ISO 27001 Statement of Applicability: Complete Guide
The Statement of Applicability (SoA) is one of the most important documents in your ISO 27001 information security management system (ISMS). It records which Annex A controls are applicable to your organisation and justifies every inclusion and exclusion.
Without a properly prepared SoA, your ISO 27001 audit will fail. This complete guide explains what an SoA is, the ISO 27001 requirements, how to create one, how to map controls, and common mistakes to avoid. Whether you are building a new ISMS or maintaining an existing one, this guide ensures your SoA stands up to auditor scrutiny.
What Is an ISO 27001 Statement of Applicability?
The Statement of Applicability (SoA) is a document that lists all controls from ISO 27001 Annex A and indicates whether each control is applicable or not applicable to your organisation. For each applicable control, the SoA references how it is implemented. For excluded controls, it provides a justification for the exclusion.
The SoA serves as the bridge between your risk assessment and the controls you implement. It demonstrates to auditors that you have systematically considered every control in Annex A and made informed decisions based on your risk context.
ISO 27001 Requirements for the Statement of Applicability
Clause 6.1.3 d) of ISO 27001:2022 requires that your organisation produces a Statement of Applicability containing the following:
| Requirement | Description |
|---|---|
| Necessary controls | List of controls selected based on the risk assessment and risk treatment process |
| Justification for inclusions | Why each control is included, typically linked to a specific risk |
| Justification for exclusions | Why each control from Annex A is not applicable |
| Implementation status | Whether each control is implemented or in progress |
| Annex A attribute mapping | Mapping of controls to Annex A (2022 or 2013 version) |
How to Create an ISO 27001 Statement of Applicability
Follow this step-by-step process to build a compliant and defensible SoA.
Step 1: Complete Your Risk Assessment
The SoA is derived from your risk assessment. Before touching the SoA, ensure your risk assessment methodology is documented, risks are identified and scored, and a risk treatment plan exists. The SoA cannot be created in isolation.
Step 2: Review Annex A Controls
ISO 27001:2022 Annex A contains 93 controls organised into 4 themes: organisational, people, physical, and technological. Review each control against your organisation’s context, risk profile, and business requirements.
Step 3: Determine Applicability
For each control, decide whether it is applicable. A control is applicable if it addresses a identified risk, is required by regulation, or is necessary for business operations. A control can be excluded if the risk is accepted, the control is irrelevant, or it is implemented by a third party.
Step 4: Justify Every Decision
For applicable controls, document how they are implemented and reference the relevant policy, procedure, or technical control. For excluded controls, provide a clear business or technical rationale. Weak justifications are a common audit finding.
Step 5: Map Implementation References
Link each applicable control to its implementation evidence. This might be a policy document name, a system configuration, a standard operating procedure, or a contract clause. Auditors will request these references during Stage 2.
Annex A Control Mapping: ISO 27001:2022
The 2022 revision reorganised Annex A from 14 clauses to 4 themes. The following table shows the high-level mapping.
| Theme | Control Count | Examples |
|---|---|---|
| Organisational controls | 37 | Information security policies, incident management, business continuity, supplier security |
| People controls | 8 | Background checks, awareness training, disciplinary process, remote working |
| Physical controls | 14 | Physical security perimeter, equipment maintenance, secure disposal, clear desk policy |
| Technological controls | 34 | Access control, cryptography, network security, malware protection, logging and monitoring |
ISO 27001 Statement of Applicability Template
A standard SoA template includes the following columns. Your SoA can be maintained in Excel, Word, or a GRC tool.
