Last updated: 11 October 2026
Quick answer: ISO 27001 Annex A controls are the 93 reference information security controls listed in ISO/IEC 27001:2022, grouped into four themes: organisational (37), people (8), physical (14) and technological (34). They are not all mandatory. You select the ones your risk assessment requires and justify every inclusion and exclusion in a Statement of Applicability.
Annex A is the part of ISO 27001 that most people picture when they think of the standard: a long list of security controls. Yet the ISO 27001 Annex A controls are also the part most often misunderstood. Some teams treat them as a compulsory checklist, others as optional reading. Neither view survives an audit.
This guide explains how the 2022 Annex A is structured, how it relates to ISO/IEC 27002, what changed from the 2013 edition, and how a CISO can turn 93 controls into a defensible, risk-based control set. It ends with a practical checklist you can use before your next audit.
What are the ISO 27001 Annex A controls?
Annex A is a normative annex to ISO/IEC 27001:2022, the third edition of the standard, published in October 2022. It lists 93 information security controls, each with a short control statement describing what should be achieved.
The main body of the standard (clauses 4 to 10) sets the requirements for the information security management system (ISMS) itself: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A supplies the menu of controls that the ISMS uses to treat risk. Clause 6.1.3 links the two: after deciding how to treat each risk, you compare the controls you have chosen with Annex A to make sure nothing necessary has been missed.
How are the 93 controls organised?
The 2022 edition groups Annex A into four themes, replacing the 14 domains and 114 controls of ISO/IEC 27001:2013. The numbering (5 to 8) mirrors the chapters of ISO/IEC 27002, which is why the first control is 5.1 rather than 1.1.
| Theme | Control numbers | Count | Typical content |
|---|---|---|---|
| Organisational | 5.1 to 5.37 | 37 | Policies, roles, asset inventory, access control, supplier security, incident management, business continuity, legal and privacy compliance |
| People | 6.1 to 6.8 | 8 | Screening, terms of employment, awareness and training, disciplinary process, confidentiality agreements, remote working, event reporting |
| Physical | 7.1 to 7.14 | 14 | Perimeters, physical entry, secure areas, physical security monitoring, equipment, storage media, clear desk and clear screen |
| Technological | 8.1 to 8.34 | 34 | Endpoints, privileged access, authentication, malware protection, backup, logging, monitoring, network security, cryptography, secure development |
Many controls are about governance and process rather than technology, so HR, facilities, legal, procurement and IT operations all own parts of Annex A.
How does Annex A relate to ISO/IEC 27002?
Annex A gives a one or two sentence statement per control. ISO/IEC 27002:2022 expands each of the same 93 controls with a purpose and detailed implementation guidance. ISO/IEC 27002 is a guidance document, so organisations certify against ISO 27001, not against ISO 27002.
ISO/IEC 27002 also introduced five attributes that let you filter and view controls in different ways:
- Control type: preventive, detective or corrective.
- Information security properties: confidentiality, integrity and availability.
- Cybersecurity concepts: identify, protect, detect, respond and recover, which echo the functions of the NIST Cybersecurity Framework.
- Operational capabilities: for example, asset management, identity and access management or threat and vulnerability management.
- Security domains: governance and ecosystem, protection, defence and resilience.
Attributes are optional, but they are useful. A CISO can, for instance, list every detective control to check monitoring coverage, or group controls by operational capability to assign owners. If you also report against NIST CSF 2.0, the cybersecurity concepts attribute gives you a head start, a point we covered in our guide to NIST CSF 2.0 and its new Govern function.
What changed from the 2013 version?
