Step 5 · Plan and implementation
Statement of Applicability (SoA) Which controls apply, and why.
The Statement of Applicability shows for each of the 93 controls in Annex A whether it applies, why, and whether it is implemented. It is one of the most important documents in an ISO 27001 audit.
What it is about
ISO/IEC 27001 clause 6.1.3 d) requires a Statement of Applicability containing the necessary controls, the justification for including them, whether they are implemented, and the justification for excluding any Annex A controls. It links risk treatment and implementation: every included control should trace back to a risk or a requirement.
- MFA for all admin accountsITdone
- Update the emergency manualCISOin progress
- Review cloud supplierPurchasingoverdue
23 of 46 measures implemented
Sample values
How to go about it
- 01
Go through all 93 controls in Annex A.
- 02
Mark each as applicable or not applicable, with a justification.
- 03
Record the implementation status.
- 04
Document version and approval, and maintain the SoA as things change.
Common mistakes
- Exclusions say “not relevant” instead of giving a reason.
- Controls have no link to a risk or requirement.
- Written once for the audit and never maintained.
What an auditor wants to see
- Approved SoA with version
- References to risks and evidence
- Change history
How UniqSuite helps
In UniqSuite the Statement of Applicability is built from your answers and justifications. You do not have to write it by hand.
References
- ISO/IEC 27001, clause 6.1.3 d)
- ISO/IEC 27001, Annex A: 93 controls
- ISO/IEC 42001 requires its own Statement of Applicability for its Annex A
Frequently asked questions
How many controls can we exclude?
There is no quota. Every exclusion needs a traceable justification, for example because there is no in-house software development.
Does NIS2 require an SoA?
The law does not require one explicitly. As evidence of which measures you implement and why, it is very useful.
Is an SoA based on the 2013 edition still valid?
No. The transition period to ISO/IEC 27001:2022 ended on 31 October 2025, and certificates based on the 2013 edition have since expired or been withdrawn. The SoA must refer to the 93 controls of the 2022 edition.
Can a control be applicable but not yet implemented?
Yes. The SoA records exactly this implementation status. The risk treatment plan then shows who implements the control and by when.
Do controls outside Annex A belong in the SoA?
Yes, if they are necessary for risk treatment. Clause 6.1.3 d) requires the necessary controls, not only those from Annex A.
See what this looks like in UniqSuite.
In half an hour we walk you through it with your own questions.
