Blog
What Is a Statement of Applicability (SoA) in ISO/IEC 27001 Certification?
The Statement of Applicability (SoA) is a crucial document of ISO/IEC 27001 certification. Learn what it includes, which security controls an organisation needs & learn how MSCi’s ISMS consultants helps you build an Information Security Management System (ISMS).
MSCi · June 27, 2026
Every business collects customer details, employee records, and other important information. However, the important question is: how are they protecting the valuable data asset?
The Statement of Applicability (SoA) has a significant role in ISO/IEC 27001; it is one of the key documents in an ISO/IEC 27001 consultancy engagement Information Security Management System (ISMS).
The SoA can be regarded as a security roadmap since it links the risks that a business encounters with the controls employed to address them. For instance, a company which deals with sensitive customer data might need to have stronger access controls, while another business could focus more on the security of its suppliers or on securing its physical premises. The appropriate controls will vary according to the specific risks and requirements of each organisation.
The Statement of Applicability (SoA) also gives auditors and business leaders a simple way to understand an organisation's approach to information security. It shows that security decisions are not made randomly but are based on identified risks and the steps taken to manage them.
A well-prepared SoA can make the ISO/IEC 27001 ISMS Consultants can make implementation process easier to understand. More importantly, it helps turn information security from a list of requirements into a practical approach that fits the way a business actually works.
What Is the Statement of Applicability (SoA) in ISO/IEC 27001?
The ISO/IEC 27001 Statement of Applicability is a document that records the security controls an organisation has considered as part of its ISMS.
ISO/IEC 27001:2022 includes 93 controls in Annex A. These controls are grouped into four categories:
- Organisational controls
- People controls
- Physical controls
- Technological controls
For each relevant control, the SoA explains whether it applies to the organisation or not. It also gives the reason for including or excluding the control.
The Statement of Applicability (SoA) generally records:
- Whether each control is included or excluded
- The reason for including or excluding the control
- Whether the control has been implemented
How the control relates to the organisation's risk treatment process
The SoA is not a document that exists on its own. It is closely connected to the ISMS risk assessment and risk treatment process.
When an organisation identifies a risk, it decides how that risk should be handled. An appropriate Annex A control may then be selected to reduce that risk. The decision is recorded in the SoA.
Why Is the ISO/IEC 27001 Statement of Applicability (SoA) Important?
Auditors pay close attention to the Statement of Applicability during an ISO/IEC 27001 certification consultancy audit. They use it to understand whether the organisation has properly assessed its information security risks and selected suitable controls.
A well-prepared SoA helps answer three simple questions:
- What risks does the organisation face?
- Which controls are being used to address those risks?
- Why were certain controls included or excluded?
This makes the SoA useful not only for auditors but also for management teams that need to understand the organisation's information security priorities.
Example of Including and Excluding ISO/IEC 27001 Controls
Imagine a fintech company that operates almost entirely through cloud-based systems.
- The company may include controls related to cryptography (Annex A 8.24) because sensitive financial information needs to be protected from unauthorised access.
- It may also include secure development life cycle (Annex A 8.25) because its software is an important part of its business.
- On the other hand, the organisation may decide that information deletion (Annex A 8.10) or other controls need to be assessed differently depending on how its cloud environment operates.
- An organisation should never exclude a control simply because it seems inconvenient. Every exclusion must have a clear and valid reason.
The decision should be linked to the organisation's risks, business activities and ISMS scope.
How Do organisations Define ISO/IEC 27001 Controls?
Defining the right ISO/IEC 27001 controls starts with understanding the risks. An organisation should not simply go through Annex A and select controls at random. Experienced ISO 27001 Consultants follow a structured process to ensure the right controls are selected for your ISMS.
The process can be understood through two main steps.
Step 1: Conduct an ISO/IEC 27001 Risk Assessment
Consider a private hospital that has recently moved its patient records from physical files to a digital records management system. The hospital now needs to understand where patient information could be exposed.