The 2022 revision consolidated controls rather than adding large amounts of new content. Many 2013 controls were merged, a few were split, and 11 controls were introduced as new:
| New control | What it asks for, in short |
|---|---|
| 5.7 Threat intelligence | Collect and analyse information about threats to inform decisions |
| 5.23 Information security for use of cloud services | Manage security across the life of cloud service use, from acquisition to exit |
| 5.30 ICT readiness for business continuity | Plan, implement and test ICT readiness against continuity objectives |
| 7.4 Physical security monitoring | Continuously monitor premises for unauthorised physical access |
| 8.9 Configuration management | Define, document and monitor secure configurations |
| 8.10 Information deletion | Delete information when it is no longer required |
| 8.11 Data masking | Mask data in line with access policy and legal requirements |
| 8.12 Data leakage prevention | Apply measures to systems, networks and devices that handle sensitive data |
| 8.16 Monitoring activities | Monitor networks, systems and applications for anomalous behaviour |
| 8.23 Web filtering | Manage access to external websites to reduce exposure to malicious content |
| 8.28 Secure coding | Apply secure coding principles to software development |
The transition window has now closed. Under the International Accreditation Forum’s mandatory document IAF MD 26, the transition period ended on 31 October 2025, and certificates based on the 2013 edition expired or were withdrawn at that point. In 2024 ISO also published Amendment 1, which added climate change considerations to clauses 4.1 and 4.2 but did not change Annex A.
Common mistake: relabelling old 2013 controls with new numbers and calling the job done. Auditors tend to probe the new controls, particularly threat intelligence, cloud services, configuration management and monitoring, precisely because a relabelled SoA often has little evidence behind them.
Are all Annex A controls mandatory?
No. Clauses 4 to 10 are mandatory for certification. Annex A controls are mandatory to consider, not to implement. Each one must appear in your Statement of Applicability with a decision and a justification.
A control can be excluded when your risk assessment shows it is not needed and no legal, regulatory or contractual requirement demands it. A fully remote company with no offices may, for example, justify excluding some physical controls, although it will still need to address home working (6.7) and equipment off premises (7.9). The reverse also applies: Annex A is not exhaustive, so you can add controls from sector rules, customer contracts or other frameworks.
The Statement of Applicability is where these decisions are recorded, as our ISO 27001 Statement of Applicability guide explains. Before an audit, a structured compliance assessment against all 93 controls is a quick way to spot missing justifications or evidence.
How do you select and implement Annex A controls?
Control selection should follow your risk treatment, not precede it. A sequence that works well:
- Fix the ISMS scope. Decide which locations, business units, systems and services are in scope.
- Run the risk assessment. Identify risks to the confidentiality, integrity and availability of in-scope information, and evaluate them against your risk criteria. A structured risk management module keeps risks, owners and treatment decisions linked.
- Decide treatment and draft controls. For each risk you treat, identify the controls needed, whether they come from Annex A or elsewhere.
- Compare with Annex A. Walk through all 93 controls and confirm nothing necessary is missing. Record inclusion and exclusion reasons.
- Assign owners and evidence. Every included control needs an owner, a description of how it operates and the evidence that proves it.
- Write or update policies. Control 5.1 expects an information security policy and topic-specific policies. Keep them short, approved and versioned, ideally in a policy management workflow that tracks approvals.
- Test and monitor. Internal audit (clause 9.2) and management review (clause 9.3) should confirm the controls operate.
If your team is already juggling ISO 27001 with SOC 2, NIS2 or DORA, it pays to map controls once and reuse the evidence. You can see how that works in Enactia’s Compliance Universe: start your 14-day free trial, no credit card needed.
Which Annex A controls do auditors look at most closely?
Every audit is different, but some controls reliably attract questions because evidence is often thin:
- 5.9 Inventory of information and other associated assets. Is it complete, owned and current?
- 5.15 to 5.18 Access control, identity management, authentication information and access rights. Are joiner, mover and leaver processes working, and are access reviews done?
- 5.19 to 5.23 Supplier and cloud security. Are suppliers assessed, contracts updated and cloud exit plans considered?
- 5.24 to 5.28 Incident management. Is there a tested plan, and is evidence collected properly?
- 8.8 Management of technical vulnerabilities. Are patching timelines defined and met?
- 8.13 Information backup. Are restores tested, not just backups taken?
- 8.15 and 8.16 Logging and monitoring. Are logs reviewed, and do alerts lead to action?
