FAQGlobalISO/IEC 27001

ISO/IEC 27001 FAQ SoA Exclusions

How should teams justify Statement of Applicability exclusions under ISO/IEC 27001?

The SoA must justify every excluded Annex A control. A necessary control that is not yet implemented is not an exclusion, and Clauses 4-10 cannot be excluded from a conformity claim.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

The records which controls are necessary, why they are included, whether they are implemented, and why any Annex A controls are excluded. An exclusion is the organization's justified conclusion that an Annex A reference control is not necessary for its scoped ISMS. The organization must first determine all controls needed for its chosen risk treatments and compare them with Annex A so none are overlooked. A may be recorded as not implemented; it cannot be relabelled as excluded. Clauses 4-10 cannot be excluded when claiming conformity.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams justify Statement of Applicability exclusions under ISO/IEC 27001?

Start with the risk-treatment process, not the Annex A table. Clause 6.1.3 requires the organization to determine every control necessary for its chosen treatments, compare those controls with Annex A to verify that none were overlooked, and then explain any Annex A exclusions in the .

An is defensible when the organization can show why that reference control is not necessary in the scoped ISMS. The reason may follow from scope, technology, locations, information handled, interfaces, dependencies, assessed risks, or applicable requirements. Another control may contribute to the explanation, but naming an alternative alone does not show that the Annex A control is unnecessary.

  • State the Annex A control identifier, exclusion rationale, scope facts, risks considered, and any alternative control or dependency relevant to the decision.
  • Check the exclusion against applicable legal, regulatory, contractual, and interested-party requirements before approval.
  • Do not use exclusion to hide a that is planned but not yet implemented; the SoA can record a necessary control as not implemented.
  • Decision sequence: define scope and applicable requirements; assess risk; select treatment options; determine necessary controls from any source; compare them with Annex A; record inclusion, implementation, and exclusion rationales; obtain the required risk-owner approvals; then review the SoA when its basis changes.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clause 6.1.3 requires necessary-control determination, comparison with Annex A, and an SoA containing implementation status and justification for excluded Annex A controls.

Question 2

What evidence should support an exclusion?

The exclusion should trace back to the documented ISMS scope, risk-assessment results, selected treatment options, necessary-control determination, and the comparison with Annex A. A short rationale can be sufficient when that chain is clear; a generic 'not applicable' label is not self-explanatory.

Keep evidence proportionate to the decision. For example, an organization that does not operate its own data centre should not automatically exclude every physical control: its scope and supplier interfaces must still show which physical risks and responsibilities remain with the organization and which are handled through the provider. A supplier performing the activity can change the implementation method without making the control unnecessary.

  • Link the SoA entry to the specific risk and scope records that support the conclusion.
  • Record the reviewer, approval date, and trigger that would make the control relevant later.
  • Check that customer-facing and certification claims do not imply coverage broader than the scoped exclusion decision.
  • Example: excluding secure development controls may be supportable when no software development exists in scope and no applicable requirement depends on it. Outsourcing development does not automatically support the same result because supplier selection, agreements, oversight, and delivered-software risk can remain in scope.
Citations
ISO/IEC 27002:2022 standard page

ISO/IEC 27002:2022 explains the intent and implementation context of information security controls, helping reviewers test an exclusion rationale.

ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 provides risk-management guidance relevant to the assessment and treatment records supporting applicability decisions.

Question 3

Who approves the SoA and its exclusions?

ISO/IEC 27001 explicitly requires risk-owner approval of the risk-treatment plan and acceptance of residual risks. It does not prescribe a universal job title that signs the SoA. The organization should define SoA approval so control selection, exclusions, treatment decisions, and residual-risk approvals remain consistent.

A practical review includes the ISMS owner, relevant risk owners, and control or service owners; legal, privacy, supplier, resilience, or technical specialists should be involved when their requirements or dependencies affect the rationale. This is governance guidance, not a certification rule that creates a mandatory committee.

  • Name the SoA owner and approver in the documented ISMS process.
  • Keep risk-owner approvals with the treatment and residual-risk records, even when the SoA is approved elsewhere.
  • Escalate conflicts between risk, contract, law, control ownership, and exclusion rationale before publishing the SoA.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 requires risk-owner approval of the treatment plan and acceptance of residual risk but does not prescribe a universal SoA approver title or committee.

Question 4

When should exclusions be reviewed?

Review exclusions when the underlying risk assessment or treatment changes. Clause 8.2 requires reassessment at planned intervals and when significant changes are proposed or occur, so the SoA should not remain frozen while scope, systems, suppliers, threats, contracts, or legal requirements change.

Also review an exclusion when audit evidence, an incident, a failed dependency, or a new service shows that the earlier applicability assumptions were incomplete. The result may be a revised rationale, a newly , or a changed .

  • Set a planned review date and specific change triggers for each material exclusion.
  • Update the risk register, treatment plan, SoA, owner, and evidence links together when the decision changes.
  • Retain prior rationale as controlled history without presenting it as the current decision.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clause 8.2 requires risk assessment at planned intervals and when significant changes are proposed or occur; linked SoA decisions should be reviewed when their basis changes.

Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 27001:2022 clause 8.2 requires risk assessment at planned intervals and when significant changes are proposed or occur; linked SoA decisions should be reviewed when their basis changes.
"Information security management systems - Requirements"
iso.org
Referenced sections
  • ISO/IEC 27002:2022 provides control guidance relevant when changed circumstances alter an applicability decision.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 provides risk-management guidance relevant to the assessment and treatment records supporting applicability decisions.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.