The Statement of Applicability is the document listing every Annex A control, whether it applies to your organisation, and the reason for each decision.
The short answer
The Statement of Applicability, usually shortened to SoA, is a mandatory ISO 27001 document required by Clause 6.1.3. It records all 93 Annex A controls, marks each as applicable or not, gives a justification either way, and states whether the applicable ones are actually implemented.
Auditors tend to open the SoA first, because it shows in one place what you claim to do and lets them pick which claims to test.
What a row contains
One row per control, ninety-three rows in total. Five columns cover everything an auditor needs.
Justifying exclusions
Excluding a control is normal and expected. What matters is that the reason is factual and verifiable.
| Exclusion | Acceptable reason |
|---|---|
| Physical entry controls | Fully remote company with no offices or data centres in scope |
| Secure development lifecycle | No software is developed in house within the certified scope |
| Cabling security | No owned network infrastructure; all systems are cloud hosted |
| Application security testing | Rarely defensible for a software company. Expect to be challenged |
Where SoAs go wrong
Copied from a template
Justifications that could belong to any company signal the risk assessment was never done.
Claiming everything
Marking all 93 controls applicable and implemented invites the auditor to test the weakest.
Left to go stale
An SoA that no longer matches the environment is a nonconformity in its own right.
How Osto helps
The SoA is only as accurate as the controls behind it. Osto deploys the technical controls and maps the resulting evidence to the corresponding Annex A references, so a row marked implemented can be shown to be implemented. The applicability decisions and justifications stay with you, since they follow from your own risk assessment.
Free security assessment
Make every implemented row provable
Osto runs the controls behind your SoA and produces the evidence, so a row marked implemented can be demonstrated.
Get a free security assessment Book a platform walkthroughLive control evidence · 200+ frameworks · One platform, everything
Frequently asked questions
What is a Statement of Applicability?
It is a mandatory ISO 27001 document listing all 93 Annex A controls, recording whether each applies to your organisation, why, and whether applicable controls are implemented. It is required by Clause 6.1.3.
Is the SoA mandatory?
Yes. It is one of the documents ISO 27001 requires explicitly, and a certification body will ask for it before the Stage 1 audit.
Can we exclude Annex A controls?
Yes, provided each exclusion has a justification grounded in fact, such as having no offices or developing no software in scope. Excluding a control because it is inconvenient is not acceptable.
How often should the SoA be updated?
Whenever the risk assessment, the scope or the control set changes, and at minimum as part of the annual management review. An outdated SoA is treated as a nonconformity.

