NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
ISO 27001 Annex A: The 93 Controls Explained (2022)
Learn

ISO 27001 Annex A: The 93 Controls Explained (2022)

·Alexander Sverdlov
ISO 27001:2022 Annex A: the four control themes and 93 controls

The ISO 27001 Annex A controls are the catalogue of information security safeguards that sit at the heart of the world's most widely recognised standard for an Information Security Management System (ISMS). If you are a CISO scoping a certification project, a compliance manager preparing for an audit, or a founder being asked for an ISO 27001 certificate by an enterprise buyer, this guide answers the practical questions: what Annex A actually contains, why the 2022 revision cut the count from 114 to 93, which controls you are obliged to apply, and how the Statement of Applicability turns a generic list into a defensible security programme tailored to your organisation.

What ISO 27001 Annex A is

ISO/IEC 27001 is the international standard that specifies the requirements for establishing, operating, maintaining and continually improving an ISMS. The main body of the standard (Clauses 4 to 10) is where the binding requirements live: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A is a normative annex attached to that main body. It is a reference list of information security controls that an organisation draws on to treat the risks it has identified.

The important nuance is that Annex A is a menu, not a checklist you must complete in full. The detailed implementation guidance for each control does not live in ISO 27001 itself; it lives in the companion standard ISO/IEC 27002:2022, which describes the purpose of each control and how to apply it. Annex A gives you the short titles and control statements; ISO 27002 gives you the depth. Together they let an auditor and an organisation speak the same language about what "good" looks like for each safeguard.

Who needs ISO 27001 and its Annex A controls

ISO 27001 is voluntary in the sense that no single law names it as mandatory for every company. In practice it has become close to compulsory for whole categories of organisations, driven by commercial pressure rather than statute. If any of the following describe you, Annex A is squarely in your future.

B2B software and cloud vendors

SaaS providers, managed service providers and data processors are the largest group pursuing certification. Enterprise procurement and security questionnaires increasingly treat an ISO 27001 certificate as the entry ticket to a deal. Winning a large customer often hinges on producing the certificate and, sometimes, the Statement of Applicability behind it.

Regulated and supply-chain-critical firms

  • Financial services and fintech, where regulators and banking partners expect a recognised security baseline.
  • Healthcare and health-tech, handling sensitive personal data at scale.
  • Public-sector suppliers, where tenders frequently make certification a scored or gating requirement.
  • Critical suppliers to larger enterprises, who inherit security obligations flowed down through contracts.

Organisations aligning multiple frameworks

Because the Annex A control set overlaps heavily with other regimes, many teams adopt ISO 27001 as their backbone and map everything else onto it. The overlap with SOC 2 is often cited at roughly 80 percent, so a company serving both European and US customers can build one control environment and evidence it against both. That crosswalk story is a major reason ISO 27001 is chosen even where no customer has explicitly demanded it.

ISO 27001 gap assessment against the Annex A controls
An ISO 27001 gap assessment scores the Annex A controls against your current state.

What ISO 27001 actually requires

A common misconception is that ISO 27001 is "the 93 controls". It is not. Certification is awarded against the management-system requirements in Clauses 4 to 10, and the controls are one input to that system. An organisation can implement every control on the list and still fail an audit if it has no working risk assessment, no management review, and no evidence that the ISMS is operating over time.

The core obligations run roughly like this. You define the scope of your ISMS and the context it operates in. Leadership commits to an information security policy and assigns responsibilities. You run a risk assessment to identify what could go wrong for the confidentiality, integrity and availability of your information, then a risk treatment process to decide how to address each risk. It is during risk treatment that you reach for Annex A: for every risk you choose to mitigate with a control, you select the relevant Annex A control (or a control of your own devising) and record why. You then operate those controls, monitor and measure their performance, conduct internal audits, hold management reviews, and act on nonconformities. The whole cycle is designed to be continual, not a one-off project.

Crucially, Annex A controls are not all mandatory. You are required to consider every control and decide whether it is applicable to your risks. A control can be excluded, but only with a documented justification. This is what keeps ISO 27001 usable for a ten-person startup and a multinational alike: the same catalogue scales because each organisation applies only what its own risk picture warrants.

The ISO 27001 ISMS certification cycle

The four Annex A themes and the Statement of Applicability

The 2022 revision was a significant restructure. The previous 2013 edition organised 114 controls into 14 domains. The 2022 edition consolidates and modernises the set into 93 controls grouped under four themes:

  • Organizational controls (37): policies, roles and responsibilities, supplier and cloud relationships, threat intelligence, incident management and business continuity governance.
  • People controls (8): screening, terms of employment, awareness and training, disciplinary process and responsibilities after leaving.
  • Physical controls (14): secure areas, equipment protection, clear desk and clear screen, and secure disposal.
  • Technological controls (34): access control, cryptography, logging and monitoring, secure development, network security and data leakage prevention.

The renumbering was not merely cosmetic. The revision merged overlapping controls and introduced 11 new controls that reflect how technology has changed, including threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. ISO 27002:2022 also added five "attributes" to each control (such as control type, security properties and cybersecurity concepts) to help organisations filter and cross-reference the set.

