Fundamentals

ISO 27001:2022 Annex A: The 93 Controls, Grouped for Humans

The 2022 version's four control themes — organizational, people, physical, technological — and the 11 new controls that trip up 2013 holdouts.

What changed in 2022

ISO 27001:2022 (published October 2022, replacing the 2013 version) restructured Annex A from 114 controls in 14 clauses to 93 controls in 4 themes: 56 were merged into 24, and 11 new ones were added. The management-system clauses (4–10) also aligned with the harmonized structure shared across ISO standards.

The four themes

ThemeWhat it covers
Organizational (37 controls)Policies, roles, risk assessment, supplier relationships, incident management, legal compliance
People (8 controls)Screening, training, disciplinary process, remote working, NDAs
Physical (14 controls)Secure areas, equipment, cabling, clear desk, media disposal
Technological (34 controls)Access control, cryptography, logging, network security, secure development, cloud services

The 11 new controls

The genuinely new additions reflect modern practice: threat intelligence, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, secure coding, and cloud service security. Cloud-native companies usually have most of these already — the work is documenting them.

Transition notes

Organizations certified to the 2013 version had until 31 October 2025 to transition. From 1 May 2024, all new certifications and recertifications have been against the 2022 version. If you're starting now, 2022 is the only version that matters.

Where companies struggle

Use the readiness quiz to see where your control set stands before engaging a CB.

Frequently asked

Do I have to implement all 93 controls?

No — you implement what your risk assessment requires and justify exclusions in the Statement of Applicability. But expect to justify every exclusion at Stage 1.

Is ISO 27001:2013 still valid?

No — the transition period ended 31 October 2025. New certifications are against the 2022 version.

Related reading

Get quotes from accredited CBs

One brief, matched certification bodies, comparable quotes. Free · 2 minutes · no obligation.

Get a free quote

More guides

Certification bodies

How to Choose an ISO 27001 Certification Body: 8 Questions to Ask

The vetting checklist we recommend: accreditation verification, audit teams, audit-day math, fees, and the red flags that signal a bad fit.

Fundamentals

ISO 27001 Stage 1 vs Stage 2 Audits: What's Actually Different

Documentation review vs effectiveness testing: what each stage checks, how long each takes, and what sinks companies at each stage.

Comparisons

ISO 27001 vs SOC 2: Which One Do Your Customers Actually Need?

Certificate vs attestation report, international vs US expectations, and the combined program that covers both — sequenced honestly.