ISO 27001:2022 Annex A Controls Explained (All 93 Controls)
ISO 27001:2022 Annex A Controls is where every ISO 27001:2022 project eventually lands. It’s the 93-control catalogue your entire ISMS gets measured against — your risk assessment points into it, your Statement of Applicability documents every decision made against it, and your Stage 1 and Stage 2 auditors test it control by control. Most teams aren’t confused by any single control; they’re overwhelmed by the list as a whole — four themes, dozens of unfamiliar codes, and no obvious place to start. This guide walks through all 93 controls, theme by theme, in plain language, so you know exactly what each one expects from your organization before an auditor asks.
Quick answer ISO 27001:2022 Annex A Controls split across four themes: Organizational (37), People (8), Physical (14), and Technological (34). You don’t implement all 93— you select the ones your risk assessment justifies, and record every decision (include or exclude) in your Statement of Applicability.
What Is Annex A, Exactly?
ISO 27001:2022 Annex A Controls is a reference catalogue, not a checklist. Clauses 4 through 10 of ISO 27001 set out the mandatory requirements for running an ISMS — that’s the ‘what.’ Annex A is the ‘how’: a menu of 93 possible safeguards you draw from once your risk assessment tells you which risks need treating. The detailed how-to guidance for each control actually lives in a companion standard, ISO/IEC 27002:2022 — Annex A gives you the control name and its intent, ISO 27002 tells you how to implement it well.
The 2022 revision reorganized Annex A significantly. The old 2013 structure spread 114 controls across 14 domains (A.5 through A.18). The 2022 version consolidated that down to 93 controls across just four themes, merging overlapping controls and adding 11 entirely new ones to address risks the 2013 version never anticipated — cloud services, threat intelligence, and data masking among them.
The Four Themes at a Glance
| Theme | Range · Count · Focus |
|---|---|
| A.5 — Organizational | 5.1–5.37 · 37 controls · Policies, roles, and governance that apply across the whole business |
| A.6 — People | 6.1–6.8 · 8 controls · Screening, training, and other human-factor safeguards |
| A.7 — Physical | 7.1–7.14 · 14 controls · Protecting premises, equipment, and physical media |
| A.8 — Technological | 8.1–8.34 · 34 controls · Access control, cryptography, secure development, and network security |
Important context : B4Q Assurance builds Statements of Applicability with clients as part of every ISO 27001:2022 engagement. The theme structure below reflects how we actually group and prioritize controls during gap analysis — not just the raw standard text.
Organizational Controls — A.5 (37 Controls)
Organizational controls form the governance backbone of the ISMS. They’re less about specific technology and more about policy, ownership, and process — who’s accountable, how suppliers are managed, how incidents get handled, and how the organization proves it’s actually doing what it says. Auditors typically start here because a weak Statement of Applicability or missing policy at this layer tends to predict gaps everywhere else.
A few of these deserve special attention during a first-time certification. Inventory of assets (5.9) and access rights (5.18) are the two most commonly cited gaps in Stage 1 audits — organizations often haven’t formally documented what they own or who can touch it. Supplier-related controls (5.19–5.22) have also grown in weight since 2022, as auditors increasingly expect evidence that vendor risk is actively managed, not just mentioned in a contract clause.
People Controls — A.6 (8 Controls)
The smallest theme by control count, but arguably the highest-risk one in practice — most breaches trace back to a person, not a piece of technology. These eight controls cover the employee lifecycle end to end: screening before hire, training during employment, and clearly defined obligations after someone leaves.
Auditors routinely interview staff during Stage 2 specifically to test these controls — it’s not enough for a security awareness policy to exist on paper if the person answering questions can’t explain what it means for their own job.
Physical Controls — A.7 (14 Controls)
Physical controls protect the tangible side of information security: buildings, server rooms, hardware, and media. Even fully cloud-based companies need to address most of these — laptops, home offices, and off-site equipment all fall under this theme.
Remote-first companies sometimes assume this theme doesn’t apply to them. It still does — off-premises asset security (7.9) and clear desk practices (7.7) apply just as much to a laptop at someone’s kitchen table as they do to an office.
