We may not have the course you’re looking for. If you enquire or give us a call on 01344203999 and speak to our training experts, we may still be able to help with your training requirements.
We ensure quality, budget-alignment, and timely delivery by our expert instructors.

Every organisation handling sensitive data needs a clear way to show how it protects that information. That’s where the ISO 27001 Statement of Applicability comes in. It's not just paperwork; It’s a smart, structured record of your chosen security controls and the reasons behind them.
Whether you're preparing for certification or simply enhancing your ISMS, the ISO 27001 Statement of Applicability is a must-have. It helps you stay compliant, clearly communicate your risk decisions, and prove you're serious about information security. In this blog, we’ll breakdown how it works, its importance, what should be included, and more. Let’s begin!
Table of Contents
1) What is a Statement of Applicability in ISO 27001?
2) Why is the ISO 27001 Statement of Applicability Important?
3) What Should be Included in a Statement of Applicability?
4) How to Write an ISO 27001 Statement of Applicability?
5) ISO 27001 Statement of Applicability Example
6) How Often Should the SoA Be Updated?
7) Can I Remove Controls from the ISO 27001 Statement of Applicability?
8) Conclusion
What is a Statement of Applicability in ISO 27001?
An ISO 27001 Statement of Applicability is a mandatory document that records which Annex A security controls an organisation has selected and why. It links the organisation's risk assessment and risk treatment process to the controls in Annex A, showing how identified information security risks are addressed.
The SoA states whether each of the 93 Annex A controls is applicable, provides reasons for any inclusions or exclusions, and confirms their implementation status. During a certification audit, Auditors use it to verify that control selection is risk-based, justified, and aligned with the organisation's security requirements.
Why is the ISO 27001 Statement of Applicability Important?
The ISO 27001 Statement of Applicability plays a key role in building and maintaining an effective Information Security Management System (ISMS). Let’s look at the key reasons that demonstrate its importance below:
a) Demonstrates Risk-based Decision-making: The SoA shows that security controls are selected through a structured risk assessment, ensuring they are appropriate for the organisation's risks and business needs.
b) Promotes Transparency and Accountability: The SoA explains why each Annex A control is included or excluded, giving stakeholders clear visibility into the organisation's information security decisions.
c) Supports Certification and Audits: The SoA is one of the first documents reviewed during an ISO 27001 audit. It helps Auditors verify that control selection is justified and complies with ISO/IEC 27001 requirements.
d) Serves as a Practical Reference: The SoA provides management, employees, and external stakeholders with a clear overview of the organisation's security controls, supporting effective ISMS management.
What Should be Included in a Statement of Applicability?
A Statement of Applicability (SoA) should document all 93 Annex A controls and explain the organisation's control selection using a clear, risk-based approach. It should demonstrate how identified risks lead to appropriate security controls and provide evidence that the Information Security Management System (ISMS) is properly managed. It should include:
a) Annex A Control Register:
a) A complete list of all 93 Annex A controls
b) Whether each control is applicable or not applicable
b) Control Selection Justification:
a) Clear reasons for including or excluding each control
b) Links between control selection, risk assessment, and risk treatment decisions
c) Implementation Details:
a) The implementation status of every applicable control
b) Assigned control owners responsible for maintaining each control
c) References to supporting policies, procedures, or technical safeguards
d) Governance and Approval:
a) Management approval and sign-off
b) Approval date and document version, where applicable
Take control of your organisation's Information security with our ISO 27001 Internal Auditor Course - register now!
ISO 27001 Control List and Its Applications
Within ISO 27001, there is a set of controls, specifically in Annex A, that organisations can use to address various Information security risks. These controls are divided into 14 categories, each addressing a different aspect of information security. Here is a list of controls in ISO 27001 along, with their general uses:
1) Information Security Policies (A.5): Defines and communicates information security policies and objectives.
2) Organisation of Information Security (A.6): Establishes roles and responsibilities to maintain information security within the organisation.
3) Human Resource Security (A.7): Ensures employees and contractors are aware of and compliant with security policies.
4) Asset Management (A.8): Identifies, classifies, and manages information assets effectively.
5) Access Control (A.9): Controls access to information systems and data, ensuring authorised access and preventing unauthorised access.
6) Cryptography (A.10): Protects sensitive information through encryption and cryptographic controls.
7) Physical and Environmental Security (A.11): Secures physical facilities and equipment to prevent unauthorised access, damage, or interference.
8) Operations Security (A.12): Ensures the secure operation of information systems and data.
9) Communications Security (A.13): Protects the confidentiality and integrity of data during transmission.
10) System Acquisition, Development, and Maintenance (A.14): Integrates security into the Software Development Lifecycle and procurement processes.
11) Supplier Relationships (A.15): Ensures that suppliers and third-party partners meet Information security requirements.
12) Information Security Incident Management (A.16): Establishes an incident response plan to properly address security breaches and incidents.
13) Information Security Continuity (A.17): Develops and maintains business continuity and disaster recovery plans.
14) Compliance (A.18): Ensures compliance with legal, regulatory, and contractual requirements concerned with Information security.
Want to gain the expertise to lead and conduct a successful ISO 27001 audit? Sign up for our ISO 27001 Lead Auditor Course today!
How to Write an ISO 27001 Statement of Applicability?
Now that we have discussed what a Statement of Applicability is, why it is essential and what it should include, we will now discuss the steps to write one.

