A Statement of Applicability, or SoA, is the ISO 27001 document that records an organization’s control decisions.
A practical SoA normally shows:
- Which Annex A controls are applicable
- Why each control is included
- Why an excluded control does not apply
- Current implementation status
- References to policies, procedures, risks, or evidence
The SoA should align with the organization’s scope and risk assessment. It is not a checklist where every control is marked applicable and it is not a document to copy from another company. It should be reviewed when risks, systems, suppliers, or business processes change.
Read what a Statement of Applicability actually does in ISO 27001.
