ISO 27001 · Documents
What is a Statement of Applicability?
A Statement of Applicability (SoA) is the ISO 27001 document that lists every Annex A control, states whether it applies to your organisation, gives the reason, and records whether it is implemented. It is the map an auditor uses to decide what to test.
What does an SoA contain?
One row per control from Annex A (93 in ISO/IEC 27001:2022) plus any control you added from your risk assessment. For each: whether it is applicable, the justification, whether it is implemented, and usually a pointer to the policy or evidence that shows it. Excluding a control is allowed; excluding it without a reason that traces back to your risk assessment is a finding.
Why does the auditor care so much about it?
Because the SoA defines the scope of the audit. The auditor samples from it at surveillance and tests all of it at certification and recertification. If the SoA says a control is implemented and the evidence says otherwise, that is a non-conformity. If it says a control does not apply and the risk register disagrees, that is one too.
How do you keep it accurate?
Do not maintain it as a separate spreadsheet. The SoA should be generated from the control tree you actually work in, so a control answered in the platform is the same control the SoA reports. Certifyi generates the Statement of Applicability from the framework control tree rather than beside it, which is why it cannot drift from what the team answered.
SoA versus risk treatment plan: what is the difference?
The risk treatment plan says which risks you have and how you will treat them. The SoA says which controls you use to do it. They must agree: every applicable control in the SoA should trace to at least one treated risk, and every treatment should land on a control the SoA marks as applicable.
Where you stand
Score your own readiness in one sitting
The free self-assessment walks through the controls an auditor samples, gives you a scored report, and takes about fifteen minutes. No account needed.
Related questions
Does SOC 2 have an equivalent?
Not by name. SOC 2 uses the Trust Services Criteria and a system description; the closest equivalent is the control matrix your auditor tests against.
How often should the SoA be updated?
Whenever the risk assessment changes and at least before every audit visit. Version it, because the auditor will ask which version was in force at the time of a finding.
Who signs it off?
The person accountable for the ISMS, usually the CISO or the information security manager, with management review recorded.