Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 Annex A controls explained - the four themes and the 93 controls in the 2022 version

ISO 27001 Annex A Controls Explained (2022)

The ISO 27001 Annex A controls are where the standard becomes concrete. Annex A lists the security controls you select to treat your information risks, and understanding them is essential to building an ISMS that will pass certification. This guide explains what the controls are, how the 2022 version organises them, and how to choose the right ones.

ISO 27001 Annex A controls explained - the four themes and the 93 controls in the 2022 version

For the full picture, see our complete ISO 27001 guide.

What are the ISO 27001 Annex A controls?

Annex A is a reference set of information security controls that support the requirements in the main body of ISO 27001. In the 2022 version there are 93 controls, each addressing a specific area of risk — from access control and cryptography to incident management and supplier relationships. You do not implement all of them by default; you select the controls that treat your assessed risks and justify your choices in the Statement of Applicability.

The four control themes

ISO 27001:2022 groups the Annex A controls into four themes, which makes them far easier to navigate than the older domain structure:

  • Organizational controls (37) — policies, roles, supplier management, threat intelligence, and information handling.
  • People controls (8) — screening, awareness, responsibilities, and conduct.
  • Physical controls (14) — secure areas, equipment, and physical entry.
  • Technological controls (34) — access control, cryptography, logging, secure development, and network security.

Together these themes cover the full spectrum of information security, from governance to the server room.

What changed in the 2022 update

ISO 27001:2022 restructured Annex A, reducing the count from 114 controls to 93 by merging overlapping items and grouping them into the four themes above. It also introduced new controls reflecting modern risks — such as threat intelligence, information security for cloud services, data masking, and secure coding. Organizations certified against the older version transition to the 2022 controls at their next surveillance or recertification cycle.

How to select and apply the controls

Selection is risk-based. You assess your information security risks, decide which Annex A controls treat them, and record the decision — including any controls you exclude and why — in the Statement of Applicability. This keeps the effort proportionate: a small SaaS company will apply a different mix than a large financial institution. The Statement of Applicability is one of the first documents an auditor reviews, so the reasoning behind your selection must be clear and defensible.

Every Annex A control, ready to apply.

Our ISO 27001 Toolkit includes a document for every Annex A control across all four themes plus a pre-built Statement of Applicability — mapped to ISO 27001:2022 and editable in Word and Excel.

Explore the ISO 27001 Toolkit →

Frequently asked questions

How many Annex A controls are in ISO 27001:2022?

There are 93 controls, grouped into four themes: organizational (37), people (8), physical (14), and technological (34).

Do I have to implement every ISO 27001 control?

No. ISO 27001 is risk-based. You apply the controls relevant to your assessed risks and justify inclusions and exclusions in the Statement of Applicability.

What changed in the ISO 27001:2022 Annex A?

The controls were reduced from 114 to 93, reorganised into four themes, and updated with new controls such as threat intelligence, cloud security, data masking, and secure coding.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.