Skip to main content
ISO 27001

ISO 27001: making sense of the 93 Annex A controls

The 93 Annex A controls of ISO 27001:2022, their four themes, the role of the Statement of Applicability and the real road to certification.

L'équipe Vigicap5 min read

ISO/IEC 27001 has a reputation for being out of reach: long, expensive, reserved for large accounts. That reputation comes mostly from a confusion about what the standard actually asks for.

Certification is not won in Annex A. It is won in clauses 4 to 10, which describe the management system. Annex A is a catalogue of controls to select from — not a list to be ticked in full. Understanding that distinction changes everything about how you sell an engagement and how you run it.

What does ISO 27001 really ask for?#

ISO 27001 certifies an ISMS — an information security management system. In other words: a process, not a technical level.

An auditor does not come to check that you have the right firewall. They come to check that you know:

  • what your scope and your context are (clause 4);
  • that top management commits and allocates resources (clause 5);
  • that you identify and treat your risks (clause 6);
  • that you have competence, awareness and documentation (clause 7);
  • that you operate what you planned (clause 8);
  • that you measure and audit (clause 9);
  • that you correct and improve (clause 10).

A small business with a modest infrastructure but an honest management system can be certified. A very well-equipped company that cannot evidence a process cannot.

How is Annex A structured since 2022?#

The 2022 revision reorganised Annex A thoroughly. It went from 114 controls across 14 domains to 93 controls across 4 themes.

ThemeNumber of controlsNature
Organisational37Policies, roles, suppliers, continuity
People8Screening, awareness, remote working
Physical14Secure areas, equipment, disposal
Technological34Access, cryptography, logging, development

The reorganisation removed very little: mostly it merged redundant controls and added eleven new ones, several of which reflect how practice has moved on.

Which controls did Annex A add in 2022?#

Eleven controls came in with the 2022 revision. They deserve particular attention, because these are the ones that organisations certified before 2022 discover during transition:

  • Threat intelligence
  • Information security for the use of cloud services
  • ICT readiness for business continuity
  • Physical security monitoring
  • Configuration management
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Monitoring activities
  • Web filtering
  • Secure coding

Seven of the eleven bear directly on subjects an IT service provider already operates for its clients. That is a commercial angle: these controls are not one more project, they are your existing services, which need to be documented as controls.

What is the Statement of Applicability for?#

The Statement of Applicability (SoA) is the one document every auditor opens first. It lists the 93 controls and, for each one:

  • whether it is applicable to the scope — and if not, why;
  • whether it is implemented, and to what degree;
  • where the evidence stands.

The classic mistake is to declare all 93 controls applicable "to be on the safe side". It is the surest way to create 93 evidence obligations, a good share of them pointless. A justified exclusion is perfectly acceptable; an unjustified exclusion is a nonconformity.

An honest SoA with ten reasoned exclusions goes down better than an exhaustive one where half the evidence is missing.

How should a service provider approach an ISO 27001 engagement?#

By reusing what the client already has, and by qualifying what they are actually after.

Do not start from zero. A client who has already been through a security diagnostic — on ANSSI's 42 cyber hygiene measures, for example, published by France's national cybersecurity agency — has already answered a large part of Annex A without knowing it. Basic hygiene, access control, logging, backups: all of it transposes.

Making the client fill in a second questionnaire of 93 lines after a first one of 42 is the best way to lose the engagement. The right approach is to derive the SoA from the diagnostic already carried out, and to ask only the questions that are genuinely new.

Certification is not always the objective. Plenty of small businesses do not need the certificate. What they need is to answer a customer questionnaire asking "are you aligned with ISO 27001?". That is a shorter engagement, cheaper, and far more frequent.

Systematically selling the full certification journey to clients who only want to get through a supplier audit is a qualification error. Offer both levels:

  1. Alignment — SoA filled in, gaps identified, evidence gathered. A few weeks.
  2. Certification — full ISMS, clauses 4 to 10, internal audit, management review, certification audit. Several months.

If your clients also fall under the NIS2 directive, note that the ten measures of Article 21 overlap heavily with Annex A: a single evidence base can serve both requirements.

How long does ISO 27001 certification take?#

For a business of 50 to 200 people with no history of security management, an honest certification journey rarely fits into less than nine to twelve months. The parts that take longest are almost never technical:

  • building an asset inventory that reflects reality;
  • actually holding a management review;
  • producing an internal audit that is not a rubber stamp;
  • gathering dated evidence rather than screenshots taken the week of the audit.

Which mistakes cost money on an ISO 27001 project?#

Confusing ISO 27001 and ISO 27002. 27001 is the certifiable standard; 27002 is the implementation guidance that details each control. You certify against 27001.

Treating the risk assessment as a formality. It is the heart of clause 6, and it is what justifies your Annex A choices. A rushed assessment undermines the whole SoA downstream.

Documenting for the auditor rather than for day-to-day operations. A policy nobody applies is a nonconformity waiting to happen, not evidence.

Forgetting the ongoing surveillance. The certification audit is only the beginning: surveillance audits follow, generally annual, over a three-year cycle.

TopicsISO 27001certificationSoAcompliance
NIS27 min

NIS2: a guide for IT service providers

Who NIS2 covers, what it concretely requires, the incident notification deadlines — and how an IT service provider turns all of it into an offer.