Skip to main content
Category: Standards and Frameworks

Annex A (Reference Controls)

Also known as: Annex A Controls, ISO 27001 Annex A, Reference Controls
Simply put

Annex A is a catalog of reference security controls attached to the ISO/IEC 27001 standard that organizations can draw on to address risks to their information security. In the 2022 revision it contains 93 controls, grouped into themes such as organizational controls. Rather than a mandatory checklist, it is a reference set that organizations select from based on their risk assessment.

Formal definition

Annex A of ISO/IEC 27001:2022 is a normative list of 93 reference information security controls organized into themes (including organizational controls). These controls are not implemented wholesale by default; they are selected and justified through a risk assessment and documented in the Statement of Applicability (SoA), which typically addresses each Annex A control and records inclusions, exclusions, and rationale. Annex A serves as a reference point against which the SoA is prepared, while the certifiable ISMS requirements themselves reside in clauses 4 through 10 of the standard. Control counts and groupings are version-specific: the 2022 revision lists 93 controls, a restructuring from the earlier edition, so the applicable edition should be specified when citing figures.

Why it matters

Annex A matters because it gives organizations a structured reference set of information security controls to draw on when addressing the risks identified in their risk assessment. Rather than requiring every organization to invent controls from scratch, ISO/IEC 27001:2022 supplies a catalog of 93 reference controls grouped into themes, providing a common vocabulary and starting point that auditors, certification bodies, and internal teams can all recognize. This shared reference makes it easier to communicate about coverage and gaps during a certification engagement.

Annex A is also central to the audit process because it is the reference point against which the Statement of Applicability (SoA) is prepared. In most engagements, the SoA addresses each Annex A control and records whether it is included or excluded along with the rationale, so the completeness and defensibility of that document depends directly on how Annex A is treated. A thoughtful selection and justification process tends to produce a smoother certification review, while unexplained gaps or unjustified exclusions typically attract scrutiny.

It is important to keep Annex A's role in proportion. Annex A is a reference set, not the certifiable requirements themselves, which reside in clauses 4 through 10 of the standard. Selecting or implementing Annex A controls does not by itself demonstrate a functioning ISMS, and the certificate ultimately covers only the defined scope of the management system. Control counts and groupings are also version-specific, so the applicable edition should always be specified when citing figures.

Who it's relevant to

Compliance and GRC managers
Those responsible for pursuing or maintaining ISO 27001 certification use Annex A as the reference set from which controls are selected and justified in the Statement of Applicability. They coordinate the risk assessment that drives which controls are included or excluded and ensure each decision is documented with a defensible rationale.
ISO 27001 auditors and certification bodies
Auditors treat the Statement of Applicability, prepared against Annex A, as central to the certification review. They examine how each reference control has been addressed and whether inclusions and exclusions are supported by the organization's risk assessment, while confirming that the certifiable requirements in clauses 4 through 10 are met.
Security engineers and control owners
Teams responsible for implementing controls draw on Annex A as a catalog of reference measures to address identified risks, spanning organizational controls and areas such as building security awareness across the employee lifecycle. They translate selected reference controls into operating practices within the ISMS scope.
HR and people-operations stakeholders
Because certain Annex A controls aim to build a culture of security awareness from the moment a new employee joins and after they leave, HR and people-operations functions are often involved in implementing controls tied to the employee lifecycle, depending on the organization's scope and control selections.

Inside Annex A (Reference Controls)

Reference Control Set
Annex A of ISO/IEC 27001 provides a catalogue of reference controls that organizations draw upon to treat risks identified through their risk assessment. In the 2022 revision the set comprises 93 controls organized into four themes, compared with 114 controls arranged across domains in the 2013 version; the applicable count depends on the edition being referenced.
Four Themes (2022 Revision)
The 2022 restructuring groups the 93 controls into four thematic categories rather than the domain structure used previously. This reorganization affects how controls are presented and referenced, which is why the specific version should be cited whenever control counts or groupings are discussed.
Statement of Applicability (SoA)
The mechanism through which an organization documents which Annex A controls are applicable, which are excluded, and the justification for each decision. Control selection is informed by the risk assessment and risk treatment process rather than by applying every control uniformly.
Relationship to Clauses 4-10
Annex A lists reference controls and is not itself the certifiable core of the standard; the certifiable ISMS requirements reside in clauses 4 through 10. Annex A supports risk treatment decisions made under those clauses.
Relationship to ISO 27002
ISO/IEC 27002 provides implementation guidance corresponding to the Annex A reference controls, offering more detailed advice on how controls may be applied. Annex A itself is a concise reference list rather than a detailed implementation manual.

