ISO 27001 Statement of Applicability: Guide and Template
Create an ISO 27001 Statement of Applicability: required content, practical steps, example structure and common mistakes across 93 controls.
The Statement of Applicability, or SoA, connects the risk assessment with selected information-security controls. It records which controls are necessary, why they are included or excluded and whether they have been implemented. It is therefore one of the central governance and audit documents of an ISMS.
What the SoA should contain
- Reference and name of each control considered
- Applicability decision
- Rationale for inclusion or exclusion
- Implementation status
- Link to a policy, process or other evidence
- Owner and, where useful, the next review date
How to create the Statement of Applicability
- Confirm scope, information assets and relevant requirements
- Complete risk assessment and choose treatment options
- Consider every Annex A control systematically
- Add other necessary controls
- Write concise, testable rationale
- Link status to evidence sources
- Approve the SoA and update it when conditions change
Simple example structure
| Field | Example |
|---|---|
| Control | Access control for cloud applications |
| Applicable | Yes |
| Rationale | Protects customer and project data from unauthorised access. |
| Status | Implemented |
| Evidence | Access-control policy, role matrix, quarterly access review |
| Owner | Head of IT |
Common mistakes
A useful SoA remains concise while pointing precisely to underlying decisions and evidence. Sensitive technical detail does not always need to sit in the document itself.
- Generic rationale such as “best practice” with no link to risk or obligation
- The SoA contradicts the risk treatment plan
- A control is marked implemented when only a policy exists
- Excluded controls have no defensible rationale
- Changes to scope, suppliers or technology are not reflected
How Sternberg Consulting supports you
We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.
Frequently asked questions
Is the SoA mandatory?
An ISMS conforming to ISO/IEC 27001 requires a Statement of Applicability as documented output of the risk treatment process.
Must the SoA be public?
No. It can contain sensitive information and should be shared in a controlled manner.
How often should it be updated?
Following relevant changes and during planned reviews, especially whenever the risk assessment or scope changes.