Guide

The Statement of Applicability: What It Is and How to Build One

The document at the center of ISO 27001, what the SoA must contain, and how to write one that holds up in a certification audit.

7 min read

The Statement of Applicability, or SoA, is the single most important document in an ISO 27001 certification. It is the bridge between your risk assessment and the Annex A controls, and the auditor will return to it again and again. If your ISMS has a spine, the SoA is it.

What the SoA Is

The Statement of Applicability lists every Annex A control and, for each one, records:

  • Whether the control is applicable to your organization.
  • If applicable, whether it is implemented, and a reference to how.
  • If not applicable, the justification for excluding it.

In other words, it is the auditable record of the decisions you made: which controls you apply, which you leave out, and why. It turns "we chose these controls" into a documented, defensible position.

Why It Matters So Much

The SoA is where an auditor checks that your control selection is deliberate rather than arbitrary. A well-built SoA shows that each control traces back to a risk, and each exclusion has a reason. A weak SoA, one with controls marked applicable but no evidence, or exclusions with no justification, is one of the fastest ways to raise findings in a certification audit.

How to Build One

  1. Start from your risk assessment. Every applicable control should treat a risk you identified.
  2. Map risks to Annex A controls. For each risk, note which controls address it.
  3. Record implementation. For applicable controls, reference the policy, process, or evidence that shows the control is in place.
  4. Justify exclusions plainly. If a control does not apply, say why in a sentence a stranger could follow.
  5. Keep it current. The SoA is a living document; update it as your risks, scope, and controls change.

How Concord Fits

Because the SoA is a map from controls to how they are implemented, keeping your controls, owners, and evidence in one place makes it far easier to maintain. In Concord Trust, your control library and coverage view give you the implemented-control side of the SoA in a single view, so the document reflects what is actually running rather than a snapshot that goes stale between audits.

Get Started

Turn Security Reviews into a Link You Send

Concord Trust turns your controls, frameworks, and scoped auditor access into a public trust center that answers security reviews and closes deals. Start free, then add a framework when you are ready.