Core workflows

Manage controls and your Statement of Applicability

Turn ISO 27001 Annex A (and any framework) into a living SoA — with owners, evidence and audit history attached to every control.

9 min read · updated July 2026

Step-by-step

  1. 1

    Open Controls

    The Controls page lists every framework you've enabled. Filter by standard, status or owner. Click any control to open its full detail view.

    Open Controls
  2. 2

    Mark applicability

    For each control, mark Applicable / Not Applicable and write a plain-language justification. The SoA export uses this exact text.

  3. 3

    Assign an owner and a review date

    Ownership drives accountability. The dashboard flags any control without an owner or with an overdue review.

  4. 4

    Link risks and evidence

    Open the Links tab to connect the control to the risks it mitigates and the evidence artifacts that prove it works. This mesh is what your auditor tests.

  5. 5

    Export the SoA

    From Controls → Export → SoA (PDF). The document is versioned, includes the crosswalk to SOC 2 CC, and carries your logo.

    The SoA export ready for auditors, buyers and boards.
    The SoA export ready for auditors, buyers and boards.
What corporate buyers look for
  • "Can you share a current Statement of Applicability?"
  • "Which Annex A controls are excluded, and what is your justification?"
  • "How do you evidence operating effectiveness of A.5, A.6, A.8 controls?"

What this workflow produces: A signed SoA plus the last three months of evidence for the top ten controls satisfies most enterprise procurement teams before a full audit report exists.

FAQ

Which control set should I start with?

ISO 27001:2022 Annex A is the widest. SOC 2 and NIST CSF crosswalk automatically, so you don't need to duplicate work.

How often should the SoA be reviewed?

At least annually and after any significant change (new product, new region, major incident).

Can I add custom controls?

Yes — add a bespoke control set with your own IDs and descriptions from Controls → Add framework.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation