Audit

How to write a Statement of Applicability your auditor will accept

4 September 2026 · 9 min read · CertAssist

Auditors send more Statements of Applicability back for vague justifications than for any other reason. Here is exactly what yours needs to include, control by control.

A Statement of Applicability an ISO 27001 auditor will accept lists all 93 controls in Annex A of ISO 27001:2022, marks each one applicable or not applicable, gives a specific justification tied to a risk assessment finding, states the implementation status, and cross-references the evidence. The Statement of Applicability is required under Clause 6.1.3(d) of ISO 27001, so a certification body cannot issue a certificate without one. Most first-time Statements of Applicability fail not because a control is missing, but because the justification for including or excluding it is too generic to survive an auditor's questions.

What is a Statement of Applicability in ISO 27001?

A Statement of Applicability, usually shortened to SoA, is the ISO 27001 document that records every control in Annex A of ISO/IEC 27001:2022 and states, for each one, whether your organisation has included it, why, and how far it has been implemented. Auditors treat the Statement of Applicability as the master index of an Information Security Management System (ISMS), because it is the single document that ties every control back to a risk in your risk assessment and to a piece of evidence in your evidence library. Without a Statement of Applicability that stands up to questioning, there is no ISO 27001 certificate.

What must a Statement of Applicability include?

A Statement of Applicability must include five things for every control, and an auditor will check for all five before signing off:

Leave any of the five off a control and an auditor has grounds to raise a nonconformity, even if the control itself is genuinely well implemented.

How do you justify including or excluding a control?

The justification is the part of a Statement of Applicability that auditors read most closely, and it is where generic templates fall apart. A justification for including a control should name the specific risk it addresses and, where possible, point to the risk register entry: "A.8.24 Use of cryptography is included because customer data is processed in transit and at rest, addressing risk R-014 (data exposure in cloud storage) from the risk assessment." A justification for excluding a control should state the factual reason it does not apply, not simply that it seems unnecessary: "A.7.4 Physical security monitoring is not applicable because the organisation operates fully remotely with no physical premises to monitor; this exclusion is reviewed at each management review." Justifications such as "not relevant" or "not required" without a stated reason are the most common cause of an SoA being sent back for rework.

ControlApplicableJustificationStatus
A.5.1 Policies for information securityYesRequired by Clause 5.2; sets direction for all other controlsImplemented
A.6.3 Information security awareness, education and trainingYesAddresses risk R-006, staff-caused data incidentsImplemented
A.7.4 Physical security monitoringNoFully remote organisation, no physical premisesNot applicable
A.8.24 Use of cryptographyYesAddresses risk R-014, data exposure in cloud storagePartially implemented, target Q4 2026

Illustrative extract only. Your own Statement of Applicability must reflect your actual risk assessment, not this example.

How many controls does ISO 27001:2022 have in Annex A?

ISO 27001:2022 has 93 controls in Annex A, organised into four themes: organisational, people, physical and technological. Every one of the 93 controls needs a decision and a justification on your Statement of Applicability, even the ones that clearly do not apply to your organisation. The table below shows how the 93 controls are distributed across the four themes.

Bar chart showing ISO 27001:2022 Annex A control counts by theme: 37 organisational, 8 people, 14 physical, 34 technological, 93 total
ThemeControlsExample
A.5 Organisational37Policies, roles, supplier relationships
A.6 People8Screening, awareness, disciplinary process
A.7 Physical14Secure areas, equipment, clear desk
A.8 Technological34Access control, cryptography, logging

What do auditors actually check in a Statement of Applicability?

An ISO 27001 auditor checks a Statement of Applicability against three other documents, not in isolation. First, against the risk assessment, to confirm every identified risk maps to at least one included control. Second, against the risk treatment plan, to confirm the implementation status on the Statement of Applicability matches what the treatment plan says is actually done. Third, against the evidence itself, by sampling a handful of "implemented" controls and asking to see the proof. An auditor who finds a control marked implemented with no matching evidence, or a risk in the risk register with no corresponding control, will raise it as a finding regardless of how polished the rest of the document looks. National guidance such as the UK National Cyber Security Centre's overview of recognised standards makes the same point: a certification is only as credible as the evidence behind it.

What are the most common reasons a Statement of Applicability gets rejected?

Each of these is fixable before an audit, and each is far cheaper to fix in a document review than in front of an auditor.

How do you keep a Statement of Applicability up to date?

A Statement of Applicability should be reviewed at least once a year, and additionally whenever your risk assessment changes, your scope changes, or you adopt a new system or supplier that introduces a new risk. Treat it as a living document tied to your management review, not a one-time deliverable produced for the initial certification audit and then forgotten; surveillance audits in years two and three will check whether it has kept pace with the business. CertAssist has the Statement of Applicability handled as one of its ISO 27001:2022 features: every Annex A control is laid out with an editable justification field and a direct link to its evidence, so updating the document when something changes is a small edit rather than a rewrite from scratch.

Frequently asked questions

What is a Statement of Applicability (SoA)?

A Statement of Applicability is the ISO 27001 document that lists all 93 controls in Annex A of ISO 27001:2022 and records whether each one is applicable to your organisation, why, and its implementation status. It is required under Clause 6.1.3(d) and is one of the first documents an auditor reviews.

What is the purpose of a Statement of Applicability?

The purpose of a Statement of Applicability is to connect every Annex A control to a risk from your risk assessment and to a piece of implementation evidence. It shows an auditor, in one document, exactly what your Information Security Management System covers and why each decision was made.

Is a Statement of Applicability confidential?

A Statement of Applicability is an internal ISMS document, not something published publicly, though auditors and certification bodies review it in full during an audit. Some organisations share a redacted summary with customers or partners on request, but the detailed version, including control-by-control justifications, is normally kept internal.

What does a Statement of Applicability look like?

A Statement of Applicability is typically a table with one row per Annex A control, and columns for the control reference, whether it is applicable, the justification, the implementation status, and a link to supporting evidence. Some organisations keep it in a spreadsheet; others manage it inside a compliance platform.

Can I exclude a control from the Statement of Applicability?

Yes. Any of the 93 Annex A controls can be marked not applicable if it genuinely does not apply to your organisation, provided you record a specific, factual justification, such as having no physical premises to secure. An auditor will challenge an exclusion that is not backed by a clear reason.

How often should a Statement of Applicability be updated?

A Statement of Applicability should be reviewed at least annually as part of your management review, and updated immediately whenever your risk assessment, scope or systems change. Surveillance audits in the years following initial certification specifically check whether the document has kept pace with the business.

Related guides

Let CertAssist keep your Statement of Applicability handled

CertAssist lays out all 93 ISO 27001:2022 Annex A controls with an editable justification and evidence field for each one, so your Statement of Applicability stays audit-ready. Launch price US$225 a month.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.