ISO/IEC 27001:2022

ISO 27001 Statement of Applicability Explained

The Statement of Applicability, commonly called the SoA, is one of the most important mandatory documents in ISO 27001 implementation.

This guide explains what the SoA is, what it should include, how it links to risk assessment and Annex A controls, and what auditors typically look for during certification audits.

10 min read SoA Implementation Guide

Key Takeaways

  • The Statement of Applicability is mandatory under ISO/IEC 27001:2022.
  • The SoA identifies which Annex A controls are applicable or not applicable.
  • Each control decision should include justification.
  • The SoA should align with risk assessment and risk treatment results.
  • Auditors will check whether the SoA reflects actual implementation, not only document completion.

In This Article

What is a Statement of Applicability? Why ISO 27001 Requires the SoA What the SoA Should Include Statement of Applicability Example Structure Applicable vs Not Applicable Controls Link Between SoA and Risk Assessment Control Implementation Status Common SoA Mistakes What Auditors Look For FAQ

What is a Statement of Applicability?

The Statement of Applicability is a controlled ISMS document that identifies the organization’s decision on each ISO 27001 Annex A control.

It explains which controls are applicable, which controls are not applicable, the justification for those decisions, and the implementation status of the selected controls.

Control Selection

Identifies which Annex A controls are applicable to the organization’s ISMS.

Justification

Explains why each control is included or excluded.

Implementation Evidence

Shows whether selected controls have been implemented, planned or require further action.

Why ISO 27001 Requires the SoA

ISO 27001 is risk-based. The organization is expected to determine information security risks and decide which controls are necessary to treat those risks.

The SoA provides a structured record of these control decisions. It prevents organizations from treating Annex A as a simple checklist and instead requires them to justify control applicability based on risk, legal requirements, contractual obligations, business needs and operational context.

The SoA helps demonstrate:

  • Which Annex A controls are applicable to the ISMS.
  • Why controls are applicable or not applicable.
  • Whether selected controls have been implemented.
  • How control selection relates to risk treatment.
  • How the organization has considered all Annex A controls.

What the Statement of Applicability Should Include

A practical SoA should be clear, complete and easy to audit. It should include enough information to explain the organization’s control decisions without becoming overly complex.

Control Reference

Annex A Control

Control number and control title from ISO/IEC 27001:2022 Annex A.

Applicability

Applicable / Not Applicable

Clear decision on whether the control applies to the organization.

Justification

Reason for Decision

Business, legal, contractual, risk-based or operational reason for inclusion or exclusion.

Status

Implementation Status

Indicates whether the control is implemented, planned, partially implemented or not applicable.

Statement of Applicability Example Structure

The table below shows a simplified SoA structure that organizations can use as a starting point.

Control Ref. Control Title Applicable? Justification Implementation Status Related Document / Evidence
A.5.1 Policies for information security Yes Required to establish information security direction and governance. Implemented Information Security Policy
A.5.9 Inventory of information and other associated assets Yes Required to identify and protect information assets within the ISMS scope. Implemented Information Asset Register
A.5.19 Information security in supplier relationships Yes Applicable due to outsourced IT and cloud services. Partially Implemented Supplier Security Evaluation
A.8.25 Secure development life cycle No Organization does not develop software internally or outsource software development. Not Applicable Justification recorded in SoA

Download the Free ISO 27001 Starter Pack

Includes implementation checklist, documented information list, information asset register sample and risk assessment sample.

Download Starter Pack

Applicable vs Not Applicable Controls

Not every Annex A control will necessarily apply to every organization. However, every control should be considered and the decision should be justified.

Applicable Control

A control is applicable when it is needed due to risk assessment results, legal requirements, contractual obligations, business needs or operational activities.

Not Applicable Control

A control may be excluded where it is genuinely not relevant to the organization’s scope, activities, information assets or risk environment.

Example:

If an organization does not develop or outsource software development, secure development controls may be not applicable. However, the reason must be documented clearly in the SoA.

Control Implementation Status

The SoA should indicate the implementation status of applicable controls. This helps the organization track progress and helps auditors understand whether selected controls are already implemented or still planned.

Status

Implemented

The control has been established and evidence is available.

Status

Partially Implemented

The control has been started but still requires further action.

Status

Planned

The control has been selected but implementation is not yet completed.

Status

Not Applicable

The control is excluded with documented justification.

Common SoA Mistakes

  • Marking all controls as applicable without proper review.
  • Excluding controls without clear justification.
  • Preparing the SoA before completing risk assessment.
  • Using generic justification copied from templates.
  • Not updating the SoA after risk assessment changes.
  • Claiming controls are implemented without objective evidence.
  • Not linking the SoA to the Risk Treatment Plan.

What Auditors Look For

Does the SoA cover all Annex A controls?
Is applicability clearly stated for each control?
Is justification provided for inclusion and exclusion?
Does the SoA align with risk assessment results?
Does the SoA align with the Risk Treatment Plan?
Is implementation status accurate and supported by evidence?
Are excluded controls genuinely not applicable?
Has the SoA been reviewed and updated when risks or controls changed?

Frequently Asked Questions (FAQ)

Yes. The Statement of Applicability is mandatory under ISO/IEC 27001:2022 and is one of the key documents reviewed during certification audits.

Yes. Controls may be excluded if they are genuinely not applicable to the organization. However, the exclusion must be justified in the SoA.

Yes. The SoA should reflect control decisions arising from risk assessment, risk treatment, legal requirements, contractual obligations and business needs.

The SoA should be reviewed when there are changes to risks, systems, business activities, legal requirements, supplier arrangements or control implementation status.

Need a Practical ISO 27001 SoA Template?

Access the complete ISO 27001 Document Kit with Statement of Applicability, risk assessment register, risk treatment plan, risk acceptance record and related ISMS templates.

View ISO 27001 Document Kit