Statement of Applicability (SoA) template

The Statement of Applicability is the first document a certification auditor reads. It lists all 93 Annex A controls, says whether each applies, justifies every decision and points to the evidence. This template gives you the exact column set that survives a Stage 1 review.

Every field, explained

FieldWhat to put in it
Control refThe Annex A reference, e.g. A.8.16. Keep all 93 rows even when excluded.
Control nameThe control title as written in ISO 27001:2022 — do not paraphrase.
Applicable (Y/N)Whether the control is in scope. Most SMEs end up with 85–93 applicable controls.
JustificationOne or two sentences. For included controls, cite the risk or requirement driving it. For excluded controls, state why it cannot apply — 'we have no in-house development' is acceptable; 'not relevant' is not.
Implementation statusNot started / In progress / Implemented. Auditors expect honesty here; partial implementation with a dated plan is fine at Stage 1.
Control ownerA named person, not a team. Unowned controls are the most common finding.
Linked risksThe risk register IDs this control treats. This traceability is what turns a list into a management system.
Evidence referenceWhere the proof lives — document name, system, or evidence library reference.
Last reviewedDate of the last review. Anything older than twelve months invites a nonconformity.

Worked examples

Control ref
A.5.7
Control name
Threat intelligence
Applicable (Y/N)
Y
Justification
Required to keep the risk assessment current; treats R-004 (unpatched exploited vulnerability).
Implementation status
Implemented
Control owner
IT Manager
Linked risks
R-004, R-018
Evidence reference
Monthly threat review notes (Evidence vault / TI-2026)
Last reviewed
2026-07-14
Control ref
A.8.28
Control name
Secure coding
Applicable (Y/N)
N
Justification
No software is developed in-house or on our behalf; all applications are commercial SaaS. Reviewed annually in case this changes.
Implementation status
N/A
Control owner
CTO
Linked risks
Evidence reference
Scope statement v3, section 2.4
Last reviewed
2026-06-02
Control ref
A.8.16
Control name
Monitoring activities
Applicable (Y/N)
Y
Justification
Detects account compromise and malware; treats R-001 and supports incident response obligations.
Implementation status
In progress
Control owner
Head of IT
Linked risks
R-001, R-009
Evidence reference
Defender alert queue export; triage log
Last reviewed
2026-08-01

How to use it

  1. Complete the risk assessment first — the SoA records decisions, it does not make them.
  2. Load all 93 controls. Never delete excluded rows; the exclusion and its justification are the evidence.
  3. Write justifications that reference a risk, a contract or a legal obligation.
  4. Assign a named owner to every applicable control before Stage 1.
  5. Attach at least one piece of evidence per applicable control.
  6. Review the whole SoA at management review and stamp the date.

What auditors pick up

  • Excluded controls with no justification, or a justification of 'not applicable'.
  • Owners recorded as a department rather than a person.
  • No link between controls and the risks they treat.
  • SoA version predates the last significant scope or system change.

FAQ

Is the Statement of Applicability mandatory for ISO 27001?

Yes. Clause 6.1.3 d) requires a Statement of Applicability containing the necessary controls, the justification for their inclusion, whether they are implemented, and the justification for excluding any Annex A controls.

How many Annex A controls can we exclude?

There is no set number. Exclusions must be genuinely justified — typically secure coding where no development happens, or some physical controls for a fully remote organisation. Most SMEs exclude fewer than eight.

How often should the SoA be reviewed?

At least annually, and whenever scope, systems, suppliers or the risk profile change materially. Record the review date on every row.

Related

Stop maintaining spreadsheets

Every template here exists as a live module inside ISO-STANDARD.app — owners, review dates, evidence links and audit trail included, with AI-generated remediation plans when something fails.

  • Pre-loaded ISO 27001, 9001, 42001 and SOC 2 content
  • Evidence vault with versioning
  • Named owners and review reminders
  • Export back to CSV any time
Start your workspace