Work through all 93 Annex A controls of ISO 27001:2022, set the reason each one is included, edit the justification in your own words, and download a formatted SOA spreadsheet you can hand to your auditor.
Every control starts with a suggested set of reasons and a draft justification written by our consultants. They are a starting point for your judgment, not a substitute for it. Change anything that does not describe your organization, because that is the part an auditor reads closely.
The Statement of Applicability is the ISO 27001 document that lists every Annex A control, states whether it applies to your organization, gives the reason, and records the justification for including or excluding it. Clause 6.1.3 d) requires it, and an auditor will ask for it at Stage 1. It is the document that defines the shape of your ISMS.
Yes. No sign-up, no email, no payment. All 93 Annex A controls are included and you can download the finished spreadsheet.
No. The builder runs entirely in your browser. Your answers are saved only in your own browser's local storage, and the spreadsheet is generated on your machine. Nothing is sent to CertAssist.
93, in four themes: 37 organizational, 8 people, 14 physical and 34 technological. The 2013 version had 114 controls across 14 domains, so the 2022 revision consolidated them rather than dropping requirements.
Yes, and exclusions are normal. What matters is that the justification is specific. “We operate no data centre or server room of our own, so physical media handling sits with our cloud provider” is defensible. “Not relevant to us” is not, and an auditor will raise it.
The reasons say why a control was selected: legal, contractual, business or risk. The justification explains, in your words, how it applies to your organization or why it does not. Auditors read the justification far more closely than the reasons.
This builder produces your Statement of Applicability once. CertAssist keeps it current: every Annex A control on a board, evidence attached where it belongs, a version history on the SOA each time it changes, and read-only access for your auditor. Flat $225 a month during the launch, normally $375, every framework included.