Statement of Applicability
The Statement of Applicability (SoA) is a mandatory documented information requirement of ISO/IEC 27001, specified in Clause 6.1.3(d) as part of the information security risk treatment process. It links the organization's risk assessment and treatment decisions to the reference controls in Annex A,… The Statement of Applicability (SoA) is a mandatory documented information requirement of ISO/IEC 27001, specified in Clause 6.1.3(d) as part of the information security risk treatment process. It links the organization's risk assessment and treatment decisions to the reference controls in Annex A, which in the 2022 edition contains 93 controls grouped into four themes: organizational, people, physical and technological. After identifying risks and selecting treatment options, the organization determines all controls needed to implement those options. It then compares them with Annex A to make sure no necessary control has been overlooked. The SoA must contain four elements: the necessary controls (whether from Annex A or other sources), the justification for including them, whether each control is implemented or not, and the justification for excluding any Annex A control. Justifications usually come from risk assessment results, legal, regulatory or contractual requirements, business needs, or best practice. Exclusions are acceptable only when properly justified, for example where no relevant risk exists or an activity is outside the ISMS scope. The SoA is a living document that must be controlled, approved by management, kept current and updated when risks, scope or controls change. Many organizations also record the version, owner, implementation status and references to policies or procedures for each control. From a Lead Auditor's perspective, the SoA is a key audit document and a roadmap for the audit. During Stage 1, the auditor checks that it exists, is complete and is consistent with the scope and risk treatment plan. During Stage 2, the auditor samples controls declared as implemented and seeks objective evidence of their effectiveness, while challenging weak exclusion justifications. Inconsistencies between the SoA, risk assessment and actual practice are common sources of nonconformities. The certificate issued typically references the SoA version, which demonstrates its central role in certification and in providing assurance to interested parties.
Statement of Applicability (SoA) in ISO/IEC 27001: A Complete Guide for Lead Auditors
Introduction
The Statement of Applicability (SoA) is one of the most important documents in an Information Security Management System (ISMS) built on ISO/IEC 27001. For an ISO 27001 Lead Auditor it is central to the audit. It connects the risk assessment, the risk treatment plan and the controls the organization has actually put in place. Exam questions about the SoA are common, and many candidates lose marks by misunderstanding its purpose and its link to Annex A.
1. What Is the Statement of Applicability?
The SoA is a mandatory documented statement required by Clause 6.1.3 d) of ISO/IEC 27001:2022. It lists the controls the organization considers necessary to treat its information security risks.
According to the standard, the SoA must contain:
• The necessary controls, whether taken from Annex A or from other sources.
• The justification for including each of those controls.
• Whether the necessary controls are implemented or not.
• The justification for excluding any Annex A controls.
In short, the SoA shows which controls apply, why they apply, whether they are in place, and why any Annex A controls were left out.
Key facts about the SoA
• In ISO/IEC 27001:2022, Annex A contains 93 controls grouped into 4 themes:
- Organizational (37 controls)
- People (8 controls)
- Physical (14 controls)
- Technological (34 controls)
• The 2013 version had 114 controls in 14 domains. Exam questions may refer to either version, so check which one is meant.
• The SoA is a controlled document. It must be version-controlled, approved, reviewed and kept up to date.
• Annex A is a reference list. Organizations must compare their selected controls against it so that no necessary control is overlooked. It is not a mandatory checklist that must be implemented in full.
2. Why Is the Statement of Applicability Important?
• It links risk to controls. The SoA shows the result of risk treatment and demonstrates that controls were chosen because of identified risks, not arbitrarily.
• It prevents omissions. Comparing selected controls with Annex A makes sure no necessary control has been missed. Clause 6.1.3 c) requires this comparison.
• It defines the certification boundary. Certificates usually cite the SoA version, for example "in accordance with Statement of Applicability version 3.1". This tells customers and stakeholders which controls are covered.
