On this page
ISO 27001 no longer organizes Annex A into domains. The 2013 edition grouped 114 controls into 14 domains. ISO/IEC 27001:2022 regrouped 93 controls into four themes: organizational (37 controls), people (8), physical (14), and technological (34). People still search for “domains”, so this page lists both structures, shows where each old domain went, and maps the four themes to the SOC 2 Trust Services Criteria. Certificates based on the 2013 edition had to expire or be withdrawn by 31 October 2025.
This page covers structure and evidence mapping. To decide which framework your buyers need, read SOC 2 vs ISO 27001 or use the five-question selector. ISO 27002 vs ISO 27001 covers how the two standards differ, and our ISO 27001 framework overview covers the framework as a whole.
What are the four ISO 27001 themes?
Annex A of ISO/IEC 27001:2022, the third edition, published in October 2022, lists 93 controls in four themes. The International Accreditation Forum’s transition rule, IAF MD 26, records the change in the matching ISO/IEC 27002:2022 control set: 114 controls in 14 clauses became 93 controls in 4 clauses. Of the 93, 11 are new, 24 merged earlier controls, and 58 were updated.
| Theme (Annex A numbers) | Controls | New in 2022 | What it covers |
|---|---|---|---|
| Organizational (5.1 to 5.37) | 37 | 5.7, 5.23, 5.30 | Policies, roles, asset handling, access rules, suppliers, incidents, continuity, legal and compliance requirements |
| People (6.1 to 6.8) | 8 | None | Screening, employment terms, awareness training, discipline, offboarding, confidentiality agreements, remote working, event reporting |
| Physical (7.1 to 7.14) | 14 | 7.4 | Perimeters, entry, secure areas, equipment siting, utilities, cabling, maintenance, disposal |
| Technological (8.1 to 8.34) | 34 | 8.9, 8.10, 8.11, 8.12, 8.16, 8.23, 8.28 | Endpoints, privileged access, authentication, malware, vulnerabilities, backup, logging, networks, cryptography, secure development, change management |
| Total | 93 | 11 |
Seven of the 11 new controls are technological: configuration management (8.9), information deletion (8.10), data masking (8.11), data leakage prevention (8.12), monitoring activities (8.16), web filtering (8.23), and secure coding (8.28). The other four are threat intelligence (5.7), information security for cloud services (5.23), ICT readiness for business continuity (5.30), and physical security monitoring (7.4). SGS lists the same eleven.
Per-theme counts follow the control numbering in the published Annex A, as listed in DataGuard’s Annex A overview. They sum to the 93 that IAF records.
What were the 14 ISO 27001 domains, and where did they go?
The 14 domains were Annex A clauses A.5 to A.18 in the 2013 edition. The table shows the main 2022 destination of each. It is our domain-level summary. The move is many-to-many, so a single old domain often feeds more than one theme. The control-by-control correspondence is Annex B of ISO/IEC 27002:2022, which ISO sells.
| 2013 domain | Main 2022 theme | Examples of where its controls landed (2022 numbers) |
|---|---|---|
| A.5 Information security policies | Organizational | 5.1 Policies for information security |
| A.6 Organization of information security | Organizational, with some in People and Technological | 5.2 Roles and responsibilities, 5.3 Segregation of duties, 6.7 Remote working, 8.1 User endpoint devices |
| A.7 Human resource security | People, with some in Organizational | 6.1 Screening, 6.3 Awareness and training, 6.5 After termination or change, 5.4 Management responsibilities |
| A.8 Asset management | Organizational, with some in Physical | 5.9 Inventory of assets, 5.12 Classification of information, 7.10 Storage media |
| A.9 Access control | Organizational and Technological | 5.15 Access control, 5.18 Access rights, 8.2 Privileged access rights, 8.5 Secure authentication |
| A.10 Cryptography | Technological | 8.24 Use of cryptography |
| A.11 Physical and environmental security | Physical | 7.1 Physical security perimeters, 7.2 Physical entry, 7.14 Secure disposal or re-use of equipment |
| A.12 Operations security | Technological, with some in Organizational | 8.7 Protection against malware, 8.8 Technical vulnerabilities, 8.13 Backup, 8.15 Logging, 5.37 Documented operating procedures |
| A.13 Communications security | Technological, with some in Organizational | 8.20 Networks security, 8.22 Segregation of networks, 5.14 Information transfer |
| A.14 System acquisition, development and maintenance | Technological, with some in Organizational | 8.25 Secure development life cycle, 8.26 Application security requirements, 8.29 Security testing, 5.8 Security in project management |
| A.15 Supplier relationships | Organizational | 5.19 Supplier relationships, 5.20 Supplier agreements, 5.22 Monitoring and review of supplier services |
| A.16 Information security incident management | Organizational, with some in People | 5.24 Incident planning, 5.26 Response, 5.27 Learning from incidents, 6.8 Event reporting |
| A.17 Business continuity aspects | Organizational, with some in Technological | 5.29 Security during disruption, 5.30 ICT readiness for continuity, 8.14 Redundancy |
| A.18 Compliance | Organizational | 5.31 Legal and contractual requirements, 5.34 Privacy and PII, 5.35 Independent review |
The numbers collide across editions. In 2013, A.6 was the organization of information security, A.7 human resources, and A.8 asset management. In 2022, controls numbered 6.x are people, 7.x physical, and 8.x technological. Check which edition a spreadsheet uses before trusting a control number. An old A.9 access control row now needs two owners: identity and access rules sit in organizational controls 5.15 to 5.18, and technical enforcement sits in 8.2 to 8.5.
