Annex A (Reference Controls)
Annex A is a catalog of reference security controls attached to the ISO/IEC 27001 standard that organizations can draw on to address risks to their information security. In the 2022 revision it contains 93 controls, grouped into themes such as organizational controls. Rather than a mandatory checklist, it is a reference set that organizations select from based on their risk assessment.
Annex A of ISO/IEC 27001:2022 is a normative list of 93 reference information security controls organized into themes (including organizational controls). These controls are not implemented wholesale by default; they are selected and justified through a risk assessment and documented in the Statement of Applicability (SoA), which typically addresses each Annex A control and records inclusions, exclusions, and rationale. Annex A serves as a reference point against which the SoA is prepared, while the certifiable ISMS requirements themselves reside in clauses 4 through 10 of the standard. Control counts and groupings are version-specific: the 2022 revision lists 93 controls, a restructuring from the earlier edition, so the applicable edition should be specified when citing figures.
Why it matters
Annex A matters because it gives organizations a structured reference set of information security controls to draw on when addressing the risks identified in their risk assessment. Rather than requiring every organization to invent controls from scratch, ISO/IEC 27001:2022 supplies a catalog of 93 reference controls grouped into themes, providing a common vocabulary and starting point that auditors, certification bodies, and internal teams can all recognize. This shared reference makes it easier to communicate about coverage and gaps during a certification engagement.
Annex A is also central to the audit process because it is the reference point against which the Statement of Applicability (SoA) is prepared. In most engagements, the SoA addresses each Annex A control and records whether it is included or excluded along with the rationale, so the completeness and defensibility of that document depends directly on how Annex A is treated. A thoughtful selection and justification process tends to produce a smoother certification review, while unexplained gaps or unjustified exclusions typically attract scrutiny.
It is important to keep Annex A's role in proportion. Annex A is a reference set, not the certifiable requirements themselves, which reside in clauses 4 through 10 of the standard. Selecting or implementing Annex A controls does not by itself demonstrate a functioning ISMS, and the certificate ultimately covers only the defined scope of the management system. Control counts and groupings are also version-specific, so the applicable edition should always be specified when citing figures.
Who it's relevant to
Inside Annex A (Reference Controls)
Common questions
Answers to the questions practitioners most commonly ask about Annex A (Reference Controls).