The risk assessment may cover:
- Electronic Health Record (EHR) software
- Laptops used by doctors and nurses
- Hospital Wi-Fi networks
- Devices used to access patient records
- Third-party laboratory systems
- Other systems that store or transfer patient information
Suppose a nurse leaves a laptop unlocked in a hospital ward. Someone without permission could use the laptop to access patient records. This creates a serious information security risk.
The hospital could address this risk through controls such as:
- Annex A 8.1 – User endpoint devices
- Annex A 7.7 – Clear desk and clear screen
The hospital also works with third-party laboratories that connect to its systems. This creates another risk because a security problem at a supplier could affect the hospital.
This risk can be considered under Annex A 5.19 – Information security in supplier relationships.
What Could Happen If These Risks Become Real?
A security incident could result in:
- Exposure of confidential patient information
- Breaches of applicable healthcare data requirements
- Loss of trust among patients
- Damage to the hospital's reputation
- Financial and operational consequences
The hospital should therefore document these risks and assess their likelihood and impact.
The results then move into the risk treatment process, where suitable controls are considered for inclusion in the SoA.
Step 2: Select Relevant ISO/IEC 27001 Annex A Controls
Once the risks are identified, the organisation can connect them with relevant Annex A controls.
The purpose is simple: each selected control should have a reason behind it.
A control may be selected because it helps address:
- An identified information security risk
- A legal or regulatory requirement
- A contractual requirement
- A specific business needs
Suppose a private hospital has identified several risks after moving patient records into a digital system.
Identified Risk Relevant Annex A Control Reason
Unauthorised access through an unlocked laptop A.8.1 – User endpoint devices Helps protect devices used to access patient information
Patient information visible on unattended screens A.7.7 – Clear desk and clear screen Reduces the chance of unauthorised viewing
Security risks from third-party laboratories A.5.19 – Information security in supplier relationships Helps manage information security risks involving suppliers
These risks are assessed according to their likelihood and potential impact. The hospital then decides how each risk should be treated. The selected controls are documented in the Statement of Applicability along with the reasons for their inclusion.
This creates a clear connection:
Risk → Risk Treatment → Relevant Control → Statement of Applicability
That connection is what makes the SoA much more than a simple list of ISO/IEC 27001 controls. It shows why each control matters to the organisation and how it supports information security.
Step 3: Align ISO/IEC 27001 Controls With Your Business Operations
Choosing controls for your Statement of Applicability (SoA) should make sense for the way your organisation works. Think about your offices, employees, technology, suppliers and information, as these factors help determine which security controls your organisation needs. An ISO 27001 implementation consultant can help align Annex A controls with your actual business environment .
Example: A Cloud-Based IT Company
A software company has a fully remote workforce. Its employees work from different locations and use both company-managed and personal devices to access business systems. In this situation, the organisation may need to consider controls such as:
- Access control management – Annex A 5.15
- Information security for the use of cloud services – Annex A 5.23
- Endpoint device security – Annex A 8.1
Physical visitor controls may be less important than controls that protect remote access, cloud platforms and employee devices.
This is why the Statement of Applicability (SoA) must reflect the organisation's actual working environment. A control that looks useful on paper may not have much value if it does not address a real business risk.
Step 4: Document Why Each Control Applies
Selecting a control is only one part of preparing an effective SoA. You also need to explain why the control is applicable. The reason should connect the control to a business risk, legal requirement, contractual obligation or another information security need.
Example: A Financial Services Company
Suppose a financial services company stores sensitive customer information on cloud platforms. One of its key risks is unauthorised access to this information.
The organisation may select:
Access control management – Annex A 5.15
The SoA could explain that the control is required to reduce the risk of unauthorised access to sensitive financial information.
The company may already have measures such as:
- Multi-factor authentication (MFA)
- Role-based access
- Access approval procedures
- Regular access reviews
The SoA can record the implementation status of these measures.
