Search Annex A controls, get descriptions and common audit evidence. Covers ISO 27001:2022 (93 controls, 4 themes) and 2013 (114 controls, 14 domains) with cross-version mapping. Built for GRC analysts prepping for audits.
Open any control for its intent, the audit evidence assessors expect, and its ISO 27001:2013 mapping.
ISO/IEC 27001:2022 Annex A defines 93 controls grouped into four themes: Organizational (37), People (8), Physical (14) and Technological (34). This tool lets you search and browse all 93, each with a description and common audit evidence.
The 2022 revision consolidated the 114 controls from the 2013 edition (across 14 domains) into 93 controls across 4 themes, merged 57 controls, and introduced 11 new ones — for example threat intelligence, cloud security, and data masking. Use the cross-version mapping in this tool to see how each 2013 control maps to 2022.
Yes. The control reference is 100% free and runs entirely in your browser — no account, no sign-up, and nothing is sent to a server. You can also map controls to NIST CSF 2.0 and SOC 2 with the Control Mapper.
Yes — each control includes typical audit evidence to help you prepare your Statement of Applicability (SoA) and gather artefacts. Pair it with the Gap Assessment to score maturity and the Risk Register to document treatment.