ISO 27001 Annex A Checklist
All 93 Annex A controls from ISO/IEC 27001:2022 across four themes. Tick each control as you implement it — progress is saved in your browser.
37
A.5 · Organisational
8
A.6 · People
14
A.7 · Physical
34
A.8 · Technological
Related Compliance Frameworks
6-function framework (GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER) for any organisation size.
18 prioritised controls in 3 implementation groups. Practical cyber hygiene baseline.
12 requirements for entities handling payment card data. Mandatory for merchants and service providers.
Trust Service Criteria audit covering Security, Availability, Confidentiality, Integrity and Privacy.
India mandatory incident reporting: 6-hour reporting window, 180-day log retention, NTP sync.
Reserve Bank of India Master Directions covering cyber risk, SOC requirements and incident reporting.
Administrative, physical and technical safeguards for electronic Protected Health Information (ePHI).
Frequently Asked Questions
What is ISO/IEC 27001:2022?
It's the international standard for an Information Security Management System (ISMS), specifying requirements for establishing, implementing, maintaining and continually improving an organisation's approach to managing information security risk.
How many Annex A controls does ISO 27001:2022 have?
93 controls organised into four themes: Organisational (37), People (8), Physical (14) and Technological (34) — reduced and reorganised from the 114 controls across 14 domains in the 2013 version.
Do I need to implement all 93 controls to get certified?
No. Annex A controls are only applied where relevant to your Statement of Applicability (SoA) — certification requires justifying inclusion or exclusion of each control based on your risk assessment, not blanket implementation.
What's the difference between ISO 27001 and ISO 27002?
ISO 27001 is the certifiable management-system standard (the requirements and the Annex A control list); ISO 27002 is the companion guidance standard explaining how to implement each control in detail.