Key Takeaways
- ISO 27001 controls are the 93 security measures in Annex A of the standard, grouped into four themes: 37 organizational, 8 people, 14 physical, and 34 technological controls.
- The revision published on 25 October 2022 restructured the previous 114 controls: 11 were added, 57 merged into 24, 23 renamed, 3 removed, and 35 carried over unchanged.
- The 11 new controls cover ground that did not exist in 2013, including threat intelligence (A.5.7), cloud security (A.5.23), data masking (A.8.11), and secure coding (A.8.28).
- No company implements all 93 controls. Which ones apply follows from your risk assessment, and the result is recorded in the Statement of Applicability.
- The transition period to the 2022 version closed on 31 October 2025. Certificates issued against ISO 27001:2013 are no longer valid, and no audit can be conducted against the older edition.
What are ISO 27001 controls?
ISO 27001 controls are the 93 security measures listed in Annex A of the standard. Each control states a security objective and the measure that achieves it, such as managing access rights, protecting against malware, or reporting security incidents. The standard itself uses the word "controls"; some national translations use "measures", and practitioners use both interchangeably.
The distinction from the main body of the standard matters. Clauses 4 to 10 set out the mandatory requirements for the management system itself: context, leadership, planning, operation, evaluation, and improvement. Those clauses always apply in full. Annex A, by contrast, is a reference list you select from. How the two parts work together, and what auditors actually examine, is covered in our guide to ISO 27001 certification.
A persistent misconception is that Annex A is a checklist to work through. It is not. Annex A is a completeness check. You identify your risks first, derive controls from them, and then compare the result against Annex A to see what you missed. Working in the opposite order produces an ISMS that fits the standard but not the business.
The detailed implementation guidance for each control sits not in ISO 27001 but in its companion standard, ISO 27002:2022. There, every control also carries five attributes that make filtering easier: control type (preventive, detective, corrective), information security property (confidentiality, integrity, availability), cybersecurity concept following the NIST pattern from Identify to Recover, operational capability, and security domain.
How many controls does ISO 27001 have?
ISO 27001:2022 contains 93 controls across four themes. The numbering follows the theme: organizational controls run from A.5.1 to A.5.37, people controls from A.6.1 to A.6.8, physical controls from A.7.1 to A.7.14, and technological controls from A.8.1 to A.8.34.
The split says something about the nature of the standard. Only 34 of the 93 controls are technical. The majority concern organization, documentation, and people. Teams that scope ISO 27001 as a pure IT project therefore routinely underestimate the work in A.5 and A.6.
The four control categories in detail
Organizational controls (A.5.1 to A.5.37)
The 37 organizational controls govern how information security is steered: which policies exist, who is accountable, how suppliers are managed, and how the company responds to incidents. It is the largest group and usually the most time-consuming, because it requires documents that often did not exist before.
People controls (A.6.1 to A.6.8)
The 8 people controls cover the full employment lifecycle, from screening before hire to obligations that survive departure. It is the smallest group and still produces a disproportionate share of audit findings, because the evidence is missing: training happens, but nobody documents attendance.
Physical controls (A.7.1 to A.7.14)
The 14 physical controls protect sites, rooms, and equipment. Even a pure cloud company with no data center of its own cannot exclude them wholesale: offices, laptops, storage media, and the disposal of old hardware all fall under A.7. For outsourced data centers, the burden of evidence shifts to supplier management in A.5.19 to A.5.22.
Technological controls (A.8.1 to A.8.34)
The 34 technological controls address the IT estate: access rights, encryption, networks, logging, backups, and secure software development. Seven of the eleven new controls from the 2022 revision sit in this group, which shows where the standard's authors saw the largest gap.
The 11 new controls in the 2022 revision
The 2022 revision introduced 11 controls. They close the gaps that opened between 2013 and 2022: cloud adoption, distributed work, software supply chains, and how data is handled in test environments.
The effort behind these eleven controls is distributed very unevenly. A.8.10 and A.8.11 can often be derived from existing data protection processes, since a deletion concept and pseudonymization are already needed for GDPR. A.5.7 and A.8.16, by contrast, require ongoing processes that cannot be assembled in the two weeks before an audit. To map Annex A against your own security architecture, our overview of where NIS2 and ISO 27001 overlap also gives the correspondence to the risk management measures in Article 21 of the NIS2 Directive.
What changed between the 2013 and 2022 versions
ISO/IEC 27001:2022 was published on 25 October 2022 and replaced the 2013 edition. The previous 114 controls in 14 domains became 93 controls in four themes. The count fell; the scope did not. Most of the reduction comes from mergers rather than removals.
