
Interactive reference covering all mandatory clauses (4–10) and all 93 Annex A controls from the current ISO/IEC 27001:2022 standard. Click any clause or control to expand its requirements.
What the mandatory clauses require
Clauses 4–10 are mandatory for every organisation seeking ISO 27001:2022 certification — there are no exceptions. Together they form the Plan-Do-Check-Act (PDCA) cycle that drives the ISMS. Annex A controls are selected and justified in the Statement of Applicability (SoA).
Key ISMS Deliverables (Certification Essentials)
Statement of Applicability (SoA)
Every Annex A control listed with applicability decision and justification
Risk Assessment Report
Documented risk assessment methodology, results, and risk register
Risk Treatment Plan (RTP)
Selected treatments, controls mapped, residual risk accepted
Information Security Policy
Top management approved; communicated to all personnel
ISMS Scope Document
Defined boundaries — systems, locations, processes, exclusions justified
Internal Audit Reports
Evidence of planned internal audit programme execution
Management Review Minutes
Top management review of ISMS performance at planned intervals
Corrective Action Records
Documented nonconformities, root cause analysis, and corrective actions
2013 → 2022 Key Changes
Controls reduced
114 controls
93 controls
24 merged, 1 deleted, 11 new added
Categories restructured
14 domains
4 themes
Org / People / Physical / Technological
Clause 6.3 added
Not present
Planning of changes
Formalises ISMS change management