Statement of Applicability (SoA)
A Statement of Applicability (SoA) is a required document in the ISO 27001 information security management system standard that lists the security controls an organization has considered, indicates which ones it applies, and explains why any are excluded. It serves as the connecting document between an organization's risk assessment and how it decides to treat those risks. Organizations pursuing ISO 27001 certification are typically required to produce and maintain this document.
The SoA is a mandatory ISO 27001 document that enumerates the Annex A controls (93 controls in the current version referenced in the evidence), records the implementation status of each (implemented or excluded), and provides justification for inclusion or exclusion. It functions as the primary link between the outputs of risk assessment and the risk treatment decisions within an Information Security Management System (ISMS), demonstrating how selected controls map to identified risks. In practice, a virtual CISO may support the development and maintenance of the SoA as part of ISO 27001 readiness work, but producing an accurate SoA depends on client cooperation, organizational context, and completed risk assessment activities; the SoA itself supports certification readiness and does not, on its own, constitute or guarantee certification, which is determined by an accredited certification body.
Why it matters
The Statement of Applicability is often described as the central document of an ISO 27001 Information Security Management System because it is where risk decisions become visible and auditable. It connects the outputs of an organization's risk assessment to the specific controls chosen to treat those risks, and it records which Annex A controls are applied, which are excluded, and the reasoning behind each decision. Without a coherent SoA, an ISMS can appear to be a collection of disconnected policies rather than a deliberate, risk-driven program, which is precisely what an accredited certification body will scrutinize.
For organizations pursuing ISO 27001 certification, the SoA is a mandatory document, not an optional artifact. It gives auditors, leadership, and other stakeholders a single reference point to understand how the organization has interpreted its risk landscape and what it has decided to do about it. Because the justifications for inclusion and exclusion are recorded, the SoA also creates accountability: a decision to exclude a control must be explained rather than left implicit, which discourages gaps from being quietly ignored.
It is important to be precise about what the SoA does and does not accomplish. Producing an SoA supports certification readiness; it does not, on its own, constitute or guarantee certification, which is determined by an accredited certification body. Its value also depends heavily on the quality of the underlying risk assessment and on organizational cooperation. An SoA built on an incomplete or superficial risk assessment will document decisions that may not withstand audit scrutiny, so the document should be treated as the output of sound governance work rather than a box-checking exercise completed in isolation.
Who it's relevant to
Inside SoA
Common questions
Answers to the questions practitioners most commonly ask about SoA.