ISO 27001 Annex A

ISO 27001 Annex A: What It Is and How to Use It the Right Way


Published 07/30/2026

Ask anyone who's been through ISO 27001 certification what confused them most early on, and there's a good chance they'll mention Annex A. It's often misunderstood as a mandatory checklist, when it's actually something closer to a menu, built to be applied selectively based on your organization's actual risk.

View Information Security Management System


What Is ISO 27001 Annex A?

ISO 27001 Annex A is a reference list of information security controls that organizations can draw from when building their Information Security Management System. Following the 2022 revision of the standard, Annex A now contains 93 controls, organized into four themes: organizational, people, physical, and technological.

Annex A itself doesn't require an organization to implement every control it lists. Instead, the standard requires organizations to conduct a risk assessment first, then select the controls that are actually relevant to the risks identified. This selection process gets documented in a required deliverable called the Statement of Applicability, which explains which controls were chosen, which were excluded, and why.

In other words, Annex A is a toolbox, not a mandate. The real requirement is that your control choices are justified by risk, not simply copied from the list wholesale.

The Four Control Categories

The 2022 version of Annex A reorganized what used to be 14 separate categories into four broader themes, making the structure easier to navigate.

Organizational Controls (37 controls)
These cover policies, roles, responsibilities, and processes that shape how information security is managed across the business. Examples include information security policies, supplier relationships, and incident management procedures.

People Controls (8 controls)
These address the human side of security, including background checks, terms of employment, security awareness training, and disciplinary processes for policy violations.

Physical Controls (14 controls)
These focus on protecting physical spaces and equipment, such as secure areas, equipment maintenance, clear desk policies, and protection against environmental threats.

Technological Controls (34 controls)
These cover the technical safeguards used to protect systems and data, including access control, encryption, malware protection, network security, and secure development practices.

Why Annex A Matters for Certification

Annex A plays a central role in how certification bodies evaluate an organization's ISMS.

It provides a common reference point. Auditors around the world use the same list of controls, making it easier to compare and evaluate ISMS implementations consistently.

It ties directly to your risk assessment. Auditors expect to see a clear, documented link between the risks you've identified and the Annex A controls you've selected to address them.

It shapes your Statement of Applicability. This document, built from Annex A, is one of the most heavily scrutinized parts of any ISO 27001 audit.

It offers flexibility without sacrificing rigor. Because organizations only implement relevant controls, smaller businesses aren't forced into the same requirements as large enterprises with far more complex environments.

How to Use Annex A Effectively

Getting the most out of Annex A comes down to using it as intended, as a reference framework rather than a rigid checklist.

1. Start with your risk assessment, not the list. Identify your actual risks first. Only then should you turn to Annex A to see which controls address them.

2. Document your reasoning for every decision. For each control, whether included or excluded, be ready to explain why. This forms the backbone of your Statement of Applicability.

3. Don't over-implement. Selecting controls that don't map to real risks wastes resources and can actually make your ISMS harder to maintain and audit.

4. Don't under-implement either. Excluding a control simply because it seems inconvenient, without a legitimate risk-based justification, is a common cause of audit findings.

5. Revisit your selections regularly. As your risk landscape changes, so should your control choices. Annex A isn't a one-time reference; it should be reviewed alongside your risk assessment.

6. Map controls to evidence. For every control you claim to have implemented, make sure you can produce documentation, logs, or records that prove it's actually in place.

Take the Next Step

ISO 27001 Annex A gives you the building blocks for a strong ISMS, but knowing which blocks to use, and being able to justify that choice, is where most organizations need support.

Sign up today and get access to Annex A mapping tools and Statement of Applicability templates built specifically for ISO 27001, so you can choose the right controls with confidence. Discover our ISO Audit Tool


View ISMS Templates, Forms and Examples


Get Started Free
Create your first Incident Report form or choose from our form templates and start recording incidents in the field