• It is the auditor's roadmap. Auditors use the SoA to plan the audit, choose controls to sample and verify implementation.
• It supports accountability and transparency. Justifications for inclusion and exclusion show that decisions were deliberate and risk-based.
• It supports legal, regulatory and contractual compliance. Controls can be justified by legal, regulatory or contractual obligations as well as by risk.
• It supports continual improvement. As risks change, the SoA is updated to show new or revised controls.
3. How Does the Statement of Applicability Work?
Step 1: Context and scope (Clauses 4.1 to 4.3)
The organization understands its internal and external issues and the needs of interested parties, then defines the ISMS scope. The SoA applies only within this scope.
Step 2: Risk assessment (Clause 6.1.2)
Information security risks are identified, analysed and evaluated using a defined methodology.
Step 3: Risk treatment (Clause 6.1.3)
The organization:
a) selects risk treatment options (modify, retain, avoid, share);
b) determines all controls needed to implement those options;
c) compares those controls with Annex A to verify that no necessary controls are omitted;
d) produces the Statement of Applicability;
e) formulates the risk treatment plan;
f) obtains risk owners' approval of the plan and acceptance of residual risks.
Step 4: Document the SoA
A typical SoA is a table with columns such as:
• Control reference (e.g., 5.15 Access control)
• Control title and description
• Applicable: Yes or No
• Justification for inclusion (e.g., risk ID R-012, legal requirement, contractual obligation, business requirement)
• Implementation status (implemented, partially implemented, planned, not implemented)
• Justification for exclusion, where not applicable
• Reference to supporting policies or procedures
• Control owner
Step 5: Approve, maintain and review
Management approves the SoA. It is reviewed after changes such as new risks, new technology, organizational changes, incidents, audit findings or management review outcomes.
Important nuances
• Exclusions must be justified. A valid justification is, for example, "The organization does not develop software, so secure development controls are not applicable." Weak justifications such as "too expensive" or "we did not have time" are not acceptable when a risk exists.
• Additional controls can be added. Organizations may include controls from other frameworks (ISO/IEC 27017, NIST, sector regulations) or their own custom controls.
• Implementation status must be stated. A control can be applicable but not yet implemented. Its implementation then appears in the risk treatment plan.
• Retained documented information. The SoA is mandatory documented information and must be controlled under Clause 7.5.
4. SoA versus the Risk Treatment Plan
Candidates often confuse these two documents:
• SoA answers WHAT controls are applicable, WHY, and whether they are implemented. It covers all Annex A controls plus any additional ones.
• Risk Treatment Plan (RTP) answers HOW, WHO and WHEN: the actions, responsibilities, resources and timelines for treating risks.
Both are required by Clause 6.1.3. The SoA is d) and the RTP is e).
5. What Auditors Look For
During a Stage 1 or Stage 2 audit, a lead auditor checks that:
• the SoA exists, is approved and is version-controlled;
• every Annex A control is addressed (included or excluded);
• justifications for inclusion trace back to the risk assessment or to legal, contractual or business requirements;
• justifications for exclusion are valid and consistent with the scope and risks;
• the implementation status matches reality, checked by sampling evidence;
• the SoA is consistent with the risk treatment plan and the scope statement;
• the SoA has been updated after relevant changes.
Typical nonconformities
• No SoA, or an SoA that omits Annex A controls: usually a major nonconformity, since it is a mandatory requirement.
• Exclusions with no justification, or invalid ones.
• Controls marked "implemented" with no evidence of implementation.
• An SoA not aligned with the risk assessment, such as controls excluded despite identified risks.
• An outdated SoA that does not reflect current scope, technology or risks.
• An SoA that is not approved or not under document control.
6. Exam Tips: Answering Questions on Statement of Applicability
Tip 1: Know the clause. The SoA is required by Clause 6.1.3 d). If a question asks where the SoA requirement sits, the answer is information security risk treatment, Clause 6.1.3.
