ISO 27001:2022 Annex A: The 93 Controls, Grouped for Humans
The 2022 version's four control themes — organizational, people, physical, technological — and the 11 new controls that trip up 2013 holdouts.
What changed in 2022
ISO 27001:2022 (published October 2022, replacing the 2013 version) restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes: 56 were merged into 24, and 11 new ones were added. The management-system clauses (4–10) also aligned with the harmonized structure shared across ISO standards.
The four themes
| Theme | What it covers |
|---|---|
| Organizational (37 controls) | Policies, roles, risk assessment, supplier relationships, incident management, legal compliance |
| People (8 controls) | Screening, training, disciplinary process, remote working, NDAs |
| Physical (14 controls) | Secure areas, equipment, cabling, clear desk, media disposal |
| Technological (34 controls) | Access control, cryptography, logging, network security, secure development, cloud services |
The 11 new controls
The genuinely new additions reflect modern practice: threat intelligence, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, secure coding, and cloud service security. Cloud-native companies usually have most of these already — the work is documenting them.
Transition notes
Organizations certified to the 2013 version had until 31 October 2025 to transition. From 1 May 2024, all new certifications and recertifications have been against the 2022 version. If you're starting now, 2022 is the only version that matters.
Where companies struggle
- Risk assessment quality. The SoA must trace to a real risk assessment — copy-paste risk registers get flagged at Stage 1.
- Supplier security. Cloud and SaaS supply chains make the supplier-relationship controls the longest workstream.
- Evidence for "soft" controls. Training, screening, and awareness need records, not assertions.
Use the readiness quiz to see where your control set stands before engaging a CB.
Frequently asked
Do I have to implement all 93 controls?
No — you implement what your risk assessment requires and justify exclusions in the Statement of Applicability. But expect to justify every exclusion at Stage 1.
Is ISO 27001:2013 still valid?
No — the transition period ended 31 October 2025. New certifications are against the 2022 version.
Related reading
Get quotes from accredited CBs
One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.
More guides
How to Choose an ISO 27001 Certification Body: 8 Questions to Ask
The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.
ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different
Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.
ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?
Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.