Annex A
ISO/IEC 27001:2022’s reference set of 93 information-security controls used in risk treatment.
In practice
Annex A is ISO/IEC 27001:2022's control catalog (93 controls in four themes). Organizations select applicable controls in the Statement of Applicability — Annex A is not a mandatory checklist of 93 implemented controls for every SaaS company.
Common confusion
Annex A is not a mandatory checklist requiring every control; justified treatment follows risk.