SecurSentry
← All notes
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

Ninety-three controls sounds like a checklist someone hands you and expects you to tick to the bottom. It isn't. Here's what Annex A really is, and why you almost certainly won't be doing all of it.

The short version

If you’ve started looking into ISO 27001, you’ve almost certainly bumped into the phrase “Annex A” and a slightly intimidating number attached to it: 93 controls. It reads like a checklist someone is about to hand you and then expect you to tick, line by line, to the very bottom. That’s the wrong picture, and it puts a lot of business owners off before they’ve properly begun.

A better way to think about Annex A is as a menu rather than a mandate. Below, I’ll walk through what it actually is, how those 93 controls are organised, and the part most people miss on the first read: you choose from the list based on your own risks. You don’t have to do all of it.

What Annex A actually is (and what it isn’t)

Annex A is the reference list of information security controls that sits at the back of the ISO 27001 standard: a catalogue you select from, not a set of jobs you all have to finish.

The heart of ISO 27001 isn’t the control list at all. It’s the requirement to build and run an Information Security Management System, usually shortened to an ISMS. In plain terms, that’s a documented, living way of working out what information you hold, what could go wrong with it, and what you’re doing to keep it safe. Annex A comes in at the “what you’re doing to keep it safe” stage. It’s the standard’s suggested toolbox of safeguards, from staff training to backups to controlling who can get into the server cupboard.

So it helps to be clear about what Annex A is not. It isn’t the certificate itself. It isn’t a legal requirement to implement every item. And it isn’t a to-do list you work through in order. It’s a well-organised catalogue that exists so you don’t have to invent your security measures from a blank page, and so an auditor can check your choices against a common reference.

The one idea worth holding on to

Annex A is risk-driven. The standard expects you to look at your own business, work out what's actually at risk, and then reach into the list for the controls that address those risks. A safeguard that has nothing to do with your situation doesn't belong on your list.

The four themes, and how the 93 controls split across them

The 93 controls are grouped into four plain-language themes, and knowing the shape of each one makes the whole list far less daunting.

Here’s how the 93 controls break down:

Add those up and you get the full 93. Four themes, one number, and none of them a mystery once you see what they’re really about. Most small businesses find the People and Physical groups quick to reason about, while the Organisational and Technological groups carry the bulk of the detail.

You don’t do all 93 — the Statement of Applicability decides

This is the point that changes how the whole thing feels: you’re expected to select the controls that fit your risks, and to write down why, in a document called the Statement of Applicability.

The mechanism works in a sensible order. First you carry out a risk assessment, which is simply a structured look at what could harm the information you hold and how likely and serious that harm would be. Then you decide how you’ll treat each of those risks, and you reach into Annex A for the controls that do the job. Finally, you compare your chosen controls against the full list to make sure you haven’t missed anything obvious.

That comparison lives in the Statement of Applicability, or SoA. It lists the Annex A controls, marks each one as applicable or not, and gives a short justification for every decision, including the ones you’ve decided to leave out. If your business has no physical premises to speak of because everyone works from home on company laptops, some of the physical controls may simply not apply, and you say so plainly. Auditors are entirely comfortable with a control marked “not applicable” as long as your reasoning is honest and clear.

What the SoA is, in a sentence

The Statement of Applicability is the document that answers "which controls did you pick, and why did you leave the others out?" It turns Annex A from a scary list of 93 into a considered, defensible set of choices that fit your actual business.

The practical upshot is reassuring. Two businesses of similar size can produce very different, equally valid control sets, because their risks differ. Nobody is scoring you on how many of the 93 you managed to implement. They’re checking that the ones you selected genuinely address the risks you found.

What changed in the 2022 version

If you’ve read older guidance and seen the number 114, that’s the previous version — the current standard reorganised and modernised the list.

The 2013 version of the standard listed 114 controls spread across 14 domains. The 2022 revision regrouped them into the 93 controls and four themes described above. A large share of the old controls were merged together where they overlapped, and most of the rest were reworded to reflect how organisations actually operate now, with far more of the working day happening in the cloud and on the move.

