Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityPublished: 10 July 2026

ISO 27001 Statement of Applicability: Guide and Template

Create an ISO 27001 Statement of Applicability: required content, practical steps, example structure and common mistakes across 93 controls.

The Statement of Applicability, or SoA, connects the risk assessment with selected information-security controls. It records which controls are necessary, why they are included or excluded and whether they have been implemented. It is therefore one of the central governance and audit documents of an ISMS.

What the SoA should contain

  • Reference and name of each control considered
  • Applicability decision
  • Rationale for inclusion or exclusion
  • Implementation status
  • Link to a policy, process or other evidence
  • Owner and, where useful, the next review date

How to create the Statement of Applicability

  1. Confirm scope, information assets and relevant requirements
  2. Complete risk assessment and choose treatment options
  3. Consider every Annex A control systematically
  4. Add other necessary controls
  5. Write concise, testable rationale
  6. Link status to evidence sources
  7. Approve the SoA and update it when conditions change

Simple example structure

Table 1: ISO 27001 Statement of Applicability: Guide and Template
FieldExample
ControlAccess control for cloud applications
ApplicableYes
RationaleProtects customer and project data from unauthorised access.
StatusImplemented
EvidenceAccess-control policy, role matrix, quarterly access review
OwnerHead of IT

Common mistakes

A useful SoA remains concise while pointing precisely to underlying decisions and evidence. Sensitive technical detail does not always need to sit in the document itself.

  • Generic rationale such as “best practice” with no link to risk or obligation
  • The SoA contradicts the risk treatment plan
  • A control is marked implemented when only a policy exists
  • Excluded controls have no defensible rationale
  • Changes to scope, suppliers or technology are not reflected

How Sternberg Consulting supports you

We help SMEs turn this step into a lean, audit-ready ISMS. Our ISO 27001 consulting covers scoping and gap assessment through to certification preparation.

Discuss your project

Frequently asked questions

Is the SoA mandatory?

An ISMS conforming to ISO/IEC 27001 requires a Statement of Applicability as documented output of the risk treatment process.

Must the SoA be public?

No. It can contain sensitive information and should be shared in a controlled manner.

How often should it be updated?

Following relevant changes and during planned reviews, especially whenever the risk assessment or scope changes.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.