
If you work towards ISO/IEC 27001 certification, one document comes up in every audit: the Statement of Applicability, often shortened to SoA. It is short to describe and easy to get wrong.
What it is
The SoA is required by clause 6.1.3 of ISO/IEC 27001:2022. It lists every control of Annex A, 93 controls in four themes (organizational, people, physical and technological), and states for each one:
- whether it is included or excluded;
- why: the justification for including or excluding it;
- whether the included controls are implemented.
It also covers any additional controls you chose beyond Annex A.
Why auditors care
The SoA connects your risk assessment to your controls. An auditor reads it to understand your scope and then checks that the controls you call implemented really work. A control you exclude needs a reason that fits your risks and your business, for example excluding outsourced development controls because you do not develop software.
Common mistakes
- Copy-pasted justifications. "Applicable" is not a reason. Link each control to a risk, a legal requirement or a customer obligation.
- Excluding to save work. If a risk calls for a control, excluding it raises questions rather than avoiding them.
- A document that never changes. When your risks, systems or scope change, the SoA must follow.
- Implemented on paper only. Each implemented control should point to evidence that it works.
Keeping it useful
Treat the SoA as a living view of your controls rather than a separate document. When each control records whether it applies, why, its status and its evidence, the SoA is simply a printout of the current state, and it never drifts from reality.
Certification still needs a certification body
Software and templates help you prepare, but certification is granted by an accredited certification body after its audit. Your SoA, risk assessment, internal audit and management review are what that audit looks at.
CloudSignLab keeps all 93 Annex A codes with applicability, justification and status, prints the Statement of Applicability, and adds readiness per clause, internal audits and management reviews. See the ISO 27001 page.
Start free