Eleven of the controls are genuinely new. They fill gaps that had opened up since 2013, and the list of names alone tells you where the world moved: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding. If you already work to the older version, none of this should feel like starting again. It’s a tidy-up and a modernisation rather than a reinvention, and much of your existing effort maps straight across.

Examples of controls a typical small business will pick

The list stops feeling abstract the moment you see the sort of everyday controls a normal SME actually lands on.

You won’t recognise every one of the 93, but you’ll recognise a good many. For a typical small or medium business, a selected control set often includes measures like these:

None of that is exotic. Much of it is good practice you may already be part-way to doing. The value of Annex A is that it gives these habits a shared name and a place in a system, so the work is visible, repeatable and provable to a client who asks. If you’d like a fuller sense of whether the standard is the right move at all, our guide to ISO 27001 for SMEs is a good companion read, and what ISO 27001 actually costs covers the money side honestly.

Where Annex A overlaps with work you may already have done

Several of the technological controls line up closely with Cyber Essentials, which means the groundwork isn’t wasted if you’ve already been down that road.

A number of Annex A’s technical controls sit in the same territory as the five controls at the core of Cyber Essentials: firewalls and secure configuration, controlling user access, protecting against malware, and keeping software up to date. If you’ve worked through a Cyber Essentials checklist and hold the certificate, you’ve already built and evidenced practices that map directly onto part of Annex A. That’s real, transferable progress rather than a separate pile of work.

The two aren’t the same thing, and it’s worth understanding the difference so you pitch your effort at the right level. Cyber Essentials is a focused technical baseline; ISO 27001 wraps a full management system around information risk across the whole organisation. Our comparison of Cyber Essentials and ISO 27001 unpacks where each one fits. The encouraging headline is that they build on each other. Sensible security done once tends to keep paying off, and Annex A is designed to recognise the good work you’ve already put in rather than make you repeat it.


SecurSentry is launching soon to help UK SMEs map controls like these to what they already have in place, so the work you do once keeps paying off. Join the waitlist to be among the first to know when we open.

This article is for general information only and does not constitute legal or compliance advice. Which controls apply varies by organisation; where in doubt, consult a qualified professional or an accredited certification body.

Frequently asked questions

How many controls are in ISO 27001 Annex A?

The current ISO/IEC 27001:2022 version of Annex A contains 93 controls. They're grouped into four themes: Organisational (37 controls), People (8 controls), Physical (14 controls) and Technological (34 controls). Those figures add up to the full 93. This is a change from the older 2013 version, which listed 114 controls across 14 domains.

Do I have to implement all 93 Annex A controls to get certified?

No. ISO 27001 asks you to run a risk assessment, then select the controls that are relevant to the risks your organisation actually faces. You record those choices in a document called the Statement of Applicability, which explains why each control is included or excluded. A control that genuinely doesn't apply to your business can be marked as not applicable, provided you give a clear, honest justification for leaving it out.

What are the four themes in ISO 27001:2022 Annex A?

The four themes are Organisational controls (37, covering policies, roles, supplier relationships and the like), People controls (8, covering staff screening, awareness and responsibilities), Physical controls (14, covering premises, equipment and physical access) and Technological controls (34, covering the technical side such as access management, encryption, backups and logging). The 2022 revision introduced these four themes to replace the older structure.

What changed between the 2013 and 2022 versions of Annex A?

The 2022 revision regrouped the controls from 114 across 14 domains into 93 across 4 themes. A lot of the old controls were merged together, most were reworded to reflect how organisations work today, and 11 entirely new controls were added — covering areas such as threat intelligence, information security for cloud services, data leakage prevention and secure coding. If you already work to the 2013 version, it's a modernisation and consolidation rather than a wholesale reinvention.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

21 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

An ISO 27001 Checklist for Small Businesses

11 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.