Compliance Colleague · Guides

How many requirements are in ISO 27001? It depends what you count

By Edward Casteloes, founder of Compliance Colleague · 15 years in GRC · September 24, 2026

The short version: ISO/IEC 27001:2022 doesn’t number its requirements, so there is no official count. The requirements sit in clauses 4 to 10: seven clauses with 23 sub-clauses. Annex A adds 93 controls, but they aren’t 93 requirements. You compare your controls against them and justify every choice in your Statement of Applicability.

Search for this question and you’ll see “11 clauses”, “93 requirements” and a range of “shall” counts. Each one is a different way of counting, and two of them will mislead you in an audit.

Myth 1: “ISO 27001 has 11 clauses”

The standard’s main body is numbered 0 to 10, which is where “11” comes from. But clauses 0 to 3 describe the standard itself: the introduction, the scope, normative references, and terms and definitions. There’s nothing in them for you to implement or for an auditor to test.

The requirements are in the seven clauses that follow:

You can’t exclude any of these and still claim conformity. They are what a certification audit tests.

Myth 2: “There are 93 requirements in Annex A”

Annex A is a reference list of 93 controls in four themes: 37 organizational (A.5), 8 people (A.6), 14 physical (A.7) and 34 technological (A.8).

They aren’t a checklist you must implement in full. Clause 6.1.3 asks you to decide which controls your risk treatment needs, compare them against Annex A so nothing necessary is missed, and record the result in a Statement of Applicability. That document justifies each control you include, gives its implementation status, and justifies each Annex A control you exclude.

So the audit question isn’t “have you done all 93?”. It’s “does your SoA follow from your risk assessment, and can you show it?”.

Myth 3: “It has exactly N ‘shall’ statements”

Some guides count every “shall” in clauses 4 to 10 and publish the total. The totals don’t agree, because one sentence can hold several obligations and people split them differently. It’s a useful exercise for building your own checklist from your licensed copy, but it isn’t a number the standard gives you.

What has changed recently

How to use this

  1. Build your readiness checklist from clauses 4 to 10, including the climate change question in 4.1 and planning of changes in 6.3. Older templates often miss both.
  2. Treat Annex A as a cross-check, not a to-do list. Every inclusion and exclusion in your SoA should trace back to a risk, a legal or contractual requirement, or a business decision.
  3. When someone quotes you a number, ask what they counted. The answer tells you whether they’re reading the standard or a summary of a summary.
Compliance Colleague answers questions like “Which Annex A controls can we exclude for a fully remote company, and how do we justify it?” with the clause or control cited, so you can check it against your own copy of the standard. Try it free, no card required →

ISO/IEC 27001 is copyrighted by ISO and IEC. This guide paraphrases its structure from public sources and doesn’t reproduce the standard’s text. For exact wording, use your licensed copy of ISO/IEC 27001:2022 and Amendment 1:2024. Not legal advice.