Common questions

Answers to the questions practitioners most commonly ask about Annex A (Reference Controls).

Are the Annex A controls a mandatory checklist that every organization must fully implement?
No. Annex A is a list of reference controls, not a mandatory checklist. Controls are selected through the Statement of Applicability and informed by the organization's risk assessment. Depending on scope and risk, some Annex A controls may be excluded with documented justification. The certifiable requirements are found in clauses 4 through 10 of ISO/IEC 27001, while Annex A serves as a reference set to be applied selectively.
Is Annex A the same as the SOC 2 Trust Services Criteria?
No. Annex A reference controls belong to ISO/IEC 27001 and should not be conflated with the Trust Services Criteria used in a SOC 2 examination. They come from different frameworks with different structures and governing standards. Mapping between the two is possible but partial, and satisfying the Trust Services Criteria does not automatically satisfy Annex A, or vice versa.
How do we decide which Annex A controls apply to our organization?
Control selection is typically driven by the risk assessment and documented in the Statement of Applicability. In most implementations, each Annex A control is evaluated for applicability, with reasons recorded for inclusion or exclusion. The outcome depends on the defined ISMS scope, identified risks, and the organization's context, so selections vary between organizations.
Why does the number of Annex A controls differ depending on which source we consult?
The control count depends on the edition of the standard. The 2013 version listed 114 controls, while the 2022 revision restructured these into 93 controls organized under four themes. When referencing control numbers, it is important to specify the version, since the precise figures differ between editions.
What is the relationship between Annex A and ISO/IEC 27002?
Annex A provides a concise list of reference controls, while ISO/IEC 27002 offers more detailed implementation guidance for those controls. In most engagements, organizations use ISO 27002 as a companion reference when determining how to apply the controls selected through the Statement of Applicability. ISO 27002 itself is not a certifiable standard.
How should exclusions of Annex A controls be handled during a certification audit?
Exclusions are typically documented in the Statement of Applicability with a stated justification linked to the risk assessment and ISMS scope. During certification, the certification body generally reviews these justifications for reasonableness. The acceptability of an exclusion depends on the certification body's assessment and the organization's defined scope, so outcomes can vary.

Common misconceptions

All Annex A controls are mandatory and every organization must implement the full set.
Annex A is a set of reference controls selected via the Statement of Applicability and informed by the risk assessment. Depending on scope and identified risks, controls may be justifiably excluded rather than universally applied.
Annex A controls are equivalent to the SOC 2 Trust Services Criteria.
The two are distinct. Annex A lists reference controls under ISO 27001, while the Trust Services Criteria (with Security as the required Common Criteria and Availability, Processing Integrity, Confidentiality, and Privacy as optional) belong to SOC 2. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other.
Annex A always contains 114 controls.
The control count depends on the edition. The 2013 version listed 114 controls, while the 2022 revision restructured these into 93 controls across four themes. The version should be specified whenever citing a control count.

Best practices

Drive Annex A control selection from the risk assessment and risk treatment process rather than adopting the full set by default, and document each inclusion or exclusion with justification in the Statement of Applicability.
Always specify the ISO 27001 edition (for example, 2013 versus 2022) when referencing control counts or thematic groupings, since the numbers and structure differ between versions.
Consult ISO/IEC 27002 for implementation guidance when applying Annex A reference controls, treating Annex A itself as a concise reference list.
Keep the Statement of Applicability aligned with clauses 4 through 10, ensuring that control decisions trace back to the ISMS requirements that form the certifiable core of the standard.
Review the Statement of Applicability and control selections periodically as scope, risks, and standard revisions change, to confirm continued relevance.
When mapping Annex A controls to other frameworks such as SOC 2, treat the correspondence as partial and verify that gaps are addressed separately rather than assuming equivalence.