Statement of Applicability (SoA) template
The Statement of Applicability is the first document a certification auditor reads. It lists all 93 Annex A controls, says whether each applies, justifies every decision and points to the evidence. This template gives you the exact column set that survives a Stage 1 review.
Every field, explained
| Field | What to put in it |
|---|---|
| Control ref | The Annex A reference, e.g. A.8.16. Keep all 93 rows even when excluded. |
| Control name | The control title as written in ISO 27001:2022 — do not paraphrase. |
| Applicable (Y/N) | Whether the control is in scope. Most SMEs end up with 85–93 applicable controls. |
| Justification | One or two sentences. For included controls, cite the risk or requirement driving it. For excluded controls, state why it cannot apply — 'we have no in-house development' is acceptable; 'not relevant' is not. |
| Implementation status | Not started / In progress / Implemented. Auditors expect honesty here; partial implementation with a dated plan is fine at Stage 1. |
| Control owner | A named person, not a team. Unowned controls are the most common finding. |
| Linked risks | The risk register IDs this control treats. This traceability is what turns a list into a management system. |
| Evidence reference | Where the proof lives — document name, system, or evidence library reference. |
| Last reviewed | Date of the last review. Anything older than twelve months invites a nonconformity. |
Worked examples
- Control ref
- A.5.7
- Control name
- Threat intelligence
- Applicable (Y/N)
- Y
- Justification
- Required to keep the risk assessment current; treats R-004 (unpatched exploited vulnerability).
- Implementation status
- Implemented
- Control owner
- IT Manager
- Linked risks
- R-004, R-018
- Evidence reference
- Monthly threat review notes (Evidence vault / TI-2026)
- Last reviewed
- 2026-07-14
- Control ref
- A.8.28
- Control name
- Secure coding
- Applicable (Y/N)
- N
- Justification
- No software is developed in-house or on our behalf; all applications are commercial SaaS. Reviewed annually in case this changes.
- Implementation status
- N/A
- Control owner
- CTO
- Linked risks
- —
- Evidence reference
- Scope statement v3, section 2.4
- Last reviewed
- 2026-06-02
- Control ref
- A.8.16
- Control name
- Monitoring activities
- Applicable (Y/N)
- Y
- Justification
- Detects account compromise and malware; treats R-001 and supports incident response obligations.
- Implementation status
- In progress
- Control owner
- Head of IT
- Linked risks
- R-001, R-009
- Evidence reference
- Defender alert queue export; triage log
- Last reviewed
- 2026-08-01
How to use it
- Complete the risk assessment first — the SoA records decisions, it does not make them.
- Load all 93 controls. Never delete excluded rows; the exclusion and its justification are the evidence.
- Write justifications that reference a risk, a contract or a legal obligation.
- Assign a named owner to every applicable control before Stage 1.
- Attach at least one piece of evidence per applicable control.
- Review the whole SoA at management review and stamp the date.
What auditors pick up
- Excluded controls with no justification, or a justification of 'not applicable'.
- Owners recorded as a department rather than a person.
- No link between controls and the risks they treat.
- SoA version predates the last significant scope or system change.
FAQ
Is the Statement of Applicability mandatory for ISO 27001?
Yes. Clause 6.1.3 d) requires a Statement of Applicability containing the necessary controls, the justification for their inclusion, whether they are implemented, and the justification for excluding any Annex A controls.
How many Annex A controls can we exclude?
There is no set number. Exclusions must be genuinely justified — typically secure coding where no development happens, or some physical controls for a fully remote organisation. Most SMEs exclude fewer than eight.
How often should the SoA be reviewed?
At least annually, and whenever scope, systems, suppliers or the risk profile change materially. Record the review date on every row.
Related
Stop maintaining spreadsheets
Every template here exists as a live module inside ISO-STANDARD.app — owners, review dates, evidence links and audit trail included, with AI-generated remediation plans when something fails.
- Pre-loaded ISO 27001, 9001, 42001 and SOC 2 content
- Evidence vault with versioning
- Named owners and review reminders
- Export back to CSV any time