This makes the decision easier for an auditor to understand. Instead of simply seeing a control marked as "applicable", the auditor can see why it was selected and how the organisation has addressed it.
How to Justify Applicable and Excluded Controls?
One of the most important parts of an SoA is the reasoning behind control decisions. An organisation should be able to explain both why a control is needed and why a particular control is not applicable, where a control is excluded from the SoA.
1. Justifying Applicable Controls
For an applicable control, connect it to the risk or requirement that makes it necessary. For example, a fintech company may identify a risk of sensitive information being exposed during transmission or storage.
It may therefore select Cryptography – Annex A 8.24.
The SoA can explain that the control helps protect sensitive information and supports the organisation's security and contractual requirements.
2. Justifying Excluded Controls
Excluding a control does not mean simply writing "not applicable". There should be a clear reason for the decision. For example, a cloud-only fintech company may not use physical storage media as part of its normal operations. Certain physical media-related controls may therefore have limited applicability.
3. Avoiding Unexplained Exclusions
An unexplained exclusion can raise questions during an audit. If a control is not applicable, the organisation should be able to show why. A strong SoA makes the decision easy to follow:
Risk identified → Control assessed → Decision made → Reason documented
ISO/IEC 27001 Control Applicability Across Different Industries
The controls included in an SoA will differ from one organisation to another. There is no universal list that every business must apply in exactly the same way. The following examples show how business activities and risks can influence control selection.
Industry Examples of Applicable Controls Possible Areas of Limited Applicability Main Reason for Selection
Healthcare Endpoint device security (A.8.1), Access control management (A.5.15), Supplier relationships (A.5.19), Information backup (A.8.13) Some physical controls may depend on the organisation's facilities and operating model Patient information, privacy requirements and connected systems
Financial Services / Fintech Cryptography (A.8.24), Secure development lifecycle (A.8.25), Logging (A.8.15), Monitoring activities (A.8.16), Supplier relationships (A.5.19) Some physical media controls may have limited relevance in cloud-only environments Customer data, fraud risks and payment-related obligations
Cloud IT / SaaS Cloud services (A.5.23), Change management (A.8.32), Secure development lifecycle (A.8.25), Network security (A.8.20) Some physical site controls may depend on whether infrastructure is owned or managed by a cloud provider Cloud infrastructure, remote access and software deployment
Manufacturing / Industrial Physical security perimeters (A.7.1), ICT readiness for business continuity (A.5.30), Network segregation (A.8.22), Access rights (A.5.18) Some cloud-related controls may have a different level of relevance in on-premise environments Plant operations, operational technology and critical assets
How Should You Maintain an ISO/IEC 27001 Statement of Applicability?
An Statement of Applicability (SoA) should not be created for the certification audit and then forgotten. Your business will change. New software may be introduced. Employees may start working remotely. A new supplier may gain access to important information. Regulations may also change.
Each of these events can affect your information security risks. The SoA should therefore be reviewed whenever there is a meaningful change that could affect the ISMS or its controls.
Review Your Statement of Applicability (SoA) When:
- A new information security risk is identified.
- New systems, applications or technologies are introduced.
- A new supplier receives access to important information or systems.
- A security incident reveals a weakness.
- Laws, regulations or contractual requirements change.
- Business processes or organisational structures change.
- The scope of the ISMS changes.
- Internal audits identify gaps or changes that require attention.
- Risk assessments lead to different control requirements.
An organisation may also establish a planned periodic review as part of its ISMS processes. The important point is that the SoA should remain current and consistent with the organisation's risk environment.
Why Internal Audits Matter for the Statement of Applicability (SoA)?
Internal audits provide a useful checkpoint for reviewing your SoA. They can help answer three simple questions:
- Are the controls still applicable?
- Are the controls actually implemented?
- Are they still helping manage the identified risks?
