
ISO 27001:2022 Annex A lists 93 information security controls grouped into four themes: organizational (37), people (8), physical (14), and technological (34). Organizations don’t have to implement every control — they select applicable ones through a risk assessment and document the decision in a Statement of Applicability (SoA). This guide explains what each control covers, in plain language, so you know exactly what your ISMS needs to address.
ISO 27001:2022 replaced the old 114-control structure from the 2013 version with a leaner set of 93 controls. Fourteen groups of overlapping controls were merged, and 11 entirely new controls were added to address threat intelligence, cloud security, and data protection practices that didn’t exist a decade ago. The four-theme structure (organizational, people, physical, technological) replaced the old 14-domain layout, making the controls easier to map against real operational functions rather than abstract clause numbers.
Organizations certified under ISO 27001:2013 had until October 2025 to transition to the 2022 version. If your certification body hasn’t already walked you through a gap assessment against the new control set, that’s the first step before your next audit cycle.
Annex A itself is not a checklist you tick off line by line. Clause 6.1.3 of the main ISO 27001 standard requires you to run a risk assessment, decide which controls address your identified risks, and record the outcome — including any controls you exclude and why — in a Statement of Applicability. Auditors use the SoA as the master reference during certification audits, cross-checking it against your risk treatment plan and the actual evidence in place for each selected control.
Most certified organizations end up applying the large majority of the 93 controls in some form, since the four themes map closely to standard operational areas: governance, HR, facilities, and IT. Full exclusions are less common than partial ones, where a control applies in scope but at a reduced level (for example, a fully cloud-based company implementing A.7.1 through a colocation provider’s physical controls rather than its own).
Organizational controls form the governance backbone of the ISMS — policy, roles, supplier management, incident response, and business continuity. This is the largest theme, with 37 controls, because it covers everything that isn’t a specific technical, physical, or people-related mechanism.
People controls cover the human side of the ISMS — screening, contracts, training, discipline, remote work, and incident reporting. Auditors weight this theme heavily because most breaches trace back to human error or insider risk rather than technical failure.
Physical controls protect information in the real world — perimeters, entry points, secure areas, equipment, and media. Even fully remote organizations need to address this theme, typically through data center and device-level controls rather than office security.
Technological controls are the largest theme after organizational, covering endpoints, access management, cryptography, secure development, and network security. This is where most of the 2022 revision’s new additions landed, reflecting how much IT risk has shifted since 2013.
Do I need to implement all 93 Annex A controls?
No. ISO 27001 requires a risk assessment that determines which controls apply to your organization. Controls not relevant to your risk profile can be excluded, provided the exclusion is justified and documented in your Statement of Applicability.
How many Annex A controls are new in ISO 27001:2022?
Eleven controls are new: threat intelligence, cloud security, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
What’s the difference between Annex A controls and the main ISO 27001 clauses?
Clauses 4–10 define the mandatory management system requirements — context, leadership, planning, support, operation, evaluation, and improvement. Annex A is a reference set of controls you draw from when your risk assessment calls for them; it doesn’t set requirements on its own.
Where do Annex A controls appear in a certification audit?
Auditors check your Statement of Applicability against your risk treatment plan, then sample evidence for the controls you’ve marked as applicable — policies, logs, records, and interviews confirming the control operates as documented.
How many controls are in each Annex A theme?
Organizational has 37 controls, people has 8, physical has 14, and technological has 34 — a total of 93 across all four themes.
What replaced the 114 controls from ISO 27001:2013?
The 2022 revision consolidated overlapping 2013 controls into 93 controls and reorganized them from 14 domains into four themes. Most 2013 controls map directly to a 2022 equivalent, with 11 genuinely new additions.
Is a Statement of Applicability mandatory for certification?
Yes. Clause 6.1.3(d) requires a documented Statement of Applicability covering every Annex A control, whether included or excluded, with justification for each decision.
Can a small business exclude most technological controls?
Only if a risk assessment genuinely supports it. Auditors expect exclusions to follow from documented risk analysis, not company size alone — most small businesses still apply the majority of technological controls in some scaled-down form.
Which Annex A controls do auditors flag most often during certification?
Access rights review (A.5.18), vulnerability management (A.8.8), logging (A.8.15), and supplier agreements (A.5.20) are common gap areas, usually due to inconsistent evidence rather than missing policy.
Do cloud-only companies still need physical controls?
Yes, but typically through their cloud provider’s controls rather than owned infrastructure. Controls like A.7.1 through A.7.14 still apply to the environment processing your data — you just rely on provider attestations and contracts as evidence.
How long does it take to implement all applicable Annex A controls?
Most first-time certifications take three to six months from gap assessment to audit-ready, depending on how many controls require new documentation, tooling, or process change versus controls already partially in place.
