The SoA explains your control position
The Statement of Applicability, or SoA, records which Annex A controls are applicable to the organisation, the justification for inclusion or exclusion and the implementation status. It is often described as a mandatory ISO 27001 document, but its practical importance is greater than that description suggests.
The SoA acts as a bridge between the organisation’s risk treatment decisions and the standard’s control reference set. It helps an auditor, customer or manager understand which controls have been considered and why the organisation’s control environment looks the way it does.
A strong Statement of Applicability makes it possible to trace from risk and obligation to control decision, implementation and evidence without contradictory records.
Applicability is not a box-ticking exercise
Annex A should be considered as part of determining whether necessary controls have been omitted from the risk treatment plan. An organisation should not simply mark every control applicable to appear comprehensive, nor exclude controls only because implementation would be inconvenient. The decision should reflect risks, legal and contractual requirements, the operating environment and other relevant obligations.
A clear justification is particularly helpful for excluded controls because it demonstrates that the control was consciously considered rather than overlooked.
Keep the SoA aligned with reality
The SoA becomes unreliable when implementation status, policies and evidence drift apart. If a control is shown as implemented while key activities are incomplete, the document no longer provides an accurate management view. Changes in technology, scope or risk can also change applicability over time.
Treat the SoA as governed information that is reviewed alongside the risk treatment plan and control evidence. A connected system makes these relationships easier to maintain because the status is not isolated in a separate spreadsheet.
Make this easier to manage in OrcaComply
OrcaComply keeps the decisions, owners, documents, controls and evidence behind your ISMS connected so the work is easier to manage and easier to explain.
Explore Statement of Applicability management →