Step 5 · Plan and implementation

Statement of Applicability (SoA) Which controls apply, and why.

The Statement of Applicability shows for each of the 93 controls in Annex A whether it applies, why, and whether it is implemented. It is one of the most important documents in an ISO 27001 audit.

What it is about

ISO/IEC 27001 clause 6.1.3 d) requires a Statement of Applicability containing the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A controls. It links risk treatment and implementation: every included control should trace back to a risk or a requirement.

Step 5Plan and implementation
Open14
In progress9
Done23
  • MFA for all admin accountsITdone
  • Update the emergency manualCISOin progress
  • Review cloud supplierPurchasingoverdue

23 of 46 measures implemented

Sample values

How to go about it

  1. 01

    Go through all 93 controls in Annex A.

  2. 02

    Mark each as applicable or not applicable, with a justification.

  3. 03

    Record the implementation status.

  4. 04

    Document version and approval, and maintain the SoA as things change.

Common mistakes

  • Exclusions say “not relevant” instead of giving a reason.
  • Controls have no link to a risk or requirement.
  • Written once for the audit and never maintained.

What an auditor wants to see

  • Approved SoA with version
  • References to risks and evidence
  • Change history

How UniqSuite helps

In UniqSuite the Statement of Applicability is built from your answers and justifications. You do not have to write it by hand.

References

  • ISO/IEC 27001, clause 6.1.3 d)
  • ISO/IEC 27001, Annex A: 93 controls
  • ISO/IEC 42001 requires its own Statement of Applicability for its Annex A

Frequently asked questions

How many controls can we exclude?

There is no quota. Every exclusion needs a traceable justification, for example because there is no in-house software development.

Does NIS2 require an SoA?

The law does not require one explicitly. As evidence of which measures you implement and why, it is very useful.

Is an SoA based on the 2013 edition still valid?

No. The transition period to ISO/IEC 27001:2022 ended on 31 October 2025, and certificates based on the 2013 edition have since expired or been withdrawn. The SoA must refer to the 93 controls of the 2022 edition.

Can a control be applicable but not yet implemented?

Yes. The SoA records exactly this implementation status. The risk treatment plan then shows who implements the control and by when.

Do controls outside Annex A belong in the SoA?

Yes, if they are necessary for risk treatment. Clause 6.1.3 d) requires the necessary controls, not only those from Annex A.

See what this looks like in UniqSuite.

In half an hour we walk you through it with your own questions.

→Demo request

Show us your questions.

We will get back to you within two working days and arrange a demo of about 30 minutes – built around your own requirements.

Please fill in.

Please fill in.

Please fill in.

Please enter a valid email address.

Please use digits, spaces and + ( ) / - only.

We use your details solely to answer your request. Details in our privacy policy.