Compliance Colleague · Answers · ISO/IEC 27001:2022

How many Annex A controls are in ISO 27001:2022, and how are they grouped?

Standard: ISO/IEC 27001:2022 · Answered by Compliance Colleague on September 30, 2026

Question as asked: How many Annex A controls are in ISO/IEC 27001:2022, and how are they grouped?

ISO/IEC 27001:2022 Annex A contains 93 controls, organized into 4 themes:

  • A.5 Organizational controls – 37 controls (A.5.1–A.5.37)
  • A.6 People controls – 8 controls (A.6.1–A.6.8)
  • A.7 Physical controls – 14 controls (A.7.1–A.7.14)
  • A.8 Technological controls – 34 controls (A.8.1–A.8.34)

This replaced the 2013 edition's 114 controls across 14 domains; Amendment 1:2024 (climate change) did not change Annex A.

A few points worth noting:

  • These are not 93 mandatory requirements. Clause 6.1.3 requires the organization to compare its chosen controls against Annex A to ensure nothing necessary has been omitted, and to produce a Statement of Applicability (SoA) justifying each inclusion and exclusion, with implementation status stated for each. Only clauses 4–10 are fully mandatory and non-excludable (per Clause 1); Annex A controls can be marked "not applicable" in the SoA if justified by the risk assessment.
  • 11 controls are new compared to 2013, including A.5.7 (Threat intelligence), A.5.23 (Cloud services security), A.8.11 (Data masking), A.8.16 (Monitoring activities), and A.8.28 (Secure coding), reflecting updated threats such as cloud adoption and supply-chain risk.

Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.

This is one answer from Compliance Colleague, which answers questions like this against 30+ security, privacy and AI governance standards, with the clause cited, and reviews your policies against them. Ask your own question free, no card required →

More answers