Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What are the ISO 27001 Annex A controls?

Last verified

Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: Organizational 37, People 8, Physical 14, Technological 34. You select them in the Statement of Applicability. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Reference, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. Clauses 4–10 are the certifiable ISMS requirements. Annex A is a selectable catalogue. ISO/IEC 27002:2022 is guidance. Do not treat all 93 controls as mandatory.

What this page is, and what it is not

Audience: a security engineer who needs the 2022 Annex A shape before writing a SoA or a crosswalk.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file. Last verified 10 September 2026.

The 2013 edition had 114 controls in 14 domains. Accredited 2013-edition certificates expired by 31 October 2025 under IAF transition arrangements. New and continuing certificates are 2022.

The four 2022 themes

Counts below are the locked 2022 theme totals. They are not a mandate to implement every control. Last verified 10 September 2026. Not legal advice.

Annex A 2022 themes and control counts (not a mandate of all 93; not legal advice; last verified 10 September 2026)
ThemeControl countWhat the theme coversKind of text
Organizational37Policies, asset management, supplier relationships (including cloud), incident management, legal and contractual topics, threat intelligence, and related organisational measures.Reference catalogue inside the certification standard, selected via the SoA.
People8Screening, terms of employment, awareness and training, disciplinary process, remote working, and related people measures.Reference catalogue — selectable.
Physical14Secure areas, entry, equipment, media, and physical monitoring.Reference catalogue — selectable. Exclusions need Clause 6.1.3 justification.
Technological34Access mechanics, cryptography, logging and monitoring, configuration, development security (including secure coding), networks, data leakage prevention, and related technical measures.Reference catalogue — selectable.
2013 edition (retired for new accredited certs)114 across 14 domainsSuperseded layout. Kept here only so you do not mix editions.Historical edition. IAF transition ended accredited 2013 certificates by 31 October 2025.
ISO/IEC 27002:2022Guidance, not a fourth countImplementation advice for Annex A, including the 11 controls new in 2022 (threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, secure coding, and others).Guidance — not Clauses 4–10.

New 2022 controls, named without pretending the list is complete

Eleven controls are new in the 2022 edition rather than merged from 2013. Named examples include threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, data leakage prevention, and secure coding. This page does not reproduce paywalled control text. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for an Annex A pass. Last verified 10 September 2026. Not legal advice.

  • Are we working from the 2022 93 / four-theme layout, not 2013 114 / 14?
  • Does every included control have an inclusion justification and an implementation status?
  • Does every Annex A exclusion have a written justification?
  • Have we labelled 27002 as guidance?
  • Have we refused the sentence “all 93 are mandatory”?
  • Can we name which theme owns each high-risk control in our SoA?

What to do now

These steps do not start a clock and do not file.

  • Rebuild any 2013-domain spreadsheet into the four 2022 themes.
  • Draft exclusions first for themes you genuinely do not operate (often some physical controls in a cloud-only company) — then justify them.
  • Read the readiness and auditor-evidence pages before Stage 1.
  • Read the what-is page if Clauses 4–10 vs Annex A is still fuzzy.
  • Re-verify ISO.org and IAF sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance maps Annex A to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass. The policies library and cyber risk register hold YOUR artefacts. Evidence collection records control-mapped rows.

ISO 27001 sits in the 24-framework library. Human judgment and an accredited certification body remain required.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022 Annex A; ISO/IEC 27002:2022; IAF transition arrangements. Theme counts used here are Organizational 37, People 8, Physical 14, Technological 34. Not legal advice.

Frequently asked questions