Skip to main content
Category: Control Types and Framework

Reference Controls

Also known as: Annex A Controls, Reference Control Set
Simply put

Reference controls are a catalog of suggested security safeguards that an organization can draw from when building its information security program, rather than a mandatory checklist that every organization must implement in full. In the context of ISO/IEC 27001, organizations select which reference controls apply to them based on their own risk assessment and document those choices, so the set of controls in use varies from one organization to another depending on scope.

Formal definition

Within ISO/IEC 27001, reference controls are the set of control objectives and controls listed in Annex A, which serves as a reference catalog rather than a prescriptive requirement. Applicability is determined through the organization's risk assessment and formalized in the Statement of Applicability (SoA), where each reference control is either selected, justified, or excluded with rationale. The certifiable requirements of the standard reside in clauses 4 through 10 (the ISMS requirements); Annex A functions as a supporting reference informed by risk treatment decisions. The structure and count of reference controls depend on the edition of the standard, as Annex A was restructured in the 2022 revision, so the specific version should be cited when referencing control counts. Because control selection is scope- and risk-dependent, the applicable reference control set differs across organizations and should not be treated as a universal mandate beyond what the standard itself requires.

Why it matters

Reference controls matter because they shift the emphasis of an information security program away from a fixed checklist and toward a risk-driven set of choices. In ISO/IEC 27001, Annex A functions as a catalog of suggested safeguards rather than a mandate to implement everything it lists. This distinction is important for compliance managers and auditors: the question during a certification audit is not whether an organization has deployed every reference control, but whether the controls it selected are justified by its risk assessment and documented appropriately in the Statement of Applicability.

This framing prevents two common failure modes. The first is treating Annex A as an exhaustive requirement and over-implementing controls that do not address the organization's actual risks, which wastes resources without improving security posture. The second is excluding controls without adequate rationale, which can lead to gaps that a certification body may flag as nonconformities. Because the applicable set of reference controls varies from one organization to another based on scope and risk, teams that understand this flexibility can build a program that is both defensible and appropriately tailored.

It is also worth noting the limits of what reference controls represent. Selecting and implementing a control from Annex A demonstrates that a safeguard has been considered and applied, but it does not by itself guarantee freedom from incidents. The certifiable requirements of ISO/IEC 27001 reside in clauses 4 through 10; Annex A supports those requirements as a reference informed by risk treatment decisions, rather than replacing them.

Who it's relevant to

Compliance and GRC Managers
Compliance and GRC managers use the reference control catalog as the starting point for building a defensible Statement of Applicability. Understanding that Annex A is a reference rather than a mandatory checklist helps them tailor control selection to the organization's scope and risk profile and avoid both over-implementation and unjustified exclusions.
ISO 27001 Auditors and Certification Bodies
Auditors reviewing an ISMS typically examine whether the reference controls selected in the SoA are justified by the risk assessment and whether exclusions carry documented rationale. Because control counts and structure depend on the edition of the standard, auditors pay attention to which version an organization is certifying against.
Security Engineers and Program Implementers
Security engineers translate selected reference controls into operational safeguards. Recognizing that the applicable set is scope- and risk-dependent allows them to focus implementation effort on the controls that address the organization's actual risks, rather than attempting to deploy the entire catalog uniformly.

Inside Reference Controls

Annex A reference controls
In ISO/IEC 27001, reference controls are catalogued in Annex A, which serves as a reference set from which organizations select applicable controls informed by their risk assessment. The 2022 revision restructured Annex A into 93 controls organized under four themes, compared with 114 controls in the 2013 version; the specific count depends on the edition being cited.
Statement of Applicability (SoA)
The mechanism through which an organization documents which Annex A reference controls are applicable, which are excluded, and the justification for each decision. Selection is driven by the risk assessment and treatment process rather than by an obligation to implement every listed control.
Relationship to ISMS requirements (clauses 4-10)
Annex A reference controls are distinct from the certifiable ISMS requirements found in clauses 4 through 10. The clauses define the management system requirements against which certification is assessed, while Annex A provides a reference list of controls to consider during risk treatment.
Link to ISO/IEC 27002
ISO/IEC 27002 provides implementation guidance for the controls referenced in Annex A. Annex A itself is a concise reference list, whereas ISO/IEC 27002 elaborates on how the controls may be applied; note these are separate documents serving different purposes.

