TL;DR: Teleport says ISO 27001:2022 shifts the compliance burden toward proving that identity, access, logging, and control ownership work in daily operations, with the 31 October 2025 migration deadline still forcing organisations off ISO 27001:2013. Certification now depends on whether access evidence, risk treatment, and audit artefacts can withstand scrutiny, not just whether the ISMS exists on paper.
Editorial analysis by NHI Mgmt Group, based on content published by Teleport: “ISO 27001:2022 Requirements Explained for 2025”.
By the numbers:
- Organizations have until 31st October 2025 to complete the migration from ISO 27001:2013 to ISO 27001:2022.
- ISO/IEC 27001:2022 formalizes its requirements across 11 main clauses.
- Annex A of ISO/IEC 27001:2022 outlines 93 security controls.
Key questions
Q: What breaks when ISO 27001 access controls exist on paper but not in daily operations?
A: The ISMS becomes difficult to defend because auditors test effectiveness, not intent.
Q: Why do over-privileged accounts matter in ISO 27001 assessments?
A: Over-privileged accounts matter because they show that access is broader than business need and that the organisation may not be enforcing least privilege consistently.
Q: How should organisations prioritise ISO 27001 migration work before the 31 October 2025 deadline?
A: Start with scope, control ownership, and evidence collection.
Practitioner guidance
- Review the ISMS scope and Statement of Applicability Confirm that the scope covers the systems, people, processes, and locations where identity evidence will be produced, and make sure each selected Annex A control has a defensible inclusion or exclusion rationale.
- Map access evidence to auditable clauses Align access revocation records, certificate issuance logs, review minutes, and monitoring outputs to clauses 4 through 10 so auditors can trace control operation end to end.
- Document privileged access ownership Assign explicit owners for privileged accounts, service credentials, and review cycles so control accountability is visible in org charts, procedures, and audit artefacts.
Bottom line: ISO 27001:2022 compliance in 2025 is less about static paperwork than about proving that identity and access controls operate as designed.
What's in the full article
Teleport's full blog post covers the operational detail this post intentionally leaves for the source:
- Clause-by-clause explanations of how ISO 27001:2022 certification evidence is typically assembled
- The article's control mapping table showing how specific new Annex A controls align to access and audit capabilities
- Examples of how organisations document risk treatment, scope, and control effectiveness for auditors
- The FAQ section's direct answers on the migration deadline, control count, and certification cycle
👉 Read Teleport's guide to ISO 27001:2022 requirements for 2025 →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
ISO 27001:2022 has become an identity evidence standard in practice: the article shows that certification now depends on whether access, ownership, and review artefacts are traceable, not just whether an ISMS exists. That is a broader shift in governance maturity, because identity controls are where organisations most often prove or fail operational effectiveness. The practitioner conclusion is that identity evidence belongs in the core ISMS evidence pack.
A question worth separating out:
Q: What is the difference between a Statement of Applicability and a risk treatment plan in ISO 27001?
A: The Statement of Applicability explains which Annex A controls are included or excluded and why, while the risk treatment plan explains how identified risks will be addressed. One is the control justification record, the other is the action plan.
👉 Read our full editorial: ISO 27001:2022 compliance in 2025 is an identity problem