Skip to content
arrow_back

ISO 27001:2022 Annex A Checklist

This is a free interactive ISO 27001:2022 Annex A checklist covering all 93 controls: 37 organisational, 8 people, 14 physical and 34 technological. Tick controls off in your browser, then download the same checklist as an Excel or CSV file. No signup, no email address, no paywall. Every control links to a plain English guide with implementation and audit evidence tips.

Last updated: August 2026. Maintained against ISO/IEC 27001:2022 (Annex A as detailed in ISO/IEC 27002:2022).

How to use this checklist

  1. Work top to bottom, or jump to a theme: Organisational (37), People (8), Physical (14), Technological (34).
  2. Mark each control Implemented, In progress or Not applicable. Your progress saves in your browser automatically. Nothing is uploaded and no account is needed.
  3. Open any control name for plain English guidance, implementation tips and audit evidence tips.
  4. Download the Excel or CSV version to work offline or in your GRC tool, or export your current progress as a CSV gap summary.

One honest caveat before you start: Annex A is not a compulsory to do list. It is a reference set of controls. Which controls apply to you is decided by your risk assessment and recorded in your Statement of Applicability, with a justification for anything you exclude. This checklist exists to help you run that decision control by control, then track implementation of the ones you keep.

Your progress

0 of 93 controls marked. Progress is saved in your browser.

Working through this with a team? Create a free account to sync your progress across devices and turn it into a live Statement of Applicability. Create a free account →

Organisational controls (37)

All organisational controls

People controls (8)

All people controls

Physical controls (14)

All physical controls

Technological controls (34)

All technological controls

What this checklist is (and is not)

  • It is a control by control tracker for Annex A of ISO/IEC 27001:2022, with the same 93 controls and four themes the standard uses.
  • It is not a full certification project plan. The management system requirements in clauses 4 to 10 (scope, leadership, risk assessment, internal audit, management review) sit outside Annex A. For the project view, use the free ISO 27001 implementation checklist from our sister site Mindset Cyber.
  • It is not a Statement of Applicability template, but the exported file gives you the control inventory and status columns an SoA is built on.
  • Running Essential Eight as well? See how the two frameworks line up in our ISO 27001 to Essential Eight mapping, or browse the full ISO 27001 Annex A controls library.

Frequently asked questions

Is this ISO 27001 checklist really free?

Yes. The interactive checklist and the Excel and CSV downloads are completely free, with no signup, no email capture and no paywall. Progress is saved in your own browser and never uploaded.

How many controls are in ISO 27001:2022 Annex A?

ISO/IEC 27001:2022 Annex A contains 93 controls in four themes: 37 organisational controls (A.5), 8 people controls (A.6), 14 physical controls (A.7) and 34 technological controls (A.8). The 2013 edition had 114 controls in 14 domains; the 2022 revision consolidated them into 93.

Do we have to implement all 93 controls?

No. Annex A is a reference set, not a mandatory to do list. You select controls through your risk assessment and record what applies in your Statement of Applicability, with a justification for any control you exclude.

Is this the same as an ISO 27001 implementation checklist?

No. This checklist covers the Annex A controls only. An implementation checklist covers the whole certification project, including the clause 4 to 10 management system requirements such as scope, leadership, risk assessment and internal audit.

Can I use this checklist for a gap analysis or internal audit?

Yes. Mark each control as Implemented, In progress or Not applicable, use each control guide for audit evidence tips, and export your progress as a CSV gap summary.

What formats can I download?

Excel (.xlsx) with a status dropdown for every control, and plain CSV. Both list all 93 controls with theme, status, owner and evidence columns, and both are direct downloads with no signup.

Want help implementing the controls?

Control Stack keeps this checklist and the 93 control guides free. If you want formal training, our sister site Mindset Cyber runs PECB accredited ISO 27001 courses, including self paced Lead Implementer and Lead Auditor eLearning. Mindset Cyber provides training and exam vouchers; it is not a certification body and cannot certify your organisation.