ISO 27001 Statement of Applicability (SoA), Explained
The Statement of Applicability, or SoA, is one of the most important documents in an ISO 27001 ISMS, and a mandatory one. Auditors review it closely.
It is the bridge between your risk assessment and your controls: it records which Annex A controls you apply, why you included or excluded each, and how far you have implemented them.
What the SoA must contain
For every Annex A control, the SoA states whether it is applicable, the justification for inclusion or exclusion, and its implementation status.
Exclusions must be justified, you cannot simply drop a control because it is inconvenient; you justify it against your risk assessment and context.
Why auditors care about it
The SoA shows the auditor that your control selection is deliberate and risk-driven, not arbitrary. A vague or inconsistent SoA is a common source of findings.
It should stay in sync with your risk treatment plan and be reviewed whenever risks or controls change.
Keeping it current
The SoA is a living document. As you add systems, change suppliers, or reassess risk, update it. Compliance platforms can track control status to keep the SoA accurate.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Automate ISO 27001 with Drata
Drata maps the controls, collects evidence automatically, and keeps you audit-ready. Automated, continuous compliance with deep integrations.
FAQ
- Is the Statement of Applicability mandatory?
- Yes. ISO 27001 explicitly requires an SoA, and auditors review it as a core document.
- Can I exclude Annex A controls?
- Yes, but every exclusion must be justified against your risk assessment and context.
- How often should the SoA be updated?
- Whenever risks, systems, or controls change, and reviewed at least as part of your regular ISMS cycle.