In practice: for each of these controls, prepare one short evidence pack: the policy or procedure, a record showing the control operating (a ticket, a review sign-off, a restore test log) and the name of the owner who can explain it.
How do Annex A controls map to NIS2, DORA and other frameworks?
Annex A overlaps heavily with other security frameworks, which is why ISO 27001 is often used as a backbone. NIS2’s Article 21 risk management measures, for example, cover areas such as incident handling, business continuity, supply chain security, access control and cryptography that all have Annex A counterparts. We explored the detail in our article on mapping NIS2 to ISO 27001:2022.
Overlap is not equivalence, though. NIS2 adds management body accountability and strict reporting timelines, and DORA adds detailed ICT third-party contract and testing requirements. A good mapping shows both reuse and the remaining gaps.
Annex A readiness checklist
Use this before a certification or surveillance audit:
- ISMS scope is documented and matches the SoA.
- All 93 Annex A controls appear in the SoA with a status and justification.
- Every included control traces back to at least one risk, legal requirement or contract.
- Every exclusion has a specific reason, not a generic “not applicable”.
- The 11 new 2022 controls have real evidence, not placeholders.
- Each control has a named owner and a current evidence record.
- Topic-specific policies are approved, versioned and communicated.
- Internal audit has sampled controls across all four themes in the last cycle.
- Management review minutes show decisions on risks and controls.
- Nonconformities from previous audits are closed or tracked.
Key takeaways
- ISO 27001:2022 Annex A contains 93 controls in four themes: organisational, people, physical and technological.
- Controls are selected through risk treatment and recorded in the Statement of Applicability; they are not a mandatory checklist.
- ISO/IEC 27002:2022 provides the implementation guidance and five optional attributes for each control.
- The transition from the 2013 edition ended on 31 October 2025, so certificates now rest on the 2022 control set.
- Good evidence and named owners matter more to auditors than long policy documents.
Frequently asked questions
How many controls are in ISO 27001 Annex A?
ISO/IEC 27001:2022 Annex A contains 93 controls. They are grouped into four themes: 37 organisational controls, 8 people controls, 14 physical controls and 34 technological controls. The previous 2013 edition had 114 controls in 14 domains, and many of those were merged into single controls in the 2022 revision rather than removed.
Do I have to implement every Annex A control?
No. You must consider every Annex A control, but you only implement those your risk assessment and your legal, regulatory and contractual obligations require. Each control must still appear in the Statement of Applicability with a clear justification for including or excluding it, and auditors will test that those reasons are credible.
What is the difference between ISO 27001 Annex A and ISO 27002?
Annex A lists the 93 controls with a brief statement of what each control should achieve. ISO/IEC 27002:2022 covers the same controls in far more depth, adding a purpose, implementation guidance and optional attributes. You certify against ISO 27001; ISO 27002 is guidance that helps you implement the controls well.
Can I add controls that are not in Annex A?
Yes. ISO 27001 recognises that Annex A is not exhaustive. You can add controls from sector regulations, customer contracts or other frameworks such as NIST SP 800-53 when your risks call for them. List these additional controls in your Statement of Applicability with the same justification and status information as Annex A controls.
Are 2013 Annex A certificates still valid?
No. The IAF transition rules set 31 October 2025 as the end of the transition period, and certificates issued against ISO/IEC 27001:2013 expired or were withdrawn at that date. Organisations that are certified today should be operating an ISMS and Statement of Applicability built around the 2022 Annex A controls.
Turning Annex A into a working control set
Annex A works best when it is treated as a check on your own risk decisions rather than a list to tick. Start with scope and risk, select controls with clear reasons, give each one an owner and evidence, and review them through internal audit and management review. That approach produces an SoA an auditor can follow and a control set your organisation can actually run.
If you want to manage ISO 27001 alongside other frameworks in one place, see how Enactia supports ISO 27001 with Enactia’s AI-powered GRC platform. Contact us with questions, or book a demo or start your 14-day free trial.