Does ISO 27001:2013 certification remain valid after the 2022 transition deadline?
No. Organizations certified under the 2013 version needed to transition to ISO 27001:2022 by October 2025; certificates issued against the older version are no longer valid for new audits.
Talk to a certification consultant about your Annex A scope — request a custom quote based on your systems, team size, and industry, with no fixed pricing tiers to work around.
QCert360 provides a wide range of services including ISO certification, audit support, compliance consulting, and training. They specialize in helping businesses achieve global standards and certifications like ISO 9001, ISO 27001, ISO 14001, and many others. Their team ensures a seamless experience from consultation to certification, supporting clients at every stage.
The time it takes to achieve certification can vary depending on the complexity of the standard and the readiness of your organization. On average, it takes about 3 to 6 months. QCert360 works closely with clients to streamline the process, ensuring that all requirements are met efficiently and within a reasonable timeline.
QCert360 is a trusted partner with years of experience in helping businesses obtain international certifications. Their expert consultants provide tailored solutions, ensuring your organization not only meets but exceeds industry standards. With a customer-centric approach, they focus on offering end-to-end support to simplify the certification journey.
QCert360 serves a wide range of industries including manufacturing, healthcare, information technology, education, and services, among others. They customize their certification solutions to meet the unique requirements of each industry, ensuring relevance and compliance with global standards.
Yes, QCert360 provides ongoing support even after certification. They offer services like surveillance audits, recertification guidance, and consultancy to help maintain and improve your certification status. Their team ensures that your organization stays compliant and up-to-date with any changes in certification standards.
Getting started with QCert360 is simple. You can contact them via their website to request a consultation. Their team will assess your needs, discuss the best certification options for your business, and outline the steps involved. From there, they’ll guide you through the entire process, ensuring you’re prepared for certification.
QCert360 stands out due to its customer-focused approach, industry expertise, and comprehensive service offerings. Their team doesn’t just help you obtain certification but works to ensure your organization thrives in compliance with international standards. They also offer personalized consultation, making the process smoother and more efficient, ensuring long-term success for your business.
The cost of certification varies depending on factors such as the type of certification, the size and complexity of your organization, and the specific industry requirements. QCert360 offers competitive pricing and provides tailored quotes based on your unique needs. They ensure transparency and work with you to find the most cost-effective solution for your certification goals.
Yes, QCert360 offers internal audit services to help assess and improve your organization’s processes. Their expert auditors conduct thorough reviews of your systems and operations to ensure they meet required standards. They also provide actionable recommendations to help enhance efficiency and compliance, making sure you’re fully prepared for external audits.
If your organization doesn’t pass an audit or certification assessment, QCert360 works with you to understand the reasons for non-compliance and provides support to rectify the issues. They offer guidance on corrective actions and help you prepare for a re-assessment. Their goal is to ensure your organization meets the necessary standards for certification, and they will be by your side to make the process as smooth as possible.
Posted on Google![]()
Parveen NandaTrustindex verifies that the original source of the review is Google.
They helped us with international standards consulting , which enabled us to expand globally with confidence.”Posted on Google![]()
Meenu NandaTrustindex verifies that the original source of the review is Google.
Their management consulting team provided us with actionable insights that transformed our business strategy.Posted on Google![]()
Navya NandaTrustindex verifies that the original source of the review is Google.
We achieved RoHS compliance consulting with their expert help, ensuring we met environmental regulations.Posted on Google![]()
Pawan KumarTrustindex verifies that the original source of the review is Google.
Their ISO Certification Services are reliable, efficient, and tailored to our industry-specific needs.Posted on Google![]()
FronterrorTrustindex verifies that the original source of the review is Google.
They guided us through CCPA compliance consulting - very Professional and attentive to our needs.Posted on Google![]()
Saarthak Gulati 24-773Trustindex verifies that the original source of the review is Google.
The Team's support for HACCP certification was detailed & thorough, making the complex process manageable for our food Business.Posted on Google![]()
Arushi SinghTrustindex verifies that the original source of the review is Google.
I visited for PIPEDA Certification and it was seamless.Posted on Google![]()
Arushi STrustindex verifies that the original source of the review is Google.
I recommend their international standards consulting.Posted on Google![]()
Palkesh GargTrustindex verifies that the original source of the review is Google.
Their management consulting firm gave us fresh insights.Posted on Google![]()
Sanjana ChauhanTrustindex verifies that the original source of the review is Google.
Their SOC compliance services are excellent.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more
Qcert360 is a specialized solutions and services provider, focusing on ISO Certification, management consulting, training programs, assessments, & managed services.
Copyright © 2018-2026 Qcert360. All rights reserved. Developed by Qcert360.
Fill out the form to get your project cost within 1 hour