By NHI Mgmt Group Editorial TeamBased on Teleport: “ISO 27001:2022 Requirements Explained for 2025” (August 13, 2025)

TL;DR: Teleport says ISO 27001:2022 shifts the compliance burden toward proving that identity, access, logging, and control ownership work in daily operations, with the 31 October 2025 migration deadline still forcing organisations off ISO 27001:2013. Certification now depends on whether access evidence, risk treatment, and audit artefacts can withstand scrutiny, not just whether the ISMS exists on paper.


At a glance

What this is: This is a 2025 guide to ISO 27001:2022 that argues certification readiness now hinges on identity, access, and audit evidence across the ISMS lifecycle.

Why it matters: It matters because IAM, PAM, and NHI teams must be able to prove control operation, not just policy intent, before the 2025 migration deadline.

By the numbers:

👉 Read Teleport's guide to ISO 27001:2022 requirements for 2025


Context

ISO 27001:2022 is an Information Security Management System standard, but the 2025 implementation challenge is really about whether identity and access controls can be evidenced, measured, and governed under audit pressure. The article frames the migration from ISO 27001:2013 as a deadline-driven governance problem, not a documentation exercise.

For IAM, PAM, and NHI programmes, the important point is that ISO 27001 clauses increasingly demand traceable operating evidence: scope, ownership, access revocation, monitoring, and corrective action. That makes identity governance part of certification readiness rather than a separate security workstream.

The article also ties Annex A controls to cloud access, short-lived credentials, configuration management, and session oversight. That combination makes ISO 27001:2022 a practical control-verification problem for organisations with distributed infrastructure and heavy reliance on privileged access.


Key questions

Q: What breaks when ISO 27001 access controls exist on paper but not in daily operations?

A: The ISMS becomes difficult to defend because auditors test effectiveness, not intent. If certificate revocation, access reviews, or role ownership are inconsistent, the organisation cannot prove that selected controls are operating as planned. That gap usually appears first in Clause 8 and Clause 9 evidence, then spreads into corrective action and certification risk.

Q: Why do over-privileged accounts matter in ISO 27001 assessments?

A: Over-privileged accounts matter because they show that access is broader than business need and that the organisation may not be enforcing least privilege consistently. In an ISO 27001 assessment, that weakens confidence in control effectiveness and often leads auditors to question whether access reviews are meaningful or merely procedural.

Q: How should organisations prioritise ISO 27001 migration work before the 31 October 2025 deadline?

A: Start with scope, control ownership, and evidence collection. If those three are weak, the rest of the migration becomes hard to defend, because auditors will look for a traceable line from risk treatment to operational control.

Q: What is the difference between a Statement of Applicability and a risk treatment plan in ISO 27001?

A: The Statement of Applicability explains which Annex A controls are included or excluded and why, while the risk treatment plan explains how identified risks will be addressed. One is the control justification record, the other is the action plan.


Technical breakdown

ISO 27001:2022 clauses turn governance into evidence

ISO 27001:2022 keeps the management-system structure of the standard, but clauses 4 through 10 are the auditable core. Clause 4 defines scope, Clause 5 assigns leadership, Clause 6 formalises risk treatment, Clause 7 covers support and documentation, Clause 8 operationalises controls, Clause 9 measures performance, and Clause 10 closes corrective-action loops. In practice, certification depends on whether the organisation can show these activities are working, not merely documented. That makes identity evidence, access records, and review artefacts part of the ISMS itself.

Practical implication: align identity, access, and logging evidence to the auditable clauses before the migration audit starts.

Annex A controls are selected through risk, not checklist compliance

ISO 27001:2022 still uses Annex A as a control reference set, but the standard does not require every control. Organisations must document a Statement of Applicability that explains which controls are selected, which are excluded, and why those decisions match the risk assessment. That matters because the control set now reflects cloud services, monitoring, and access governance more directly than older perimeter-era assumptions. The governance test is whether the selected controls map cleanly to actual risks and can be defended to an auditor.

Practical implication: tie every selected Annex A control to a documented risk and a traceable implementation record.

Identity evidence is now central to ISO 27001 auditability

The article repeatedly links certification readiness to access revocation, certificate issuance, session logs, role ownership, and documentation control. That is the operational layer where many ISMS programmes fail: they have policy, but not enough demonstrable control operation. For modern cloud and hybrid estates, the standard implicitly rewards short-lived access, monitored sessions, and explicit control ownership because those produce evidence auditors can trace. Identity governance has therefore become a primary audit mechanism, not a supporting activity.

Practical implication: prove that privileged access is issued, monitored, and revoked in ways an auditor can trace end to end.


NHI Mgmt Group analysis

ISO 27001:2022 has become an identity evidence standard in practice: the article shows that certification now depends on whether access, ownership, and review artefacts are traceable, not just whether an ISMS exists. That is a broader shift in governance maturity, because identity controls are where organisations most often prove or fail operational effectiveness. The practitioner conclusion is that identity evidence belongs in the core ISMS evidence pack.

Clause-based compliance fails when control operation is not observable: the article’s examples rely on logs of certificate issuance, revocation, monitoring, and review cycles to satisfy audit expectations. That means paper policies without operational traceability are no longer enough for modern ISO 27001 assessments. Practitioners should treat evidence production as a control requirement, not a post-audit scramble.

