Coverage
The 2022 structure, and where the work actually lands
The 2022 edition replaced the 2013 edition’s fourteen domains with 93 controls across four themes. Your Statement of Applicability — which controls apply, which do not, and why — is the first document any certification auditor opens.
Organizational controls (37)
Policies, roles and responsibilities, supplier and cloud-service relationships, incident management, business continuity, threat intelligence and the legal and regulatory register. The largest theme by count, and the one most often under-documented.
People controls (8)
Screening, terms of employment, awareness and training, the disciplinary process, remote working and confidentiality agreements. Small in number, disproportionately common as a nonconformity.
Physical controls (14)
Secure areas, equipment siting and protection, clear desk and clear screen, secure disposal and media handling. Routinely skipped by cloud-only teams, and still assessed — a co-working desk and an unlocked laptop are in scope.
Technological controls (34)
Access control, cryptography, logging and monitoring, malware protection, data leakage prevention and secure development (A.8.25–A.8.29). This is where independent testing evidence goes straight into the file rather than being asserted.
Clauses 4 to 10
The management-system requirements that are not in Annex A at all: context, leadership, planning, support, operation, performance evaluation and improvement. Certification is failed here more often than on a technical control.
Scope definition
Which entities, sites, systems and services are being certified, and what is legitimately excluded. This single decision is the largest lever on both cost and audit duration, and it is the first thing we settle.