Auditors send more Statements of Applicability back for vague justifications than for any other reason. Here is exactly what yours needs to include, control by control.
A Statement of Applicability an ISO 27001 auditor will accept lists all 93 controls in Annex A of ISO 27001:2022, marks each one applicable or not applicable, gives a specific justification tied to a risk assessment finding, states the implementation status, and cross-references the evidence. The Statement of Applicability is required under Clause 6.1.3(d) of ISO 27001, so a certification body cannot issue a certificate without one. Most first-time Statements of Applicability fail not because a control is missing, but because the justification for including or excluding it is too generic to survive an auditor's questions.
A Statement of Applicability, usually shortened to SoA, is the ISO 27001 document that records every control in Annex A of ISO/IEC 27001:2022 and states, for each one, whether your organisation has included it, why, and how far it has been implemented. Auditors treat the Statement of Applicability as the master index of an Information Security Management System (ISMS), because it is the single document that ties every control back to a risk in your risk assessment and to a piece of evidence in your evidence library. Without a Statement of Applicability that stands up to questioning, there is no ISO 27001 certificate.
A Statement of Applicability must include five things for every control, and an auditor will check for all five before signing off:
Leave any of the five off a control and an auditor has grounds to raise a nonconformity, even if the control itself is genuinely well implemented.
The justification is the part of a Statement of Applicability that auditors read most closely, and it is where generic templates fall apart. A justification for including a control should name the specific risk it addresses and, where possible, point to the risk register entry: "A.8.24 Use of cryptography is included because customer data is processed in transit and at rest, addressing risk R-014 (data exposure in cloud storage) from the risk assessment." A justification for excluding a control should state the factual reason it does not apply, not simply that it seems unnecessary: "A.7.4 Physical security monitoring is not applicable because the organisation operates fully remotely with no physical premises to monitor; this exclusion is reviewed at each management review." Justifications such as "not relevant" or "not required" without a stated reason are the most common cause of an SoA being sent back for rework.
| Control | Applicable | Justification | Status |
|---|---|---|---|
| A.5.1 Policies for information security | Yes | Required by Clause 5.2; sets direction for all other controls | Implemented |
| A.6.3 Information security awareness, education and training | Yes | Addresses risk R-006, staff-caused data incidents | Implemented |
| A.7.4 Physical security monitoring | No | Fully remote organisation, no physical premises | Not applicable |
| A.8.24 Use of cryptography | Yes | Addresses risk R-014, data exposure in cloud storage | Partially implemented, target Q4 2026 |
Illustrative extract only. Your own Statement of Applicability must reflect your actual risk assessment, not this example.
ISO 27001:2022 has 93 controls in Annex A, organised into four themes: organisational, people, physical and technological. Every one of the 93 controls needs a decision and a justification on your Statement of Applicability, even the ones that clearly do not apply to your organisation. The table below shows how the 93 controls are distributed across the four themes.
| Theme | Controls | Example |
|---|---|---|
| A.5 Organisational | 37 | Policies, roles, supplier relationships |
| A.6 People | 8 | Screening, awareness, disciplinary process |
| A.7 Physical | 14 | Secure areas, equipment, clear desk |
| A.8 Technological | 34 | Access control, cryptography, logging |
An ISO 27001 auditor checks a Statement of Applicability against three other documents, not in isolation. First, against the risk assessment, to confirm every identified risk maps to at least one included control. Second, against the risk treatment plan, to confirm the implementation status on the Statement of Applicability matches what the treatment plan says is actually done. Third, against the evidence itself, by sampling a handful of "implemented" controls and asking to see the proof. An auditor who finds a control marked implemented with no matching evidence, or a risk in the risk register with no corresponding control, will raise it as a finding regardless of how polished the rest of the document looks. National guidance such as the UK National Cyber Security Centre's overview of recognised standards makes the same point: a certification is only as credible as the evidence behind it.
Each of these is fixable before an audit, and each is far cheaper to fix in a document review than in front of an auditor.
A Statement of Applicability should be reviewed at least once a year, and additionally whenever your risk assessment changes, your scope changes, or you adopt a new system or supplier that introduces a new risk. Treat it as a living document tied to your management review, not a one-time deliverable produced for the initial certification audit and then forgotten; surveillance audits in years two and three will check whether it has kept pace with the business. CertAssist has the Statement of Applicability handled as one of its ISO 27001:2022 features: every Annex A control is laid out with an editable justification field and a direct link to its evidence, so updating the document when something changes is a small edit rather than a rewrite from scratch.
A Statement of Applicability is the ISO 27001 document that lists all 93 controls in Annex A of ISO 27001:2022 and records whether each one is applicable to your organisation, why, and its implementation status. It is required under Clause 6.1.3(d) and is one of the first documents an auditor reviews.
The purpose of a Statement of Applicability is to connect every Annex A control to a risk from your risk assessment and to a piece of implementation evidence. It shows an auditor, in one document, exactly what your Information Security Management System covers and why each decision was made.
A Statement of Applicability is an internal ISMS document, not something published publicly, though auditors and certification bodies review it in full during an audit. Some organisations share a redacted summary with customers or partners on request, but the detailed version, including control-by-control justifications, is normally kept internal.
A Statement of Applicability is typically a table with one row per Annex A control, and columns for the control reference, whether it is applicable, the justification, the implementation status, and a link to supporting evidence. Some organisations keep it in a spreadsheet; others manage it inside a compliance platform.
Yes. Any of the 93 Annex A controls can be marked not applicable if it genuinely does not apply to your organisation, provided you record a specific, factual justification, such as having no physical premises to secure. An auditor will challenge an exclusion that is not backed by a clear reason.
A Statement of Applicability should be reviewed at least annually as part of your management review, and updated immediately whenever your risk assessment, scope or systems change. Surveillance audits in the years following initial certification specifically check whether the document has kept pace with the business.
CertAssist lays out all 93 ISO 27001:2022 Annex A controls with an editable justification and evidence field for each one, so your Statement of Applicability stays audit-ready. Launch price US$225 a month.
See pricing FrameworksFlat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.