AccreditAZ

← All articles

ISO 27001 · 7 min read · Published 20 April 2026 · Reviewed 17 August 2026

ISO 27001:2022 in NZ: The Updated Control Set and What It Means for Certification

ISO 27001:2022 replaced the 2013 version and restructured Annex A from 114 to 93 controls. NZ organisations certifying or recertifying need to understand the changes before engaging an auditor.

ISO/IEC 27001:2022 was published in October 2022, replacing the 2013 version. Organisations certified against the 2013 standard had until October 2025 to transition — that deadline has now passed, meaning any organisation currently pursuing or maintaining ISO 27001 certification must be working against the 2022 version.

The 2022 revision made structural and substantive changes. This post covers what changed in Annex A, how the transition affects existing ISMS documentation, and what NZ organisations engaging a UKAS or JAS-ANZ accredited certification body should expect.

Annex A restructure: 114 controls to 93

The most visible change in ISO 27001:2022 is the restructure of Annex A, which now contains 93 controls organised into four categories (down from 14 domains in 2013):

Controls were consolidated, renamed, and in some cases materially updated. Eleven controls are new in 2022 with no direct 2013 equivalent.

New controls with no 2013 equivalent

These eleven controls require new ISMS documentation where none previously existed:

5.7 — Threat intelligence: The organisation must collect and analyse threat intelligence relevant to its information security risks. This is not a requirement to build a threat intel programme from scratch, but your ISMS must document how threat intelligence is sourced, reviewed, and used in risk management decisions.

5.23 — Information security for use of cloud services: A dedicated control for cloud security governance — covering selection, use, management, and exit from cloud services. This formalises what many organisations were doing informally under the 2013 access control and supplier security clauses.

5.30 — ICT readiness for business continuity: Requires ICT continuity planning to be integrated with business continuity management. Documents must address recovery time objectives (RTOs) and recovery point objectives (RPOs) specifically.

6.8 — Information security event reporting: Adds specificity to incident reporting requirements — clear reporting channels, defined event types that trigger reporting, and handling of reports to preserve evidence.

7.4 — Physical security monitoring: Formalises requirements for CCTV, access logging, and monitoring of physical security controls in sensitive areas.

8.9 — Configuration management: Configuration baselines for systems, applications, and networks must be documented, maintained, and audited.

8.10 — Information deletion: Addresses secure deletion of information when no longer required — covering storage media, cloud services, and end-of-life assets.

8.11 — Data masking: Requires masking of sensitive data (particularly personal data) in non-production environments.

8.12 — Data leakage prevention: Technical controls to prevent unauthorised exfiltration of sensitive data (DLP tooling or equivalent).

8.16 — Monitoring activities: Consolidates and strengthens requirements for security monitoring — log collection, SIEM or equivalent, alerting on anomalous activity.

8.28 — Secure coding: Requires documented secure coding standards and their application in software development.

What existing certified organisations need to update

For organisations transitioning from 2013 certification, the documentation delta typically includes:

  1. Statement of Applicability (SoA) — Must be rebuilt against the 93 Annex A controls, with applicability and justification for each. The SoA is the central certification document; the 2013 version is not acceptable to a 2022 auditor.
  1. Risk treatment plan — Risk treatment decisions must be mapped to the 2022 Annex A reference numbers.
  1. New control policies — At minimum, policies or procedures for the eleven new controls that have no 2013 equivalent.
  1. Supplier management — The 2022 supplier security controls (5.19–5.22) are more specific than the 2013 versions. Supplier agreement templates and assessment procedures may need updating.
  1. Clause 6.3 — Planning of changes — New in 2022; requires that changes to the ISMS are carried out in a planned manner. Smaller organisations that manage ISMS changes informally need a documented change management process.

What NZ certification bodies expect

JAS-ANZ accredited certification bodies conducting ISO 27001:2022 audits will look for:

The ISO 27001:2022 standard can be purchased directly from ISO. The NCSC NZ has guidance on information security management at ncsc.govt.nz that complements the standard for government and critical infrastructure contexts.

Practical steps for certification preparation

  1. Map your existing SoA to the 2022 control numbering — identify which 2013 controls correspond to which 2022 controls (many are consolidated)
  2. Gap assess the eleven new controls — determine current state for each and what documentation or implementation is needed
  3. Rebuild your SoA against the 93 controls with justification for each
  4. Update supplier agreement templates to reference 2022 Annex A obligations
  5. Conduct an internal audit against the 2022 control set before engaging your certification body
  6. Brief your management review on the transition and ensure the next review covers 2022 compliance status

AccreditAZ maintains an ISO 27001:2022 control library with SoA templates, policy templates for all 93 controls, and gap assessment tooling. If your organisation also operates under NZISM, read NZISM 3.7: What Changed — the supplier assurance and cloud security updates align closely with ISO 27001:2022 Annex A and the evidence can often be consolidated. Sign up to begin your 2022 transition or certification preparation.

Manage your NZISM, ISO 27001, Essential Eight and PSR compliance in one place.

Start free trial →