Get Demo
↑

ISO 27001 Statement of Applicability (SoA): Guide and Template

ISO/IEC...

Published: September 2026 Compliance · ISO 27001 10–14 min read

Under Clause 6.1.3 d), organizations shall produce a Statement of Applicability that contains: the necessary controls; justification for their inclusion; justification for excluding any Annex A controls; and whether the necessary controls are implemented.

Structure lock: SoA is mandatory documented information tied to risk treatment (6.1.3), not an optional spreadsheet.

Template Columns

Column
Content
Control ID / title
Annex A or designed control
Applicable?
Yes / No
Justification
Inclusion or exclusion rationale
Implemented?
Status and evidence link
Owner
Accountability

Operationalize ISO 27001:2022 with Continuous Evidence

CyberSilo CSA tracks SoA and mandatory records; ThreatHawk supports logging and monitoring artefacts for technological controls.

Frequently Asked Questions

Is the SoA mandatory?

Yes. Clause 6.1.3 d) requires the organization to produce a Statement of Applicability.

What must the SoA contain?

The necessary controls (see 6.1.3 b and c); justification for inclusions; justification for exclusions of controls from Annex A; and whether the necessary controls are implemented.

Is Annex A a menu you can ignore?

Annex A is normative as a reference set. You compare necessary controls to Annex A so necessary controls are not inadvertently omitted; you may add controls from other sources.

ISO 27001 hub · 93 controls · SoA · CSA · Risk assessment · Mandatory documents

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!