ISO 27001 Annex A Controls - All 93 Controls Explained
ISO 27001:2022 includes 93 controls across 4 themes. Here is every control with implementation effort ratings and cost context to help you plan your budget.
Updated July 2026
93
Total Annex A controls
37
Organisational (A.5)
8+14
People (A.6) + Physical (A.7)
34
Technological (A.8)
Not all controls are mandatory
You must assess which controls are applicable based on your risk assessment and document justification in the Statement of Applicability. Controls not applicable must still be listed with an exclusion reason. In practice, most organisations implement 70-85 of the 93 controls.
Organisational Controls
37 controlsCost: Low-MediumPolicies, procedures, roles, and governance. Documentation-heavy but low external cost. Most controls are policy-based and require internal time rather than tool investment.
People Controls
8 controlsCost: LowHR-related controls from screening to off-boarding. Primarily require policy changes and training investment. Low external cost but require HR department engagement.
Physical Controls
14 controlsCost: VariablePhysical security for premises, equipment, and media. Cost is highly variable: cloud-native remote companies may exclude most of these. Organisations with offices and data centres need significant investment.
Technological Controls
34 controlsCost: HighTechnical controls covering endpoints, access management, encryption, vulnerability management, logging, and secure development. Most expensive theme due to potential tool purchases (SIEM, MDM, DLP, endpoint protection).
Running Annex A alongside other frameworks
Annex A controls address the same underlying security practices that other frameworks ask about, so evidence gathered once often answers more than one framework. We do not publish an overlap percentage. A credible one would have to come from a control-by-control mapping against a specific framework version and a specific ISMS scope, and the answer would change with both. Anyone quoting you a single percentage is describing their scope, not yours.
SOC 2
A US attestation report from a CPA firm, usually annual, against the Trust Services Criteria. Different instrument, overlapping evidence. See ISO 27001 vs SOC 2.
The platforms price them the same
Drata lists every framework at the same flat figure on AWS Marketplace, and Secureframe's first-framework dimension is a choice of any framework. On published platform pricing, ISO 27001 carries no premium over SOC 2, HIPAA, PCI DSS or GDPR.
Where the real saving sits
Not in a discount, but in collecting evidence once. The same access reviews, change records and risk assessments answer several frameworks, provided the scope is drawn to cover them from the start.
Integrated management systems
Certifying ISO 9001 or ISO 14001 alongside ISO 27001 means two audit-time instruments apply: IAF MD 5 for those schemes and ISO/IEC 27006-1 for the ISMS. Ask your body how it combines them. See audit cost.