Manage controls and your Statement of Applicability
Turn ISO 27001 Annex A (and any framework) into a living SoA — with owners, evidence and audit history attached to every control.
Step-by-step
- 1
Open Controls
The Controls page lists every framework you've enabled. Filter by standard, status or owner. Click any control to open its full detail view.

- 2
Mark applicability
For each control, mark Applicable / Not Applicable and write a plain-language justification. The SoA export uses this exact text.
- 3
Assign an owner and a review date
Ownership drives accountability. The dashboard flags any control without an owner or with an overdue review.
- 4
Link risks and evidence
Open the Links tab to connect the control to the risks it mitigates and the evidence artifacts that prove it works. This mesh is what your auditor tests.
- 5
Export the SoA
From Controls → Export → SoA (PDF). The document is versioned, includes the crosswalk to SOC 2 CC, and carries your logo.

The SoA export ready for auditors, buyers and boards.
- "Can you share a current Statement of Applicability?"
- "Which Annex A controls are excluded, and what is your justification?"
- "How do you evidence operating effectiveness of A.5, A.6, A.8 controls?"
What this workflow produces: A signed SoA plus the last three months of evidence for the top ten controls satisfies most enterprise procurement teams before a full audit report exists.
FAQ
ISO 27001:2022 Annex A is the widest. SOC 2 and NIST CSF crosswalk automatically, so you don't need to duplicate work.
At least annually and after any significant change (new product, new region, major incident).
Yes — add a bespoke control set with your own IDs and descriptions from Controls → Add framework.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
