ISO27K

Which of the 93 Annex A controls apply to you

ISO 27001:2022 carries 93 controls across four themes. This counts how many stay applicable on your answers, theme by theme, and sets out every exclusion you would have to argue for in front of an auditor.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. Every one of them needs a recorded decision, applicable or not, with a reason. The count that matters to a project plan is how many land on the applicable side, because that is the number of controls somebody has to operate and evidence for the life of the certificate.

Seven questions settle almost all of it. The count appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

Are there premises inside the scope?

This single answer moves the physical theme more than anything else in the annex.

Does anyone work from a fixed site only?

One people control turns on this. The other seven apply to anybody who employs anybody.

Do you develop software?

Infrastructure as code, deployment scripts, report macros and low-code applications all count as development in an auditor's reading.

Does production data reach non-production systems?

Have you signed an availability commitment?

An uptime percentage, a recovery time objective or a recovery point objective in any signed customer agreement.

What cloud services are in use?

Where are you in the project?

How many people work there?

The four themes and what sits in them

The 2022 revision reorganised the old fourteen clauses into four themes and cut the count from 114 to 93, mostly by merging near-duplicates rather than dropping requirements. Eleven controls are new, and the new ones are where first-time projects find their gaps.

ISO/IEC 27001:2022 Annex A, controls by theme
ThemeControlsHow much of it is arguable
Organizational (A.5)37Almost none. These are policies, roles, supplier management, incident handling and legal obligations, and they apply to any organization with staff and customers.
People (A.6)8One control, remote working, turns on whether anyone works away from a site. The other seven follow from employing people.
Physical (A.7)14Half of it goes if no premises are inside the boundary. The half that follows the equipment rather than the building stays.
Technological (A.8)34The largest block of arguable exclusions, all of it downstream of whether you develop software and whether live data reaches test systems.

The eleven new controls

Threat intelligence, information security for use of cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. None of the eleven is excludable on the grounds that it is new, and two of them, configuration management and monitoring activities, are where organizations with mature technical practice still fail, because the practice exists and the documented evidence does not. The reading version is on the Annex A controls page, and ISO 27002 carries the implementation guidance the annex itself leaves out.

Applicable and not yet implemented is a legitimate state

Excluding a control means it is not necessary to treat your risks. Cost, effort and inconvenience are not part of that test. A control you have not built yet should be recorded as applicable and not implemented, with an owner and a target date, which survives an audit. A cost-based exclusion does not.

Common questions

Do I have to give an email address to see the result?

No. The theme counts and every exclusion the answers make arguable render on this page as soon as you finish the questions. The field underneath sends a written version with the control references set out, which is useful for pasting into a document. Skipping it costs you nothing.

Is a high applicable count bad?

No. Ninety-three applicable controls is the most defensible Statement of Applicability there is, because there is no argument to lose. What a high count costs is operating effort, since each applicable control needs evidence that it runs. There is no target number and an auditor does not reward a short list.

How does this differ from the Statement of Applicability tool?

This one counts. It tells you how many controls land on the applicable side of each theme, which is the number a project plan and an audit quote are built from. The Statement of Applicability tool writes the justification wording for the exclusions themselves. Most people want both, in that order.

Can we decide applicability before the risk assessment?

Not properly. Clause 6.1.3 has you determine controls necessary to treat the risks you identified, then compare that set against Annex A to check nothing was missed. Deciding applicability first and writing risks to match is the wrong order and reads that way at audit. Use this to plan the effort, then let the risk assessment confirm it.

Do the 27701 or 42001 control sets change this count?

They add to it rather than change it. ISO 27701 extends the management system with privacy controls for controllers and processors, and ISO 42001 brings its own annex for AI management. Both sit on top of the 93 rather than replacing any of them.

Get the control decisions reviewed

Tell us your scope and where you are, and we will put it in front of Canadian firms doing ISO 27001 readiness work.

Get matched