The document that ties all of this together is the Statement of Applicability (SoA). The SoA is a mandatory output of the ISMS. It lists every Annex A control, states whether you have applied it, describes how (or references where it is implemented), and justifies any exclusion. Auditors treat the SoA as the map of your control environment; it is often the first artefact a certification body asks to see. A well-maintained SoA is the difference between an audit that flows and one that stalls.

How to actually comply: a practical programme

  1. Define the scope. Decide which parts of the business, systems and locations the ISMS covers. A tight, honest scope is easier to certify and maintain than an over-ambitious one.
  2. Secure leadership and a policy. Get documented management commitment, an information security policy, and clear ownership. This is a Clause 5 requirement, not optional.
  3. Run a risk assessment. Identify information assets and the risks to them, then rate those risks with a consistent methodology you can repeat and defend.
  4. Produce the risk treatment plan. For each risk you choose to mitigate, select the relevant Annex A controls and record the decision.
  5. Write the Statement of Applicability. Go through all 93 controls, mark each as applicable or excluded, and justify every exclusion. This document evolves with the ISMS.
  6. Implement the selected controls. Put the policies, technical measures and processes in place, and start generating the evidence that shows they operate.
  7. Operate, monitor and audit internally. Collect metrics, run internal audits, and hold management reviews so nonconformities surface before an external auditor finds them.
  8. Engage an accredited certification body. A Stage 1 audit reviews your documentation and readiness; a Stage 2 audit tests whether the ISMS works in practice. The certificate is typically valid for three years, with annual surveillance audits and recertification at the end of the cycle.

Software helps you run steps three through seven: it centralises the risk register, generates and versions the SoA, maps evidence to controls, and keeps the ISMS auditable between assessments. It does not, and cannot, issue the certificate. Certification is always granted by an accredited certification body after an independent audit. Any tool that implies otherwise is misrepresenting how the standard works.

Reusing ISO 27001 and SOC 2 evidence through a crosswalk
ISO 27001 and SOC 2 overlap heavily; a crosswalk reuses the evidence once.

For a control-by-control view of how a single platform maps evidence to each Annex A control and maintains the Statement of Applicability, see how Venvera handles ISO 27001. If you are still choosing tooling, our overview of ISO 27001 compliance software compared walks through what to look for.

ISO 27001 by the numbers: 93 Annex A controls in four themes

Frequently Asked Questions

How many controls are in ISO 27001 Annex A?

The 2022 revision of ISO 27001 contains 93 Annex A controls, down from 114 in the 2013 version. They are grouped into four themes: 37 organizational, 8 people, 14 physical and 34 technological controls. The reduction came from merging overlapping controls, and the revision also introduced 11 genuinely new controls.

Are all 93 Annex A controls mandatory?

No. You are required to consider every control, but you only apply the ones your risk assessment shows are relevant. A control can be excluded provided you document a justification. Those applicability decisions are recorded in the Statement of Applicability, which is itself a mandatory part of the ISMS.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the certifiable standard: it sets the management-system requirements and lists the Annex A controls as short statements. ISO 27002 is the accompanying guidance that explains the purpose of each control and how to implement it. You certify against ISO 27001; you use ISO 27002 to understand and apply the controls in depth.

What is the Statement of Applicability?

The Statement of Applicability (SoA) is a mandatory document that lists all Annex A controls, states whether each one applies to your organisation, describes how applicable controls are implemented, and justifies any exclusions. Certification auditors rely on it as the map of your control environment, so it is often the first document they request.

How does ISO 27001 relate to SOC 2?

The two frameworks address the same underlying security concerns and their control sets overlap substantially, with the overlap often estimated at around 80 percent. Many organisations serving both European and US customers build a single control environment and evidence it against both ISO 27001 and SOC 2, which reduces duplicated effort considerably.

How long is an ISO 27001 certificate valid?

A certificate issued by an accredited certification body is typically valid for three years. During that period you undergo annual surveillance audits to confirm the ISMS is still operating, and a recertification audit at the end of the cycle to renew for another three years. The certificate comes from the certification body, never from software.

Primary sources

  • ISO/IEC 27001:2022 - the standard defining the requirements for an ISMS, including Annex A. ISO 27001 at iso.org.
  • ISO/IEC 27002:2022 - the control guidance describing the purpose and implementation of each Annex A control. ISO 27002 at iso.org.

Scope note. This article summarises the structure of ISO 27001 and its Annex A for orientation. Control counts and requirements should be confirmed against the official ISO standards, and your applicability decisions should reflect your own risk assessment and your certification body's guidance.

Run your ISO 27001 ISMS in one place

Venvera maps all 93 Annex A controls to your evidence natively, generates and versions your Statement of Applicability, and keeps the ISMS audit-ready between surveillance audits, at flat pricing from EUR 399/month with EU data residency. See the ISO 27001 module.

By Alexander Sverdlov, CEO and Founder, Venvera. Published 20 July 2026 - Last reviewed 20 July 2026.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS