ISO 27001 Annex A controls for a small team

Annex A is a reference list, not a checklist. Here is what each of the four themes asks of a small company, and how exclusions are recorded.

How many ISO 27001 Annex A controls are there? Ninety three in the 2022 revision, in four themes. The accreditation system and a compliance platform both state the count:

  • IAF MD 26 states that the number of information security controls went from 114 controls in 14 clauses to 93 controls in 4 clauses, of which 11 are new, 24 are merged from existing controls and 58 are updated. Source, read 2026-09-28.
  • Drata states that ISO 27001:2022 includes 93 controls grouped into four themes: Organizational with 37 controls, People with 8, Physical with 14 and Technological with 34. Source, read 2026-09-28.

The number matters less than the rule behind it. You do not implement all 93. You decide which ones your risks need, and you write down why the rest do not apply.

That rule is the difference between a certification that fits a twelve person company and one that buries it. This page reads Annex A the way a small, cloud-hosted team meets it, theme by theme.

Annex A is a reference list

Annex A sits at the back of ISO/IEC 27001. The implementation guidance for each control is a separate standard, ISO/IEC 27002.

  • IAF MD 26 states that Annex A of ISO/IEC 27001:2022 references the information security controls in ISO/IEC 27002:2022, and that Annex A is normative. Source, read 2026-09-28.
  • ISO lists ISO/IEC 27002:2022 as edition 3, published in February 2022 and 152 pages long, and describes it as offering best practices and control objectives, while ISO/IEC 27001 outlines the requirements for an ISMS. Source, read 2026-09-28.

Normative means you must use it. It does not mean you must implement every control in it. What the standard requires is a comparison.

  • IAF MD 26 states that the requirements in ISO/IEC 27001 that use Annex A are the comparison of the controls an organization has determined against Annex A, in clause 6.1.3 c), and the production of a Statement of Applicability, in clause 6.1.3 d). Source, read 2026-09-28.
  • Drata states that not all Annex A controls are mandatory, that controls are selected based on a risk assessment, and that exclusions need justifications in the Statement of Applicability. Source, read 2026-09-28.

So the order is fixed. Risks first, then the controls that treat them, then Annex A as a check that nothing was missed. A Statement of Applicability written from the list downwards gets the order backwards, and the risk register will not explain it.

The four themes, read for a small team

The areas below are described rather than quoted, with their clause ranges, so you can line them up against the standard. Annex A text is copyrighted, and ISO sells it.

ThemeAreas coveredFor a small cloud-hosted team
Organizational (5.1 to 5.37)Policies, roles, threat intelligence, asset inventory, classification, access and identity, suppliers and cloud services, incidents, continuity, legal and privacy requirements, independent reviewNearly all of it applies. Most of the evidence is a policy plus a record that the policy ran: an access review, a supplier review, an incident log
People (6.1 to 6.8)Screening, terms of employment, awareness and training, disciplinary process, duties after leaving, confidentiality agreements, remote working, reporting security eventsExpect to keep all eight once anyone works for you, contractors included. Remote working is in scope for a distributed team
Physical (7.1 to 7.14)Perimeters, entry, offices, physical monitoring, environmental threats, secure areas, clear desk and screen, equipment, off-site assets, storage media, utilities, cabling, maintenance, disposalThe data center controls sit with your cloud provider, managed as a supplier. Office controls depend on whether you have an office. Laptops, media and disposal still apply
Technological (8.1 to 8.34)Endpoints, privileged access, authentication, source code, malware, vulnerabilities, configuration, deletion and masking, data leakage, backup, logging and monitoring, networks, cryptography, secure development and changeMost of it applies to a software company, and this is where the engineering time goes. Much of the evidence can come straight from your cloud and code host settings

Two themes carry most of the work. Organizational controls are mostly policies and the records that prove they ran. Technological controls are mostly settings in your cloud account, your identity provider and your code host.

The people theme is small and easy to underrate. Screening, training records and signed confidentiality agreements all need a record per person. Contractors count.