The title of the annex changed too, from "Reference control objectives and controls" to "Information security controls reference". That is more than cosmetic: the control objectives are gone, and the intent now sits inside each control itself.
The transition period has closed. Set by the IAF for accredited certification bodies, it ended on 31 October 2025; certificates based on ISO 27001:2013 have not been valid since that date. For a first certification, the older edition is therefore irrelevant. If a quote you receive today still references the 2013 version, that is worth questioning.
In 2024, ISO/IEC 27001:2022/Amd 1:2024 added a small amendment. It does not touch Annex A but clauses 4.2 and 6.1.2: companies must consider whether climate change is relevant to their management system. The count of 93 controls is unaffected.
Which controls apply to your company?
Which of the 93 controls are applicable follows from your risk assessment, not from a prescription in the standard. You record the result in the Statement of Applicability. That document lists all 93 controls and justifies, for each one, whether it applies and why. Auditors read it first; it is the single most scrutinized document in the entire ISMS.
Exclusions are explicitly permitted, but only with a substantive justification. "Not relevant" is not enough. "We do not develop software in house, so A.8.25 to A.8.31 do not apply" is a justification that holds, as long as it matches the actual business model.
A concrete example: a 45-person SaaS company running entirely on AWS, with no data center of its own and a single office. Almost all organizational and people controls apply, because they are independent of size. On the physical side, the work reduces to the office, endpoints, and disposal, while data center security is evidenced through supplier management. The technological controls are almost fully in scope, because the company writes its own software. In the end, very few genuine exclusions remain.
The most common misconception in a first certification is that a control is handled once a document exists. An audit does not check that a policy exists; it checks that the policy is followed. For every applicable control you need continuous evidence, not just an approval. That is where most findings originate: not on missing controls, but on controls with no evidence from the preceding months available at audit time. How the four audit phases run, and what auditors examine in each, is covered in the ISO 27001 certification guide.
What that effort translates to in numbers, meaning audit days, certification body fees, and internal time, is set out in our breakdown of ISO 27001 certification costs.
How Kertos supports control implementation
Kertos maps all 93 Annex A controls in the platform and links each one to the evidence that supports it. Instead of collecting evidence in the run-up to an audit, automated checks pull it continuously from connected systems such as identity management, device management, and the cloud environment. The Statement of Applicability is generated from the risk assessment and stays connected to it, rather than aging as a separate spreadsheet.
Alongside the platform sit certified experts who share responsibility for control selection and justification, and who accompany you through the audit. AskUI reached ISO 27001 certification in 8 to 10 weeks this way. What an ISMS requires before individual controls come into play is covered in our guide to building an ISMS.
To see what the mapping from controls to evidence looks like in your environment, book a demo.
Frequently asked questions
How many controls does ISO 27001 have?
ISO 27001:2022 contains 93 controls in Annex A, split into 37 organizational, 8 people, 14 physical, and 34 technological controls. The previous edition, ISO 27001:2013, contained 114 controls across 14 domains.
Do I have to implement all 93 controls?
No. Which controls apply follows from your risk assessment. You do have to assess all 93 individually in the Statement of Applicability and give a substantive justification for every exclusion. An unjustified exclusion becomes a finding at audit.
What is the difference between ISO 27001 controls and the clauses of the standard?
Clauses 4 to 10 set out the mandatory management system requirements and always apply in full. Annex A is a reference list of 93 controls that you select from on a risk basis. Certification covers both, but only the main body is binding without exception.
Which controls are new in ISO 27001:2022?
Eleven controls were added in 2022: threat intelligence (A.5.7), information security for use of cloud services (A.5.23), ICT readiness for business continuity (A.5.30), physical security monitoring (A.7.4), configuration management (A.8.9), information deletion (A.8.10), data masking (A.8.11), data leakage prevention (A.8.12), monitoring activities (A.8.16), web filtering (A.8.23), and secure coding (A.8.28).
Is there a downloadable list of the ISO 27001 controls?
The complete list is in the tables above, sorted by the four themes. The binding wording and the implementation guidance sit in the standards themselves: the requirements in ISO/IEC 27001:2022, and the detailed guidance per control in ISO/IEC 27002:2022. Both are available from ISO for a fee.
Is an ISO 27001:2013 certificate still valid?
No. The transition period ended on 31 October 2025. Certificates based on ISO 27001:2013 have not been valid since that date, and audits are conducted exclusively against the 2022 edition.




.png)