IAF MD 26 required certification bodies to finish moving certified clients to the 2022 edition by 31 October 2025, and says all certifications based on the 2013 edition expire or are withdrawn at the end of that period. A certificate or Statement of Applicability that still names the 2013 edition is out of date.
ISO still uses the word “domain” in a different sense. ISO/IEC 27002:2022 tags each control with five attributes, one of which is “security domains”: governance and ecosystem, protection, defence, and resilience, as InfoGuard summarizes. That tag is a filter on the catalogue, not the Annex A structure.
How do the themes map to the SOC 2 Trust Services Criteria?
The AICPA’s Trust Services Criteria have 61 criteria in five categories: 33 Common Criteria (CC1 to CC9) that make up Security, plus Availability (A1, 3 criteria), Confidentiality (C1, 2), Processing Integrity (PI1, 5), and Privacy (P1 to P8, 18). Our Trust Services Criteria guide lists every series.
The matrix below is our reading of where ISO 27001 evidence usually supports each SOC 2 series. It is not an AICPA or ISO crosswalk. The AICPA lists a mapping of the 2017 Trust Services Criteria to ISO 27001 for members, dated May 2018. We could not open it, and it predates the 2022 Annex A. Control numbers below are Annex A controls with the A. prefix. “Clause” means a management-system requirement in clauses 4 to 10 of ISO 27001, outside Annex A.
| SOC 2 series | Annex A controls that usually supply evidence | Other ISO 27001 sources and gaps |
|---|---|---|
| CC1 Control environment | Organizational: A.5.1, A.5.2, A.5.4. People: A.6.1 to A.6.4. | Clause 5 (leadership) and clause 9.3 (management review) cover management oversight. |
| CC2 Communication and information | Organizational: A.5.5, A.5.6, A.5.14. People: A.6.3, A.6.8. | Clauses 7.4 (communication) and 7.5 (documented information). |
| CC3 Risk assessment | Organizational: A.5.7, A.5.8. | Clauses 6.1.2 and 8.2 (risk assessment) and 6.1.3 (risk treatment). The ISO assessment covers information security risk, so CC3.3 (fraud risk) usually needs its own evidence. |
| CC4 Monitoring activities | Organizational: A.5.35, A.5.36. | Clauses 9.1 (monitoring and measurement), 9.2 (internal audit), 9.3 (management review), and 10.2 (corrective action). |
| CC5 Control activities | Organizational: A.5.1, A.5.37. | Clause 6.1.3 (control selection and the Statement of Applicability). |
| CC6.1 to CC6.3, CC6.6 to CC6.8 Logical access, boundary protection, data movement, malicious software | Organizational: A.5.15 to A.5.18. Technological: A.8.2 to A.8.5, A.8.7, A.8.20 to A.8.22, A.8.24. People: A.6.5. | A.6.5 (offboarding) feeds CC6.2. A.5.14 and A.8.12 feed CC6.7. |
| CC6.4, CC6.5 Physical access, asset disposal | Physical: A.7.1 to A.7.4, A.7.10, A.7.14. | When a cloud provider runs the facility, SOC 2 usually treats it as a subservice organization. See carve-out vs inclusive method. |
| CC7 System operations | Technological: A.8.8, A.8.9, A.8.15, A.8.16. Organizational: A.5.24 to A.5.28. People: A.6.8. | CC7.1 and CC7.2 (detection, monitoring) line up with the technological controls. CC7.3 to CC7.5 (evaluation, response, recovery) line up with incident management. |
| CC8 Change management | Technological: A.8.25, A.8.29, A.8.31 to A.8.33. Organizational: A.5.8. | A.8.32 is the single change-management control. See SOC 2 change management controls. |
| CC9 Risk mitigation | Organizational: A.5.19 to A.5.23, A.5.29, A.5.30. Technological: A.8.14. | A.5.23 and A.5.30 are new in 2022, so a 2013 library has no row for them. |
| A1 Availability | Technological: A.8.6, A.8.13, A.8.14. Physical: A.7.5, A.7.8, A.7.11. Organizational: A.5.29, A.5.30. | Optional category. Add it only if it is in scope for your report. |
| C1 Confidentiality | Organizational: A.5.12 to A.5.14. People: A.6.6. Technological: A.8.10 to A.8.12, A.8.24. Physical: A.7.14. | Optional category. |
