporting. Article 23(4) sets an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. No Annex A control starts that clock, and the nearest one, A.5.5 Contact with authorities, carries no deadline at all.
- Registration. Article 3(4) requires Member States to compel entities to submit their identifying details to the competent authority. An ISMS cannot perform a legal act on your behalf.
- Management accountability and training. Article 20 requires management bodies to approve the measures, oversee implementation and be capable of being held liable, and requires their members to follow training. ISO 27001 requires leadership commitment and management review; it does not create personal liability or oblige directors to train.
- Scope. An ISMS scope statement can lawfully be narrower than your regulated operations. The obligation is not. If you have not tested one against the other, the 0–5 maturity gap analysis method is the fastest way to find the overhang.
- Risk treatment. ISO lets you accept or transfer a risk. Article 21(1) requires measures that ensure a level of security appropriate to the risks posed, and Article 21(4) requires corrective measures without undue delay once you find you are not complying.
What that means in practice differs sharply by role:
| Role | What the 2022 revision changes | What it does not change |
|---|---|---|
| CISO / IT security manager | Your Statement of Applicability is now written against 93 controls with purposes and attributes, and six of the new controls carry mapping weight against the Implementing Regulation. Clause 6.3 means ISMS changes need planning evidence. | Detection-to-report timing under Article 23 still sits outside the ISMS and needs its own procedure and clock. |
| Compliance officer | Your evidence pack can now cite the same clause and control references ENISA cites — 69 of 93 controls appear in the official mapping, which is a far stronger position than a percentage claim. | Registration and notification remain legal acts performed by your organisation, not controls that can be audited into existence. |
| Board member / owner | No recertification is needed for the climate amendment. A lapsed 2013 certificate, however, means paying for full recertification rather than a transition audit. | Article 20 liability sits with the management body personally. No certificate, in any edition, transfers it. |
Frequently Asked Questions
Is ISO 27001:2022 mandatory under NIS2?
No. Article 25(1) requires Member States to encourage European and international standards without imposing or favouring a particular technology, and the Directive does not name ISO 27001 anywhere in its enacting terms.
My certificate is against the 2013 edition. Is it still valid?
No. IAF MD 26:2023 states that all certifications based on ISO/IEC 27001:2013 expire or are withdrawn at the end of the transition period, which ended on 31 October 2025. Recertification now runs as a fresh Stage 1 and Stage 2 audit.
Does Amendment 1:2024 require recertification?
No. The joint IAF and ISO position treats the climate-action text as a clarification rather than a new requirement, so no full transition programme applies. It is examined at your next scheduled audit.
If I am in scope of the Implementing Regulation, which new controls should I prioritise?
The six ENISA actually cites: A.5.7, A.5.23, A.5.30, A.7.4, A.8.9 and A.8.16. Each maps to a named Annex requirement, so implementation evidence does double duty. The remaining five may still be justified by your own risk assessment — they simply will not be supported by the official crosswalk.
Is there such a thing as NIS2 certification?
Not as a single EU-wide scheme. Article 24 permits Member States to require ICT products, services and processes certified under schemes adopted pursuant to Regulation (EU) 2019/881, and several Member States name national schemes. Germany’s BSI states plainly that an ISO 27001 certificate cannot be treated as proof of NIS2 conformity.
Sources
- IAF MD 26:2023, Issue 2 — Transition Requirements for ISO/IEC 27001:2022 — International Accreditation Forum, 15 February 2023. Source of the publication date, the 36-month transition period and its key dates, the 11 listed clause changes, the 114-to-93 and 11/24/58 control counts, the auditor-day minimums, and the expiry-or-withdrawal rule.
- ISO/IEC 27001:2022 catalogue record — ISO. Third edition, published 25 October 2022, stage 60.60, 19 pages.
- ISO/IEC 27001:2022/Amd 1:2024 catalogue record — ISO. Amendment 1: Climate action changes, published February 2024, one page.
- ISO/IEC 27002:2022 published preview (front matter and complete contents list) — ISO/IEC, third edition 2022-02, corrected version 2022-03. Source of the four-theme structure, the per-theme control counts, and the verbatim titles of the 11 new controls.
- Directive (EU) 2022/2555 (NIS2) — EUR-Lex. Articles 3(4), 20, 21, 23, 24 and 25, and Recitals 33, 58 and 79.
- Commission Implementing Regulation (EU) 2024/2690 — EUR-Lex. Recital 3, Article 1 scope, and the Annex requirement points.
- ENISA Technical Implementation Guidance — Mapping table, version 1.2 — ENISA, 21 August 2025 (XLSX). Source of every mapping count in this article.
- NIS2 Technical Implementation Guidance — ENISA, 26 June 2025. The guidance the mapping table accompanies; summarised in our practical summary of the ENISA guidance.
- #nis2know: ISO/IEC 27001 im Kontext NIS-2/BSIG — BSI (German federal competent authority), in German. Source of the quoted position and the five named gap areas.
- IAF/ISO Joint Communiqué on Addition of Climate Change Considerations to MSS — IAF and ISO, 22 February 2024, with the IAF Technical Committee final decision.
Method note: the mapping counts in this article were produced by parsing ENISA’s published mapping table (version 1.2) against the contents list in the ISO/IEC 27002:2022 preview, and the “27001” and “ISO/IEC” counts are full-text searches of the EUR-Lex texts, counted separately for recitals and enacting terms. Anyone can reproduce them from the linked files. One practical warning if you try: several ISO references in ENISA’s spreadsheet are typed with a Greek capital alpha instead of a Latin “A”, alongside spacing typos such as “A5.7” and “A.5 .24”, so a naive search misses rows.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
