iso27001partnersUK certification, costed Get a cost estimate

The Annex A controls, by theme

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 9 min read
4 primary sources cited on this page. How we check what is on this site
ISO/IEC 27001:2022 93 controls, four themes

The withdrawn ISO/IEC 27001:2013 had 114 in 14 clauses. The count fell because controls were merged, not because requirements were removed — 11 of the 93 did not exist at all before 2022.

Two things are worth settling before the list. The edition year belongs with every control count, because both numbers are still in circulation. And Annex A is not what you are certified against — clauses 4 to 10 are. Annex A is the reference set you check your risk treatment against.

Annex A controls by theme, 2022 edition against 2013 A proportional bar split into four themes totalling 93 controls in the 2022 edition, above a bar showing the 114 controls of the withdrawn 2013 edition for comparison. ISO/IEC 27001:2022 — Annex A: 93 controls, four themes Each block is drawn in proportion to the number of controls it holds. 37 Organisational A.5 8 People A.6 14 Physical A.7 34 Technological A.8 ISO/IEC 27001:2013 — Annex A: 114 controls, 14 clauses 114 controls, withdrawn — certificates against this edition expired on 31 October 2025 11 of the 93 are genuinely new. The rest are the 2013 controls merged and rewritten — the count fell because controls were combined, not because requirements were dropped.
Always ask which edition a control count belongs to. A document that says “114 controls” today was written before October 2022 and has not been revisited since.
The same diagram as a table
Annex A control counts, by edition
ThemeReferenceControlsCovers
OrganisationalA.537Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed.
PeopleA.68Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working.
PhysicalA.714Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring.
TechnologicalA.834Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about.
ISO/IEC 27001:2022 total93Four themes
ISO/IEC 27001:2013 total114 14 clauses, A.5 to A.18. Withdrawn.

The four themes

ISO/IEC 27001:2022 Annex A, by theme
ThemeReferenceControlsWhat sits in it
OrganisationalA.537Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed.
PeopleA.68Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working.
PhysicalA.714Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring.
TechnologicalA.834Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about.

The arrangement is the headline change from 2013, where the controls sat in 14 clauses numbered A.5 to A.18. The four themes are easier to allocate to owners, which matters more than it sounds: most of the practical failure in an ISMS is a control that nobody thinks belongs to them.

Each control also carries attributes in ISO/IEC 27002:2022 — control type, information security properties, cybersecurity concepts, operational capabilities and security domains — which exist so you can slice the set in whatever way suits your organisation. They are a navigation aid, not a requirement, and no auditor will ask you to have used them.

The 11 genuinely new controls

These have no counterpart in the 2013 edition. If your management system was built before October 2022 and has not been revisited since, this is the list to start from.

Controls introduced in ISO/IEC 27001:2022
ReferenceControlWhy it is new
A.5.7Threat intelligenceThe 2013 edition had nothing about knowing what is being used against you. Expect to be asked what sources you use and what you do with what they tell you.
A.5.23Information security for use of cloud servicesCloud was treated as ordinary supplier risk in 2013. It now has its own control covering acquisition, use, management and exit.
A.5.30ICT readiness for business continuityBusiness continuity for the technology, separately from business continuity in general.
A.7.4Physical security monitoringThe physical counterpart to logging. Monitoring of premises for unauthorised access.
A.8.9Configuration managementConfigurations have to be established, documented, implemented, monitored and reviewed. In practice this is where infrastructure-as-code earns its keep.
A.8.10Information deletionDeleting information when it is no longer required — which is also a data protection obligation, so the two usually get evidenced together.
A.8.11Data maskingMasking in line with access control policy. Most often relevant to non-production environments containing real data.
A.8.12Data leakage preventionDetecting and preventing unauthorised disclosure. Rarely satisfied by buying a product.
A.8.16Monitoring activitiesNetworks, systems and applications monitored for anomalous behaviour, with defined responses.
A.8.23Web filteringManaging which external sites can be reached, to reduce exposure to malicious content.
A.8.28Secure codingSecure coding principles applied to software development. The control most often under-evidenced by teams that genuinely do it well.

Where the count went

11 new, 24 formed by merging controls from the 2013 edition, and 58 updated. That is 93. A smaller number of controls describing more ground is a reorganisation, not a relaxation.

Annex A is not a checklist, and treating it as one is expensive

The sequence the standard actually sets out runs the other way from the one most teams assume. You assess risk (clause 6.1.2), decide how to treat it (6.1.3), and then compare the controls your treatment produced against Annex A to verify that nothing necessary was overlooked. Annex A is the cross-check, not the starting point.

Clause 6.1.3 d) then asks for a Statement of Applicability containing the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A control you left out. That last part is the one organisations under-do. “Not applicable” is a conclusion; the standard asks for the reasoning that produced it.