Tip 2: Memorize the required content. Necessary controls, justification for inclusion, implementation status, and justification for exclusion of Annex A controls. Remember the phrase "include, justify, status, exclude".
Tip 3: Annex A is not mandatory to implement in full. Watch for distractors such as "all 93 Annex A controls must be implemented". This is false. Controls are selected based on risk, but every Annex A control must be considered and addressed in the SoA.
Tip 4: Exclusions need valid justification. In scenario questions, ask whether the exclusion is consistent with the scope and the risk assessment. If an organization excludes a control while related risks exist, that is a nonconformity.
Tip 5: Distinguish the SoA from the risk treatment plan. If a question mentions timelines, responsibilities or resources, it is about the RTP. If it mentions applicability, justification or implementation status, it is about the SoA.
Tip 6: Remember the link to certification. Certificates reference the SoA version, so the SoA defines which controls are covered by certification.
Tip 7: Classify nonconformities correctly. A missing SoA is a major nonconformity. A single poorly justified exclusion or one outdated entry is often minor, unless it shows a systemic failure.
Tip 8: Think like an auditor in scenario questions. Ask yourself:
• Does the SoA trace to the risk assessment?
• Is the implementation status supported by evidence?
• Is the SoA approved, current and controlled?
• Is it consistent with the scope?
Tip 9: Additional controls are allowed. Organizations can include controls beyond Annex A. A statement like "the SoA may contain only Annex A controls" is incorrect.
Tip 10: Know the 2022 changes. 93 controls in 4 themes; 11 new controls (e.g., 5.7 Threat intelligence, 5.23 Information security for use of cloud services, 8.9 Configuration management, 8.10 Information deletion, 8.11 Data masking, 8.12 Data leakage prevention, 8.16 Monitoring activities, 8.23 Web filtering, 8.28 Secure coding, 7.4 Physical security monitoring, 5.30 ICT readiness for business continuity). The 2022 version also added attributes (control type, security properties, cybersecurity concepts, operational capabilities, security domains) described in ISO/IEC 27002:2022.
Tip 11: Use precise terminology. In essay or open-ended answers, use terms such as mandatory documented information, risk-based selection, justification, traceability, implementation status and Annex A comparison.
Tip 12: Structure scenario answers clearly. State the requirement (clause), describe what you observed (evidence), identify the gap and propose the finding classification. For example: "Clause 6.1.3 d) requires justification for exclusions. Control 8.28 Secure coding was excluded without justification although the organization develops software internally. This is a nonconformity."
7. Sample Exam Questions
Q1: Which clause requires the organization to produce a Statement of Applicability?
Answer: Clause 6.1.3 d), Information security risk treatment.
Q2: An organization excluded control 7.4 Physical security monitoring and stated "budget constraints" as the reason, although the risk assessment identified unauthorized physical access as a high risk. What should the auditor conclude?
Answer: The exclusion is not validly justified and is inconsistent with the risk assessment. This is a nonconformity against Clause 6.1.3. Budget may affect the treatment approach, but a risk cannot be ignored without formal risk acceptance by the risk owner.
Q3: True or false: The SoA must list only implemented controls.
Answer: False. It must list all necessary controls and their implementation status, including those not yet implemented.
Q4: What is the difference between the SoA and the risk treatment plan?
Answer: The SoA identifies applicable controls, justifications and implementation status. The RTP defines how, by whom and when risk treatment actions will be carried out.
8. Summary
The Statement of Applicability is the link between an organization's risk assessment and its implemented controls. It is mandatory under Clause 6.1.3 d). It must address every Annex A control, justify each inclusion and exclusion, and state implementation status. For the exam, remember: risk-based selection, full Annex A comparison, valid justifications, traceability, document control, and the distinction from the risk treatment plan. If you approach SoA questions from an auditor's evidence-based point of view, you will be well prepared.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!