GlossaryGlossary

Statement of Applicability

A Statement of Applicability records which ISO 27001 Annex A controls apply, which do not, why decisions were made, and how implementation is tracked.

August 31, 2026Updated August 2026
ISO 27001Statement of ApplicabilitySecurity controls

A Statement of Applicability, or SoA, is the ISO 27001 document that records an organization’s control decisions.

A practical SoA normally shows:

  • Which Annex A controls are applicable
  • Why each control is included
  • Why an excluded control does not apply
  • Current implementation status
  • References to policies, procedures, risks, or evidence

The SoA should align with the organization’s scope and risk assessment. It is not a checklist where every control is marked applicable and it is not a document to copy from another company. It should be reviewed when risks, systems, suppliers, or business processes change.

Read what a Statement of Applicability actually does in ISO 27001.