How many requirements are in ISO 27001? It depends what you count
The short version: ISO/IEC 27001:2022 doesn’t number its requirements, so there is no official count. The requirements sit in clauses 4 to 10: seven clauses with 23 sub-clauses. Annex A adds 93 controls, but they aren’t 93 requirements. You compare your controls against them and justify every choice in your Statement of Applicability.
Search for this question and you’ll see “11 clauses”, “93 requirements” and a range of “shall” counts. Each one is a different way of counting, and two of them will mislead you in an audit.
Myth 1: “ISO 27001 has 11 clauses”
The standard’s main body is numbered 0 to 10, which is where “11” comes from. But clauses 0 to 3 describe the standard itself: the introduction, the scope, normative references, and terms and definitions. There’s nothing in them for you to implement or for an auditor to test.
The requirements are in the seven clauses that follow:
- 4 Context of the organization (4.1–4.4): context, interested parties, scope, the ISMS itself.
- 5 Leadership (5.1–5.3): commitment, the information security policy, roles.
- 6 Planning (6.1–6.3): risk assessment and treatment, objectives, planning of changes.
- 7 Support (7.1–7.5): resources, competence, awareness, communication, documented information.
- 8 Operation (8.1–8.3): operational control, and carrying out risk assessment and treatment.
- 9 Performance evaluation (9.1–9.3): monitoring and measurement, internal audit, management review.
- 10 Improvement (10.1–10.2): continual improvement, nonconformity and corrective action.
You can’t exclude any of these and still claim conformity. They are what a certification audit tests.
Myth 2: “There are 93 requirements in Annex A”
Annex A is a reference list of 93 controls in four themes: 37 organizational (A.5), 8 people (A.6), 14 physical (A.7) and 34 technological (A.8).
They aren’t a checklist you must implement in full. Clause 6.1.3 asks you to decide which controls your risk treatment needs, compare them against Annex A so nothing necessary is missed, and record the result in a Statement of Applicability. That document justifies each control you include, gives its implementation status, and justifies each Annex A control you exclude.
So the audit question isn’t “have you done all 93?”. It’s “does your SoA follow from your risk assessment, and can you show it?”.
Myth 3: “It has exactly N ‘shall’ statements”
Some guides count every “shall” in clauses 4 to 10 and publish the total. The totals don’t agree, because one sentence can hold several obligations and people split them differently. It’s a useful exercise for building your own checklist from your licensed copy, but it isn’t a number the standard gives you.
What has changed recently
- 2022 edition. Clause 6.3, planning of changes, is new: changes to the ISMS must be carried out in a planned way. Nonconformity and corrective action is now 10.2, and continual improvement 10.1. Annex A went from 114 controls in 14 domains to 93 in four themes, with 11 new controls.
- Amendment 1 (February 2024). Clause 4.1 now requires you to determine whether climate change is a relevant issue for your ISMS. A note in 4.2 adds that interested parties can have climate-related requirements. Annex A is unchanged.
- 2013 edition. Withdrawn. The transition period ended on 31 October 2025, and 2013-based certificates are no longer valid.
How to use this
- Build your readiness checklist from clauses 4 to 10, including the climate change question in 4.1 and planning of changes in 6.3. Older templates often miss both.
- Treat Annex A as a cross-check, not a to-do list. Every inclusion and exclusion in your SoA should trace back to a risk, a legal or contractual requirement, or a business decision.
- When someone quotes you a number, ask what they counted. The answer tells you whether they’re reading the standard or a summary of a summary.
ISO/IEC 27001 is copyrighted by ISO and IEC. This guide paraphrases its structure from public sources and doesn’t reproduce the standard’s text. For exact wording, use your licensed copy of ISO/IEC 27001:2022 and Amendment 1:2024. Not legal advice.
- ISO: ISO/IEC 27001:2022
- ISO: ISO/IEC 27001:2022/Amd 1:2024, climate action changes
- Advisera: ISO 27001 clauses and Annex A explained
- Advisera: ISO 27001 Annex A controls
- Advisera: The Statement of Applicability
- Cyberzoni: ISO/IEC 27001:2022 clauses 4–10
- Protiviti: ISO 27001:2022 key changes and transition