Technological Controls — A.8 (34 Controls)
The largest and most technical theme, covering the digital perimeter end to end — endpoint devices, access management, cryptography, network security, and the entire secure development lifecycle. Engineering and IT teams will own most of the evidence collection for this section.
Six of the eleven controls added in 2022 sit in this theme alone (configuration management, information deletion, data masking, data leakage prevention, monitoring activities, and web filtering) — a clear signal of where the standard’s authors saw the biggest gaps in the old 2013 control set.
How Organizations Actually Use ISO 27001:2022 Annex A Controls
The Statement of Applicability (SoA)
The SoA is the document auditors scrutinize most closely. For every one of the 93 controls, it records whether the control applies, why, its implementation status, and — for any control marked as excluded — the justification for leaving it out. A rushed or generic SoA (“included” copy-pasted 93 times with no rationale) is one of the fastest ways to trigger Stage 1 findings.
Common mistake :Treating Annex A as a checklist to tick off in order, rather than letting the risk assessment drive selection. Auditors can tell the difference between a control that was implemented because a real risk demanded it and one that was implemented because it was next on the list.
The 11 New Controls Introduced in 2022
If your organization is transitioning from a 2013 certificate, these are the controls that didn’t exist before and will need fresh evidence — they can’t simply be carried over from an old audit file.
| Control | Title (Theme) |
|---|---|
| A.5.7 | Threat intelligence — Organizational |
| A.5.23 | Information security for use of cloud services — Organizational |
| A.5.30 | ICT readiness for business continuity — Organizational |
| A.7.4 | Physical security monitoring — Physical |
| A.8.9 | Configuration management — Technological |
| A.8.10 | Information deletion — Technological |
| A.8.11 | Data masking — Technological |
| A.8.12 | Data leakage prevention — Technological |
| A.8.16 | Monitoring activities — Technological |
| A.8.23 | Web filtering — Technological |
| A.8.28 | Secure coding — Technological |
How B4Q Assurance Helps
B4Q Assurance works with organizations at every stage of mapping Annex A to their actual risk profile — running the gap analysis, building the Statement of Applicability, and preparing the evidence auditors expect to see for both Stage 1 and Stage 2. Rather than treating all 93 controls as equally urgent, we help clients prioritize the controls their specific risk assessment and customer contracts actually demand.
Ready to Map Your Own ISO 27001:2022 Annex A Controls ?
A short gap assessment against these 93 controls is usually the fastest way to see exactly where your ISMS stands today.
Next step :Book a free strategy call with B4Q Assurance to scope your Annex A gap assessment and Statement of Applicability
Resources
ISO — ISO/IEC 27001:2022 (Official Standard) https://www.iso.org/standard/27001.html
ISO/IEC 27002:2022 (Implementation Guidance for Annex A Controls) https://www.iso.org/standard/75652.html
ISO/IEC 27005:2022 (Information Security Risk Management) https://www.iso.org/standard/80585.html
ISO/IEC 27000:2018 (Overview and Vocabulary for ISMS) https://www.iso.org/standard/73906.html
FAQS
Do we have to implement all 93 Annex A controls?
No. You implement the controls your risk assessment justifies, and document any exclusions with a clear reason in your Statement of Applicability. Annex A is a risk-based menu, not a mandatory list.
What's the difference between Annex A and ISO 27002?
Annex A lists the control names and their intent. ISO/IEC 27002:2022 is the companion standard that provides detailed implementation guidance for each of those same controls.
How many controls were added in the 2022 update?
Eleven new controls were introduced, covering areas like threat intelligence, cloud services, configuration management, and data masking — topics the 2013 version didn’t address.
Which theme has the most controls?
Technological controls (A.8), with 34. Organizational controls (A.5) is close behind with 37 — technically the largest by count, though Technological is often the most resource-intensive to implement.
Is a 2013-based Statement of Applicability still valid?
No. Certificates issued against the 2013 version expired after 31 October 2025. Any current SoA needs to be built against the 2022 structure and its 93 controls.