If the answer to any of these questions’ changes, the organisation may need to update its risk assessment, controls or SoA. This keeps the document connected to the real ISMS rather than turning it into a file that is opened only when an auditor arrives.
What Makes a Good ISO 27001 Statement of Applicability (SoA)?
A useful SoA should be clear enough for someone to understand without needing a long explanation from the person who created it. At a minimum, it should clearly show:
- Which controls are applicable?
- Which necessary controls have been included?
- Which controls are not applicable where justified?
- Why controls have been selected.
- Why exclusions have been made.
- The current implementation status of applicable controls.
The SoA should also remain consistent with the organisation's risk assessment, risk treatment plan and ISMS scope. When these documents tell the same story, managing the ISMS becomes much easier.
Why the ISO/IEC 27001 Statement of Applicability Matters?
The Statement of Applicability brings several important ISMS decisions together in one place.
First, the organisation identifies its information security risks. It then decides how those risks should be treated. Relevant controls are selected and the reasons behind those decisions are documented. The result is more than a compliance document.
A well-prepared SoA shows how an organisation has connected its risks, security controls and business needs. It also gives auditors a clear picture of the organisation's approach to information security.
Whether you are preparing an SoA for the first time, updating an existing ISMS or getting ready for an ISO/IEC 27001 audit, the process does not have to become complicated.
MSCi can help you assess your information security risks, identify suitable controls and prepare the documentation needed for your ISO/IEC 27001 journey. With decades of experience in management system consultancy, our ISO 27001 consultants in India can help you build an ISMS that works in practice rather than one that simply looks good on paper. Get in touch with MSCi to discuss your ISO/IEC 27001 requirements. We also provide our ISO 27001 certification consultancy services in the USA and across 30+ countries globally.
FAQs About the ISO/IEC 27001 Statement of Applicability
Q1. What is a Statement of Applicability (SoA) in ISO 27001?
A Statement of Applicability is a required document within an ISO/IEC 27001 ISMS. It records the necessary information security controls; explains why they are applicable and documents the justification for excluding controls that are not applicable.
Q2. Is the Statement of Applicability mandatory for ISO 27001 certification?
Yes. ISO/IEC 27001 requires an organisation to produce a Statement of Applicability as part of its risk treatment process. Certification auditors may review it to understand how the organisation selected and addressed its information security controls.
Q3. What does an ISO/IEC 27001 SoA include?
Statement of Applicability (SoA) normally identifies the necessary controls, explains their applicability and provides the justification for including or excluding controls. It should also indicate the implementation status of applicable controls.
Q4. How often should the ISO/IEC 27001 Statement of Applicability be reviewed?
ISO/IEC 27001 does not prescribe a simple "once every year" rule for reviewing the SoA. Instead, the organisation should keep it up to date as part of its ISMS. A review should be considered when there are significant changes to risks, technology, suppliers, processes, regulations or the ISMS scope.
Q5. Why is the Statement of Applicability important?
The SoA connects an organisation's information security risks with the controls used to manage them. It helps management understand control decisions and gives auditors a clear view of how the organisation has treated its information security risks.
Q6. Can an organisation exclude ISO/IEC 27001 Annex A controls?
Yes, where a control is determined not to be necessary based on the organisation's risk treatment and other applicable requirements. The reason for the exclusion should be clearly documented in the SoA.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- How to Fix the most Common Mistakes in ISO Compliance
Do you think ISO certifications guarantee long-term compliance? Think again.
June 23, 2025
- India’s New Data Law: Is Your Business Ready?
India's Digital Personal Data Protection Act changed what organisations here have to prove about the personal data they hold. What the Act requires, and how a management system answers it.
April 5, 2025
- How does an ISO 27001 Consultant help IT Companies to understand Data Security Protocols
As of February 2025, approximately 5.56 billion people worldwide are internet users, representing 67.9% of the global population.
March 27, 2025