There is a commercial consequence. Approaching the standard as 93 controls to implement produces an enormous amount of unnecessary work and an ISMS that does not reflect what your organisation actually risks. It is also how a consultancy engagement gets quoted at a size nobody needed.

What auditors sample, and what they find

The controls that produce findings are rarely the exotic ones. They are the ones where the activity is real but the evidence is not:

  • Monitoring activities (A.8.16) — the alerting exists, but nobody can show what was reviewed, by whom, or what happened next.
  • Configuration management (A.8.9) — configurations are managed in practice, but not documented, monitored and reviewed in a way that can be sampled. Teams running everything as code are usually closest to compliant and furthest from evidencing it.
  • Secure coding (A.8.28) — review happens on every pull request, and there is no stated principle, no record of training, and nothing tying it to the control.
  • Supplier controls (A.5.19 to A.5.23) — a folder of supplier certificates that nobody has checked for expiry or scope. Since certificates against the withdrawn edition expired on 31 October 2025, that folder is worth a pass.
  • Physical controls in a remote-first company (A.7) — waved away rather than reasoned about. Homes and devices are premises for this purpose, and the exclusions need the same justification as everything else.

Annex A, ISO 27002, and which one to buy

Annex A gives you the control titles and a line each. ISO/IEC 27002:2022, Information security controls is a separate standard covering the same controls at length: purpose, implementation guidance and other information for each one. You are certified against ISO 27001; ISO 27002 is what your team reads when working out what a control means in your context.

Neither is free. If you are buying one to start with, buy ISO 27001, because it contains the clauses you are actually audited against. ISO 27002 becomes worth having once somebody is doing the implementation work and arguing about what “adequate” means.

Where to go next

Common questions

How many controls does ISO 27001 have?

ISO/IEC 27001:2022 lists 93 controls in Annex A, arranged in four themes: organisational (37), people (8), physical (14), technological (34). The withdrawn ISO/IEC 27001:2013 had 114 in 14 clauses numbered A.5 to A.18. Always attach the edition to the number: a document that says 114 today was written before October 2022 and has not been revisited.

Did the 2022 edition remove requirements?

No. The count fell from 114 to 93 because controls were merged, not dropped. Of the 93, 11 are genuinely new, 24 were formed by merging controls from the 2013 edition, and 58 are updated versions of existing ones. The scope of what is expected went up, not down — threat intelligence, cloud services, secure coding and data leakage prevention were not there before.

Do we have to implement all of them?

No, and a Statement of Applicability that applies all 93 without reasoning is as much of a finding as one that excludes too many. Annex A is a reference set. Clause 6.1.3 requires you to compare the controls your risk treatment produced against Annex A to check you have not missed anything, then produce a Statement of Applicability giving the justification for inclusions and for exclusions. The reasoning is the deliverable, not the count.

What is the difference between ISO 27001 Annex A and ISO 27002?

Annex A of ISO/IEC 27001 gives the control titles in one page each, as a reference set to check your risk treatment against. ISO/IEC 27002:2022 is the separate, much longer standard that explains each of the same controls: purpose, guidance and other information. You are certified against ISO 27001. ISO 27002 is what your team reads when deciding what a control actually means in your organisation.

Which controls do organisations most often get wrong?

From the shape of the standard rather than any survey: the ones requiring evidence of an ongoing activity rather than a document. Monitoring activities, configuration management and secure coding are all things competent teams do daily and rarely record in a form an auditor can sample. The other recurring gap is the exclusion justification in the Statement of Applicability — writing “not applicable” where the standard asks for the reason.

Do the four themes map onto our teams?

Loosely, and it is worth not forcing it. The technological theme is the largest at 34 controls and is mostly engineering. Organisational, at 37, is the largest single block and spans legal, procurement, HR and management. People, at 8, is HR almost entirely. Physical, at 14, belongs to whoever runs your premises — and for a fully remote company is the theme most often waved away when it should be reasoned about instead.

What changed with the 2024 amendment?

ISO/IEC 27001:2022/Amd 1:2024, Climate action changes, published February 2024. Two climate-change additions to clause 4: whether climate change is a relevant issue must be determined, and interested parties may have climate-related requirements. It changed no Annex A control and added no new control. If a supplier tells you the amendment added controls, they are mistaken.

Sources cited on this page

  1. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
  2. ISO/IEC 27002:2022, Information security controls
  3. ISO/IEC 27001:2022/Amd 1:2024, Climate action changes
  4. IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Work out which of these you already satisfy

Say what exists today and a consultancy can tell you what is genuinely missing rather than quoting for all 93 of them.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — it is the most common answer.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now