Which of the 93 Annex A controls apply to you
ISO 27001:2022 carries 93 controls across four themes. This counts how many stay applicable on your answers, theme by theme, and sets out every exclusion you would have to argue for in front of an auditor.
Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Every one of them needs a recorded decision, applicable or not, with a reason. The count that matters to a project plan is how many land on the applicable side, because that is the number of controls somebody has to operate and evidence for the life of the certificate.
Seven questions settle almost all of it. The count appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
The four themes and what sits in them
The 2022 revision reorganised the old fourteen clauses into four themes and cut the count from 114 to 93, mostly by merging near-duplicates rather than dropping requirements. Eleven controls are new, and the new ones are where first-time projects find their gaps.
| Theme | Controls | How much of it is arguable |
|---|---|---|
| Organizational (A.5) | 37 | Almost none. These are policies, roles, supplier management, incident handling and legal obligations, and they apply to any organization with staff and customers. |
| People (A.6) | 8 | One control, remote working, turns on whether anyone works away from a site. The other seven follow from employing people. |
| Physical (A.7) | 14 | Half of it goes if no premises are inside the boundary. The half that follows the equipment rather than the building stays. |
| Technological (A.8) | 34 | The largest block of arguable exclusions, all of it downstream of whether you develop software and whether live data reaches test systems. |
The eleven new controls
Threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. None of the eleven is excludable on the grounds that it is new, and two of them, configuration management and monitoring activities, are where organizations with mature technical practice still fail, because the practice exists and the documented evidence does not. The reading version is on the Annex A controls page, and ISO 27002 carries the implementation guidance the annex itself leaves out.
Applicable and not yet implemented is a legitimate state
Excluding a control means it is not necessary to treat your risks. Cost, effort and inconvenience are not part of that test. A control you have not built yet should be recorded as applicable and not implemented, with an owner and a target date, which survives an audit. A cost-based exclusion does not.
Common questions
Do I have to give an email address to see the result?
No. The theme counts and every exclusion the answers make arguable render on this page as soon as you finish the questions. The field underneath sends a written version with the control references set out, which is useful for pasting into a document. Skipping it costs you nothing.
Is a high applicable count bad?
No. Ninety-three applicable controls is the most defensible Statement of Applicability there is, because there is no argument to lose. What a high count costs is operating effort, since each applicable control needs evidence that it runs. There is no target number and an auditor does not reward a short list.
How does this differ from the Statement of Applicability tool?
This one counts. It tells you how many controls land on the applicable side of each theme, which is the number a project plan and an audit quote are built from. The Statement of Applicability tool writes the justification wording for the exclusions themselves. Most people want both, in that order.
Can we decide applicability before the risk assessment?
Not properly. Clause 6.1.3 has you determine controls necessary to treat the risks you identified, then compare that set against Annex A to check nothing was missed. Deciding applicability first and writing risks to match is the wrong order and reads that way at audit. Use this to plan the effort, then let the risk assessment confirm it.
Do the 27701 or 42001 control sets change this count?
They add to it rather than change it. ISO 27701 extends the management system with privacy controls for controllers and processors, and ISO 42001 brings its own annex for AI management. Both sit on top of the 93 rather than replacing any of them.
Get the control decisions reviewed
Tell us your scope and where you are, and we will put it in front of Canadian firms doing ISO 27001 readiness work.
Get matched