ISO 27001:2022 has 93 controls in Annex A, organised into 4 themes. The previous 2013 version had 114 controls across 14 domains. If you're seeing both numbers online and wondering which is current, 93 is the answer for any certification issued under the 2022 revision, which is now the only version certification bodies audit against.
The 4 Themes and Their Control Counts
| Theme | Controls | Covers |
|---|---|---|
| A.5 Organizational | 37 | Policies, roles, asset management, supplier relationships, incident management |
| A.6 People | 8 | Screening, terms of employment, awareness training, disciplinary process |
| A.7 Physical | 14 | Secure areas, equipment, media handling, clear desk and screen |
| A.8 Technological | 34 | Access control, cryptography, logging, malware protection, secure development |
| Total | 93 | — |
Organizational is the largest theme by a wide margin, which surprises people who assume ISO 27001 is mostly a technical standard. In practice, governance, roles and supplier management carry more individual controls than the technology stack itself.
What Changed From the 2013 to 2022 Revision
The 2013 version organised its 114 controls across 14 separate domains, labelled A.5 through A.18, covering everything from information security policies to compliance. The 2022 revision consolidated this into just 4 themes and 93 controls.
That's a reduction of 21 controls, but it does not represent a reduction in security scope. Two things happened simultaneously:
- Consolidation. Multiple 2013 controls covering closely related requirements were merged into single, broader 2022 controls. Several access-management-related entries, for instance, became fewer but more comprehensive controls.
- 11 genuinely new controls were added to address security concerns that matured after 2013, mostly around cloud infrastructure and modern development practices.
The 11 New Controls Introduced in 2022
- Threat intelligence
- Information security for use of cloud services
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
The pattern is obvious once you see the list: cloud services, DevSecOps, and data governance barely featured in security programmes when the 2013 version was written. These 11 controls are why organisations already certified under 2013 needed a transition audit rather than an automatic carryover.
Controls Are Not the Same as the Mandatory Clauses
A common point of confusion: Annex A's 93 controls are not the whole standard, and they are not all individually mandatory. Clauses 4 through 10 of the main body of ISO 27001, covering context of the organisation, leadership, planning, support, operation, performance evaluation, and improvement, are mandatory for every certified organisation, no exceptions.
Annex A, by contrast, is a reference list. You select which controls apply based on your risk assessment, and document the selection, plus justification for any exclusions, in your Statement of Applicability. This is why two ISO 27001-certified companies can have meaningfully different sets of implemented controls and both be legitimately compliant.
Do You Have to Implement All 93?
No. You apply what your risk assessment justifies and formally exclude the rest in the Statement of Applicability, with a stated reason. Most organisational and people controls are policy and process work with no direct licence cost; the expensive ones tend to be technological, particularly logging and monitoring, endpoint management, and data loss prevention. We cover the cost implications of scoping Annex A in our guide to ISO 27001 certification cost.
Not sure which controls apply to your organisation?
A gap analysis maps your current state against all 93 controls and tells you exactly what's applicable, before you pay for an audit that tells you the same thing.
Get a Free QuoteThe 5 Control Attributes Introduced in 2022
Alongside the 93 controls themselves, the 2022 revision introduced five attribute tags that let you filter and group controls by function rather than only by theme number:
- Control type: preventive, detective, or corrective
- Information security properties: confidentiality, integrity, availability
- Cybersecurity concepts: identify, protect, detect, respond, recover, mapped to the widely used NIST framing
- Operational capabilities: practical groupings such as governance, asset management, or physical security
- Security domains: governance and ecosystem, protection, defence, resilience
These attributes are a genuine practical improvement over 2013: they let a security team pull, say, "every detective control tagged to the defence domain" as a cross-cutting view, rather than reading through themes sequentially.
Ready to see how the 93 controls apply to you?
We have guided 3,000+ organisations across 40+ markets through Annex A scoping and certification.
Talk to an Avantcert ExpertFrequently asked questions about ISO 27001 controls
How many controls are in each of the 4 Annex A themes?
Organizational controls: 37. Technological controls: 34. Physical controls: 14. People controls: 8. That totals the 93 controls in ISO 27001:2022's Annex A.
How many controls were in the old 2013 version of ISO 27001?
114 controls organised across 14 domains, labelled A.5 through A.18. The 2022 revision consolidated these into 93 controls across just 4 themes, mainly by merging overlapping controls rather than removing security requirements.
What are the 11 new controls added in the 2022 revision?
Threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. All 11 reflect security concerns that matured after 2013, particularly cloud and DevSecOps practices.
Why does ISO 27001:2022 have fewer controls than the 2013 version?
Consolidation, not reduction in scope. Many controls that were listed separately in 2013 were merged into single, broader controls in 2022, for example several access-control-related entries became fewer, more comprehensive controls. Combined with 11 genuinely new controls, the net effect is fewer total line items covering an equal or greater security scope.
Is Annex A the same as the mandatory requirements of ISO 27001?
No. Clauses 4 through 10 of the main standard, covering context, leadership, planning, support, operation, performance evaluation and improvement, are mandatory for every certified organisation. Annex A's 93 controls are a reference list you select from based on your risk assessment, not a mandatory checklist you must fully implement.
What are the 5 control attributes in ISO 27001:2022?
Control type (preventive, detective, corrective), information security properties (confidentiality, integrity, availability), cybersecurity concepts (identify, protect, detect, respond, recover), operational capabilities (such as asset management or governance), and security domains (governance, defence, resilience). These tags, new in the 2022 revision, let organisations filter and group controls by function rather than only by theme number.
Do small companies need to implement fewer Annex A controls than large ones?
The list of 93 controls is identical regardless of company size; what differs is applicability. A small company's risk assessment often justifies excluding controls that assume infrastructure or organisational complexity it doesn't have, documented in the Statement of Applicability, rather than the standard itself offering a shorter list for smaller organisations.
Which Annex A theme has the most controls?
Organizational controls, with 37, covering policies, roles, asset management, supplier relationships, and incident management. Technological controls come second with 34, followed by Physical controls with 14 and People controls with 8.
About Avantcert. Avantcert is an ISO and compliance certification consultancy that has guided 3,000+ organisations across 40+ markets to certification, with Annex A gap analysis and Statement of Applicability support. See our ISO 27001 service or request a free quote.