Companies should treat the revision as a controls mapping exercise, not a reset of their compliance programme. Start by comparing existing controls against the new themes, identifying removed, consolidated, and newly added controls, then update policies, evidence collection, and audit documentation. The key is to preserve risk treatment continuity while aligning implementation details with the revised control structure before the next certification cycle.
How to approach ISO 27001 certification after ISO 27002 control reorganization
The practical answer is to treat the change as a control translation and evidence realignment exercise, not as a reason to restart your ISMS. iso 27001 is still the certification target, while ISO 27002 remains the implementation guide for control selection and detail. That means you map the old control set to the reorganized themes, preserve the risk treatment logic, and update the audit trail so the certification story stays coherent.
That approach matters because auditors look for continuity between risk assessment, statement of applicability, implemented controls, and evidence. If the control catalogue changes but your governance narrative does not, the gap usually appears as inconsistent naming, outdated mappings, or missing proof that a consolidated control is still operating effectively.
What changes, and what should stay stable
The reorganized ISO 27002 structure changes how controls are grouped and described, but it does not change the need to manage risk, assign ownership, and demonstrate implementation. The first job is to crosswalk each existing control to the new themes and note whether it was removed, merged, or expanded in scope. That lets you keep the substance of the control environment intact while updating the reference structure used in policies and audit documents.
For certification planning, the important distinction is between control content and control representation. A merged or renamed control may require refreshed wording, new evidence labels, or a revised procedure, but not necessarily a new technical implementation. The organisation should be able to show that the same security objective is still covered, even if the ISO 27002 reference number or theme changed.
Where companies already maintain a compliance mapping library, this is the right time to normalise it against the revised control themes and improve traceability. NHIMG’s Identity Security Regulatory Map is a useful example of the kind of structured control-to-obligation mapping that helps preserve continuity across standards updates.
How to run the migration without breaking your audit trail
Start with a side-by-side mapping of the old and new control sets, then classify each control into one of four buckets: unchanged, consolidated, renamed, or newly introduced. That classification should drive the workplan for policy updates, technical evidence, and management review input. In practice, the most efficient sequence is to update the statement of applicability first, then align procedures and evidence, then refresh internal audit materials before the next external certification cycle.
Companies usually get into trouble when they update control references without updating the supporting evidence. If a control has been consolidated, the old evidence may still be valid, but it should be re-tagged so auditors can see how it supports the new control theme. If a control is newly added, you need to determine whether the implementation already exists under another label or whether you actually have a gap to close.
For governance-heavy programmes, the closest operational analogue is access and entitlement recertification: the control objective stays the same, but the review lens and documentation must match the current model. NHIMG’s IAM and IGA Basics can help teams think clearly about control ownership, policy logic, and evidence continuity when a control model is reorganized. Where review campaigns exist, Access Reviews and Certification Guide is a useful operational reference for keeping governance evidence current.
What good certification readiness looks like after the reorganization
A strong readiness posture shows that every revised ISO 27002 theme is covered by a clear owner, a current implementation, and evidence that is easy to trace back to the statement of applicability. The best indicator is not whether your documents use the newest wording everywhere, but whether an auditor can follow the logic from risk to control to proof without encountering broken references or duplicated control intent.
It also helps to test whether control consolidation has created blind spots. When several older controls are folded into one theme, teams sometimes keep only the most obvious evidence and lose visibility into edge conditions such as exceptions, delegated ownership, or compensating controls. That is where the revised structure can expose weak governance that was previously hidden by a more fragmented control list.
NHIMG’s IGA Buyer's Guide is relevant here because a mature control programme depends on clean ownership, reviewability, and lifecycle discipline, not just a static policy set. Likewise, Segregation of Duties (SoD) Guide is a useful reminder that control redesign should preserve preventive intent, not merely satisfy a new taxonomy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.37 — Documented operating procedures | Supports updating control documentation and audit evidence after control reorganization. |
| A.5.36 — Compliance with policies, rules and standards for information security | Applies because certification readiness depends on aligning controls to the current ISO structure. | |
| A.5.35 — Independent review of information security | Relevant to internal audit and readiness checks during the transition. | |
| Recommendation — Revise documented procedures to reflect the reorganized control structure before certification. Map the revised controls to policy requirements and verify operational compliance. Use independent review to confirm the new control mapping is complete and evidence-backed. | ||
Practitioner Guidance
What to prioritise: Update the statement of applicability and control crosswalk before the certification deadline, because that is where misalignment becomes visible first. Then refresh evidence labels and audit narratives so they point to the reorganized controls rather than the retired structure.
What to verify: Confirm that each revised control theme has an owner, an implementation, and at least one current evidence source that supports the same risk treatment objective. If a control was consolidated, verify that nothing material was lost in the merge.
Common mistake: Treating the revision as a documentation-only exercise. The control names may change faster than the underlying implementation, but auditors will still expect the governance model, evidence trail, and exception handling to line up.
Practitioner takeaway: The safest path is to preserve continuity of risk treatment while deliberately remapping the control narrative, so the certification package reflects the new structure without suggesting that the programme itself was reset.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org