ISO 27001 Statement of Applicability

ISO 27001 Statement of Applicability: The Document Auditors Read First


Published 07/30/2026

Of all the documentation required for ISO 27001 certification, one tends to draw the closest attention from auditors: the Statement of Applicability. It's often the first document they turn to, and there's good reason for that. It's where your risk assessment, your control choices, and your entire ISMS come together into a single, coherent story, one that shows not just what you've done, but why.



View ISMS Here

What Is a Statement of Applicability?

The Statement of Applicability, often shortened to SoA, is a formal document required under ISO 27001 that accounts for every control listed in Annex A and explains whether it's been implemented, and why. For each of the 93 controls, the SoA records whether it applies to your organization, whether it's been adopted, and the reasoning behind that decision.

Research into ISO 27001 audit outcomes consistently points to the same pattern: certification bodies rely on the SoA as their primary reference point for understanding how an organization actually approached information security, not just what it claims on paper. It isn't a summary or a formality. It's the connective thread between the risks you've identified and the specific safeguards you've chosen to address them, and auditors will trace that thread carefully against your policies, procedures, and evidence.

A thoughtfully built Statement of Applicability gives your ISMS a clear, defensible narrative. Without one, even a genuinely strong security program can struggle to demonstrate itself convincingly, simply because the paper trail connecting risk to action isn't there.



Why the Statement of Applicability Matters

The SoA carries a role that extends well beyond paperwork.

It demonstrates thoughtful, risk-based decision-making. Rather than adopting controls by default, the SoA shows that each choice reflects a genuine assessment of risk, considered and documented with care.

It fulfills a core requirement of the standard. Clause 6.1.3 of ISO 27001 asks organizations to produce a Statement of Applicability as part of the certification process, and it's treated as foundational, not optional.

It supports both internal and external audits. Auditors use it as a reference point to understand and verify that the controls an organization claims are genuinely in place and functioning as intended.

It creates shared accountability. By documenting who made which decisions and why, the SoA helps distribute ownership of security across the organization, rather than leaving it with a single person or team.

It preserves institutional knowledge over time. As the ISMS evolves, the SoA becomes a living record of how and why control decisions have changed, offering useful context for future reviews.



How to Build a Statement of Applicability That Holds Up

Creating an accurate, audit-ready SoA takes more than filling in a template. It's a process worth approaching thoughtfully.

1. Begin with your completed risk assessment. Let the SoA grow out of the risks you've actually identified, rather than building it independently or borrowing from a generic list that doesn't reflect your organization.

2. Work through every control in Annex A with care. Take the time to consider each of the 93 controls individually, weighing whether it genuinely applies given your specific risk landscape and business context.

3. Write justifications that actually explain your reasoning. A note like "not applicable" with nothing further rarely satisfies an auditor. Every inclusion or exclusion deserves a clear, thoughtful explanation tied to identified risks, business needs, or legal obligations.

4. Connect each control to real, tangible evidence. For anything marked as implemented, make sure there's a supporting policy, procedure, log, or record behind it. Studies of common audit findings show that claiming a control without documentation to back it up remains one of the most frequent gaps organizations encounter.

5. Bring in leadership and relevant stakeholders. Because the SoA reflects decisions that affect the whole organization, it benefits from being reviewed collaboratively rather than assembled in isolation by one department.

6. Revisit it as your organization changes. The SoA isn't meant to be static. Set aside time to review it whenever your risk assessment shifts, new systems come online, or the business evolves, and be wary of leaning on a generic template that doesn't truly reflect your environment.



Take the Next Step

A well-built Statement of Applicability is often what separates a smooth ISO 27001 audit from a stressful one. It's the document that ties your entire security program together into something coherent and defensible, and getting it right takes more thoughtfulness than a simple checklist exercise.

Sign up today and get access to Statement of Applicability templates and expert guidance built specifically for ISO 27001, so your documentation is ready to support you when it matters most.
Discover our ISO Audit Tool


View ISMS Templates, Forms and Examples


Get Started Free
Create your first Incident Report form or choose from our form templates and start recording incidents in the field