Practical toolGlobalISO/IEC 27001

ISO/IEC 27001 Statement of Applicability Template

Use this field structure to document the necessary controls, why they are included, whether they are implemented, and why any Annex A controls are excluded.

Adapt it to the ISMS rather than copying Annex A mechanically. The SoA should stay aligned with risk treatment, legal and contractual requirements, control evidence, exceptions, and change history.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This field design helps any organization applying create a for its documented scope; ISO does not prescribe a form. Start with the four decisions: necessary controls, inclusion justification, whether each necessary control is implemented, and justification for excluding controls. Add owners, evidence links, dates, and workflow status only where they help operate and control the record.

Section 1

Which fields belong in an auditable SoA?

requires the SoA to contain the necessary controls, justification for their inclusion, whether those necessary controls are implemented, and justification for excluding controls. The standard does not prescribe a spreadsheet, status vocabulary, approver title, or row layout, so label added fields as internal controls rather than ISO requirements.

Necessary controls can be designed by the organization or selected from any source. Use a field that distinguishes references from organization-specific or other-source controls so the SoA does not imply that Annex A is exhaustive.

is an ISO/IEC 27001 conformity requirement. ISO/IEC 27002 gives control guidance, and ISO/IEC 27005 gives risk-management guidance. This template's owner, evidence-pointer, review, and workflow fields are Sorena's practical recommendations.

  • Control identifier and source: , organization-designed, legal, contractual, or another framework.
  • Decision and rationale: necessary-control inclusion or exclusion, linked to risk or requirement.
  • Required implementation status: state whether each necessary control is implemented. Internal sub-statuses such as planned, partial, or blocked can add detail but must not obscure that required answer.
  • Recommended owner: name the person or role responsible for implementation and current evidence.
  • Recommended evidence pointer: identify the authoritative record, test, log, policy, approval, period, and repository.
  • Recommended review control: record the last decision date, next planned review, change trigger, version, and approval history.
Section 3

Who should draft, challenge, approve, and maintain the SoA?

The organization chooses who maintains the SoA. A practical split is for an coordinator to control the record, risk owners to approve the treatment plan and accept residual risk, and control owners to confirm implementation and evidence. Only the risk-owner approvals are stated explicitly in ; the other role names are internal governance choices.

ISO/IEC 27001 does not prescribe a universal SoA approver title. Define approval in the governance process and include specialists where legal, contractual, privacy, supplier, resilience, physical, or technical requirements affect the decision.

  • Draft: owner consolidates controls, rationales, status, owners, and evidence pointers.
  • Challenge: risk, control, legal, privacy, supplier, and technical owners test completeness and consistency.
  • Approve: use the organization's defined governance while preserving required risk-owner approvals.
Section 4

Which template shortcuts create misleading control claims?

A prefilled list of 93 rows is useful only if each row reflects the organization's actual risk-treatment comparison. Copying 'applicable' into every row does not determine necessary controls, and copying 'not applicable' does not justify an exclusion.

Another misleading shortcut is marking a control implemented because a policy exists. The status should match the scoped implementation and operating evidence, including material exceptions and dependencies.

  • Do not cite a standard title as evidence that a process is operating.
  • Do not reuse an old audit artifact without checking whether it remains relevant after the scope, service, supplier, or risk has changed.
  • Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.
Section 5

When should the SoA be versioned and reapproved?

ISO/IEC 27001 does not set a universal SoA review interval or require a named SoA reapprover. Define those controls internally. Reassess affected entries when planned or significant-change risk assessments alter treatment, or when scope, applicable requirements, suppliers, systems, control design, implementation status, or material exceptions change.

Keep prior rationales and approvals as controlled history under the rules. A current SoA should explain today's necessary controls and implementation state without erasing the decision trail used in earlier audits or reviews.

  • Set a review date and a change-trigger rule.
  • Track findings until closure and connect them to corrective actions or risk acceptance.
  • Use management review to decide needed changes and improvement actions, including resources, scope, risk criteria, or evidence controls where relevant.
Primary sources

References and citations

iso.org
Referenced sections
  • Clauses 7.5 and 8.2 support controlled documented information and risk reassessment at planned intervals or when significant changes are proposed or occur.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • This source supports control implementation guidance and control-implementation expectations supporting ISO/IEC 27001 governance.
"Information security controls"
iso.org
Referenced sections
  • This source supports risk treatment and monitoring context that informs control decisions and residual risk handling.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.