ISO 27001:2022 has 93 Annex A controls organized into four themes (Organizational 37, People 8, Physical 14, Technological 34). Most organizations apply 70 to 85 of the 93 controls, excluding those that do not apply with documented justification (Source: ISO/IEC 27001:2022 standard). The Statement of Applicability (SoA) is the audit-facing document that lists each control, its applicability, justification, and implementation status. Signed by the CISO or accountable executive.
Last verified: Sep 14, 2026.
At a glance
- 93 Annex A controls in ISO 27001:2022 (consolidated from 114)
- Four themes: Organizational (37), People (8), Physical (14), Technological (34)
- Typical applicability: 70-85 of 93 controls
- SoA is mandatory, signed by accountable executive, reviewed annually
- Exclusions require justification with risk treatment rationale
ISO 27001:2022 Annex A control structure
ISO 27001:2022 reorganized Annex A into four themes rather than the previous 14 domains. The new structure is more intuitive: Organizational controls (policies, roles, supplier relationships), People controls (screening, training, disciplinary process), Physical controls (perimeter security, equipment protection), and Technological controls (access control, cryptography, system security).
| Theme | Number of Controls | Example Controls |
|---|---|---|
| Organizational | 37 | A.5.1 Information security policies, A.5.19 Supplier relationships, A.5.23 Cloud services security |
| People | 8 | A.6.1 Screening, A.6.3 Information security awareness and training, A.6.8 Disciplinary process |
| Physical | 14 | A.7.1 Physical security perimeter, A.7.4 Physical security monitoring, A.7.9 Security of assets off-premises |
| Technological | 34 | A.8.2 Privileged access rights, A.8.5 Secure authentication, A.8.24 Use of cryptography, A.8.28 Secure coding |
| Total | 93 | Consolidated from 114 in ISO 27001:2013 |
Source: ISO/IEC 27001:2022 Annex A control structure.
SoA template structure
The SoA template typically includes these columns per control. Each row covers one Annex A control with metadata that supports audit review and management reporting.
| Column | Description | Example |
|---|---|---|
| Control ID | Annex A reference | A.5.1 |
| Control name | Per ISO 27001:2022 | Policies for information security |
| Applicable (Y/N) | Whether the control applies to your ISMS scope | Y |
| Justification | Reason for inclusion or exclusion | Information security policies are required for all employees regardless of role |
| Implementation status | Implemented / Partial / Planned / Not applicable | Implemented |
| Implementation evidence | Documents, tools, or processes that satisfy the control | ISMS Policy v3.2 published 2026-08-15; signed by CEO |
| Owner | Person accountable for the control | CISO |
| Risk treatment reference | Link to risk treatment plan entry | RTP-007 Information security governance |
| Last reviewed | Date of most recent review | 2026-08-15 |
Source: ISO 27001 SoA best practices from Schellman and ISMS.online, 2026.
Common exclusions and their justification
Most organizations exclude a handful of controls with clear justification. Auditors accept exclusions that reflect actual scope and risk, not convenience.
| Control | Typical Justification |
|---|---|
| A.7.4 Physical security monitoring | All processing occurs in AWS GovCloud or Microsoft Azure with inherited physical controls from the cloud provider's own certifications |
| A.7.9 Security of assets off-premises | Employees work remotely but use company-managed MDM laptops with full-disk encryption, MDM enrollment, and remote wipe capability |
| A.8.10 Information deletion | Cloud-native workloads use AWS S3 Object Lock or Azure Blob Immutable Storage for retention requirements that override deletion |
| A.8.19 Installation of software on operational systems | All production systems run immutable container images with no in-place installations permitted |
Source: ISO 27001 SoA review with multiple certified organizations, 2026.
SoA review and audit cadence
The SoA should be reviewed at least annually and updated for significant changes. Treat the SoA as a living document that management reviews during the management review meeting and that auditors can read to understand your entire ISMS at a glance. Outdated SoAs are a leading indicator of an aging ISMS program.
Internal links
See related ISO 27001 implementation guides: ISO 27001 cost guide, SOC 2 audit prep checklist, and HIPAA risk assessment template.
FAQs
See FAQ section above for SoA purpose, Annex A control counts in ISO 27001:2022, exclusion rules, signature authority, and update cadence.
Annex A control themes and examples
ISO 27001:2022 Annex A consolidates controls into four themes. Understanding the structure helps build a logical SoA document that auditors can review efficiently.
| Theme | Categories | Example Controls |
|---|---|---|
| Organizational (37 controls) | A.5 Policies, A.6 People, A.7 Physical, A.8 Tech (org level) | A.5.1 Information security policies, A.5.7 Threat intelligence, A.5.19 Supplier relationships |
| People (8 controls) | A.6 People controls | A.6.1 Screening, A.6.3 Awareness training, A.6.8 Disciplinary process |
| Physical (14 controls) | A.7 Physical controls | A.7.1 Physical security perimeter, A.7.4 Monitoring, A.7.9 Off-premises |
| Technological (34 controls) | A.8 Technical controls | A.8.2 Privileged access, A.8.5 Auth, A.8.24 Crypto, A.8.28 Secure coding |
Source: ISO/IEC 27001:2022 Annex A structure, 2026.
FAQ expansion
Q: What is the difference between required and addressable controls in ISO 27001? ISO 27001 uses "shall" for required controls (must implement) and "should" for addressable controls (must implement or document alternative). Annex A controls use "control" language that requires implementation unless an exclusion is justified.
Q: How long does ISO 27001 certification take? ISO 27001 certification typically takes 9-18 months for a first-time certification. The schedule driver is remediation of identified gaps. Many organizations spend 6-12 months implementing missing controls before the certification audit, then 2-3 months for the audit and report issuance.
Q: Can ISO 27001 and SOC 2 be done together? Yes. ISO 27001 and SOC 2 share 70-80 percent of their control requirements. Many organizations pursue both certifications simultaneously to maximize audit efficiency. Auditors can often do combined Stage 1 / readiness and combined certification / Type II audits with shared evidence.






