Free tool · no sign-up

ISO 27001 Statement of Applicability builder

Work through all 93 Annex A controls of ISO 27001:2022, set the reason each one is included, edit the justification in your own words, and download a formatted SOA spreadsheet you can hand to your auditor.

Nothing leaves your browser. There is no account and no upload. Your answers are kept in this browser only, so you can close the tab and pick up where you left off, and the spreadsheet is built on your own machine. We never see it.

Every control starts with a suggested set of reasons and a draft justification written by our consultants. They are a starting point for your judgment, not a substitute for it. Change anything that does not describe your organization, because that is the part an auditor reads closely.

0 included
0 excluded

Questions people ask about the SOA

What is a Statement of Applicability?

The Statement of Applicability is the ISO 27001 document that lists every Annex A control, states whether it applies to your organization, gives the reason, and records the justification for including or excluding it. Clause 6.1.3 d) requires it, and an auditor will ask for it at Stage 1. It is the document that defines the shape of your ISMS.

Is this builder really free?

Yes. No sign-up, no email, no payment. All 93 Annex A controls are included and you can download the finished spreadsheet.

Does my data get uploaded anywhere?

No. The builder runs entirely in your browser. Your answers are saved only in your own browser's local storage, and the spreadsheet is generated on your machine. Nothing is sent to CertAssist.

How many controls are in ISO 27001:2022 Annex A?

93, in four themes: 37 organizational, 8 people, 14 physical and 34 technological. The 2013 version had 114 controls across 14 domains, so the 2022 revision consolidated them rather than dropping requirements.

Can a control be excluded?

Yes, and exclusions are normal. What matters is that the justification is specific. “We operate no data centre or server room of our own, so physical media handling sits with our cloud provider” is defensible. “Not relevant to us” is not, and an auditor will raise it.

What is the difference between the reasons and the justification?

The reasons say why a control was selected: legal, contractual, business or risk. The justification explains, in your words, how it applies to your organization or why it does not. Auditors read the justification far more closely than the reasons.

The SOA is one document. The ISMS is the rest of the year.

This builder produces your Statement of Applicability once. CertAssist keeps it current: every Annex A control on a board, evidence attached where it belongs, a version history on the SOA each time it changes, and read-only access for your auditor. Flat $225 a month during the launch, normally $375, every framework included.

Related reading

What a Statement of Applicability is and how to write one
What changed in ISO 27001:2022
What ISO 27001 certification actually costs
SOC 2 vs ISO 27001: which one do you need?