1) Understand the Requirements
The first step to writing an effective ISO 27001 Statement of Applicability is understanding the requirements that can be overwhelming if one is new to ISO 27001 Checklist or Information security standards in general. Nevertheless, a comprehensive understanding of these requirements will help ensure that your Statement of Applicability is accurate and complete.
2) Conduct a Risk Assessment
Before preparing an ISO 27001 Statement of Applicability, it is important to carry out a thorough risk assessment. This step helps identify and evaluate potential information security risks that could impact your organisation. If a risk assessment has already been completed, its findings can be used as a foundation to support the SoA.
3) Define Your Risk Treatment Plan
At this stage, you establish how identified risks will be managed by defining an appropriate risk treatment approach. This includes selecting suitable security controls, such as encryption or access controls, to reduce or mitigate risks effectively. By aligning these measures with your risk assessment, you can clearly determine which controls are required to protect your organisation’s information systems.
4) Map Annex A Controls to Risks and Treatment Decisions
Review the 93 Annex A controls across the organisational, people, physical, and technological categories. Determine whether each control is applicable and ensure every selected control directly addresses the risks identified during the risk assessment and treatment process.
5) Complete the SoA Table with Clear Justifications
Record key details for each Annex A control to create a complete and defensible SoA. Also, it is important to ensure all justifications are clear, specific, and based on risk. This should include:
a) Applicability (applicable or not applicable)
b) Reason for inclusion or exclusion
c) Link to the relevant risk treatment
d) Implementation status
e) Assigned control owner
f) Reference to supporting policies or procedures
6) Review and Maintain the SoA Regularly
Keep the Statement of Applicability updated by reviewing it whenever risks, business processes, systems, or regulatory requirements change. Ensure it is management-approved and version-controlled, as Auditors will assess it for completeness during Stage 1 and verify its implementation during Stage 2 of the certification audit.
Want to elevate your organisation's Cyber Security practices? Register for our industry-leading ISO 27001 Internal Auditor Course - today!
ISO 27001 Statement of Applicability Example
An ISO 27001 Statement of Applicability (SoA) example typically presents a structured list of all Annex A controls, showing whether each control is applicable, along with a clear justification and its implementation status. It acts like a checklist that explains which security measures an organisation has chosen and why certain controls are excluded based on risk and business needs.
In practice, an SoA example often includes columns such as control ID, control name, applicability (yes or no), justification, and implementation status. This format helps organisations clearly demonstrate how their selected controls address specific risks and provides auditors with a transparent view of their information security approach.

How Often Should the SoA Be Updated?
The Statement of Applicability (SoA) should be reviewed and updated at least once a year to ensure it remains aligned with your organisation’s current risk environment and security controls.
In addition, updates should be made whenever there are significant changes such as new risks, business or technology updates, audit findings, or security incidents. Keeping the SoA regularly updated helps maintain compliance and ensures your ISMS reflects the latest security requirements.
Can I Remove Controls from the ISO 27001 Statement of Applicability?
Yes, you can exclude controls from the ISO 27001 Statement of Applicability, but only if they are justifiably not applicable based on your organisation’s risk assessment, legal, regulatory, or contractual requirements. Properly conducting and documenting this process often starts with how you Develop an Asset Inventory for ISO 27001, ensuring each exclusion is clearly recorded and explained in the SoA.
Conclusion
The ISO 27001 Statement of Applicability demonstrates a risk-based approach to information security and justifies control decisions with confidence. By keeping the SoA accurate and updated, organisations can strengthen their Information Security Management System, simplify audits, and build trust with customers, partners, and regulators.
Take the first step towards securing your organisation's information with our comprehensive ISO 27001 Foundation Course.
Frequently Asked Questions
Is the Statement of Applicability Mandatory for ISO 27001 Certification?
Yes, the Statement of Applicability is mandatory for ISO 27001 Certification. It is a core document that shows how your organisation has selected security controls based on identified risks. Without a complete and justified SoA, you cannot meet the standard's certification requirements.
What’s the Difference Between ISO 27001 SoA and Scope?
The Scope of ISO 27001 defines the boundaries of the Information Security Management System (ISMS), specifying what parts of the organisation, assets, and processes are covered. The Statement of Applicability (SoA) lists the security controls chosen, justifies their inclusion or exclusion, and other details of their implementation status.
The Knowledge Academy is a world-leading provider of professional training courses, offering globally recognised qualifications across a wide range of subjects. With expert trainers, up-to-date course material, and flexible learning options, we aim to empower professionals and organisations to achieve their goals through continuous learning.
Top Rated Course