Skip to content
compliancebase

Annex A

ISO/IEC 27001:2022’s reference set of 93 information-security controls used in risk treatment.

In practice

Annex A is ISO/IEC 27001:2022's control catalog (93 controls in four themes). Organizations select applicable controls in the Statement of Applicability — Annex A is not a mandatory checklist of 93 implemented controls for every SaaS company.

Common confusion

Annex A is not a mandatory checklist requiring every control; justified treatment follows risk.

Related controls

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above