The Statement of Applicability, commonly called the SoA, is one of the most important mandatory documents in ISO 27001 implementation.
This guide explains what the SoA is, what it should include, how it links to risk assessment and Annex A controls, and what auditors typically look for during certification audits.
The Statement of Applicability is a controlled ISMS document that identifies the organization’s decision on each ISO 27001 Annex A control.
It explains which controls are applicable, which controls are not applicable, the justification for those decisions, and the implementation status of the selected controls.
Identifies which Annex A controls are applicable to the organization’s ISMS.
Explains why each control is included or excluded.
Shows whether selected controls have been implemented, planned or require further action.
ISO 27001 is risk-based. The organization is expected to determine information security risks and decide which controls are necessary to treat those risks.
The SoA provides a structured record of these control decisions. It prevents organizations from treating Annex A as a simple checklist and instead requires them to justify control applicability based on risk, legal requirements, contractual obligations, business needs and operational context.
The SoA helps demonstrate:
A practical SoA should be clear, complete and easy to audit. It should include enough information to explain the organization’s control decisions without becoming overly complex.
Control number and control title from ISO/IEC 27001:2022 Annex A.
Clear decision on whether the control applies to the organization.
Business, legal, contractual, risk-based or operational reason for inclusion or exclusion.
Indicates whether the control is implemented, planned, partially implemented or not applicable.
The table below shows a simplified SoA structure that organizations can use as a starting point.
| Control Ref. | Control Title | Applicable? | Justification | Implementation Status | Related Document / Evidence |
|---|---|---|---|---|---|
| A.5.1 | Policies for information security | Yes | Required to establish information security direction and governance. | Implemented | Information Security Policy |
| A.5.9 | Inventory of information and other associated assets | Yes | Required to identify and protect information assets within the ISMS scope. | Implemented | Information Asset Register |
| A.5.19 | Information security in supplier relationships | Yes | Applicable due to outsourced IT and cloud services. | Partially Implemented | Supplier Security Evaluation |
| A.8.25 | Secure development life cycle | No | Organization does not develop software internally or outsource software development. | Not Applicable | Justification recorded in SoA |
Includes implementation checklist, documented information list, information asset register sample and risk assessment sample.
Download Starter PackNot every Annex A control will necessarily apply to every organization. However, every control should be considered and the decision should be justified.
A control is applicable when it is needed due to risk assessment results, legal requirements, contractual obligations, business needs or operational activities.
A control may be excluded where it is genuinely not relevant to the organization’s scope, activities, information assets or risk environment.
Example:
If an organization does not develop or outsource software development, secure development controls may be not applicable. However, the reason must be documented clearly in the SoA.
The SoA should not be prepared separately from the risk assessment. It should be developed after the organization has assessed information security risks and determined risk treatment options.
| Risk Identified | Possible Treatment | Relevant SoA Control Decision |
|---|---|---|
| Unauthorized access to customer database | Strengthen access control and authentication | Access control and identity management controls marked applicable |
| Ransomware affecting file server | Improve backup, malware protection and incident response | Backup, malware protection and incident management controls marked applicable |
| Cloud storage misconfiguration | Review supplier and cloud service controls | Supplier and cloud security controls marked applicable |
| Loss of laptop with confidential information | Implement endpoint security and encryption | User endpoint device and information protection controls marked applicable |
The SoA should indicate the implementation status of applicable controls. This helps the organization track progress and helps auditors understand whether selected controls are already implemented or still planned.
The control has been established and evidence is available.
The control has been started but still requires further action.
The control has been selected but implementation is not yet completed.
The control is excluded with documented justification.
Yes. The Statement of Applicability is mandatory under ISO/IEC 27001:2022 and is one of the key documents reviewed during certification audits.
Yes. Controls may be excluded if they are genuinely not applicable to the organization. However, the exclusion must be justified in the SoA.
Yes. The SoA should reflect control decisions arising from risk assessment, risk treatment, legal requirements, contractual obligations and business needs.
The SoA should be reviewed when there are changes to risks, systems, business activities, legal requirements, supplier arrangements or control implementation status.
Access the complete ISO 27001 Document Kit with Statement of Applicability, risk assessment register, risk treatment plan, risk acceptance record and related ISMS templates.
View ISO 27001 Document Kit