Skip to content

Controls

Statement of Applicability: how the SoA becomes a steering document

The SoA connects risks, selected controls, justifications and implementation status. It is more than a ticked-off Annex A list.

Back to ISO 27001

8 minute read · Content as of 21.07.2026

Every selection needs a traceable origin

Controls follow from risk treatment, legal and contractual requirements, and internal decisions. Annex A is a reference set for the completeness check, not the only possible source.

Four fields make the SoA auditable

For every Annex A control it should be clear whether it is applicable, why that decision was made, how it is implemented and which evidence supports the status. Exclusions need a defensible justification just as much as inclusions.

  • Applicability and reason for the decision
  • Implementation status and responsible role
  • Reference to control, process or policy
  • Evidence and date of the last effectiveness check

Avoid parallel truths

If the risk register, the treatment plan and the SoA are maintained separately, status entries drift apart. Use shared IDs and clear maintenance responsibility. The SoA starter already contains these linking fields.

Sources used

Back to ISO 27001