The 93 controls in ISO 27001, and how to think about them

By Eoghan Kenny · 21 September 2026

ISO 27001:2022 has 93 controls in Annex A, organised into four themes. The 2013 version had 114 controls across 14 domains.

The reduction was consolidation rather than removal. Controls that overlapped were merged, a small number were added to cover threat intelligence, cloud security, configuration management and similar areas that had become significant since 2013, and the whole set was restructured.

The four themes

ThemeControls
Organisational37
People8
Physical14
Technological34

The restructure matters more than the count. The 2013 domains were organised around subject areas. The 2022 themes are organised around what the control acts upon, which makes it easier to see who owns what. People controls belong with HR. Physical controls belong with facilities. Organisational controls are the largest group and the one most likely to have no obvious owner at all.

Why the number is the least interesting fact

Annex A is a reference set. You do not implement 93 controls because there are 93 controls. You determine which apply based on your risk assessment, and you justify every exclusion.

The document that records those decisions is the Statement of Applicability. It is required by the standard, and it is the single most examined document in an ISO 27001 audit. It lists every control, says whether it applies to you, explains why any are excluded, and points to how each included one is implemented.

An auditor uses it as a map of your entire system. Which is why it has to be produced after the risk assessment and not before: the justification for including or excluding a control has to trace back to a risk. Select controls first and write the justification afterwards, and the logic runs backwards, which becomes obvious under questioning.

The controls are not the standard

A point that costs organisations a great deal of time.

ISO 27001 has two parts. Clauses 4 to 10 define the management system: context, leadership, planning, support, operation, performance evaluation and improvement. These are mandatory and cannot be excluded or tailored. Annex A contains the controls, and those are selected.

An auditor will spend a great deal of their time on the clauses, because that is where they decide whether you meet the standard. A set of well-implemented controls with no management system around them does not get you certified.

What I see most organisations focus on first is the controls themselves, because that is the part that feels like doing something: policies, procedures, evidence. The clauses tend to get treated as a formality, worked through once at the start to identify stakeholders and scope, written down, and left alone unless something in the business changes significantly. Meanwhile, the day-to-day attention goes on risk, keeping the Statement of Applicability current, and aligning with other standards. That is the wrong way round from how an auditor reads the system. The clauses are what they use to judge whether you understand your own management system, and they are usually the part that gets the least attention until an auditor starts asking about it.

What changed in 2022, in practice

Eleven controls were new, addressing areas that had grown in significance: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

Alongside the control changes, the management system requirements were adjusted. Clause 6.3 on planning for changes was added. Clause 9.2 on internal audit and clause 9.3 on management review were restructured.

A separate amendment in 2024 introduced climate-related considerations, requiring organisations to consider whether climate change is a relevant issue in their context.

If you are reading older material

Certifications to the 2013 version had to transition by 31 October 2025. Any checklist, template or guide that refers to 114 controls across 14 domains describes a version that is no longer certifiable.

There is no ISO 27001:2026 edition. The 2022 version, with its 2024 amendment, is the current standard. ISO 27000 was reissued in July 2026, but that is an overview document rather than a certifiable standard.

For ISO 27001 certification support, see how 3Be supports regulated SaaS organisations.

Common questions

How many controls are in ISO 27001:2022?

ISO 27001:2022 has 93 controls in Annex A, across four themes: organisational, people, physical and technological. The 2013 version had 114 controls across 14 domains.

Do you have to implement all 93 controls?

No. Annex A is a reference set. You determine which controls apply based on your risk assessment, and justify every exclusion in your Statement of Applicability.

What is the Statement of Applicability?

The document required by clause 6.1.3 that lists all Annex A controls, states which apply, justifies exclusions, and indicates how each included control is implemented. It is the most examined document in a certification audit.

Is there an ISO 27001:2026?

No. ISO 27001:2022 remains the current certifiable standard, along with its 2024 climate amendment. ISO 27000:2026 is an overview document and does not replace it.

What changed between ISO 27001:2013 and 2022?

Annex A moved from 114 controls in 14 domains to 93 in four themes, with eleven new controls. Clause 6.3 on planning for changes was added, and clauses 9.2 and 9.3 were restructured.

Get started

How mature is your compliance today?

Our team built a free, practical health check so you can see your maturity across governance, risk, evidence, ownership and operations, which one is holding you back, and what to do about it first. Start the Health Check.