Back to all articles
Compli.st Journal#ISO 27001#Annex A#Controls#Checklist

ISO 27001 Checklist: All 93 Annex A Controls Explained

Complete checklist of all 93 ISO 27001 Annex A controls (2022 version): 4 themes explained with implementation tips for SMBs.

CS

Compli.st Team

Security & compliance experts

Published
Reading time

3 min read

Annex A of ISO 27001:2022 — What Changed

The 2022 update restructured Annex A from 114 controls in 14 domains to 93 controls in 4 themes, adding 11 new controls.

The 4 Themes

Theme 1: Organizational Controls (37)

Governance, policies, roles, asset management, access control, business continuity, compliance. Key controls: A.5.1 (policies), A.5.15 (access control), A.5.23 (cloud security — new).

Theme 2: People Controls (8)

HR security from hiring to departure. A.6.7 (remote working) is new and highly relevant.

Automate Your Security Questionnaires

Compli.st answers your ISO 27001, SOC 2 and GDPR questionnaires in minutes using AI.

Try for Free

Theme 3: Physical Controls (14)

Premises, equipment, storage media security. For full-remote SaaS: document your cloud provider's certifications.

Theme 4: Technological Controls (34)

Encryption, networking, secure development, monitoring. New controls include configuration management (A.8.9), DLP (A.8.12), and secure coding (A.8.28).

The 11 New Controls in 2022

Threat intelligence, cloud security, ICT readiness, remote working, physical monitoring, configuration management, data deletion, data masking, DLP, monitoring activities, web filtering.

Statement of Applicability

You don't need all 93 controls. The SoA justifies applicability of each control for your organization.

Compli.st auto-maps your existing controls to Annex A and identifies gaps.

Start your ISO 27001 checklist →

Keep learning

Hand-picked playbooks from the team

Curated by Compli.st strategists so you stay in the flow.

Ready to automate trust?

Move from endless questionnaires to answers in hours.

Connect your policies, controls, and our AI to deliver customer evidence on the very first security follow-up.

Try Compli.stSchedule a demo

“Compli.st replies to customer questionnaires in under 24 hours. It became our secret weapon during enterprise closes.”

Security Lead · B2B SaaS scale-up