Report · PDF · Word · Excel
Statement of Applicability Every control with its justification.
The Statement of Applicability (SoA) lists every control with its applicability, justification and implementation status, as ISO/IEC 27001 clause 6.1.3 d) requires. UniqSuite builds it from your answers.
What it is about
The SoA is created for your lead framework. For ISO/IEC 27001 it is the Statement of Applicability in the sense of clause 6.1.3 d). ISO/IEC 42001 also requires a Statement of Applicability in clause 6.1.3; for it, as for NIS2, the AI Act and the Cyber Resilience Act, UniqSuite provides the control catalogue in the same form. Controls you added during risk treatment and rejected controls have their own sections. Before the file is created, UniqSuite checks that the overview and the tables show the same numbers.
What you need it for
- Mandatory document in the ISO/IEC 27001 certification audit
- Evidence of which NIS2 measures you implement and why
- Link between risk treatment and implementation
- Basis for approval by management
What the report contains
- 01
Header
Company name, title and date; for the AI Act also the legal baseline.
- 02
Overview
Total, applicable, implemented, partial, not implemented, not assessed, applies later, not applicable and excluded, with a short explanation of each status.
- 03
Tables per category
ID, control, applicability, status and justification. Below each control: owner, role and, where relevant, the date from which it applies.
- 04
Missing justifications
If a control has no justification yet, the SoA marks it in red: “Justification missing – add before approval”.
- 05
Added controls
Controls you added from risk treatment.
- 06
Rejected controls
With the reason for rejection, traceable for any auditor.
- 07
AI systems (AI Act)
For registered AI systems, a matrix of system, role and control with owners, approval and evidence.
Formats
- Word
- Excel
With your company name, in German or English. The gap analysis, risk, audit and board reports also show your logo in the PDF.
Approve versions
In UniqSuite you approve states of the SoA as versions. Each version records who approved it, when, and the applicability and justification of every control.
Frequently asked questions
Which framework is the SoA created for?
For your lead framework. For ISO/IEC 27001 as the Statement of Applicability under clause 6.1.3 d). ISO/IEC 42001 also requires a Statement of Applicability in clause 6.1.3; for it, as for NIS2, the AI Act and the Cyber Resilience Act, UniqSuite creates the control catalogue in the same form.
What happens if a justification is missing?
If you mark a control as not applicable without a justification, the SoA flags it in red: “Justification missing – add before approval”. You see before the audit where work is left.
Can I edit the SoA afterwards?
Yes. Besides the PDF there is a Word file and an Excel file with every control, justification, owner and legal basis.
When can I approve a version of the SoA?
As soon as every control marked as not applicable has a justification. The version gets a sequential number and records the date, the approver and an optional note.
What is the SoA built from?
The implementation status comes from your gap analysis; owners and due dates come from risk treatment. UniqSuite suggests applicability from your answers, and your own decision and justification take precedence.
See your own reports.
In half an hour we show you how the reports are built from your data.