Common questions

Answers to the questions practitioners most commonly ask about Reference Controls.

Are Annex A reference controls the same as the SOC 2 Trust Services Criteria?
No. Annex A reference controls belong to ISO/IEC 27001 and are selected via a Statement of Applicability informed by risk assessment, while the Trust Services Criteria belong to the SOC 2 framework and are evaluated in an attestation examination. Although some concepts overlap and partial mapping between the two is possible, they are distinct sets from different frameworks, and addressing one does not automatically satisfy the other.
Are all ISO 27001 Annex A reference controls mandatory?
Not in the sense of being universally required. The certifiable requirements sit in clauses 4 through 10, and Annex A provides reference controls that are selected or excluded through the Statement of Applicability based on the organization's risk assessment. In most engagements, controls that are not relevant to the defined scope can be excluded with documented justification, so applicability depends on scope rather than being fixed.
How do we decide which reference controls apply to our organization?
Selection is typically driven by the risk assessment and the defined scope of the ISMS, with the results documented in the Statement of Applicability. Depending on scope, controls found relevant to identified risks are included, and those deemed not applicable are excluded with recorded justification. The specific mix varies by organization, risk profile, and the certification body's review.
Where do we document our selection of reference controls?
The Statement of Applicability is the customary place to record which reference controls are included or excluded and the rationale for each decision. It links the selected controls back to the risk assessment and, in most engagements, is reviewed by the certification body as part of assessing the ISMS.
Do the number and grouping of reference controls depend on the standard version?
Yes. Annex A was restructured in the 2022 revision, moving from 114 controls in the 2013 version to 93 controls organized into four themes. When citing control counts or structure, it is important to specify the edition, since the precise numbers depend on the version in use.
Can we look to ISO 27002 for help implementing these reference controls?
ISO 27002 provides implementation guidance corresponding to the Annex A reference controls and is commonly used to inform how controls are put into practice. It is a separate guidance document rather than a certifiable standard, so it supports implementation while certification is assessed against ISO/IEC 27001 itself.

Common misconceptions

All Annex A reference controls must be implemented to achieve ISO 27001 certification.
Annex A is a reference set from which controls are selected based on the risk assessment and documented in the Statement of Applicability. Controls may be excluded with appropriate justification; in most engagements the selection depends on scope and identified risks rather than a requirement to adopt every control.
The number of Annex A controls is fixed, so citing a single control count is always accurate.
The count depends on the edition. The 2013 version listed 114 controls, while the 2022 revision restructured these into 93 controls across four themes. The applicable version should always be specified when referencing control numbers.
ISO 27001 Annex A reference controls are equivalent to the SOC 2 Trust Services Criteria.
These belong to different frameworks and should not be conflated. The Trust Services Criteria underpin a SOC 2 attestation examination, while Annex A controls support an ISO 27001 certification. Mapping between the two is possible but partial, and satisfying one framework does not automatically satisfy the other.

Best practices

Always specify the ISO/IEC 27001 edition (e.g., 2013 or 2022) when referencing Annex A control counts, since the numbers and structure differ between versions.
Drive control selection from the organization's risk assessment and treatment decisions, documenting each inclusion or exclusion with justification in the Statement of Applicability.
Treat Annex A as a reference set to be tailored to scope rather than a mandatory checklist, and confirm that any excluded controls have defensible rationale.
Keep the certifiable ISMS requirements in clauses 4-10 distinct from Annex A reference controls when planning and documenting the management system.
Consult ISO/IEC 27002 for implementation guidance on the selected controls, recognizing it as a separate companion document to Annex A.
When comparing to SOC 2, treat any mapping between Annex A controls and the Trust Services Criteria as partial, and avoid assuming that meeting one framework satisfies the other.