Writing exclusions that survive Stage 1

An exclusion is a sentence in the Statement of Applicability. It needs a reason tied to your scope or your risk assessment. Convenience is not a reason.

A reason that holds
“No office. All staff work remotely on company laptops, and production runs in a public cloud managed as a supplier.” It names the fact that makes the control irrelevant.
A reason that does not
“Not applicable to our business.” It names nothing, and an auditor will ask what changed.

Watch the ones that look physical but are not. A remote team still has laptops, still has storage media and still disposes of equipment. Those controls stay applicable even when the office ones go.

Suppliers are the other trap. Handing a control to your cloud provider does not remove it. It moves it into your supplier controls, where you evidence that you checked the provider.

What the 2022 revision changed

If you read an older guide, the numbers will not match. The 2013 edition had 114 controls in fourteen clauses. The 2022 edition merged many of them and added eleven.

  • ISO lists ISO/IEC 27001:2022 as edition 3, published in October 2022 and 19 pages long, with one amendment published in 2024. The 2013 edition is listed as withdrawn. Source, read 2026-09-28.
  • Drata lists the 11 controls new in ISO 27001:2022 as threat intelligence (5.7), information security for use of cloud services (5.23), ICT readiness for business continuity (5.30), physical security monitoring (7.4), configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage protection (8.12), monitoring activities (8.16), web filtering (8.23) and secure coding (8.28). Source, read 2026-09-28.
  • IAF MD 26 set 31 October 2025 as the date by which certification bodies had to complete the transition of their certified clients to ISO/IEC 27001:2022. Source, read 2026-09-28.

Several of the new ones land squarely on a software company. Cloud services, configuration management, deletion, data leakage, monitoring and secure coding are all things a startup already does. The work is writing down how, and keeping the record.

How Annex A lines up with SOC 2

If a buyer has also asked for SOC 2, most of these controls feed the Trust Services Criteria too. The themes map cleanly even where single controls do not. ISO 27001 to SOC 2 prints the full crosswalk, and SOC 2 vs ISO 27001 compares the two frameworks end to end.

Where we fit

On Polara G.R.C. the Statement of Applicability arrives seeded. All 93 Annex A controls are pre-filled from your intake answers, each marked applicable or excluded with a justification, and you confirm every row yourself. Readiness is $5,000 one time.

The ISO 27001 product page lists everything the readiness work includes. How long ISO 27001 takes covers the calendar from here to Stage 2, and what ISO 27001 certification costs covers both invoices.

Who certifies you

Polara Labs is not a certification body. Certification audits are performed by independent accredited certification bodies.

Questions

How many controls are in ISO 27001 Annex A?
Ninety three, in the 2022 revision, grouped into four themes: organizational, people, physical and technological. The 2013 edition had 114 controls in 14 clauses. The International Accreditation Forum records that 11 of the 93 are new, 24 were merged from older controls and 58 were updated.
Do I have to implement all 93 Annex A controls?
No. Your risk assessment decides which controls you need. Annex A is the reference list you compare that selection against, so nothing necessary is missed. Every control is recorded in the Statement of Applicability, either as applicable or as excluded with a justification.
What is a Statement of Applicability?
The document that lists every Annex A control, says whether it applies to you, and gives the reason either way. A certification body reads it early, because it shows how your risk assessment turned into controls.
Can a remote startup exclude the physical controls?
Some of them, with a reason. If there is no office, office controls can be justified as not applicable. Data center controls are usually met through the cloud provider, managed as a supplier. Controls covering laptops, storage media and disposal still apply to a fully remote team.
Where can I read the Annex A control text?
In the standard itself, which ISO sells. ISO/IEC 27002 gives the implementation guidance for each control. This page describes the areas and clause ranges rather than reproducing the text.

Get audit-ready without a compliance team.

The readiness assessment is free, with no payment and no card. $4,000 one time for SOC 2 Type 1 when you are ready, with the first examination and the auditor engagement fee included. audit-ready starting at about a week.

Take the free assessment

Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.