Already using OrcaComply?Existing customer login →New customer registration →
Statement of Applicability

Your Statement of Applicability, connected to the rest of your ISMS.

Manage control applicability, ownership, implementation and evidence from one place while keeping the reasons behind each decision visible.

OrcaComply platform illustration
Why it matters

The SoA should explain your control decisions

The Statement of Applicability is one of the most important outputs of an ISO 27001 ISMS because it explains which Annex A controls are relevant and why. OrcaComply keeps applicability decisions separate from implementation status, helping teams distinguish between a control that is required and a control that is already fully operating.

That distinction matters. A control can be applicable because of risk, legal, contractual or organisational needs while still being planned or implemented with exceptions. Keeping the reasoning visible makes the SoA more useful than a simple yes-or-no table.

OrcaComply illustration
Why it matters

Connect the SoA to evidence and ownership

Each applicable control can be linked to the people responsible for it, the policies that govern it and the evidence that demonstrates operation. Testing, assurance exceptions and audit findings can then feed back into the same record.

The result is a Statement of Applicability that reflects the real ISMS and can be exported with clearer context for certification and management review.

OrcaComply illustration

Ready to make compliance easier?

Bring policies, risks, controls, evidence and audit activity into one connected workspace with clear ownership and practical next actions.