Statement of Applicability (SoA), defined

Updated

The Statement of Applicability (SoA) is a mandatory document in ISO/IEC 27001 that lists every control in Annex A and records, for each one, whether it is applicable, the justification for including or excluding it, and its implementation status. It is the bridge between an organization's risk assessment and the controls it actually operates.

Required by clause 6.1.3 d) of ISO/IEC 27001, the SoA is one of the first documents a certification auditor reviews, because it shows that control selection was driven by risk rather than copied from a template. It is a living document: as risks, systems, and controls change, the SoA is updated to stay consistent with the risk treatment plan.

What the SoA is and why ISO 27001 requires it

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It requires an organization to assess its information security risks and then select controls to treat them. The Statement of Applicability is the document that records that selection decision, control by control, against the reference set in Annex A of the standard.

Clause 6.1.3 d) names the SoA explicitly: it must state the necessary controls, give justification for their inclusion, note whether each is implemented, and give justification for excluding any Annex A controls. That structure is what makes the SoA auditable — it forces every included control to trace back to a risk and every exclusion to a stated reason, so an auditor can test that the control set is deliberate rather than boilerplate.

What an SoA contains

In practice an SoA is a register with one row per Annex A control. The 2022 revision of ISO/IEC 27001 restructured Annex A into 93 controls grouped in four themes — organizational, people, physical, and technological — replacing the 114 controls across 14 domains in the 2013 version. Whichever version an organization certifies against, the SoA covers the full control set of that version.

  • Every Annex A control appears — inclusions and exclusions alike.
  • Each inclusion ties back to a driver: an identified risk, a legal or regulatory obligation, or a contractual requirement.
  • Each exclusion carries a documented justification an auditor can challenge.
  • Status shows the gap between selected and operating controls at a point in time.
Typical columns in a Statement of Applicability.
ColumnWhat it records
Control referenceThe Annex A control identifier and title
Applicable?Whether the control is included in the ISMS scope
JustificationWhy the control is included (e.g. risk, legal, contractual) or the reason for exclusion
Implementation statusWhether and how far the control is implemented
ReferenceLink to the policy, procedure, or evidence that operates the control

How the SoA relates to the risk assessment and risk treatment plan

The SoA sits downstream of the risk assessment and alongside the risk treatment plan (RTP). The risk assessment identifies and evaluates risks; the RTP decides how each risk will be treated and which controls will be applied; the SoA is the consolidated statement of which controls are in and out, and why. Read together, the three documents let an auditor follow a clean line from a risk to the control that treats it to the evidence that the control operates.

Because it is derived from risk, the SoA is not a one-time artifact. When the organization adds a system, changes scope, or reassesses risk, the SoA is revisited so it stays consistent with current controls and the RTP. A stale SoA — one that no longer matches the controls actually running — is a common source of audit findings, because it breaks the traceability the document exists to provide.

Frequently asked questions

Is a Statement of Applicability mandatory for ISO 27001?

Yes. The SoA is a required document under clause 6.1.3 d) of ISO/IEC 27001. An ISMS cannot be certified without one, because it is how the organization demonstrates that its control selection was driven by risk and how the auditor tests that decision.

What is the difference between the SoA and the risk treatment plan?

The risk treatment plan decides how each identified risk will be handled and which controls will address it. The Statement of Applicability is the consolidated list of every Annex A control with its applicability, justification, and status. The RTP is per-risk; the SoA is per-control.

Can you exclude Annex A controls in the SoA?

Yes, provided each exclusion carries a documented justification. Controls that do not apply to the organization's scope or risks can be marked not applicable, but the standard requires the reasoning to be stated so an auditor can review whether the exclusion is defensible.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.