iso-27001-statement-of-applicability

By July 25th, 2026ISO Audit And Certificate7 min read

ISO 27001 Statement of Applicability: Complete Guide

The Statement of Applicability (SoA) is one of the most important documents in your ISO 27001 information security management system (ISMS). It records which Annex A controls are applicable to your organisation and justifies every inclusion and exclusion.

Without a properly prepared SoA, your ISO 27001 audit will fail. This complete guide explains what an SoA is, the ISO 27001 requirements, how to create one, how to map controls, and common mistakes to avoid. Whether you are building a new ISMS or maintaining an existing one, this guide ensures your SoA stands up to auditor scrutiny.

What Is an ISO 27001 Statement of Applicability?

The Statement of Applicability (SoA) is a document that lists all controls from ISO 27001 Annex A and indicates whether each control is applicable or not applicable to your organisation. For each applicable control, the SoA references how it is implemented. For excluded controls, it provides a justification for the exclusion.

The SoA serves as the bridge between your risk assessment and the controls you implement. It demonstrates to auditors that you have systematically considered every control in Annex A and made informed decisions based on your risk context.

ISO 27001 Requirements for the Statement of Applicability

Clause 6.1.3 d) of ISO 27001:2022 requires that your organisation produces a Statement of Applicability containing the following:

RequirementDescription
Necessary controlsList of controls selected based on the risk assessment and risk treatment process
Justification for inclusionsWhy each control is included, typically linked to a specific risk
Justification for exclusionsWhy each control from Annex A is not applicable
Implementation statusWhether each control is implemented or in progress
Annex A attribute mappingMapping of controls to Annex A (2022 or 2013 version)

How to Create an ISO 27001 Statement of Applicability

Follow this step-by-step process to build a compliant and defensible SoA.

Step 1: Complete Your Risk Assessment

The SoA is derived from your risk assessment. Before touching the SoA, ensure your risk assessment methodology is documented, risks are identified and scored, and a risk treatment plan exists. The SoA cannot be created in isolation.

Step 2: Review Annex A Controls

ISO 27001:2022 Annex A contains 93 controls organised into 4 themes: organisational, people, physical, and technological. Review each control against your organisation’s context, risk profile, and business requirements.

Step 3: Determine Applicability

For each control, decide whether it is applicable. A control is applicable if it addresses a identified risk, is required by regulation, or is necessary for business operations. A control can be excluded if the risk is accepted, the control is irrelevant, or it is implemented by a third party.

Step 4: Justify Every Decision

For applicable controls, document how they are implemented and reference the relevant policy, procedure, or technical control. For excluded controls, provide a clear business or technical rationale. Weak justifications are a common audit finding.

Step 5: Map Implementation References

Link each applicable control to its implementation evidence. This might be a policy document name, a system configuration, a standard operating procedure, or a contract clause. Auditors will request these references during Stage 2.

Annex A Control Mapping: ISO 27001:2022

The 2022 revision reorganised Annex A from 14 clauses to 4 themes. The following table shows the high-level mapping.

ThemeControl CountExamples
Organisational controls37Information security policies, incident management, business continuity, supplier security
People controls8Background checks, awareness training, disciplinary process, remote working
Physical controls14Physical security perimeter, equipment maintenance, secure disposal, clear desk policy
Technological controls34Access control, cryptography, network security, malware protection, logging and monitoring

ISO 27001 Statement of Applicability Template

A standard SoA template includes the following columns. Your SoA can be maintained in Excel, Word, or a GRC tool.

Annex A Control IDControl NameApplicable (Y/N)JustificationImplementation ReferenceStatus
5.1Information security policyYRequired for policy governanceISP-001 InfoSec PolicyImplemented
5.2Information security roles and responsibilitiesYRequired for accountabilityORG-001 RACI MatrixImplemented
5.3Segregation of dutiesYMitigates fraud riskHR-003 SOD PolicyImplemented
5.4Management responsibilitiesYClause 5.1 requirementISP-001 Section 3Implemented
5.5Contact with authoritiesNHandled by legal teamN/A – outsourcedExcluded
5.6Contact with special interest groupsNNo current membershipN/A – not applicableExcluded
5.7Threat intelligenceYRequired for cyber threat awarenessSOC-001 Threat Intel FeedIn progress

Common SoA Mistakes and How to Avoid Them

MistakeRiskSolution
Excluding controls without justificationMajor non-conformityDocument a business or risk-based reason for every exclusion
Copying from another organisationAuditor identifies misalignmentTailor every entry to your context and risk assessment
No link to risk assessmentSoA lacks audit trailReference risk register IDs in the justification column
Outdated control referencesNon-compliance with 2022 revisionUse the 2022 Annex A control IDs and attributes
Missing implementation referencesAuditor cannot verify controlsAlways include a document name, system name, or process reference
Not reviewed and approvedLack of management commitmentHave the SoA approved by the ISMS owner and reviewed annually

SoA Maintenance: Keeping It Current

Your SoA is a living document. It must evolve with your organisation, risk landscape, and business environment.

  • Annual review – Review the SoA during the management review meeting. Confirm that all controls remain applicable and that implementation status is accurate.
  • Trigger-based updates – Update the SoA whenever there is a significant change: new business processes, new technology, regulatory changes, major incidents, or changes to risk appetite.
  • Version control – Maintain version history. Auditors want to see that the SoA has been managed over time, not created moments before the audit.
  • Integration with risk treatment plan – Keep the SoA synchronised with the risk treatment plan. If a risk is mitigated with a new control, update both documents simultaneously.

SoA and the Internal Audit

Your internal audit programme (clause 9.2) should verify the SoA. The internal auditor should check that the SoA accurately reflects implemented controls, that exclusions remain justified, and that the SoA aligns with the risk assessment. Findings from the internal audit should feed back into SoA updates.

Frequently Asked Questions

Is the Statement of Applicability a mandatory ISO 27001 document?

Yes. Clause 6.1.3 d) explicitly requires a Statement of Applicability. It is one of the mandatory documents listed in ISO 27001:2022 and will be reviewed during both Stage 1 and Stage 2 audits.

How many controls should I include in my SoA?

There is no fixed number. Most organisations find 60 to 80 of the 93 Annex A controls applicable. The exact number depends on your industry, size, risk profile, and regulatory obligations. What matters is that each decision is justified.

Can I exclude a control because it is too expensive?

Yes, cost can be a legitimate basis for exclusion, but it must be supported by a risk acceptance decision. The risk owner must formally accept the residual risk associated with not implementing the control.

What is the difference between SoA and risk treatment plan?

The risk treatment plan (RTP) documents how specific risks will be treated (mitigated, transferred, accepted, or avoided). The SoA lists which Annex A controls are implemented and why. The SoA is derived from the RTP but focuses on controls rather than risks.

Do I need to update my SoA for ISO 27001:2022 transition?

Yes. If you are certified to ISO 27001:2013, the transition to the 2022 revision requires updating your SoA to use the new 2022 control structure and attribute system. The transition deadline was October 2025.

Can I use software to manage my SoA?

Yes, GRC tools such as Bitrixme’s ISMS platform can automate SoA creation, maintenance, and version control. Software reduces errors and ensures your SoA is always audit-ready.

Build Your ISO 27001 Statement of Applicability with Bitrixme

Bitrixme provides ISO 27001 consulting services across the GCC, including SoA development, risk assessment facilitation, and full ISMS implementation. Our experts ensure your Statement of Applicability is compliant, defensible, and tailored to your organisation.

Contact Bitrixme today for ISO 27001 SoA support or reach out on WhatsApp to speak with an expert now.