GlossaryISO 27001

Statement of Applicability

Short answer

The Statement of Applicability (SoA) is a mandatory ISO 27001 document that lists all Annex A controls, states which ones apply to the organisation, explains why each is included or excluded, and records whether it has been implemented.

What the SoA contains

For every control in Annex A, the SoA states whether it is included, why, and whether it is already implemented. It must also justify any exclusion. It can include additional controls the organisation uses beyond Annex A.

How it connects to risk

The SoA is the output of risk treatment. Controls are included because the risk assessment shows they are needed, or because a law, contract or customer requires them. A control excluded without a solid reason is one of the first things an auditor questions.

Why it matters in the audit

Auditors use the SoA as their map: it tells them which controls to test and what evidence to ask for. It is also often shared with customers to show the scope of the security programme.

Keeping it current

The SoA is a living document. It should be updated when the scope changes, new risks appear or controls are implemented, and it is reviewed at every surveillance audit.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub