Free tool

A free ISO 27001 Statement of Applicability builder, with all 93 Annex A controls already written

13 September 2026 · 7 min read · CertAssist

Most free Statement of Applicability templates hand you an empty spreadsheet and a column headed “justification”. That column is the work. So we built something that starts with it filled in.

You can use it here: the free ISO 27001 Statement of Applicability builder. All 93 Annex A controls of ISO 27001:2022, each one with the four reasons for inclusion pre-set and a draft justification already written. Change what does not fit, download the spreadsheet, and you have your SOA. There is no sign-up, no email wall, and nothing is uploaded anywhere.

What it is: a free Statement of Applicability generator covering all 93 Annex A controls of ISO 27001:2022, exporting a formatted Excel SOA template. What it is not: a substitute for your own judgment. Every justification is a starting point you should rewrite in your own words.

Why another free SOA template?

Search for a free ISO 27001 Statement of Applicability template and you will find plenty. Nearly all of them are the same artifact: an .xlsx or Word file listing the 93 Annex A controls with blank columns for applicable, justification and implementation status. Most ask for your email first.

The blank columns are the problem. Listing the controls is the easy part, and it is the part that is identical across every template on the internet, because the control list comes from the standard. The hard part is writing 93 justifications that an auditor will accept, and no template helps with that. You download the file, open it, look at A.5.1, and the blinking cursor is exactly where you were before.

We already had the other half. CertAssist ships with a justification for every Annex A control, written by the consultants who use the product to take clients through certification. Putting that behind a login when it could be a free tool made no sense, so it is now a free tool.

What the Statement of Applicability builder actually does

Open the page and you get all 93 controls grouped into the four themes of ISO 27001:2022: 37 organizational, 8 people, 14 physical and 34 technological. For each control you can set the four reasons for inclusion and edit the justification text.

Nothing you type leaves your browser

This matters more than it usually would. The people filling in a Statement of Applicability are the people whose job is to ask where data goes. It would be a strange tool that asked them to upload a description of their security controls to a vendor they have never bought anything from.

So the builder has no account and no server side. Your answers are stored in your own browser, which means you can close the tab and come back to them, and the spreadsheet is generated on your machine. We never see any of it. That is also why we cannot email you a copy: we do not have one.

How to fill in a Statement of Applicability in an afternoon

A first SOA is usually treated as a week of work. It does not need to be, provided you do it in the right order.

1. Do your risk assessment first. This is the step people skip, and it is the one that makes everything else fast. The Statement of Applicability is downstream of your risk assessment, not a substitute for it. Clause 6.1.3 asks you to determine the controls necessary to treat your risks, then compare them against Annex A. If you write the SOA first you will be reverse-engineering justifications, and an auditor can tell.

2. Deal with your exclusions deliberately. Go through the list and find the controls that genuinely do not apply. For most small software companies that is a handful of physical controls, because they have no data centre or server room of their own. Write a specific reason for each, then leave the rest alone.

3. Read every remaining justification and make it yours. This is the actual work and it is where the builder saves you time, because editing a sentence is much faster than writing one. If the draft says something your organization does not do, change it. A justification that describes someone else's company is worse than a blank one.

4. Download, then keep it alive. The SOA is not a document you write once. More on that below.

What makes an auditor reject a Statement of Applicability

In practice it is rarely a missing control. It is almost always the justification, and the failure modes are consistent:

If you want the longer treatment of this, we wrote it up separately: how to write a Statement of Applicability your auditor will accept.

The part a spreadsheet is bad at

We should be straight about the limits of what we have just given you, because the honest answer is also the reason CertAssist exists.

A downloaded Statement of Applicability is a snapshot. It is correct on the afternoon you make it. Then you migrate to a new identity provider, onboard a subprocessor, change your backup schedule, and the file in your shared drive quietly stops describing your organization. Nobody notices until the surveillance audit, when the auditor asks why the SOA says something different from what they just observed.

It is also disconnected from the evidence. Your SOA says A.8.13 is implemented. The proof that it is implemented is a restoration test report living somewhere else entirely, and at audit time somebody spends two days reuniting the two.

That is what the product does: the same 93 controls, but on a board where evidence attaches to the control it proves, every change is recorded, a new SOA version is written each time the document actually changes, and your auditor gets read-only access instead of a zip file. If the free builder is all you need, take it and go. It is genuinely free and there is no catch in it.

Frequently asked questions

Is the Statement of Applicability mandatory for ISO 27001?
Yes. Clause 6.1.3(d) of ISO 27001 requires it, and a certification body cannot issue a certificate without one. It is normally the first document an auditor asks for at Stage 1.

How many controls are in the ISO 27001:2022 Statement of Applicability?
93, across four themes: 37 organizational, 8 people, 14 physical and 34 technological. The 2013 version had 114 controls in 14 domains. The 2022 revision merged and restructured them rather than dropping requirements, so a Statement of Applicability written against the old Annex A needs remapping, not just renumbering.

Can I exclude controls from the Statement of Applicability?
Yes, and most organizations exclude several. The requirement is justification, not inclusion. An exclusion is defensible when it states a fact about your organization that makes the control irrelevant.

Is this Statement of Applicability template really free?
Yes. No account, no email, no payment, and no limit on downloads. All 93 controls are included.

What format does the SOA export in?
A formatted Excel .xlsx file with a header block, a filterable table and one row per control, ready to attach to an audit pack or drop into your own template.

How often should the Statement of Applicability be reviewed?
At least annually as part of management review, and immediately whenever your scope, risk assessment or systems change materially.

Open the free SOA builder

Keep the Statement of Applicability alive, not just written

The free builder gives you the document. CertAssist keeps it current: all 93 Annex A controls on a board, evidence attached to the control it proves, a new SOA version recorded whenever the document actually changes, and read-only access for your auditor. Launch price US$225 a month, normally US$375, every framework included.

Open the free builder Try the live demo

← Back to the blog

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $2,475 a year (12 months for the price of 11). All prices in USD.