Annex A in 2022 reflects cloud-era access reality rather than static perimeter thinking: the new and revised controls the article highlights centre on cloud services, monitoring, configuration, and data leakage prevention. That signals where the standard is heading, and it aligns with the reality that access governance now spans sessions, infrastructure, and distributed identities. The practitioner conclusion is that IAM and PAM teams sit on the certification critical path.

Auditability is the control, not the afterthought: ISO 27001 programmes that cannot show measurable operation of access revocation, monitoring, and corrective action will struggle as the 2025 deadline closes. This is especially true where cloud access and privileged credentials are involved, because those environments produce the evidence trail the standard expects. The practitioner conclusion is to redesign evidence collection as part of access operations.

Control ownership is now a governance test across security and business teams: the article makes clear that leadership approval, role assignment, and ongoing review cycles are expected, not optional. That pushes ISO 27001 beyond a security-team checklist into cross-functional accountability for identity and access decisions. The practitioner conclusion is that certification readiness depends on named owners and repeatable review cadence.

What this signals

Identity evidence is becoming the decisive audit surface: organisations that cannot connect access issuance, revocation, and review records to the ISMS will struggle to demonstrate control operation. The practical shift is away from policy-only compliance toward observable control behaviour across cloud and privileged access.

ISO 27001:2022 also pushes security teams to treat session logging, configuration control, and role ownership as evidence-producing mechanisms, not just operational hygiene. That makes IAM and PAM teams part of certification design, because they generate the artefacts auditors need.

ISMS evidence should be designed like a control chain: scope, treatment decision, ownership, operation, monitoring, and corrective action need to line up. If one link is missing, the standard may still be written down, but the organisation cannot prove it is working.


For practitioners

  • Review the ISMS scope and Statement of Applicability Confirm that the scope covers the systems, people, processes, and locations where identity evidence will be produced, and make sure each selected Annex A control has a defensible inclusion or exclusion rationale.
  • Map access evidence to auditable clauses Align access revocation records, certificate issuance logs, review minutes, and monitoring outputs to clauses 4 through 10 so auditors can trace control operation end to end.
  • Document privileged access ownership Assign explicit owners for privileged accounts, service credentials, and review cycles so control accountability is visible in org charts, procedures, and audit artefacts.
  • Use short-lived access where possible Reduce standing privilege by issuing time-bounded credentials for administrative and infrastructure access, then retain logs that prove issuance, use, and revocation.
  • Build corrective-action closure into review cycles When an access review or monitoring exercise finds a gap, record the root cause, update the workflow, and keep evidence of the correction and follow-up verification.

Key takeaways

  • ISO 27001:2022 compliance in 2025 is less about static paperwork than about proving that identity and access controls operate as designed.
  • The 31 October 2025 migration deadline and the 93-control Annex A model make traceable evidence the main audit risk for lagging organisations.
  • Teams that can connect scope, ownership, access logs, and corrective actions will be better positioned to defend certification under the 2022 standard.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access ControlThe article centres on auditable access governance and control evidence under ISO 27001:2022.
A.5.16 — Identity ManagementIdentity ownership and role assignment are core to the article's certification-readiness argument.
A.5.17 — Authentication InformationThe article explicitly uses certificate issuance and access revocation as evidence of control operation.
Recommendation — Document and enforce access control decisions so auditors can trace who can access what and why. Maintain clear identity ownership records for users, admins, and service accounts across the ISMS. Track authentication information lifecycle events and retain evidence of issuance, use, and revocation.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about proving that permissions and entitlement decisions are governed.
Recommendation — Review entitlements regularly and keep evidence that access decisions are approved, monitored, and revoked.

Key terms

  • Statement of Applicability: A Statement of Applicability lists the security controls an organisation has selected, excluded, or adapted for its ISMS. It matters because it forces explicit justification, which makes audit discussions easier and exposes weak control decisions that were previously implied or undocumented.
  • Information Security Management System: An information security management system is the operating structure an organisation uses to manage security policies, controls, responsibilities, and evidence. Under ISO 27001, it is the framework auditors assess, but its real strength depends on whether access, logging, and remediation work consistently in practice.
  • Auditability: Auditability is the ability to reconstruct who or what acted, what permissions were used, and what data or tools were touched. For AI and NHI governance, it is the minimum evidence needed to investigate incidents, validate controls, and prove that autonomous actions stayed within approved scope.
  • Control Operation: Control operation is the day-to-day functioning of a security control in the live environment. For ISO 27001:2022, the question is whether identity, access, monitoring, and corrective-action controls can be shown to work repeatedly across the ISMS lifecycle.

What's in the full article

Teleport's full blog post covers the operational detail this post intentionally leaves for the source:

  • Clause-by-clause explanations of how ISO 27001:2022 certification evidence is typically assembled
  • The article's control mapping table showing how specific new Annex A controls align to access and audit capabilities
  • Examples of how organisations document risk treatment, scope, and control effectiveness for auditors
  • The FAQ section's direct answers on the migration deadline, control count, and certification cycle

👉 Teleport's full post breaks down the clause-by-clause audit expectations and Annex A control changes.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org