| Annex A Control ID | Control Name | Applicable (Y/N) | Justification | Implementation Reference | Status |
|---|---|---|---|---|---|
| 5.1 | Information security policy | Y | Required for policy governance | ISP-001 InfoSec Policy | Implemented |
| 5.2 | Information security roles and responsibilities | Y | Required for accountability | ORG-001 RACI Matrix | Implemented |
| 5.3 | Segregation of duties | Y | Mitigates fraud risk | HR-003 SOD Policy | Implemented |
| 5.4 | Management responsibilities | Y | Clause 5.1 requirement | ISP-001 Section 3 | Implemented |
| 5.5 | Contact with authorities | N | Handled by legal team | N/A – outsourced | Excluded |
| 5.6 | Contact with special interest groups | N | No current membership | N/A – not applicable | Excluded |
| 5.7 | Threat intelligence | Y | Required for cyber threat awareness | SOC-001 Threat Intel Feed | In progress |
Common SoA Mistakes and How to Avoid Them
| Mistake | Risk | Solution |
|---|---|---|
| Excluding controls without justification | Major non-conformity | Document a business or risk-based reason for every exclusion |
| Copying from another organisation | Auditor identifies misalignment | Tailor every entry to your context and risk assessment |
| No link to risk assessment | SoA lacks audit trail | Reference risk register IDs in the justification column |
| Outdated control references | Non-compliance with 2022 revision | Use the 2022 Annex A control IDs and attributes |
| Missing implementation references | Auditor cannot verify controls | Always include a document name, system name, or process reference |
| Not reviewed and approved | Lack of management commitment | Have the SoA approved by the ISMS owner and reviewed annually |
SoA Maintenance: Keeping It Current
Your SoA is a living document. It must evolve with your organisation, risk landscape, and business environment.
- Annual review – Review the SoA during the management review meeting. Confirm that all controls remain applicable and that implementation status is accurate.
- Trigger-based updates – Update the SoA whenever there is a significant change: new business processes, new technology, regulatory changes, major incidents, or changes to risk appetite.
- Version control – Maintain version history. Auditors want to see that the SoA has been managed over time, not created moments before the audit.
- Integration with risk treatment plan – Keep the SoA synchronised with the risk treatment plan. If a risk is mitigated with a new control, update both documents simultaneously.
SoA and the Internal Audit
Your internal audit programme (clause 9.2) should verify the SoA. The internal auditor should check that the SoA accurately reflects implemented controls, that exclusions remain justified, and that the SoA aligns with the risk assessment. Findings from the internal audit should feed back into SoA updates.
Frequently Asked Questions
Is the Statement of Applicability a mandatory ISO 27001 document?
Yes. Clause 6.1.3 d) explicitly requires a Statement of Applicability. It is one of the mandatory documents listed in ISO 27001:2022 and will be reviewed during both Stage 1 and Stage 2 audits.
How many controls should I include in my SoA?
There is no fixed number. Most organisations find 60 to 80 of the 93 Annex A controls applicable. The exact number depends on your industry, size, risk profile, and regulatory obligations. What matters is that each decision is justified.
Can I exclude a control because it is too expensive?
Yes, cost can be a legitimate basis for exclusion, but it must be supported by a risk acceptance decision. The risk owner must formally accept the residual risk associated with not implementing the control.
What is the difference between SoA and risk treatment plan?
The risk treatment plan (RTP) documents how specific risks will be treated (mitigated, transferred, accepted, or avoided). The SoA lists which Annex A controls are implemented and why. The SoA is derived from the RTP but focuses on controls rather than risks.
Do I need to update my SoA for ISO 27001:2022 transition?
Yes. If you are certified to ISO 27001:2013, the transition to the 2022 revision requires updating your SoA to use the new 2022 control structure and attribute system. The transition deadline was October 2025.
Can I use software to manage my SoA?
Yes, GRC tools such as Bitrixme’s ISMS platform can automate SoA creation, maintenance, and version control. Software reduces errors and ensures your SoA is always audit-ready.
Build Your ISO 27001 Statement of Applicability with Bitrixme
Bitrixme provides ISO 27001 consulting services across the GCC, including SoA development, risk assessment facilitation, and full ISMS implementation. Our experts ensure your Statement of Applicability is compliant, defensible, and tailored to your organisation.
Contact Bitrixme today for ISO 27001 SoA support or reach out on WhatsApp to speak with an expert now.