| PI1 Processing integrity | No Annex A control is aimed at whether processing is complete and accurate. | A.8.26 and A.8.29 cover application security requirements and testing, not processing accuracy. Input, processing, and output checks are evidence you build outside the ISMS. |
| P1 to P8 Privacy | Organizational: A.5.34, A.5.31. | Annex A has one control written for privacy. Notice, consent, access, and disclosure criteria need their own evidence. ISO/IEC 27701 is the ISO privacy information management standard. |
Organizational controls appear against every series except physical access and processing integrity. Technological controls carry the system-level series, CC6 to CC8 and A1. People controls are a small band, feeding CC1, CC2, CC6, CC7, and C1. Physical controls cover a narrow set of criteria: physical access, asset disposal, and environmental protection under Availability.
Two SOC 2 areas lean on the management-system clauses instead of Annex A: risk assessment (CC3) and monitoring (CC4). A team that builds its library from the Annex A list alone will miss both.
What will an auditor ask to see, by theme?
Annex A tells you what safeguards to consider. A SOC 2 auditor tests whether the control was designed to meet the selected criterion and, in a Type 2 report, whether it operated across the period. For each mapped control, name the owner, the population, the operating frequency, and the artifact.
Organizational evidence is the approved information security policy with version history, the risk assessment and register, supplier due-diligence files, the incident response plan with test records, and continuity materials. Auditors look for approval, an owner, and proof that management reviews them on a schedule.
People evidence is screening records where applicable, training completion for the assigned population with follow-up on overdue staff, signed confidentiality terms, and dated offboarding tickets. The usual gap is showing that the policy exists without showing how exceptions and departures were handled.
Physical evidence for your own premises is office access logs, visitor records, equipment inventories, and disposal records. For a facility a cloud provider operates, keep the provider’s assurance report and your review of it. Do not describe a control as yours if a third party runs it.
Technological evidence is where most system-generated records sit: access configurations and reviews, encryption settings, log sources and alert reviews, vulnerability scans with remediation tickets, code review and deployment approvals, and incident tickets. A screenshot with no owner, date, or system rarely shows sustained operation.
The Statement of Applicability, required by clause 6.1.3, records which Annex A controls apply, why, and whether each is implemented. It is a useful inventory of what to map. SOC 2 has no equivalent document, so your SOC 2 scope still comes from the system description and the criteria you select.
What goes wrong when you reuse an ISO control library for SOC 2?
An ISO 27001 certificate is not SOC 2 readiness. The two share policies, risk assessment, access reviews, incident procedures, and supplier oversight. An accredited certification body certifies an ISMS against the scope you set. A CPA firm gives an opinion on controls against the Trust Services Criteria you chose, for a defined system and period. SOC 2 vs ISO 27001 covers what carries over.
Rebuild a 2013 spreadsheet instead of renaming its rows. The 11 controls added in 2022, such as threat intelligence (5.7), cloud services (5.23), configuration management (8.9), and secure coding (8.28), have no 2013 row. Each needs a named owner, a procedure, and evidence.
The ISMS scope and the SOC 2 system boundary can differ. Check that support staff, contractors, and critical suppliers sit inside both.
A single broad policy mapped to several criteria does not show that any of them operates. Tie each criterion to the activity that runs and the record it leaves.
If you are picking a firm for SOC 2 while keeping an ISO 27001 program, compare the firms that do both or request quotes.
More in Framework Comparisons