Manage control applicability, ownership, implementation and evidence from one place while keeping the reasons behind each decision visible.
The Statement of Applicability is one of the most important outputs of an ISO 27001 ISMS because it explains which Annex A controls are relevant and why. OrcaComply keeps applicability decisions separate from implementation status, helping teams distinguish between a control that is required and a control that is already fully operating.
That distinction matters. A control can be applicable because of risk, legal, contractual or organisational needs while still being planned or implemented with exceptions. Keeping the reasoning visible makes the SoA more useful than a simple yes-or-no table.
Each applicable control can be linked to the people responsible for it, the policies that govern it and the evidence that demonstrates operation. Testing, assurance exceptions and audit findings can then feed back into the same record.
The result is a Statement of Applicability that reflects the real ISMS and can be exported with clearer context for certification and management review.
Bring policies, risks, controls, evidence and audit activity into one connected workspace with clear ownership and practical next actions.