Statement of Applicability: What Auditors Check

Statement of Applicability in ISO 27001 explained

The Statement of Applicability is the document listing every Annex A control, whether it applies to your organisation, and the reason for each decision.

  • Glossary
  • Compliance

The short answer

The Statement of Applicability, usually shortened to SoA, is a mandatory ISO 27001 document required by Clause 6.1.3. It records all 93 Annex A controls, marks each as applicable or not, gives a justification either way, and states whether the applicable ones are actually implemented.

Auditors tend to open the SoA first, because it shows in one place what you claim to do and lets them pick which claims to test.

What a row contains

One row per control, ninety-three rows in total. Five columns cover everything an auditor needs.

ANATOMY OF ONE SoA ROW REFERENCE A.8.5 CONTROL NAME Secure authentication APPLICABLE? Yes JUSTIFICATION Risk R-04, customer data access STATUS Implemented The justification column is the one auditors read closely. It must trace back to a specific risk, not to a generic statement. Risk assessment → treatment decision → control selected → SoA row Every row should be traceable back along this chain

Justifying exclusions

Excluding a control is normal and expected. What matters is that the reason is factual and verifiable.

ExclusionAcceptable reason
Physical entry controlsFully remote company with no offices or data centres in scope
Secure development lifecycleNo software is developed in house within the certified scope
Cabling securityNo owned network infrastructure; all systems are cloud hosted
Application security testingRarely defensible for a software company. Expect to be challenged

Where SoAs go wrong

Copied from a template

Justifications that could belong to any company signal the risk assessment was never done.

Claiming everything

Marking all 93 controls applicable and implemented invites the auditor to test the weakest.

Left to go stale

An SoA that no longer matches the environment is a nonconformity in its own right.

How Osto helps

The SoA is only as accurate as the controls behind it. Osto deploys the technical controls and maps the resulting evidence to the corresponding Annex A references, so a row marked implemented can be shown to be implemented. The applicability decisions and justifications stay with you, since they follow from your own risk assessment.

Free security assessment

Make every implemented row provable

Osto runs the controls behind your SoA and produces the evidence, so a row marked implemented can be demonstrated.

Get a free security assessment Book a platform walkthrough

Live control evidence · 200+ frameworks · One platform, everything

Frequently asked questions

What is a Statement of Applicability?

It is a mandatory ISO 27001 document listing all 93 Annex A controls, recording whether each applies to your organisation, why, and whether applicable controls are implemented. It is required by Clause 6.1.3.

Is the SoA mandatory?

Yes. It is one of the documents ISO 27001 requires explicitly, and a certification body will ask for it before the Stage 1 audit.

Can we exclude Annex A controls?

Yes, provided each exclusion has a justification grounded in fact, such as having no offices or developing no software in scope. Excluding a control because it is inconvenient is not acceptable.

How often should the SoA be updated?

Whenever the risk assessment, the scope or the control set changes, and at minimum as part of the annual management review. An outdated SoA is treated as a nonconformity.