Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What are the ISO 27001 Annex A controls?
Last verifiedAnnex A of ISO/IEC 27001:2022 lists 93 controls in four themes: Organizational 37, People 8, Physical 14, Technological 34. You select them in the Statement of Applicability. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Reference, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. Clauses 4–10 are the certifiable ISMS requirements. Annex A is a selectable catalogue. ISO/IEC 27002:2022 is guidance. Do not treat all 93 controls as mandatory.
What this page is, and what it is not
Audience: a security engineer who needs the 2022 Annex A shape before writing a SoA or a crosswalk.
This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.
The 2013 edition had 114 controls in 14 domains. Accredited 2013-edition certificates expired by 31 October 2025 under IAF transition arrangements. New and continuing certificates are 2022.
The four 2022 themes
Counts below are the locked 2022 theme totals. They are not a mandate to implement every control. Last verified 10 September 2026. Not legal advice.
| Theme | Control count | What the theme covers | Kind of text |
|---|---|---|---|
| Organizational | 37 | Policies, asset management, supplier relationships (including cloud), incident management, legal and contractual topics, threat intelligence, and related organisational measures. | Reference catalogue inside the certification standard, selected via the SoA. |
| People | 8 | Screening, terms of employment, awareness and training, disciplinary process, remote working, and related people measures. | Reference catalogue — selectable. |
| Physical | 14 | Secure areas, entry, equipment, media, and physical monitoring. | Reference catalogue — selectable. Exclusions need Clause 6.1.3 justification. |
| Technological | 34 | Access mechanics, cryptography, logging and monitoring, configuration, development security (including secure coding), networks, data leakage prevention, and related technical measures. | Reference catalogue — selectable. |
| 2013 edition (retired for new accredited certs) | 114 across 14 domains | Superseded layout. Kept here only so you do not mix editions. | Historical edition. IAF transition ended accredited 2013 certificates by 31 October 2025. |
| ISO/IEC 27002:2022 | Guidance, not a fourth count | Implementation advice for Annex A, including the 11 controls new in 2022 (threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, secure coding, and others). | Guidance — not Clauses 4–10. |
Legal requirement, regulatory guidance, best practice, or our recommendation
Annex A is the place people most often say “mandatory” incorrectly. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| Clauses 4–10 are the certifiable ISMS requirements. | Certification standard. | Does not make Annex A a second copy of those clauses. |
| Annex A controls are selected and justified in the SoA (Clause 6.1.3). | Certification standard (planning). | Does not mean all 93 are mandatory. |
| ISO/IEC 27002:2022. | Guidance. | Does not add certifiable “shall” statements of its own in the way people sometimes assume. |
| Map each in-scope Annex A control to an owner and an evidence source. | Industry best practice. | Does not replace the SoA. |
| Crosswalk Annex A to about 72 canonical controls and show density, not a pass. | ShipReady Metrics recommendation. | Does not issue a certificate and is not an auditor's opinion. |
New 2022 controls, named without pretending the list is complete
Eleven controls are new in the 2022 edition rather than merged from 2013. Named examples include threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, and secure coding. This page does not reproduce paywalled control text. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for an Annex A pass. Last verified 10 September 2026. Not legal advice.
- Are we working from the 2022 93 / four-theme layout, not 2013 114 / 14?
- Does every included control have an inclusion justification and an implementation status?
- Does every Annex A exclusion have a written justification?
- Have we labelled 27002 as guidance?
- Have we refused the sentence “all 93 are mandatory”?
- Can we name which theme owns each high-risk control in our SoA?
What to do now
These steps do not start a clock and do not file.
- Rebuild any 2013-domain spreadsheet into the four 2022 themes.
- Draft exclusions first for themes you genuinely do not operate (often some physical controls in a cloud-only company) — then justify them.
- Read the readiness and auditor-evidence pages before Stage 1.
- Read the what-is page if Clauses 4–10 vs Annex A is still fuzzy.
- Re-verify ISO.org and IAF sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance maps Annex A to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass. The policies library and cyber risk register hold YOUR artefacts. Evidence collection records control-mapped rows.
ISO 27001 sits in the 24-framework library. Human judgment and an accredited certification body remain required.
Primary sources (last verified 10 September 2026)
ISO/IEC 27001:2022 Annex A; ISO/IEC 27002:2022; IAF transition arrangements. Theme counts used here are Organizational 37, People 8, Physical 14, Technological 34. Not legal advice.